Listing Thumbnail

    Fortinet Managed Rules for AWS WAF - Complete OWASP Top 10

     Info
    Deployed on AWS
    The Complete OWASP Top 10 Ruleset delivers comprehensive web application protection to protect against the OWASP Top 10 web application threats
    4.1

    Overview

    This product is not for AWS WAF Classic. Fortinets WAF rulesets are based on the FortiWeb web application firewall security service signatures, and are updated on a regular basis to include the latest threat information from FortiGuard Labs. The Complete OWASP Top 10 Ruleset provides a comprehensive package for web application protection offered by Fortinet to help cover the entire list of OWASP Top 10 web application threats. Includes protection for SQL Injection, Cross Site Scripting, General and Known Exploits, Malicious Bots and Common Vulnerabilities and Exposures (CVE).

    For extended web application firewall features such as protection for zero attacks using AI-based behavioral attack detection, detailed attack log visibility, custom whitelisting and dedicated tools to fine tune and manage detections you can try Fortinet FortiWeb Cloud WAF-as-a-Service, a SaaS service that requires no hardware or software deployed https://aws.amazon.com/marketplace/pp/Fortinet-Inc-Fortinet-FortiWeb-Cloud-WAF-as-a-Serv/B07PXMWJT1 .

    Fortinet Managed Rules for AWS WAF Video Tutorial https://pages.awscloud.com/mp-kickstart-fortinet.html?&trk=ta_a134p000003yoFjAAI&trkCampaign=AWSMP_pap_x_x_content-hub-resources&sc_channel=ta&sc_campaign=ta_awsmp_card&sc_outcome=Marketplace&sc_geo=mult 

    Pricing information: Pricing consists of two dimensions:

    • $30 per month for each web ACL using the Fortinet Managed Rules, per region
    • $1.8 per million requests in each region

    Pricing examples:

    pricing example: 2x web acl in a single region (ie us-east-1)

    Managed rule group charges = $60.00 (2x units for 2x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $78.00/month

    pricing example: 2x web acl in two regions (ie us-east-1 & us-east-2)

    Managed rule group charges = $60.00 (2x units for 2x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $78.00/month

    pricing example: 3x web acl in two regions and one using a CloudFront (ie us-east-1, us-east-2, CloudFront)

    Managed rule group charges = $90.00 (3x units for 3x web ACLs) Managed rule group request charges = $1.80/million * 10 million = $18.00 Total AWS Marketplace charges = $108.00/month

    Highlights

    • Complete set to help protect against the OWASP Top 10
    • Can be configured to log, alert and/or block
    • Regular updates from FortiGuard Labs

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet Managed Rules for AWS WAF - Complete OWASP Top 10

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $30.00
    Charge per million requests in each available region
    $1.80

    AI Insights

     Info

    Dimensions summary

    You pay for this rule set through two usage-based charges that apply together. The first is a monthly charge in each region where you deploy, pro-rated by the hour. This covers keeping the managed rule group active in that region. The second is a charge per million web requests inspected in each region. This scales with the traffic your protected applications receive. You deploy separately in each AWS region that needs coverage, so both charges repeat per region. There is no upfront commitment; costs track your actual regions and request volume.

    Top-of-mind questions for buyers

    Version choice does not change how you are billed. Both charges still apply: the monthly per-region charge and the per-million-requests charge. Static versions receive no new signatures until you switch versions manually. Each static version is supported for up to six months before revocation and a 30-day grace period.
    A request is a single web request that the managed rule group inspects in a given region. Requests are counted per region and billed per million. Deploying to protect a global content delivery service applies globally; otherwise you count requests separately in each region where you add the rule group.
    Both charges apply together on the same invoice. The monthly per-region charge is fixed for each region where you deploy. The per-million-requests charge grows with your traffic. For applications with heavy request volume, the request charge usually dominates. For low-traffic applications spread across many regions, the monthly charges add up faster.
    community.fortinet.com
    Helpful?

