Try our new research platform with insights from 80,000+ expert users

AWS WAF vs FortiWeb Web Application Firewall (WAF) comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
8.0
Number of Reviews
57
Ranking in other categories
Web Application Firewall (WAF) (1st)
FortiWeb Web Application Fi...
Average Rating
8.2
Number of Reviews
22
Ranking in other categories
Web Application Firewall (WAF) (16th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Rohit Kesharwani - PeerSpot reviewer
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
Integrating AWS WAF with other AWS services in our infrastructure is fairly easy. There are different tools through which we can do it. AWS WAF is a fairly easy solution. Users need to build a few rules by themselves based on the vulnerability attack within the application. Overall, I rate the solution a nine out of ten.
Nitith Unarat - PeerSpot reviewer
Identifies potential DDoS attacks and suspicious domain activity
The price could be close to Imperva; Imperva is the number one firewall. FortiWeb cannot do some kind of ADC solution, like load balancing. I hope they improve that. I'm looking for the ADC solution, the load balancing solution. Because application firewalls with multiple line solutions do come with it. So, I think it should be integrated within FortiWeb WAF.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"The solution provides good load balancing and protection against DDoS attacks."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"The attacker won't have details since my public IP is anonymous. It offers us good privacy."
"The most valuable feature is the web application firewall."
"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"Easier http to https redirect using page rules"
"The most valuable feature of the solution is external DNS. It is also very secure. They have their own main server and once you configure it, the product takes care of everything. There are no issues in resolving IPs and low latency is also present."
"We can host any DB or application on the solution."
"The most valuable feature is the way it blocks threats to external applications."
"The most valuable feature is the capability to limit access based on geographical location by restricting specific IP addresses."
"The initial setup was very straightforward. Deployment took about ten minutes or less."
"We do not have to maintain the solution."
"The most valuable features of AWS WAF are its cloud-native and on-demand."
"One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
"Its best feature is that it is on the cloud and does not require local hardware resources."
"The initial setup was easy since it was possible to get remote support for the product."
"The machine learning feature reduces the false positives."
"FortiWeb has a very extensive library of known attack signatures, which makes the product fit for any environment, regardless if the customer uses Windows-specific or non-Windows-specific applications."
"The product's initial setup phase was easy."
"The machine learning on FortiWeb WAF is valuable."
"We use it to secure VMs and applications. It protects against DDoS attacks. It's very user-friendly."
"The solution's integration with other products is easy. Its most valuable feature is the antivirus engine. The tool helps us comply with GDPR and KVKK standards."
"FortiWeb Web Application Firewall helps us to block certain categories of browsing, such as weapons, and other inappropriate content on the client side. We have also blocked social media sites like TikTok and Facebook to enhance user productivity and maintain application security."
 

Cons

"It should have easier documentation for the configuration. It's very technical and people who aren't technical should also be able to do the configuration."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"There are some issues with the CDN services."
"The product support needs to be accessible from more places, a wider area of coverage."
"Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"The solution could be more reliable."
"The solution can improve its price."
"I find the documentation somewhat complex to implement during the initial stages."
"The cost must be reduced."
"We need more support as we go global."
"The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."
"For now, there is no feature to protect against attack of the bad bots"
"We haven't faced any problems with the solution."
"FortiWeb Web Application Firewall needs to improve its performance."
"FortiWeb Web Application Firewall's signature database updates could be improved."
"It would be good if the solution integrated with other solutions, like SAP."
"There could be ADC offering as well."
"The tool's price and performance are areas of concern where improvements are required."
"The product is complicated to set up."
"FortiWeb could have an inbound load balancing pack."
"For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting."
 

Pricing and Cost Advice

"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"A free version of the solution is available."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"We are using the free version."
"That is one of the great features. I was able to access the majority of the features and services for free."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"The product's pricing is minimal compared to other products."
"Its price is fair. There is a very fair amount that they charge. It has a pay-as-you-go model, so it pretty much depends on how much a user uses it. As per the cloud norms, the more you use, the more you pay. I would rate it a five out of ten in terms of pricing."
"AWS WAF costs $5 monthly plus $1 for the rule. It's cheap, cost-wise. It's worth the money."
"The pricing should be more affordable, especially as it pertains to small clients."
"It has a variable pricing scheme."
"The product’s pricing is reasonable."
"There are no separate licensing costs we pay for since it is included in the plan we purchase."
"The pricing is good and manageable."
"AWS WAF has reasonable pricing."
"I rate the tool's pricing an eight out of ten."
"It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee."
"The product provides very good prices to customers. The price is set well and offers great value for money."
"FortiWeb Web Application Firewall's pricing is suited for small or medium organizations."
"This product offers two pricing options: a standard package and an advanced package."
"FortiWeb has a good presence because of its price."
"I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price."
"FortiWeb Web Application Firewall is not expensive."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
823,795 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
7%
Financial Services Firm
7%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
8%
Government
5%
Financial Services Firm
14%
Comms Service Provider
11%
Manufacturing Company
11%
Computer Software Company
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapes...
What needs improvement with FortiWeb Web Application Firewall (WAF)?
For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting. T...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Information Not Available
Find out what your peers are saying about AWS WAF vs. FortiWeb Web Application Firewall (WAF) and other solutions. Updated: December 2024.
823,795 professionals have used our research since 2012.