Listing Thumbnail

    Fortinet Managed Rules for AWS WAF - Complete OWASP Top 10

     Info
    Deployed on AWS
    The Complete OWASP Top 10 Ruleset delivers comprehensive web application protection to protect against the OWASP Top 10 web application threats
    4.1

    Overview

    This product is not for AWS WAF Classic. Fortinets WAF rulesets are based on the FortiWeb web application firewall security service signatures, and are updated on a regular basis to include the latest threat information from FortiGuard Labs. The Complete OWASP Top 10 Ruleset provides a comprehensive package for web application protection offered by Fortinet to help cover the entire list of OWASP Top 10 web application threats. Includes protection for SQL Injection, Cross Site Scripting, General and Known Exploits, Malicious Bots and Common Vulnerabilities and Exposures (CVE).

    For extended web application firewall features such as protection for zero attacks using AI-based behavioral attack detection, detailed attack log visibility, custom whitelisting and dedicated tools to fine tune and manage detections you can try Fortinet FortiWeb Cloud WAF-as-a-Service, a SaaS service that requires no hardware or software deployed https://aws.amazon.com/marketplace/pp/Fortinet-Inc-Fortinet-FortiWeb-Cloud-WAF-as-a-Serv/B07PXMWJT1 .

    Fortinet Managed Rules for AWS WAF Video Tutorial https://pages.awscloud.com/mp-kickstart-fortinet.html?&trk=ta_a134p000003yoFjAAI&trkCampaign=AWSMP_pap_x_x_content-hub-resources&sc_channel=ta&sc_campaign=ta_awsmp_card&sc_outcome=Marketplace&sc_geo=mult 

    Pricing information: Pricing consists of two dimensions:

    • $30 per month for each web ACL using the Fortinet Managed Rules, per region
    • $1.8 per million requests in each region

    Pricing examples:

    pricing example: 2x web acl in a single region (ie us-east-1)

    Managed rule group charges = $60.00 (2x units for 2x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $78.00/month

    pricing example: 2x web acl in two regions (ie us-east-1 & us-east-2)

    Managed rule group charges = $60.00 (2x units for 2x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $78.00/month

    pricing example: 3x web acl in two regions and one using a CloudFront (ie us-east-1, us-east-2, CloudFront)

    Managed rule group charges = $90.00 (3x units for 3x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $108.00/month

    Highlights

    • Complete set to help protect against the OWASP Top 10
    • Can be configured to log, alert and/or block
    • Regular updates from FortiGuard Labs

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet Managed Rules for AWS WAF - Complete OWASP Top 10

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $30.00
    Charge per million requests in each available region
    $1.80

    AI Insights

     Info

    Dimensions summary

    You pay for this rule set through two usage-based charges that apply together. The first is a monthly charge in each region where you deploy, pro-rated by the hour. This covers keeping the managed rule group active in that region. The second is a charge per million web requests inspected in each region. This scales with the traffic your protected applications receive. You deploy separately in each AWS region that needs coverage, so both charges repeat per region. There is no upfront commitment; costs track your actual regions and request volume.

    Top-of-mind questions for buyers

    Version choice does not change how you are billed. Both charges still apply: the monthly per-region charge and the per-million-requests charge. Static versions receive no new signatures until you switch versions manually. Each static version is supported for up to six months before revocation and a 30-day grace period.
    A request is a single web request that the managed rule group inspects in a given region. Requests are counted per region and billed per million. Deploying to protect a global content delivery service applies globally; otherwise you count requests separately in each region where you add the rule group.
    Both charges apply together on the same invoice. The monthly per-region charge is fixed for each region where you deploy. The per-million-requests charge grows with your traffic. For applications with heavy request volume, the request charge usually dominates. For low-traffic applications spread across many regions, the monthly charges add up faster.
    community.fortinet.com
    Helpful?

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    OWASP Top 10 Protection Coverage
    Comprehensive ruleset protecting against all OWASP Top 10 web application threats including SQL Injection, Cross Site Scripting, General and Known Exploits, Malicious Bots, and Common Vulnerabilities and Exposures (CVE)
    Threat Intelligence Updates
    Regular updates from FortiGuard Labs to include latest threat information and security signatures
    Configurable Response Actions
    Rules can be configured to log, alert, and/or block detected threats
    FortiWeb Security Signatures
    Rulesets based on FortiWeb web application firewall security service signatures
    AWS WAF Integration
    Managed rule group compatible with AWS WAF for web application firewall deployment across multiple web ACLs and regions
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Comprehensive protection against all OWASP Top 10 Web Application Threats
    Code Injection Prevention
    Managed rules targeting code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Protection
    Dedicated rules for known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Malicious Bots rulesets included for bot-based threat mitigation
    OWASP Top 10 Attack Protection
    Provides protection against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation.
    Managed Rule Updates
    Rules are written, managed and regularly updated by F5's security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules can be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Automated Threat Detection
    Utilizes security expertise to identify and mitigate vulnerabilities that are part of the OWASP Top 10 attack vectors.
    Pay-as-You-Go Licensing Model
    Rules are licensed on a consumption-based pricing structure where usage determines costs.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    73 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    31%
    58%
    11%
    0%
    0%
    15 AWS reviews
    |
    58 external reviews
    External reviews are from G2  and PeerSpot .
    Prateek M.

