Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Fortinet FortiWeb Web Application Firewall WAF (PAYG)

Fortinet Inc. | 7.6.1

Linux/Unix, Other 7.6.1 - 64-bit Amazon Machine Image (AMI)

Reviews from AWS customer

5 AWS reviews

External reviews

38 reviews
from and

External reviews are not included in the AWS star rating for the product.


    ManjunathA

Effective in protecting web applications include web filtering, DDoS protection, and geo-location blocking

  • May 12, 2025
  • Review provided by PeerSpot

What is our primary use case?

The FortiWeb Web Application Firewall (WAF) is used when customers want to publish their sites and protect their internal public websites. Some customers ask to protect their AWS or Azure network, and during that time, we also suggest the web solution. In the network, we can use next-generation firewalls upstream or in flows wherever required, making it mandatory with the parameter-level layer security.

We focus on websites with FortiWeb Web Application Firewall (WAF). Features such as anomaly input validation, XML protection, and API protection are already present, but we also need configuration settings that indicate the advantages or disadvantages of enabled features. If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.

What is most valuable?

The features of FortiWeb Web Application Firewall (WAF) that have proven most effective in protecting web applications include web filtering, DDoS protection, geo-location blocking, and blocking SQL injection attacks.

The AI machine learning capabilities included in FortiWeb Web Application Firewall (WAF) analyze patterns effectively. For example, if any user tries to input any text format in a web form mistakenly using SQL queries, the web solution detects the input, checking whether it's impacting or analyzing queries in the database. Everything is analyzed to ensure protection.

What needs improvement?

Their AI technology is good. Overall, Fortinet is only good.

The improvement needed is in their response time. In the past three to four years, whenever we called for support, they responded quickly, often within five to ten minutes, and addressed our issues immediately. Now it takes longer, and they talk about SLA and 48-hour response times. Even with critical issues, they say, 'Okay, that ticket is assigned; we need to wait for their update in four hours or two hours,' which is taking too long now.

If there are issues, we need to contact the development team since we don't have configurations we can do ourselves; most features or configurations are managed by the development team. The graphical user interface looks difficult to understand, as other products allow us to see all features in one place.

The AI in FortiWeb Web Application Firewall (WAF) is just a checkmark option. To use machine learning features, we only need to enable or disable it. However, we must check how useful it is in real-time environments to determine how it protects or identifies threats.

There are features like web filtering, DDoS protection, geo-location blocking, SQL injection blocking, anomaly input validation, XML protection, and API protection already present, however, we also need configuration settings that indicate the advantages or disadvantages of enabled features. If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful. Currently, we cannot see any logs for allow traffic or monitor daily traffic effectively, which requires external syslog servers or cloud subscriptions. If inbuilt larger logging capability is added, it would enhance usability, and features like clickable options to unblock or create exceptions would greatly assist customers in managing their websites.

For how long have I used the solution?

I have been working with them for Five years.

How are customer service and support?

The technical support by Fortinet is good. The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

The pricing for FortiWeb Web Application Firewall (WAF) is reasonable. That said, it depends on how many websites we need to protect. The licensing is based on the number of websites or individually. If the customer has multiple websites, the price reduces automatically since it depends on the number only. If the customer wants to buy initially, there is a default license available.

When going for multiple websites, the price also reduces.

What other advice do I have?

I am providing next-generation firewalls or FortiWeb Web Application Firewalls (WAF).

Both web application firewalls and next-generation firewalls are available, which we are doing daily.

I usually recommend the FortiWeb Web Application Firewall (WAF) for various types of companies, including retail, hospitals, manufacturing, construction, and banking.

It is the best option on the market.

I rate FortiWeb Web Application Firewall (WAF) eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Mohammed S.

I'm an technical support for a lot of network security products

  • March 27, 2025
  • Review provided by G2

What do you like best about the product?
FortiWeb is the best Solution for the company that publish it's Website or the company that need to access the internet
What do you dislike about the product?
Nothing it's a customized product for the big organization
What problems is the product solving and how is that benefiting you?
It can filter all the URLs and customize the sites that I can login and also help me to protect my network from any attacks.


    reviewer2641242

Offers competitive pricing and robust channel support with good training

  • January 09, 2025
  • Review provided by PeerSpot

What is our primary use case?

