


Fortinet FortiWeb and Check Point CloudGuard WAF compete in the web application firewall category, with Check Point CloudGuard WAF having an advantage due to its scalability and advanced AI-driven features that enhance real-time threat detection.
Features: Fortinet FortiWeb is known for its integration within the Fortinet Security Fabric and features such as application control, web filtering, SSL offloading, and virtual patching. It supports a wide array of Fortinet products. Check Point CloudGuard WAF offers robust API integration, seamless deployment across cloud environments, and uses machine learning for real-time threat detection. Its scalability and AI-driven capabilities ensure comprehensive threat prevention while reducing false positives.
Room for Improvement: Fortinet FortiWeb could improve integration with non-Fortinet products, enhance DDoS protection, and refine the user interface. Users report occasional bugs in new releases. Check Point CloudGuard WAF users suggest better documentation and real-time monitoring improvements, highlighting periodic technical support delays and a need for more visibility features.
Ease of Deployment and Customer Service: Fortinet FortiWeb is mainly deployed on-premises with some hybrid cloud options, benefiting from feature integration within the Fortinet ecosystem. Technical support reviews are mixed regarding responsiveness and expertise. Check Point CloudGuard WAF offers versatile deployment across public and private cloud environments, suitable for hybrid setups, with customer service considered strong, though some users call for enhanced technical support infrastructure.
Pricing and ROI: Fortinet FortiWeb is seen as cost-effective with straightforward licensing and a good ROI, particularly within the Fortinet ecosystem. Check Point CloudGuard WAF has higher pricing, justified by its features and capabilities, with users noting cost savings through bundled features despite some finding the cost less competitive. Both solutions demonstrate good ROI, with Fortinet users citing savings from reduced maintenance, while Check Point users express satisfaction with performance relative to initial costs.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
When we are attacked, we can understand how important the solution is.
When you migrate to the cloud, it feels like saving 90% of your time.
Most of the operations happen in the background, so I do not spend much time on it.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
They need to increase the number of people for 24/7 support.
They were responsive even before we committed to buying their solution.
I also received full technical support, especially during the implementation.
Their support is truly exceptional when I compare it with similar large-sized companies.
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
If I need to scale, I open a Whatsapp group with the director and the team, and we quickly proceed to do so.
They have sufficient resources, and there are no challenges from a scalability perspective.
Check Point CloudGuard WAF's scalability is very good.
You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
It is very stable.
It is very stable, never crashing or giving me an error that I can see.
I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.
We have not faced any significant issues during deployments.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
The provider could improve by providing better guidance and support during the configuration process.
Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
A machine learning-based adaptive mode could help the WAF learn over time and auto-tune policies.
If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.
Fine-tuning is a room for improvement in Fortinet FortiWeb.
After the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer.
It is more expensive than f5, where we purchased everything as bundles, and Check Point costs more, but it is worth the money.
It is less costly than Cloudflare, Fortinet, and other vendors.
I know that its price is relatively expensive compared to other products but it gives benefits that are worth it.
For VM machines, the price increases based on CPU configurations of 2, 4, or 8 CPUs.
Most security products charge less at the time of purchase because of competition, but when we go to renewals, the prices become very high.
Fortinet FortiWeb is cost-effective compared to solutions like F5.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
Upon implementation and evaluation with third-party penetration testing, it meets rigorous security standards required for dealing with financial institutions.
It can protect against zero-day attacks and hidden anomalies.
The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.
Fortinet FortiWeb has positively impacted my organization because most of our servers and applications are secure from hackers and other security threats.
Fortinet's pricing is way more competitive than Cisco or Palo Alto.
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiWeb | 7.5% |
| Cloudflare Web Application Firewall | 5.4% |
| Check Point CloudGuard WAF | 2.6% |
| Other | 84.5% |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 34 |
| Midsize Enterprise | 20 |
| Large Enterprise | 19 |
| Company Size | Count |
|---|---|
| Small Business | 60 |
| Midsize Enterprise | 27 |
| Large Enterprise | 36 |
Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting over 27 Million websites. Suspicious requests can be blocked, challenged or logged as per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premise or in the cloud. Analytics and Cloudflare Logs enable visibility into actionable metrics for the user.
Check Point CloudGuard WAF offers advanced security for web applications and APIs with features such as intrusion prevention, bot prevention, and AI-driven threat detection, ensuring organizations achieve high-level protection and efficient security management.
Check Point CloudGuard WAF integrates with APIs, providing a seamless security enhancement while reducing false positives. Its scalability supports rapid deployment, valuable for companies aiming to secure resources in clouds like AWS and Azure. Enhanced threat prevention, comprehensive compliance support, and advanced threat protection methods such as SQL injection and cross-site scripting prevention are key strengths. Despite its robust capabilities, there are opportunities for improvement, such as lower costs, improved third-party tool integration, and a more intuitive interface to enhance usability.
What are the key features of Check Point CloudGuard WAF?Check Point CloudGuard WAF is predominantly applied within industries requiring stringent security standards, such as financial services, healthcare, and e-commerce. Its deployment strengthens the defense of critical APIs, facilitates compliance, and supports efficient multi-cloud security management, aligning well with evolving industry demands.
Fortinet FortiWeb is a Web Application Firewall (WAF) that protects your web applications and APIs from attacks targeting known as well as unknown vulnerabilities. As the surface of your web applications evolves with each change of existing features and deployment of new features, your APIs are left exposed. Fortinet FortiWeb provides the board protection capabilities required to protect web applications without sacrificing performance or manageability.
Fortinet FortiWeb is an automatic, advanced multi-layer solution that provides secure protection by discerning irregular behavior and distinguishing between malicious and benign anomalies. In addition, the approach delivers powerful bot mitigation capacities which authorize harmless bots to connect while blocking malicious bot activity securely. Regardless of where an application is hosted, Fortinet FortiWeb will safeguard business applications by providing deployment options, such as virtual machines, hardware appliances, and containers that can be deployed in the data center, cloud environments, or in the cloud-native SaaS solution.
Fortinet FortiWeb Features and Benefits
APIs and web applications have become integral to the rising demand for business-critical applications. Now more than ever, businesses are in need of an automatic firewall that will provide them with security, without sacrificing performance or reliability. Fortinet FortiWeb offers a variety of features and benefits, including:
Reviews from Real Users
Fortinet FortiWeb offers an industry-leading Web Application Firewall, and users are satisfied with it for a number of reasons, including the ability to control everything from the dashboard and the PCI-compliant reports it offers.
Carlos P., director of business and digital transformation at SERNIVEL3, notes, "You have the ability to control everything from one single dashboard."
A director at a tech service company, says, "Banks have to be compliant with PCI and other things, and FortiWeb is absolutely amazing in terms of providing these reports. Otherwise, they will have to spend a lot of time on them."
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.