Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Fortinet FortiWeb comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024
 

Categories and Ranking

AWS WAF
Ranking in Web Application Firewall (WAF)
1st
Average Rating
8.0
Reviews Sentiment
8.0
Number of Reviews
56
Ranking in other categories
No ranking in other categories
Fortinet FortiWeb
Ranking in Web Application Firewall (WAF)
4th
Average Rating
7.8
Reviews Sentiment
6.5
Number of Reviews
92
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of November 2024, in the Web Application Firewall (WAF) category, the mindshare of AWS WAF is 13.7%, down from 15.4% compared to the previous year. The mindshare of Fortinet FortiWeb is 8.4%, up from 7.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF)
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
Integrating AWS WAF with other AWS services in our infrastructure is fairly easy. There are different tools through which we can do it. AWS WAF is a fairly easy solution. Users need to build a few rules by themselves based on the vulnerability attack within the application. Overall, I rate the solution a nine out of ten.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the security, making sure that files are protected, preventing unauthorized users from accessing the system."
"The ability to take multiple data sets and match those data sets together is the solution's most valuable feature. The data lake that comes with it is very useful because that allows us to match data sets with different configurations that we wouldn't normally be able to match."
"The product's initial setup phase was very simple."
"AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry."
"This product supplies options for web security for applications accessing sensitive information."
"We can host any DB or application on the solution."
"The most valuable feature is the way it blocks threats to external applications."
"They filter a lot of attacks out."
"The solution is stable."
"Banks have to be compliant with PCI and other things, and FortiWeb is absolutely amazing in terms of providing these reports. Otherwise, they will have to spend a lot of time on them."
"If I need something from tech support, I can get it answered within the hour."
"We were able to protect our web servers from outside attacks."
"FortiWeb has antivirus, web filtering, and application control features."
"It's stable and works efficiently against OWASP Top 10 attacks."
"It is a good product. We have just blocked everything coming from some geographical locations or certain countries, and it has been working very efficiently when I look at logs, events, and incidents generated from the system. It is generating very good analytic reports about it. This is the most valuable thing about this solution. It has load balancing and almost everything that a web application firewall needs. It is very flexible and easy to learn and configure. It can be easily learned and configured by using the information available on different channels such as YouTube."
"The support is quite good."
 

Cons

"The area of reporting in the product needs to have a proper format."
"For now, there is no feature to protect against attack of the bad bots"
"The product should improve the DDoS-related features."
"One area for improvement in AWS WAF could be the limitation on the number of rules, particularly those from third-party sources, within the free tier."
"In a future release I would like to see automation. There's no interaction between the applications and that makes it tedious. We have to do the preparation all over again for each of our other applications."
"I would like to be able to view a graphical deployment map in the user interface that will give me an overview of the configuration and help to determine whether I have missed any steps."
"They should work to define more threats, add more security, and make it more compliant with more security companies."
"We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down."
"Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration."
"The integration with other products should be improved."
"F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented."
"They can introduce a scaled-down version for the SMB market. It would be very competitive in the environment."
"The solution could offer more integration opportunities."
"I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted."
"When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it."
"A better load balancer is needed when multiple servers are used for the same website."
 

Pricing and Cost Advice

"AWS WAF has reasonable pricing."
"For our infrastructure, we probably pay around $16,000 per month for AWS WAF. Because alternative WAF solutions provide even more features, I think the AWS WAF is a bit pricey"
"The price of AWS WAF is expensive if you do not know how to manage your software up or down. I price of the solution is average amongst the other competitors but it would be better if it was less expensive."
"The pricing should be more affordable, especially as it pertains to small clients."
"AWS WAF is pay-as-you-go, I only pay for what I'm using. There is no subscription or any payment upfront, I can terminate use at any time. Which is an advantage."
"The product is moderately priced."
"It has a variable pricing scheme."
"AWS is not that costly by comparison. They are maybe close to $40 per month. I think it was between $29 or $39."
"The license to use Fortinet FortiWeb is approximately $14,000."
"If one is cheap and ten is expensive, I rate the tool an eight."
"All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500."
"There are no costs in addition to the standard licensing fees."
"The pricing is in the middle. I would rate the pricing a five out of ten. It feels like a justified cost for the features."
"The solution is a bit expensive when compared to other products."
"There are no licensing costs."
"Keep a loose margin between your actual bandwidth and the product sizing when using hardware appliances. Only virtual machines are upgradable to larger sizes."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
816,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
14%
Manufacturing Company
8%
Government
5%
Educational Organization
42%
Computer Software Company
10%
Financial Services Firm
7%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
It's better. Yeah, it's really good. It's one of the main points why we offer it. Since we are partners with them, sometimes we offer our customers a lower price.
What needs improvement with Fortinet FortiWeb?
Fortinet's technical support is pretty slow, especially when you have quick questions. The support kind of delays itself and sometimes takes more time. That's the only thing that I can think of at ...
 

Also Known As

AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about AWS WAF vs. Fortinet FortiWeb and other solutions. Updated: October 2024.
816,406 professionals have used our research since 2012.