I mentioned that the firewalls, such as the one from Fortinet, help protect my infrastructure from outside attacks. They perform a lot of network scanning and do not allow any unauthorized person to access my details and data. That's their application. A similar action is performed by the web application firewall, where web applications are restricted to certain users. This means that not anyone with malicious intent can access my web application content.

What is most valuable?

The good thing about Fortinet is that their enablement is very good in terms of training me and enabling resources on their technology. 

Secondly, if I look at their pricing, Fortinet's pricing is way more competitive than Cisco or Palo Alto. They have almost 45% share in the firewall market, as per IDC. Fortinet is a large-sized company where their channel program is very robust and very flexible. They also understand the different personas of the channel stakeholders. In that way, they are rapidly growing in the channel ecosystem space and have started getting a lot of business. They are replacing many big traditional players in that space.

What needs improvement?

There are some issues pertaining to the migration. If some of my customers want to migrate from F5 to Fortinet Firewall, or the Fortinet WAF solution, there are some migration issues since I cannot migrate all the elements quickly using Fortinet Firewall. There is some integration work required to do that.

For how long have I used the solution?

I have been working with Fortinet for almost one year and eight or nine months.

How are customer service and support?

Their support is truly exceptional when I compare it with similar large-sized companies. In that category, they are top-notch at this point in time.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I was with SquadCast earlier.

Which other solutions did I evaluate?

F5 is a leader. They have some technical supremacy. F5 is more in demand, however, other players like Radware are also available in the market.

What other advice do I have?

I would rate the solution eight out of ten at least. 

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other


    Andreas Lalos

Enhanced application protection with an extensive attack signature library

  • November 11, 2024
  • Review provided by PeerSpot

What is our primary use case?

FortiWeb is used for web application protection. It protects a web application against attacks targeting their web applications, such as cross-site scripting, SQL injection, and other common application-specific attacks.

How has it helped my organization?

FortiWeb allows the organization to operate efficiently without any downtime or serious security breach.

What is most valuable?

FortiWeb has a very extensive library of known attack signatures, which makes the product fit for any environment, regardless if the customer uses Windows-specific or non-Windows-specific applications. It also has a very low rate of false positives and incorporates other FortiGuard capabilities, such as detection of botnet traffic.

What needs improvement?

For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting. The product could offer better capabilities and analytics to pinpoint threat landscapes more efficiently.

For how long have I used the solution?

I have been working with FortiWeb for approximately four years, maybe more.

What do I think about the stability of the solution?

FortiWeb has proven to be very stable and does not introduce latency in the network.

What do I think about the scalability of the solution?

The product can scale according to the organization's traffic and architecture. It is available as a virtual appliance and a hardware appliance.

How are customer service and support?

Fortinet provides very good support, which I would rate as eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

At the moment, we are only working with Fortinet and not with other web application firewalls.

How was the initial setup?

Someone without prior experience with the product might find it challenging to deploy. However, Fortinet provides good online training to assist administrators.

What was our ROI?

The total cost of ownership should be calculated based on the actual protection it offers to the application. Deploying FortiWeb can save 20% to 30% of resources within the organization.

What's my experience with pricing, setup cost, and licensing?

FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapest solution. That said, it is worth the investment.

Which other solutions did I evaluate?

I have experience with other web application products.

What other advice do I have?

I'd rate the solution nine out of ten.


    Martin Janzsó

Has good integration with load-balancing applications

  • September 05, 2024
  • Review provided by PeerSpot

What is our primary use case?

Our company provides data center and cloud services as infrastructure providers. When customers need infrastructure like VMs or server allocation, we provide them with the vendor and offer services to operate, manage, implement, and integrate these security components.

What is most valuable?

The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection.

What needs improvement?

Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees.

For how long have I used the solution?

I have been using the product for four to five years. 

What do I think about the stability of the solution?

I rate the tool's stability a nine out of ten. 

What do I think about the scalability of the solution?

It's not good with normal perpetual licensing, but we can solve the problem using flex licensing. That's why I'd rate it nine out of ten. We're satisfied with it. Many of our customers, including small, medium, and enterprise businesses, use FortiWeb WAF.

How was the initial setup?

I rate the tool's deployment ease as seven out of ten. We have spent about 600 working hours to implement it. 

What's my experience with pricing, setup cost, and licensing?

