Try our new research platform with insights from 80,000+ expert users

Azure Web Application Firewall vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Azure Web Application Firewall
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
13
Ranking in other categories
Web Application Firewall (WAF) (13th), Microsoft Security Suite (20th)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
94
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Mano Senaratne - PeerSpot reviewer
Comprehensive suite simplifies configuration while frequent updates require management
Mainly, it comes with the complete suite of Microsoft services. I can use it in conjunction with the best options and other features that come with it. Configuration is much easier than using different platforms. For example, if I have hosted the application in AWS and am using the Application Firewall from Azure, there are certain additional steps to follow when configuring them. With Microsoft, everything is within a single suite, making it easier to configure and plan. Azure continually upgrades platforms and sends us messages to upgrade to the next version, simplifying the process. Later, it's much easier if I want to upgrade the software platform, scale it, or move it to a different application host as the whole suite comes together. The return on investment is good. If I am doing applications for clients, I can invoice them for better costs. Most applications that I run and use have a better return on investment.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"The solution is stable, and the DNS servers are simple to use."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"The solution offers the flexibility to control configuration rules."
"The most valuable feature is its usability."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"New and innovative way to protect the client's data."
"Cloudflare has many features."
"The integration it has with GitHub is great."
"I can only strongly recommend using the Azure Web Application Firewall."
"It's quite a stable product and works well with Microsoft products."
"The most valuable feature of Azure Web Application Firewall is its ability to filter requests and block false positives by using custom rules and the OWASP rule set."
"It is almost impossible to access these assets from outside, requiring a very skilled attacker to obtain asset tokens of a customer using Azure."
"We have found the most valuable features to be the web application, minimal skills required for management, control through policies, and automation."
"The return on investment is good."
"The solution has good dashboards."
"The ease of configuration is valuable. We have Azure WAF, we have OCI WAF, and we also have Cloud Armor for GCP, but their configuration isn't very easy. It's pretty simple in FortiWeb, and we can enable or configure whatever we want."
"The GUI is user-friendly and it's easy to understand how to manage it."
"Technical support is very good."
"I like FortiWeb's usability and ease of configuration. It's simple to configure rules and exceptions inside the attack log. We block everything by default. If something isn't working, we ask the system admin to adjust the template and add exceptions."
"FortiGate is a stable product."
"FortiWeb is easy to operate with a reasonably high level of protection. FortiWeb provides multiple deployment options with a physical or virtual (FortiWeb-VM) appliance, and acts either as a reverse/transparent proxy or out-of-band. It is also available on AWS and Azure."
"The most valuable feature is the attack signature and machine learning."
"Also, if you serve files or you accept files with your server, Fortiweb has built-in antivirus. The Fortinet product family also provides good IP intelligence (botnet C&C, etc.)."
 

Cons

"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"Cloudflare's console should be made more user-friendly."
"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"Integration involving API with other products could be more user-friendly."
"Some Azure applications, like the web application firewall, require a certain level of SKU for hosting setup. The basic setup does not allow me to use the web application firewall and other additional services."
"The knowledge base could be improved."
"In Brazil, we have some problems with the phone service that affect our connection with the cloud. However, it isn't common."
"There is a need to be able to configure the solution more."
"Azure WAF should not be deployed in the middle of the traffic."
"From a reporting perspective, they could do more there."
"From my point of view, there is no need for improvement."
"The management can be improved."
"Fortinet FortiWeb is not scalable. You'll need more budget to change the hardware."
"We have had problems with deployments where we've had to contact technical support to resolve them."
"I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted."
"Integration and learning about attacks. I would improve these areas by making FortiWeb integrate with other network technologies and feedback from multiple platforms."
"It is not entirely user-friendly."
"The tool's WAF or web application firewall area has certain aspects that can be improved."
"HA Architecture needs improvement. I would improve it by working on AP HA."
"The solution could improve its ease of use and add more advanced WAF features in future releases."
 

Pricing and Cost Advice

"We are using the free version."
"We don't have any issues with the price."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The price is reasonable."
"The product's pricing is minimal compared to other products."
"The tool is a premium product, so it is very expensive."
"The price of the solution is expensive."
"We are using the free tier of the solution."
"The price is reasonable. It is approximately $2,000 US per month."
"Azure WAF has price advantages over other WAF solutions. The pricing model is flexible because you pay on a scale based on the level of protection you need."
"I give the pricing a nine out of ten."
"We have an enterprise agreement with Microsoft and the pricing is good."
"The price is for this solution is fair and there is a license needed."
"The price of the solution depends on your architecture and how you manage it. You can control the cost in Azure quite well. The costs do not directly correlate to expenses in the features we are using."
"When I use any other firewall, I have to take a license. It could be a perpetual license or subscription-based. In both cases, we have to pay some amount in advance, whereas in the case of FortiWeb, when using it as a service, I am paying half a dollar only for the domain name, and then I am paying based on the traffic or the number of requests."
"Previously, for each project, the cost was $800 to $1,000 per application. Now, it's $100 to $120. For some of the applications, there is a 90% reduction, and for some of the applications, there is a 50% reduction. We're paying only $500 to $600."
"It is fine now. We had to earlier negotiate the price."
"The maintenance fee for this product could be improved."
"The price is competitive."
"FortiWeb is more expensive than some competing products."
"It's an expensive solution, although there are no additional costs."
"The license cost depends on the size of the box or the size of the solution. It can go from €200 Euros to a few hundred thousand Euros a year depending on your size."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
842,296 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
13%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
19%
Financial Services Firm
12%
Manufacturing Company
10%
Government
6%
Educational Organization
41%
Computer Software Company
9%
Financial Services Firm
7%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What is your experience regarding pricing and costs for Azure Web Application Firewall?
The pricing is okay at the moment. Sometimes, when opting for a higher SKU, it's not the WAF itself that's costly but...
What needs improvement with Azure Web Application Firewall?
While using it, I identified certain areas where it would have been good to have additional features. Right now, I ca...
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
I would rate the licensing cost as seven out of ten, considering it good value for money. The price is affordable and...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in the portability on multi-cloud environments. Enhanced DDoS integration to make Forti...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Azure Web Application Firewall vs. Fortinet FortiWeb and other solutions. Updated: March 2025.
842,296 professionals have used our research since 2012.