Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.6
Number of Reviews
58
Ranking in other categories
Web Application Firewall (WAF) (1st)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
94
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Rohit Kesharwani - PeerSpot reviewer
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
Integrating AWS WAF with other AWS services in our infrastructure is fairly easy. There are different tools through which we can do it. AWS WAF is a fairly easy solution. Users need to build a few rules by themselves based on the vulnerability attack within the application. Overall, I rate the solution a nine out of ten.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool is user-friendly."
"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"The solution provides good load balancing and protection against DDoS attacks."
"The most valuable features of the solution are performance and security."
"The solution is very good at mitigating threats."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"The tool’s stability is very good."
"One of the most valuable features of AWS WAF is its ability to filter web app traffic, allowing us to specify conditions such as IP addresses and HTTP headers."
"We do not have to maintain the solution."
"The product’s availability, ease of configuration, and documentation are valuable."
"The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
"The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances."
"The most valuable feature is the addition of managed tools that help us create customizable rules. In case we want to block a particular request, we can make use of those rules."
"AWS WAF is a stable solution. The performance of the solution is very good."
"The customers are very happy with this solution because of two things. First, the IPS integration with a web application is very tightly done on Fortinet. Second, the ease of use is there. The management interface or the GUI interface is very easy to use, configure, and manage. These are the two main valuable features. It supports integration with other Fortinet products. It also integrates very well with the firewall and sandboxing technology. They already have enough integration with different technologies. They have got a complete tech intelligence view of the whole product."
"Fortinet FortiWeb is priced well."
"The solution is stable."
"Even though most products have the same functionality nowadays, FortiWeb is easy to integrate."
"It is easy to install and to maintain."
"The support services, performance, and pricing are all valuable features. The performance is excellent."
"The product's initial setup phase was straightforward, and since our company didn't have any problems with it, we didn't encounter many problems with the tool."
"The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities."
 

Cons

"The pricing could be improved."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"DNS Management."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"The solution could work at being less expensive. It costs a lot to use it."
"Even if I wanted to, I wouldn't be able to buy Cloudflare in my country."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"The product could be improved by expanding the weightage units of rules."
"An improvement area would be that it's more of a manual effort when you have to enable rules. That's one of the downsides. If that can be done in an automated way, it would be great. That's a lagging feature currently."
"We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down."
"I would like to be able to view a graphical deployment map in the user interface that will give me an overview of the configuration and help to determine whether I have missed any steps."
"For uniformity, AWS has a well-accepted framework. However, it'll be better for us if we could have some more documented guidelines on how the specific business should be structured and the roles that the cloud recommends."
"It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."
"I find the documentation somewhat complex to implement during the initial stages."
"The technical support does not respond to bugs in the coding of the product."
"We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
"The product's scalability could be better."
"I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device."
"We have had problems with deployments where we've had to contact technical support to resolve them."
"The initial setup in our data center was somewhat complex."
"The solution is rather complicated. If you know what to do, it's not bad, but it's complicated for a first time user to configure the solution. What I'd like to improve are the custom signatures."
"The solution could improve by providing more integration with solutions other than the Fortinet family."
"The product’s stability could be improved."
 

Pricing and Cost Advice

"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"We are using the free tier of the solution."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"The tool is a premium product, so it is very expensive."
"The price is reasonable."
"The price of the solution is expensive."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"AWS is not that costly by comparison. They are maybe close to $40 per month. I think it was between $29 or $39."
"There are no costs in addition to the standard licensing fees."
"We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven or eight out of ten."
"The pricing is good and manageable."
"The product is moderately priced."
"It's quite affordable. It's in the middle."
"For our infrastructure, we probably pay around $16,000 per month for AWS WAF. Because alternative WAF solutions provide even more features, I think the AWS WAF is a bit pricey"
"The pricing is pretty good. We do pass a lot of traffic through our API servers. Something like 100 gigs of web traffic is a fair amount for reduced JSON API calls, but the cost is $50. For that peace of mind, we have thousands and thousands of customers that are protected by that $50, so it's a no-brainer."
"The solution is a bit expensive when compared to other products."
"If one is cheap and ten is expensive, I rate the tool an eight."
"The license to use Fortinet FortiWeb is approximately $14,000."
"All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500."
"It should be somewhere about 36,000 Euros. That's the cost for three years. It's moderately priced."
"The license cost depends on the size of the box or the size of the solution. It can go from €200 Euros to a few hundred thousand Euros a year depending on your size."
"The maintenance fee for this product could be improved."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
7%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
8%
Government
6%
Educational Organization
43%
Computer Software Company
9%
Financial Services Firm
7%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
I would rate the licensing cost as seven out of ten, considering it good value for money. The price is affordable and...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in the portability on multi-cloud environments. Enhanced DDoS integration to make Forti...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about AWS WAF vs. Fortinet FortiWeb and other solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.