The product provides very good prices to customers. The price is set well and offers great value for money.

What other advice do I have?

I rate the overall solution an eight out of ten. I advise others looking to use FortiWeb WAF to create deeper policy rules.

Which deployment model are you using for this solution?

On-premises


    Martin Ellmann

Provides users with ease of policy configuration and good integration capabilities

  • August 08, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution in my company to make web applications more secure because we have a special portal or web interface that we have to make secure for cybersecurity and different accesses. We found that FortiWeb Web Application Firewall (WAF) works fine for such use cases.

What is most valuable?

The tool's most valuable feature is the web access it offers. We control every access, like who goes in and what they do.

What needs improvement?

The tool's price and performance are areas of concern where improvements are required.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for three years.

What do I think about the stability of the solution?

It is a 100 percent stable solution. Stability-wise, I rate the solution a ten out of ten.

What do I think about the scalability of the solution?

My company has three customers using the tool. One of the customers has 1,00,000 users.

How are customer service and support?

My company manages the technical support with around four people, so it is not a complex process for us to handle. In general, the tool's support team is friendly.

How was the initial setup?

The product's initial setup phase was easy.

The solution's deployment needs a bit of time because we have to discuss it with the deployment team, which consists of software. The project keeps growing and changing daily, so if the people involved in the deployment make new software, we have to change something. It is an easy process and can be managed in around two weeks by one person.

What's my experience with pricing, setup cost, and licensing?

The tool is really expensive. In our company, we could do a lot more, but the price is always a point covering areas like why we need one, whether it is important to discuss, why it is so expensive and so on.

Speaking about the licensing model, people need to opt for a subscription-based model. My company likes to have a subscription for at least three or five years because, otherwise, you have to renew the license. Managing the licensing part for one person can also be very complex.

What other advice do I have?

The solution helps protect our company's web applications against common threats up to 99 percent. We feel very safe with the tool.

Speaking about how the tool has effectively mitigated web security threats for an application, I would say that it is an application behind the web portal, so there are about a hundred or thousand people who can access a website. If it is a sensitive application, and we have to watch every access to it to make it really safe, that is the reason why we need WAF on the application.

My company doesn't use AI with the tool.

I recommend the product to others. I would say that others need to have it if they have a shopping website or something similar. I know it is hard to sell because we find it quite hard whenever my company tries to do so.

The solution offers 100 percent integration with other Fortinet security products.

The ease of policy configuration in the tool is okay.

I rate the tool a nine to ten out of ten.


    BatuAkalin

Has antivirus features and helps to comply with GDPR and KVKK

  • July 18, 2024
  • Review provided by PeerSpot

What is most valuable?

The solution's integration with other products is easy. Its most valuable feature is the antivirus engine.  The tool helps us comply with GDPR and KVKK standards. 

What needs improvement?

FortiWeb WAF's tuning causes trouble. It's complicated. The solution needs to improve the signature feature as well. 

For how long have I used the solution?

I have been working with the product for five years. 

What do I think about the stability of the solution?

I rate the solution's pricing a ten out of ten. 

What do I think about the scalability of the solution?

My company has 50 users. 

How are customer service and support?

The solution's support is very good. 

Which solution did I use previously and why did I switch?

I use Palo Alto and Symantec products simultaneously. We chose FortiWeb WAF because of its pricing and easy implementation. 

How was the initial setup?

The solution's deployment is easy and takes ten days to complete. We have two resources involved in its maintenance. 

What was our ROI?

The solution is cost-effective since it is cheaper than other alternatives. Also, the false positive rates are low. 

What's my experience with pricing, setup cost, and licensing?

I rate the tool's pricing an eight out of ten. 

What other advice do I have?

I rate the overall product a nine out of ten. 

Which deployment model are you using for this solution?

On-premises


    HarishKM

Improves latency by optimizing traffic routing at an affordable price

  • July 16, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for branch optimization. Initially, it was all in MPLS, but they converted to the broadband network. Implementing it reduced the cost, and its redundancy was also better.

How has it helped my organization?

It improves latency by optimizing traffic routing. When a better link is available, it reroutes traffic through it. Additionally, MPLS helps reduce costs. Critical data can be prioritized on MPLS, while other data uses broadband connectivity, leading to better resource utilization. This setup supports load sharing, allowing multiple links to work simultaneously for improved performance.