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    OWASP Top 10 Protection Coverage
    Comprehensive ruleset protecting against all OWASP Top 10 web application threats including SQL Injection, Cross Site Scripting, General and Known Exploits, Malicious Bots, and Common Vulnerabilities and Exposures (CVE)
    Threat Intelligence Updates
    Regular updates based on latest threat information from FortiGuard Labs security research
    Configurable Response Actions
    Rules can be configured to log, alert, and/or block detected threats
    AWS WAF Integration
    Managed rule group compatible with AWS WAF for web application firewall deployment
    Multi-Region Support
    Deployable across multiple AWS regions with per-region configuration capabilities
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Managed rules designed to mitigate and minimize all vulnerabilities on OWASP Top 10 Web Application Threats list
    Code Injection Prevention
    Targeted rules for common code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Detection
    Managed rules targeting known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Rulesets for identifying and blocking malicious bot traffic
    OWASP Top 10 Attack Protection
    Protects against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation as defined in OWASP Top 10.
    Managed Rule Updates
    Rules are written, managed, and regularly updated by security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules are designed to be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Rule Management by Security Experts
    Rulesets are continuously monitored and maintained by F5's security experts to address emerging threat vectors.
    Rapid Deployment Capability
    Rules can be attached to AWS WAF instances within minutes following a three-step deployment process.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.1
    90 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    37%
    53%
    10%
    0%
    0%
    16 AWS reviews
    |
    74 external reviews
    External reviews are from G2  and PeerSpot .
    Mohammed R.

    Strong, Ready-to-Deploy Protection with Fortinet Managed Rules for AWS WAF

    Reviewed on Sep 20, 2026
    Review provided by G2
    What do you like best about the product?
    Fortinet Managed Rules for AWS WAF provides strong, ready-to-deploy protection against common web threats, helping us secure applications without the complexity of creating and managing custom WAF rules.
    What do you dislike about the product?
    One drawback of Fortinet Managed Rules for AWS WAF is that customization options can be somewhat limited for highly specific application requirements. In addition, troubleshooting false positives can occasionally require extra tuning and monitoring to ensure legitimate traffic is not blocked.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect web applications from common threats such as SQL injection, cross-site scripting (XSS), bots, and other malicious attacks without having to build and maintain complex security rules ourselves.
    Amrit P.

    Strong Web Attack Protection with Easy Deployment

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules offer strong protection against common web attacks without requiring me to build everything from scratch. They’re straightforward to deploy, and I can tune them based on real traffic to cut down on false positives while keeping the protection effective.
    What do you dislike about the product?
    Some rules can be overly aggressive and may need tuning to reduce false positives. The default rule set doesn’t always align with application-specific traffic, so customization is sometimes necessary. When an application has unusual or complex request patterns, managing exceptions can quickly become time-consuming.
    What problems is the product solving and how is that benefiting you?
    It reduces the effort required to manually create and maintain WAF rules for common web attacks. As a result, we get a more consistent security baseline, save time, and still protect our applications from common threats.
    Banking

    Managed Rules with Centralized Security

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    Managed rules provide pre-configured, regularly updated security rules which make it easier to protect web applications from common threats without having to build and maintain everything from scratch. The centralized management and Fortinet’s threat intelligence also help simplify ongoing security operations.
    What do you dislike about the product?
    Need fine-tuning for false positives, especially for applications with custom or complex traffic patterns. It would be helpful to have more granular customization and clearer rule-level visibility when troubleshooting blocked requests.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect web applications from common threats such as SQL injection, cross-site scripting, and malicious requests without having to create and maintain all the rules ourselves.
    Anonymous

    Effortless Protection with Fortinet Managed Rules

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I use Fortinet Managed Rules for AWS WAF because it saves a lot of time with everything being managed end-to-end. It's easy to use and offers great coverage and security practices. I appreciate that it covers each web application with rules that include the OS top 10 and some custom detections, along with threat IDs. It's better than others in terms of cost and detection. The initial setup is straightforward and requires just one click. Overall, it's a reliable service that provides good results.
    What do you dislike about the product?
    The only area where I think Fortinet Managed Rules for AWS WAF could improve is in the threat intelligence aspect. It would be better if they could fine-tune the system to update more rapidly in nearly real-time when it comes to identifying malicious traffic from URLs. This would enhance its effectiveness against threats.
    What problems is the product solving and how is that benefiting you?
    It saves me time by managing and configuring rules end-to-end, offering strong security practices and easy use.
    Suprim C.

    Easy Integration and Strong Protection

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    The ready-to-use managed rules and easy AWS WAF integration are the most valuable features for me. They save time in rule management and provide reliable protection against common web threats. The interface is simple to manage, and Fortinet support is helpful when needed. Overall, it improves security while reducing the effort required for daily administration.
    What do you dislike about the product?
    The rules sometimes need fine-tuning for specific applications, especially when handling false positives. More detailed rule explanations and easier customization would make troubleshooting and policy tuning simpler.
    What problems is the product solving and how is that benefiting you?
    It reduces the effort of creating and maintaining WAF security rules manually. The managed rules provide ready-to-use protection against common web attacks, helping improve security while saving time on daily WAF management.
    View all reviews