Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

2 AWS reviews

External reviews

33 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Nitith Unarat

Identifies potential DDoS attacks and suspicious domain activity

  • May 13, 2024
  • Review from a verified AWS customer

What is our primary use case?

My company is a Fortinet partner and specializes in FortiWeb. We often compete against cloud-native solutions like Azure Application Gateway WAF. We typically conduct proof-of-concept tests for potential clients. They are usually looking for API protection and bot mitigation, which FortiWeb excels at. We take responsibility for implementing and supporting the solution for our customers.

We also conduct simulation tests and review feedback from colleagues and customers. Customers often seek solutions for bottlenecks, especially regarding machine learning. We can do a detailed review of the WAF services and provide a report for the customer.

How has it helped my organization?

If a customer has a website, a firewall alone is not enough. While a firewall can act as an application firewall, it may not be sufficient. If we have a firewall at layer four and layer seven, and the customer needs protection against OWASP Top 10 vulnerabilities or requires IT audits, a web application firewall becomes crucial. 

Additionally, if DDoS protection is a concern, it often comes integrated with WAF. For networking, some WAFs can even provide load-balancing functionality.

What is most valuable?

In my experience, we put my customer's website in monitor mode, not protect mode. So, we initially set up FortiWeb in monitor mode to avoid disruptions to the customer's website.

While in monitor mode, machine learning observed the web application. Once machine learning had enough data to analyze, we discussed unusual traffic patterns with the customer. 

FortiWeb identified potential DDoS attacks and suspicious domain activity, showcasing the value of its machine-learning capabilities.

What needs improvement?

The price could be close to Imperva; Imperva is the number one firewall.

FortiWeb cannot do some kind of ADC solution, like load balancing. I hope they improve that.

I'm looking for the ADC solution, the load balancing solution. Because application firewalls with multiple line solutions do come with it. So, I think it should be integrated within FortiWeb WAF.

For how long have I used the solution?

I used it for two years. I started working with it when a client company moved their web application to the cloud (Azure or AWS) and needed protection. We implemented a FortiWeb solution as their WAF.

Which solution did I use previously and why did I switch?

I have used Check Point for email security. 

What was our ROI?

For security products, from my experience, customers will compare costs if they have been attacked. They may consider insurance. If you provide more protection, the return on investment is the compromise to use the application.

What's my experience with pricing, setup cost, and licensing?

This product offers two pricing options: a standard package and an advanced package. The advanced package includes credential stuffing protection, while the standard package includes automatic application learning, bot mitigation, and web application protection. 

If you simply need to protect your website, the standard package is sufficient. However, if you need credential stuffing protection, the advanced package is necessary. This is the key difference between the two packages.

What other advice do I have?

Overall, I would rate the solution an eight out of ten. 


    Som Sharma

Used for web filtering purposes and has a user-friendly interface

  • April 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for web filtering purposes. We use it to allow or block any application.

What is most valuable?

The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS. The solution's console is very user-friendly and very easy to manage. The solution has good stability and a user-friendly interface.

What needs improvement?

It would be good if the solution integrated with other solutions, like SAP.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for nine to ten years.

What do I think about the stability of the solution?

FortiWeb Web Application Firewall is a very stable solution.

I rate the solution’s stability ten out of ten.

What do I think about the scalability of the solution?

Every location with 200 to 300 people has installed the FortiWeb Web Application Firewall.

I rate the solution a nine out of ten for scalability.

How are customer service and support?

Our experience with the solution's technical support has been good. We promptly get support from the technical support team.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution’s initial setup is easy and can be done in a few hours.

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a nine or ten out of ten.

What other advice do I have?

I would recommend FortiWeb Web Application Firewall to other users because it is a good product.

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud


    IgnitiusMolepo

Protects internal applications and prevents target attacks

  • February 20, 2024
  • Review provided by PeerSpot

What is our primary use case?

The tool is a valuable web application that protects our internal mobile money application. It enforces policies, ensuring secure access for users connecting to the application. It complies with PCI DSS, safeguarding financial transactions and contributing to our revenue. The solution effectively addresses malware threats.

