


Fortinet FortiWeb and F5 Advanced WAF are competitors in the web application firewall market, each with strengths appealing to different business needs. Fortinet FortiWeb offers a more economical package with machine-learning capabilities, attracting enterprises focused on integrated solutions and cost-effectiveness. F5 has an edge in stability and detailed threat detection, appealing to enterprises requiring top-tier security architecture, despite higher costs.
Features: Fortinet FortiWeb integrates antivirus and VPN support, application control, and web filtering with robust layer-7 server load balancing and Fortinet product integration. It uses AI for enhanced threat detection. F5 Advanced WAF provides advanced threat detection and load balancing, support for OWASP top 10 threat protection, positive and negative security models, and bot detection, focusing on comprehensive security architecture.
Room for Improvement: Fortinet FortiWeb users report issues with frequent patch bugs and complex upgrades and express a need for cloud-hosted options and better DDoS protection. F5 Advanced WAF could improve in pricing, cloud service integration, and reporting features, and enhance its bot protection and automatic learning capabilities to reduce false positives.
Ease of Deployment and Customer Service: Both Fortinet FortiWeb and F5 Advanced WAF deploy effectively across on-premises and cloud environments. Fortinet offers wider deployment choices with strong hybrid cloud capabilities, although some users mention delays in support. F5 is known for high support costs despite its quality, with a stable historical reputation, but Fortinet FortiWeb might offer faster resolutions due to its consolidated support structure.
Pricing and ROI: Fortinet FortiWeb is praised for its cost-effectiveness, with a simple licensing model and competitive pricing suitable for various enterprises. It provides a solid ROI compared to the more premium F5 Advanced WAF, which commands a higher price justified by its extensive features and capabilities, yet both solutions report favorable returns on investment.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
Time savings in daily operations come from the automatic learning and signature update reducing the need for constant manual rule management, allowing the security and network teams to spend significantly less time handling false positive application-related escalations.
Subscription models offer clearer ROI due to a more competitive pricing scheme.
The amount of attacks it protects against is immense, more than F5 Advanced WAF itself costs.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
Both response time and availability need to be improved.
If there is a bug, the support is usually understanding and resolves issues.
I have interacted with F5's support, and while I have no major complaints, they could improve.
Their support is truly exceptional when I compare it with similar large-sized companies.
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
I can run it in HA mode or even divide the traffic volume to the number of instances that I have based on their resource sizing.
You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
F5 Advanced WAF has been very reliable and consistent for us; in our on-premise enterprise setup, it has been stable and predictable in day-to-day operations without any unexpected crashes or WAF-related downtime in production.
F5 Advanced WAF is pretty stable.
We have not faced any significant issues during deployments.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
Deployment training for F5 Advanced WAF is lacking and restricts growth by being inaccessible and costly for partners.
Overall, these are not blockers, merely enhancement opportunities, and once tuned, F5 Advanced WAF is very stable and reliable; improving usability, reporting, and onboarding would make it even more effective for larger environments.
There is excellent clarity in the LTM and the WAF.
If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.
Fine-tuning is a room for improvement in Fortinet FortiWeb.
After the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer.
Licensing is capacity-driven, so you need careful planning based on traffic volume and use cases, and adding features such as Bot Protection impacts costs; once licensing is clear and sized correctly, there are no surprises.
Subscription models have competitive pricing, while perpetual licenses involve an upfront higher cost.
The price is affordable and satisfactory.
For VM machines, the price increases based on CPU configurations of 2, 4, or 8 CPUs.
Most security products charge less at the time of purchase because of competition, but when we go to renewals, the prices become very high.
Fortinet FortiWeb is cost-effective compared to solutions like F5.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
The Advanced Attack Signature database is very strong and regularly updated, effectively blocking SQL injections, cross-site scripting, command injections, and file inclusion attacks while allowing selective enabling or disabling of signatures to avoid blocking genuine traffic.
The perpetual license, despite an initial higher cost, lacks transparency regarding support expiration.
It contains the logic of both negative and positive security combined.
Fortinet FortiWeb has positively impacted my organization because most of our servers and applications are secure from hackers and other security threats.
Fortinet's pricing is way more competitive than Cisco or Palo Alto.
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiWeb | 6.5% |
| F5 Advanced WAF | 6.0% |
| Cloudflare Web Application Firewall | 4.7% |
| Other | 82.8% |

| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 26 |
| Midsize Enterprise | 15 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 60 |
| Midsize Enterprise | 27 |
| Large Enterprise | 36 |
Cloudflare Web Application Firewall integrates DDoS protection, load balancing, and firewall capabilities. Its ease of use, configurability, and robust security measures make it a versatile choice for protecting web applications.
Cloudflare Web Application Firewall provides a comprehensive defense against threats with advanced reporting and robust security measures. It includes DNS integration, rate limiting, and extensive rule sets, all within a SaaS model that allows API configurability. Users value its caching, scalability, and pricing, although enhancements are needed in rate-limiting and third-party integration. Improvements in customer support, especially in India, real-time controls, and user documentation are also desired. Users seek a more intuitive dashboard, better log management, and improved alert systems, along with multitenancy capabilities and enhanced reporting.
What are the key features of Cloudflare Web Application Firewall?Cloudflare Web Application Firewall finds application in industries like banking and retail by acting as a comprehensive security gateway, managing authentication and authorization while protecting web applications from malicious Layer 7 traffic. It also implements load balancing, CDN, and zero-trust policies, supported by advanced reporting, analytics tools, and threat scoring to meet specific industry needs.
F5 Advanced WAF delivers robust web security with features like signature-based threat protection and behavior analysis, ensuring app stability and security.
F5 Advanced WAF integrates advanced security with functionalities such as SQL injection defense and real-time threat intelligence. It enhances security for applications with load balancing, bot detection, and DDoS protection alongside comprehensive attack monitoring capabilities. Popular among diverse sectors, its usability and easy integration make it a practical choice by providing a stable security infrastructure across both on-premises and cloud environments.
What are the key features?Particularly relevant in banking and financial services, F5 Advanced WAF safeguards applications from threats like SQL injections and DDoS attacks, ensuring compliance and API security. Its capabilities are leveraged for both load balancing and application defense, offering a versatile deployment model suited for protecting critical infrastructure in competitive and demanding industries.
Fortinet FortiWeb provides advanced web application protection, using AI-driven threat detection and seamless integration with Fortinet products, ensuring robust security and easy management. It's favored for its scalability in protecting websites, mobile apps, and APIs from threats like SQL injection.
Fortinet FortiWeb offers robust web application security with features like machine learning-driven threat detection, load balancing, and OWASP protection. Its comprehensive security measures include web traffic filtering and DDoS protection, making it ideal for securing APIs and web servers. Cost-effectiveness and easy deployment further enhance its appeal as it serves banking, e-commerce, and industrial sectors. Areas needing enhancement include load balancing capabilities, comprehensive documentation, and improved support response times, addressing user-reported issues such as false positives and integration challenges. Documentation for cloud deployment is crucial for enhanced logging and performance stability.
What are Fortinet FortiWeb's Key Features?Companies across banking, e-commerce, and financial sectors implement Fortinet FortiWeb for its comprehensive security features in protecting web applications from SQL injection and cross-site scripting. Its use as a web application firewall provides essential protection and load-balancing capabilities, ensuring compliance with standards like PCI DSS in cloud environments and industrial settings.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.