
Overview
Video 1
Video 1
Video 2
Fortinet's WAF rulesets are based on the FortiWeb web application firewall security service and web application signatures, and are updated on a regular basis to include the latest threat information from FortiGuard Labs. The Malicious Bots Ruleset analyzes requests and blocks known content scrapers, spiders looking for vulnerabilities, and other unwanted automated clients that OWASP has identified as risks to web applications. Please see our other rulesets for additional protections.
Highlights
- Detects automated tools that scan for vulnerabilities
- Can be configured to log, alert and/or block
- Regular updates from FortiGuard Labs
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/unit |
|---|---|
Charge per month in each available region (pro-rated by the hour) | $5.00 |
Charge per million requests in each available region | $0.50 |
Vendor refund policy
Non-Refundable
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Managed Rules Feel Too Broad—False Positives and Limited Rule-Trigger Visibility
Ready-to-Use Security Rules That Simplify API Protection
Set-and-Forget Security with Auto-Updating Rules
Reliable protection with minimal maintenance
Managed rules have strengthened web security and reduce manual protection effort for internal sites
What is our primary use case?
My main use case for Fortinet Managed Rules for AWS WAF is to protect our internal intranet sites and to publish some load as we are using it there.
Regarding my main use case, ease of adoption, rule training, and cost model are vital because it is a managed rule group inside AWS WAF, meaning you do not get the FortiWeb full feature set. A learning-based positive security model without detailed app layer analytics and dashboarding means you need to make it there. When teams move to full FortiWeb cloud, they transition to self-managed FortiWeb.
What is most valuable?
The best features Fortinet Managed Rules for AWS WAF offers are real-time protection against OWASP Top Ten threats, FortiGuard threat intelligence, and automatic rule updates without manual maintenance, which leads to low false positives and easy integration with AWS WAF. What stands out most is the combination of continuously updated threat intelligence and managed protections, helping secure web applications with minimal operational effort.
Fortinet Managed Rules for AWS WAF has positively impacted my organization by improving overall web application security by blocking common attacks such as SQL injections and XSS for traffic before they reach the application. It reduced the workload of the security team through automatic updates, improved compliance, and minimized the risk of downtime caused by web-based attacks. Overall, it strengthened our security posture while reducing operational effort.
The automatic rule updates have reduced the operational effort for our team because we did not need to manually track new web vulnerabilities and update WAF signatures. For example, when new CVEs or emerging web attacks are released, Fortinet automatically updates the managed rule group, FortiGuard, which saves us time, ensures faster protection, and allows the team to focus on network operations instead of continuously tuning WAF rules.
What needs improvement?
Overall, Fortinet Managed Rules for AWS WAF is a solid solution, but it could be improved with more granular customization of managed rules, better visibility into why specific requests are blocked, more detailed reporting and analytics, and tighter integration with SIEM and SOAR platforms for incident response, which would add value. These improvements would make troubleshooting and security operations more efficient.
Besides better rule customization and reporting, I would prefer to see a more intuitive management interface with easier policy tuning and clearer dashboards. Improved integration with third-party SIEM/SOAR and DevSecOps tools would streamline security operations. Faster support for newly discovered threats and more detailed documentation with deployment best practices would also help organizations adopt and manage the solution more effectively.
For how long have I used the solution?
I have been using Fortinet Managed Rules for AWS WAF for seven years.
What do I think about the stability of the solution?
Fortinet Managed Rules for AWS WAF is stable.
What do I think about the scalability of the solution?
The scalability of Fortinet Managed Rules for AWS WAF has been very good because it is built on AWS WAF, which scales automatically with application traffic without requiring additional infrastructure. As our traffic increased, we did not experience any major performance issues, and the managed rule continues to provide consistent protections. The automatic updates and cloud-native architecture made it easy to support growth with minimal operational effort.
How are customer service and support?
The customer support for Fortinet Managed Rules for AWS WAF is very good. Whenever we had an issue, they solved it immediately.
Which solution did I use previously and why did I switch?
Fortinet Managed Rules for AWS WAF is our first time using it with AWS WAF.
What about the implementation team?
I was not directly involved in the purchasing process of Fortinet Managed Rules for AWS WAF; the subscription was handled through our procurement cloud team. My role focused on deployment, configurations, and tuning the security aspects.
What was our ROI?
There is a positive return on investment because the managed rules reduced manual administration and improved protection against common attacks.
When I mention reducing personnel, I mean my team spends less time managing web security now, not that we reduced the headcount. Since the managed rules are updated automatically, we spend less time creating and maintaining WAF rules manually, allowing the team to focus on higher value tasks such as security monitoring, incident response, and infrastructure improvements, which is helpful for our team to reduce spending.
What's my experience with pricing, setup cost, and licensing?
The pricing was reasonable considering the automatic updates, FortiGuard threat intelligence, and reduced operational effort.
What other advice do I have?
Overall, Fortinet Managed Rules for AWS WAF is a strong solution providing effective protection against common web threats while benefiting from FortiGuard threat intelligence and reduced operational effort through automatic rule updates.
My advice to others looking into using Fortinet Managed Rules for AWS WAF is that we hardly open support cases. I would rate this solution an 8 out of 10.