What is most valuable?

The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises.

You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary.

The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.

What needs improvement?

We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version. 

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the stability of the solution?

You may encounter problems if you don't have FortiAnalyzer. 

What do I think about the scalability of the solution?

My company has 11,000 users. 

How are customer service and support?

We've encountered several issues before, like the web and firmware's lack of responsiveness for 50 minutes. The Firewall, FortiWeb Manager firmware, and firmware updates must sync properly. We've addressed this, and our partners have helped resolve these issues.

Which solution did I use previously and why did I switch?

I tried to work with Cisco, but it wasn't working well. 

How was the initial setup?

FortiWeb Web Application Firewall's deployment is not complex. The setup involves connecting the switch and the firewall. Our main task is to redirect all traffic from the application to the website. The overall process can be completed in two weeks. Maintaining it isn't challenging, but the issue arises when the firmware becomes outdated; you must check and update it.

What about the implementation team?

FortiWeb Web Application Firewall helped us with the deployment. 

What other advice do I have?

I rate the overall solution a nine out of ten. 


    Aung Min Oo

A tool to protect websites from malware and adware attacks that needs to improve its scalability

  • January 09, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution for some of my company's clients who want to protect their websites from malware and adware attacks.

How has it helped my organization?

From a benefit perspective, FortiWeb Web Application Firewall (WAF) protects the customers’ websites, which are used to communicate with the audience or clients.

What is most valuable?

I am not sure about what I like in the solution because I think most of the customers ask for the product whenever they want a WAF tool for any of their projects. After our company had a discussion with one of our local teams, we sold it by providing the features of the FortiWeb Web Application Firewall (WAF) that our customers like, as we mostly follow the customer requirements. Our company sells FortiWeb Web Application Firewall (WAF) if it meets our customers' requirements.

What needs improvement?

To deal with zero-day attacks, FortiWeb Web Application Firewall (WAF) needs to expand and update its database since it is one of the areas where the tool currently lacks. In short, FortiWeb Web Application Firewall (WAF) needs to update its attack prevention database.

In FortiWeb Web Application Firewall (WAF), there is a substantial amount of improvement required in the scalability area.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for less than a year.

What do I think about the stability of the solution?

Stability-wise, I rate the solution a seven out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a five out of ten.

My company only has two customers who use FortiWeb Web Application Firewall (WAF). My company wants to sell the tool to medium and large-sized businesses with 500 or more users.

How was the initial setup?

The solution is deployed on an on-premises model.

Sometimes, the product's deployment takes over one or two days because customers need to check their requirements and then may want some features. In general, it takes a minimum of two or three days to deploy the product.

What's my experience with pricing, setup cost, and licensing?

Compared to the other products in the market, FortiWeb Web Application Firewall (WAF) is a reasonably priced product, but sometimes people may consider it a bit expensive. I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price.

What other advice do I have?

The product is easy to configure.

I have a separate team of three engineers in the company to manage FortiWeb Web Application Firewall (WAF).

Based on my experience and the comments from our company's customers who use the solution, I can say that FortiWeb Web Application Firewall (WAF) is a good product. Our company's customers who use the solution like it since they have been using it for about a year without any bad opinions or comments about it.

Feature-wise, FortiWeb Web Application Firewall (WAF) needs to add more functionalities. Some of the customers who use it want it to have more features, but we cannot find any in the tool presently. I can say what kind of features are required right now in the product. One customer who may want 20 features in the tool may get only 15 features that comply with the customer's requirements.

I rate the overall tool a six out of ten.

Which deployment model are you using for this solution?

On-premises


    CharlesFamisaran

Easy to setup, stable and scalable solution

  • January 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

My main use case is for security and routing.

What is most valuable?

It is good for web tracking applications.  

What needs improvement?

There is room for improvement in pricing, and actually, the price is a bit higher because on the same terms I purchased, the support subscription is so high.

For how long have I used the solution?

I've been using it for a long time. It has been more than three years now. 

What do I think about the stability of the solution?

Stability is guaranteed stability. I'm okay with stability. I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten. 

How are customer service and support?

