Listing Thumbnail

    Fortinet Managed Rules for AWS WAF Classic - Complete OWASP Top 10

     Info
    Deployed on AWS
    The Complete OWASP Top 10 Ruleset delivers comprehensive web application protection to protect against the OWASP Top 10 web application threats
    4.1

    Overview

    Play video

    This listing is for AWS WAF Classic only. Fortinets WAF rulesets are based on the FortiWeb web application firewall security service signatures, and are updated on a regular basis to include the latest threat information from FortiGuard Labs. The Complete OWASP Top 10 Ruleset combines Fortinets other AWS WAF rulesets into one comprehensive package to protect web applications and to cover the entire list of OWASP Top 10 web application threats. Included are the SQLi/XSS, General and Known Exploits, and Malicious Bots rulesets.

    For extended web application firewall features such as detailed trigger/event visibility, custom whitelisting and dedicated tools to fine tune and manage detections as well as detailed event visibility and AI-based behavioral attack detection you can try the FortiWeb Cloud Product: https://aws.amazon.com/marketplace/pp/prodview-rbkvcwsvcpgsk?sr=0-1&ref_=beagle&applicationId=AWSMPContessa 

    For more information on AWS WAF Classic, you can find documentation here: https://docs.aws.amazon.com/waf/latest/developerguide/classic-waf-chapter.html 

    Pricing information: Pricing consists of two dimensions:

    • $30 per month for each web ACL using the Fortinet Managed Rules, per region
    • $1.8 per million requests in each region

    Pricing examples:

    pricing example: 2x web acl in a single region (ie us-east-1)

    Managed rule group charges = $60.00 (2x units for 2x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $78.00/month

    pricing example: 2x web acl in two regions (ie us-east-1 & us-east-2)

    Managed rule group charges = $60.00 (2x units for 2x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $78.00/month

    pricing example: 3x web acl in two regions and one using a CloudFront (ie us-east-1, us-east-2, CloudFront)

    Managed rule group charges = $90.00 (3x units for 3x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $108.00/month

    Highlights

    • Complete set of all rules offered by Fortinet
    • Can be configured to log, alert and/or block
    • Regular updates from FortiGuard Labs

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet Managed Rules for AWS WAF Classic - Complete OWASP Top 10

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $30.00
    Charge per million requests in each available region
    $1.80

    AI Insights

     Info

    Dimensions summary

    This listing charges you two ways that work together. First, you pay a recurring monthly fee for each AWS region where you run the rules. That charge is pro-rated by the hour, so partial months cost less. Second, you pay based on usage, measured per million requests processed in each region. Your total cost combines both parts and grows as you add regions or handle more traffic. The rules pair with AWS WAF Classic to protect against OWASP Top 10 web application threats.

    Top-of-mind questions for buyers

    A request is a single web application call that AWS WAF Classic inspects using the Fortinet rules. The charge accrues per million inspected requests in each region. High-traffic applications generate more requests, so this part of your bill scales with the volume of traffic reaching your protected applications.
    Both charges apply at the same time and appear together. The monthly per-region fee is fixed and pro-rated by the hour. The per-million-request charge grows with traffic. For high-traffic applications, request volume tends to dominate. For low-traffic sites, the monthly fee is the larger part.
    Both charges apply separately in each region. You pay one monthly fee per region and one per-million-request charge per region. Adding a region adds a new monthly fee plus request charges for traffic in that region. Total cost rises with each region you add.
    www.fortinet.com
    Helpful?

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    OWASP Top 10 Coverage
    Comprehensive protection against the complete OWASP Top 10 web application threats including SQLi/XSS, general exploits, known exploits, and malicious bots
    Threat Signature Updates
    Regular updates from FortiGuard Labs with latest threat information and security signatures
    Rule-Based Detection Actions
    Configurable detection modes supporting logging, alerting, and blocking capabilities
    Web Application Firewall Signatures
    Security signatures derived from FortiWeb web application firewall service
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Managed rules designed to mitigate and minimize all vulnerabilities on OWASP Top 10 Web Application Threats list
    Code Injection Prevention
    Targeted rules for common code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Detection
    Managed rules targeting known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Rulesets for identifying and blocking malicious bot traffic
    OWASP Top 10 Attack Protection
    Protects against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation as defined in OWASP Top 10.
    Managed Rule Updates
    Rules are written, managed, and regularly updated by security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules are designed to be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Rule Management by Security Experts
    Rulesets are continuously monitored and maintained by F5's security experts to address emerging threat vectors.
    Rapid Deployment Capability
    Rules can be attached to AWS WAF instances within minutes following a three-step deployment process.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    41 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    34%
    54%
    7%
    5%
    0%
    14 AWS reviews
    |
    27 external reviews
    External reviews are from G2  and PeerSpot .
    Cristíano D.

    Custom rules that facilitate management and give full control of processes

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    Because it allows creating custom rules and having better control of all processes. This makes it easier to manage the platform. It is a great differentiator of the product.
    What do you dislike about the product?
    It allows improving performance and minimizing impact, depending on the platform being used. However, it has a significant price and the return on investment of the product, the support
    What problems is the product solving and how is that benefiting you?
    With AI, we can solve various problems and, thanks to its support for integrations, it facilitates the optimization of all the integrations we need to implement for what is to come.
    Ranjeet T.