    Easy, Reliable AWS WAF Protection with Fortinet Managed Rules

    Reviewed on Aug 24, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Fortinet Managed Rules for AWS WAF is how easy it is to strengthen application security without having to build and maintain every rule manually. The managed rules provide broad coverage against common web application threats, are regularly updated to address emerging vulnerabilities, and integrate smoothly with AWS WAF. This saves time for security teams while providing reliable protection and reducing the effort required for ongoing rule management.
    What do you dislike about the product?
    One area that could be improved is the cost, especially for larger environments with multiple applications and AWS accounts. Some rules may also require tuning to reduce false positives and fit specific application requirements. More detailed documentation, clearer rule explanations, and easier troubleshooting would make it simpler to fine-tune the rules and understand why specific requests are being blocked.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect our web applications from common threats such as SQL injection, cross-site scripting, bots, and other malicious traffic without having to create and maintain all the security rules ourselves. The managed rules reduce the operational effort required for WAF management, improve our overall security posture, and help us respond to emerging threats more quickly. This allows our security team to focus more on higher-value security initiatives while maintaining consistent protection across AWS-hosted applications.
    shubham t.

    Robust Security with Easy Integration

    Reviewed on Aug 22, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules for AWS WAF enhances firewall protection, blocking threats before they reach the application and defending against common web attacks and known CVEs. I find the integration with AWS SNS really useful because it provides real-time updates to admins, letting them quickly respond to updates. Integrating Fortinet with AWS WAF is super easy, and the documentation is helpful.
    What do you dislike about the product?
    I think they have everything that is needed. I dont have any dislike points to be mentioned
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to enhance firewall protection, blocking threats and common web attacks before they reach my application. It provides robust safety against AI-driven threats, offers seamless AWS integration, and sends real-time updates for immediate action.
    Emmanuel N.

    Strong AWS Protection for EC2 and S3 with Proactive Security Controls

    Reviewed on Aug 21, 2026
    Review provided by G2
    What do you like best about the product?
    I like using it as one of the AWS services to protect what I run on AWS, such as applications deployed on EC2 and assets stored in an S3 bucket. It also helps me set up security measures in advance, before requests reach my apps.
    What do you dislike about the product?
    I’d say there’s something I dislike: if I had to, I would disconnect myself from the service and let requests hit my app through AWS WAF as a proxy for protection.
    What problems is the product solving and how is that benefiting you?
    This AWS WAF service helps me improve my cybersecurity measures by reducing suspicious requests to my applications hosted on AWS S3 bucket, where I keep sensitive assets.
    Accounting

    Out-of-the-Box OWASP Top 10 & Bot Coverage With Self-Updating Rules

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    Honestly the best part is not having to write my own rules — it just covers the OWASP Top 10 and bots out of the box, and the rules update themselves.
    What do you dislike about the product?
    Mainly the UI. Policy management isn't the most intuitive, and the reporting side could be a lot better.The dashboard could be simplerBit of a learning curve at the start too.
    What problems is the product solving and how is that benefiting you?
    Mainly blocking common web/API attacks like SQL injection and bots. The big win is I'm not writing or maintaining custom rules — it updates itself, scales automatically.
    Mohamed J.

    Managed Rules Feel Too Broad—False Positives and Limited Rule-Trigger Visibility

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best is the combination of **strong, continuously updated threat protection and ease of management**. Fortinet’s managed rules add protection against common web and API attacks, including OWASP Top 10 threats, SQL injection, XSS, known exploits, CVEs, and malicious bots, while the rules are regularly updated through FortiGuard Labs. This reduces the amount of time and effort required to maintain WAF rules manually.
    What do you dislike about the product?
    The main drawback is that managed rules can sometimes be **too broad or generate false positives**, requiring additional tuning and exclusions for specific applications. It would also be helpful to have more granular visibility into why a particular rule triggered and simpler customization options without increasing the management overhead.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF help reduce the effort required to protect our web applications and APIs from common threats such as SQL injection, XSS, and known exploits. The continuously updated rules reduce manual rule maintenance, improve our security coverage, and help our team respond to emerging threats more quickly while saving time on WAF management.
    View all reviews