I am okay with the support. The support's subscription is high. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

pfSense is open-source and free, while FortiWeb is subscription-based. Both are manageable, but FortiWeb's features scale up connections per second, depending on the payment plan. 

How was the initial setup?

I would rate my experience with the initial setup a nine out of ten, where one is difficult, and ten is easy.

It took us two days to set up.

What about the implementation team?

I deployed it myself.  I just got a reference from the old system, and I configured it.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing a seven out of ten, where one is cheap and ten is expensive. 

What other advice do I have?

Overall, I would rate it a solid eight out of ten.  

Which deployment model are you using for this solution?

On-premises


    reviewer2323683

User-friendly, stable and efficiently secure VMs and applications

  • December 18, 2023
  • Review provided by PeerSpot

What is our primary use case?

I initially deployed it for my company, but now I administrate it for a client.

What is most valuable?

We use it to secure VMs and applications in Azure. It protects against DDoS attacks.

It's very user-friendly.

What needs improvement?

There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support. 

In future releases, I would like to see added antivirus features that provide user-based activity indicators. For example, if a user downloads a large number of files or connects frequently, the WAF could flag this activity for investigation.

For how long have I used the solution?

I have been using it for three months now. 

What do I think about the stability of the solution?

It is a stable solution. 

What do I think about the scalability of the solution?

It is a scalable product. 

How are customer service and support?

For some initial issues. It's good, but not during the first year. FortiWeb could improve response time and first-level support clarity.

How would you rate customer service and support?

Positive

What about the implementation team?

The first implementation with an expert took two hours. My solo attempt took three weeks.

What other advice do I have?

Take time to test it thoroughly. Consider buying an existing solution if needed.

Overall, I would rate the solution an eight out of ten. 


    reviewer2314347

A security solution for securing the Internet facing servers but lacks several security features

  • November 24, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for securing the Internet-facing servers where you can do the  load balancing with the web appliance.

What needs improvement?

FortiWeb WAF lacks several security features compared to F5. F5 can incept the traffic to layer seven; FortiWeb can do it, too, but it is a tough process. We have to get support from Fortinet.

For how long have I used the solution?

I have been using FortiWeb as a partner for two years. We are using V7.2 of the solution.

What do I think about the stability of the solution?

Fortinet has many issues, like the zero-day attacks. Certain critical work vulnerabilities need to be immediately upgraded as an enterprise. You cannot initiate the upgrade anytime because it affects production. Usually, we schedule the upgrade. We do the configuration and scheduling of the updates. Fortinet is a 24/7 company that can release updates any time, regardless of the day of the week. FortiWeb WAF is a security solution that can be updated at any time, irrespective of the day of the week.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

On two recent occasions, I experienced delays in resolving technical issues with Fortiweb WAF, particularly when configuring explicit proxies on FortiGate firewalls. As a Fortinet partner, I was disappointed that our dedicated support channel was unavailable and that I could not obtain licenses or hardware assistance despite escalating to the country manager. Additionally, the technical support response times in the Middle East region have been inconsistent, with some areas providing excellent support while others have been unresponsive. This inconsistency has been particularly frustrating when dealing with urgent issues at remote sites. Overall, the support experience for Fortiweb WAF has been inconsistent and frustrating, particularly for Fortinet partners.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Kemp before, but I also dislike the FortiWeb. I'm trying to move to F5 because F5 is very good.

How was the initial setup?

FortiWeb comes with an IP address. You need to log into the web console, and you can do it with the CLI using the console cable. You have to go in; it will initially give you a setup wizard and configure the hostname, interfaces, etc. The setup is relatively easy, but when it comes to advanced deployments. Kemp is a relatively affordable and capable solution. Fortiweb WAF offered all the features, making Kemp less appealing for enterprise-level applications. Kemp is suitable for smaller or regional websites, but it may not be as robust for global deployments.

Additionally, I could not locate the virtual domain feature in Fortiweb WAF. This feature would allow me to assign different domain names to a single website based on the user's location. Fortiweb WAF presented EDS as a workaround, but the process was overly complex and inconvenient.