    Efficient Security Management with Easy Setup

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    I like how Fortinet Managed Rules for AWS WAF helps me manage both my internal and public domain requests. It effectively stops unauthorized access and ensures only genuine requests reach the server. I appreciate its capability to monitor my payment system and protect my entire subdomains. The setup and configuration process is very easy, and I find the log analysis feature quite useful.
    What do you dislike about the product?
    Nothing
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to manage internal and public domain requests, stop unauthorized access, and protect subdomains. It monitors my payment system effectively. The setup and configuration are also very easy, making log analysis straightforward.
    Milan D.

    Strong, Low-Maintenance Protection for AWS Workloads

    Reviewed on Aug 30, 2026
    Review provided by G2
    What do you like best about the product?
    The biggest advantage is the combination of strong security coverage and ease of management. The preconfigured rules make it much easier to protect AWS workloads against common threats such as SQL injection, XSS, and known exploits without having to build and maintain everything from scratch. The integration with AWS WAF is straightforward, and the managed updates help keep protection aligned with new threats. Overall, it saves time while providing an additional layer of security for web applications and APIs.
    What do you dislike about the product?
    The main downside is that the rules can sometimes require tuning to avoid false positives, especially for applications with custom traffic patterns. It would also be helpful to have more detailed documentation and clearer guidance for fine-tuning rules for specific workloads. Pricing can also become a consideration as the number of protected resources grows.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect our web applications and APIs from common attacks without having to create and maintain WAF rules ourselves. It provides consistent security coverage against threats like SQL injection, XSS, and other known exploits while reducing the time we spend on security rule management. This lets our team focus more on application and infrastructure work while still maintaining a strong security posture.
    Subigya G.

    OP: AWS WAF | Know the real power

    Reviewed on Aug 30, 2026
    Review provided by G2
    What do you like best about the product?
    The main reason we use Fortinet's managed rules is how easily they plug into our existing AWS setup to cover core security risks like SQL injection and cross-site scripting. Building and updating custom WAF rules by hand takes way too much time, so having Fortinet's team handle the threat intelligence and signature updates behind the scenes saves a massive headache. It gives our public-facing APIs a solid baseline defense right out of the box without forcing us to spend hours tweaking custom logic every time a new vulnerability drops.
    What do you dislike about the product?
    The biggest issue is dealing with false positives when you first turn the rules on. If you jump straight to blocking mode, legitimate traffic or unusual API payloads will definitely get caught and blocked. You end up having to run everything in Count mode for a while, dig through CloudWatch logs, and set up override rules to fix the false alarms before you can actually enforce blocks. Another downside is the lack of visibility into the actual underlying rule logic. Because the signatures are proprietary black boxes, troubleshooting why a specific request got flagged takes more time than it should. On top of that, cost can accumulate quickly if you are running these rules across high-traffic Application Load Balancers, since AWS charges for rule evaluations alongside the subscription cost.
    What problems is the product solving and how is that benefiting you?
    It solves the hassle of keeping web endpoints and open APIs safe from bad traffic, web scrapers, and common attack vectors without forcing us to build or patch security rules by hand. Because Fortinet handles threat signatures automatically, new vulnerabilities are covered right away, saving us from constantly checking security advisories just to tweak firewall settings. The biggest win for us is cut-down workload. We get solid, hands-off security built right into our cloud setup, which lets us put our time toward building features instead of sifting through network logs to craft custom filter rules. It simply gives us a dependable safety net for our web apps without adding extra day-to-day maintenance.
    敏熙 .

    FortiGuard-Powered Managed Rules That Stop SQLi and XSS with Zero Added Latency

    Reviewed on Aug 29, 2026
    Review provided by G2
    What do you like best about the product?
    The automated threat intelligence powered by FortiGuard Labs is the biggest win for our team. We use the Fortinet OWASP Top 10 and Known Bad Inputs/Bots Rulesets on our public-facing ALBs. Instead of constantly monitoring new CVEs and manually writing complex regex rules in-house, the rule sets are updated automatically in the background. It effectively neutralizes SQLi, XSS, and automated vulnerability scanner probes without adding latency to our applications.
    What do you dislike about the product?
    While the protection is robust, diagnosing occasional false positives can be challenging due to the 'black-box' nature of managed rules. When a legitimate multi-step API request containing complex JSON payloads gets blocked, AWS WAF logs show the rule group and rule ID, but not the exact string or parameter that triggered the match. We have to spend extra time cross-referencing logs and writing custom label-based exception rules. It would be a huge improvement if Fortinet/AWS could provide more granular trigger explanations or context directly in the logs to speed up root-cause analysis.
    What problems is the product solving and how is that benefiting you?
    Before implementing Fortinet Managed Rules, our security team struggled with manually tracking new CVEs and writing custom regex rules for our AWS WAF, which consumed 6–8 engineering hours each week and left a window of vulnerability during zero-day events. By switching to Fortinet Managed Rules, we now have automated, continuously updated threat intelligence applied directly to our CloudFront and ALB distributions. This has eliminated the operational overhead of rule maintenance, cut our vulnerability triage time by roughly 70%, and ensured our public-facing APIs are consistently shielded against OWASP Top 10 threats and automated exploit probes.
    View all reviews