We use FortiWeb Web Application Firewall for security features while working in the financial area.

External reviews
External reviews are not included in the AWS star rating for the product.
34
Protection Against Web Application Attacks: Fortinet Managed Rules help mitigate threats such as SQL injection, cross-site scripting (XSS), and other OWASP Top Ten vulnerabilities. This protection ensures the integrity and availability of web applications and APIs.
Automated Threat Intelligence: Fortinet incorporates real-time threat intelligence into their rules, allowing organizations to stay updated on emerging threats without manual intervention. This proactive approach helps defend against new attack vectors and vulnerabilities.
Ease of Implementation: By providing pre-configured security rules, Fortinet simplifies the process of setting up and managing security for AWS API Gateway. This can save time and resources compared to manual rule creation.
Centralized Management: Organizations can manage security policies across multiple API Gateway instances using Fortinet's centralized management console. This streamlines the administration of security rules and ensures consistency.
Customization: While offering pre-configured rules, Fortinet Managed Rules also allow customization. Organizations can tailor security policies to their specific application requirements, ensuring a balance between security and functionality.
Scalability: Fortinet's solution can scale with the organization's infrastructure, accommodating increased API traffic and maintaining effective security measures as the business grows.
Compliance Support: For organizations subject to regulatory requirements, Fortinet Managed Rules can help establish and maintain the necessary security controls to meet compliance standards, thus avoiding potential legal and financial penalties.
I have 2 project experiences using Fortinet Managed Rules for AWS WAF with API Gateway
Compliance: If your application needs to meet specific compliance requirements, such as PCI DSS or HIPAA, Fortinet Managed Rules can help you meet those requirements by providing a set of security rules and configurations that align with industry standards.
Simplified Implementation: Fortinet Managed Rules offer an easy-to-use solution for adding security to your applications. The rules are designed to integrate seamlessly with AWS API Gateway, making it convenient for .NET developers to implement and manage security measures without extensive manual configuration.
Time and Cost Savings: By leveraging Fortinet Managed Rules, you can save time and effort in implementing and maintaining custom security rules. The pre-configured rules provided by the service eliminate the need for you to create and manage complex rule sets from scratch, potentially reducing development and maintenance costs.
Overall, Fortinet Managed Rules for AWS WAF - API Gateway is solving security-related problems that can benefit .NET developers by providing an easy-to-use, pre-configured solution that enhances the security of their web applications running on AWS API Gateway, while also potentially saving time and cost.
Strict rules for adequate security
fortinet is good
Provides efficient integration features and has good scalability
What is our primary use case?
What is most valuable?
The product has good integration features.
What needs improvement?
The product's integration with Cisco needs improvement.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall for 30 years.
What do I think about the stability of the solution?
The platform's stability is good, with good assessment and low-level design.
What do I think about the scalability of the solution?
FortiWeb Web Application Firewall's scalability is good.
Which solution did I use previously and why did I switch?
I have used Palo Alto and Check Point before.
How was the initial setup?
The product is complicated to set up. The deployment time depends on the customer. Some customers have a deployment time of six to seven months, while others have a deployment time of two months. The process involves an assessment for a month, then a low-level design for another month.
What's my experience with pricing, setup cost, and licensing?
FortiWeb has a good presence because of its price.
What other advice do I have?
We are integrators with all the product certifications. We have a good team. We prefer assessment and low-level design before starting with the project.
I rate FortiWeb Web Application Firewall an eight out of ten.
A cost-effective firewall that remains stable while providing security to its users
What is our primary use case?
In my company, we use FortiWeb Web Application Firewall (WAF) for security.
What is most valuable?
FortiWeb is a small tool that can be used by those of our customers who use Fortinet FortiGate as their firewall. I will use Barracuda Email Protection for any customer who uses a firewall from a solution provider other than Fortinet FortiGate.
What needs improvement?
The product lacks features offered by enterprise-level firewall tools. The solution needs to offer more enterprise features like other brands.
It would be great if FortiWeb Web Application Firewall (WAF) had something like a wizard to allow for more integrations with other popular firewall products like Fortinet, Palo Alto, and so on.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall (WAF) for three years. I use the solution's latest version.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution an eight out of ten.
There are 2,000 users of the solution in my company.
How are customer service and support?
The solution's technical support was helpful and responsive. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have previously used SonicWall.
How was the initial setup?
The initial setup was easy since it was possible to get remote support for the product.
The solution is deployed on-premises.
What's my experience with pricing, setup cost, and licensing?
It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee.
What other advice do I have?
There are five engineers needed for the maintenance of the solution.
If there is a requirement and one is already using a firewall from Fortinet, then it is easier to deploy FortiWeb Web Application Firewall (WAF). Overall, I rate the solution an eight out of ten.