Firstly, expect load balancing and a web application firewall for the same product Fortinet is offering. Start by booting up the device and use FortiWeb to connect the file by application firewall. There's a default IP address without any password. You log in, and then it shows your initial setup wizard. The wizard helps you set up the host names, Fortinet account, FortiCloud account, etc. After that, you start setting up your physical servers; then you give a virtual server, which will be a point. In a network with a firewall and port forwarding, the FortiWeb WAF device can act as a load balancer and a security gateway. It can receive traffic from the firewall, decrypt SSL/TLS traffic, inspect traffic for layer seven vulnerabilities, and then forward traffic to the appropriate internal server based on load-balancing algorithms and application-specific information provided by the servers. The FortiWeb WAF can monitor server health and performance and automatically switch traffic away from unhealthy servers.

Deployment depends on how much complexity you want to add to the product. If the customer requirement is easy, you may deploy it in one day. For example, I was working on a project with around 16 servers. Each server has a different data source; one server gives the back end, whereas the other provides the front end. That was a complex deployment. It will take around four to five days to deploy if you want to go deeper into it.

What was our ROI?

We have achieved 70% ROI.

What's my experience with pricing, setup cost, and licensing?

FortiWeb is expensive. F5 is also very expensive, but it is value for money.

What other advice do I have?

The solution’s maintenance and UI are easy, but some features are hidden. Their quality assurance needs to work. We used to have the upgrades and patches every month or 15 days, but now they are coming every week too. We have vulnerability.

The product needs to get more mature.

Overall, I rate the solution a six out of ten.

Which deployment model are you using for this solution?

On-premises


    Jishain-Ali

An easy-to-deploy solution with machine learning features that reduce false positives

  • October 18, 2023
  • Review provided by PeerSpot

What is most valuable?

The product has some unique features. The machine learning feature reduces the false positives. The tool detects zero-day attacks. It has an in-built antivirus, which most WAF tools do not have.

What needs improvement?

Advanced configurations require high skill. FortiWeb team should work on making it easier. The documentation is poor. The tool must provide advanced and robust DDoS protection.

For how long have I used the solution?

I have been using the solution for almost six years.

How are customer service and support?

The technical support is fine. The support team gives delayed responses if there is a complex issue.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have worked with F5 Advanced WAF. It is a robust product and is suitable for complex environments. It is flexible. However, it depends on other solutions for inbuilt security and packet inspection.

How was the initial setup?

The initial setup is easy. It requires less intervention.

What's my experience with pricing, setup cost, and licensing?

I recommend the product to others. Overall, I rate the solution an eight out of ten.


    Md. Al Imran Chowdhury

An useer-friendly solution with easy configuration

  • October 12, 2023
  • Review provided by PeerSpot

What is most valuable?

The tool's HTTP traffic, website fixing, and blocking are fantastic. It is user-friendly with easy configuration. 

What needs improvement?

FortiWeb Web Application Firewall needs to improve its performance. 

What do I think about the scalability of the solution?

FortiWeb Web Application Firewall is scalable. 

How are customer service and support?

The tool's tech support is good. 

How was the initial setup?

The tool's installation is straightforward. 

What's my experience with pricing, setup cost, and licensing?

FortiWeb Web Application Firewall is not expensive. 

What other advice do I have?

I rate the solution an eight out of ten. 


    Oche Eluma

Helps us to view all of our logs on one platform

  • September 21, 2023
  • Review provided by PeerSpot

What is our primary use case?

I have a multi-cloud environment. I have a production workload in Nigeria, with some data centers in Continental Europe and in the East US in multiple regions.

We have two different public clouds, AWS and Azure. Because of how Fortinet works, we connect to our customers via a remote access VPN.

What is most valuable?

The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature. 

Emails can be configured, and text messages can be sent via the mobile app. 

It is a cheap solution. 

What needs improvement?

The user interface can be improved. Also, there are authentication failures that need improvement in the next release. 

For how long have I used the solution?


How are customer service and support?

The technical support team is bad. 

How would you rate customer service and support?

Neutral

What other advice do I have?

I would rate the overall solution a eight out of ten due to the support and user interface issues.