What is most valuable?

From the web application perspective, it offers comprehensive features, including URL filtering and DNS protection. Additionally, FortiWeb provides SD-WAN capabilities, such as load sharing based on latency or packet drops. Its extensive feature set allows customers to choose and customize according to their needs and preferences.

What needs improvement?

FortiWeb could have an inbound load balancing pack. Currently, they don't have it, but they have the print product for that. It'll be better if they have it on the same product.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for three years.

What do I think about the scalability of the solution?

It is primarily for the enterprise environment segment. Even if one of the three links goes down, another link will appear to resolve the issue. FortiWeb primarily relies on its high availability features.

How are customer service and support?

We had a quick response from support since we have partnered with them. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was easy because we had training. Also, the FortiGate team provides good support. It took around around five to six days to complete. It is only a plug-and-play environment.

What's my experience with pricing, setup cost, and licensing?

The price is cheap compared to other products in the market. It costs 15-20% less than CheckPoint.

What other advice do I have?

It is more than a basic firewall. It includes various features for enhanced security, such as protection against threats and vulnerabilities specific to web applications. Depending on their roles and responsibilities, some people who work on EDS may also interact with FortiWeb WAF.

FortiWeb offers a comprehensive product suite for SOC integration, including automation and SIEM capabilities. It also offers a complete integration package, including physical components that ensure a consistent experience for internal and external teams.

It includes an analyzer that provides comprehensive visibility. It is designed to optimize costs while sending detailed analytics and other relevant data.

I recommend the solution for security.

I rate the solution a nine out of ten.


    Director_45785

Helps block certain applications and websites to enhance user productivity and maintain application security

  • June 06, 2024
  • Review provided by PeerSpot

What is our primary use case?

The solution helps us to block certain applications and websites.

How has it helped my organization?

The use of FortiWeb Web Application Firewall, combined with Office 365 and Azure ID, has streamlined our VPN use and network security. With single sign-on, users only need to remember one process instead of two or three, which has improved our business security. 

What is most valuable?

FortiWeb Web Application Firewall helps us to block certain categories of browsing, such as weapons, and other inappropriate content on the client side. We have also blocked social media sites like TikTok and Facebook to enhance user productivity and maintain application security.             

What needs improvement?

We haven't faced any significant issues with FortiWeb Web Application Firewall. But they can lower the pricing, since it is a concern, especially in South Africa and the technical support, could be more responsive at times.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall of the past two years.

What do I think about the stability of the solution?

We have encountered some issues with the stability and would rate it an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten.

How are customer service and support?

The customer services is good but sometimes they are unresponsive.

Which solution did I use previously and why did I switch?

Before FortiWeb and Fortinet, we used to work with Sophos. We switched to Fortinet mainly due to better support and the availability of distributors in our country. In South Africa, Sophos lacked sufficient support and the resolution times for queries were often prolonged. With more vendors and better support, Fortinet has proven to be a more reliable choice.

How was the initial setup?

The deployment process of FortiWeb Web Application Firewall was easy. It took half an hour to be deployed.

What was our ROI?

FortiWeb Web Application Firewall has definitely helped with notifications of potential threats and vulnerabilities. It has impacted our operational costs by reducing them by 20%. This is mainly due to savings on bandwidth and infrastructure costs, as well as improved efficiency in handling potential threats.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing a four out of ten.

What other advice do I have?

FortiWeb should include log retention for 90 or 180 days built into the product, without requiring an additional license. Having to buy extra licenses for longer log retention is problematic and adds to the cost.

I would recommend FortiWeb to other users.

Overall, I would rate FortiWeb an eight out of ten. 

Which deployment model are you using for this solution?

On-premises


    reviewer2379189

Transparent, easy to use, and integrates well with the existing security infrastructure

  • May 31, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the solution in our headquarters. We have some agents outside our company.

What is most valuable?

The solution is transparent and smooth. So far, the tool has integrated well with our existing security infrastructure.

What needs improvement?

The price is a little higher than the competitors.

For how long have I used the solution?

I have been using the solution for more than five years.

How are customer service and support?

The technical support team is okay.

What about the implementation team?

We have a consultant who gives us advice about the implementation.

What other advice do I have?

Overall, I rate the product a nine out of ten.