Try our new research platform with insights from 80,000+ expert users

F5 Advanced WAF vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
F5 Advanced WAF
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
67
Ranking in other categories
Web Application Firewall (WAF) (2nd)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
94
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Ahmed Moamen - PeerSpot reviewer
Protects applications with versatile authentication features
F5 offers a versatile solution that can be integrated with APM in cases where integration with an external IDB is needed. It is useful for authentication backup if the on-prem directory service is unavailable. Additionally, its WAF functionality is valuable for protecting applications from attacks. It is a versatile and strong solution that's easy to understand and deploy.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Easier http to https redirect using page rules"
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"The technical support is good."
"The attacker won't have details since my public IP is anonymous. It offers us good privacy."
"I like Cloudflare's application gateway and DDoS protection."
"The most valuable feature of Cloudflare DNS is its global reach and it is always evolving."
"Centralized, full-featured DNS."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"The most valuable features of F5 Advanced WAF are SSL uploading, signature, and anomaly detection. It is overall a high-quality solution."
"The most valuable features of F5 Advanced WAF are the easy identification of events and customization. We can pinpoint our settings."
"The solution's most valuable features include application DDoS protection, bot blocking, and HTTP header verifications."
"The solution isn't too expensive. The license allows you to license what you need and leave out what you don't need."
"I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode."
"The most valuable features of F5 Advanced WAF are the balancer and you can change policies very easily."
"It also has antivirus and DDoS mitigation capabilities. We have enabled these features."
"Customers find the load balancer feature as the most valuable."
"The solution's most valuable feature is its security profile."
"The ability to configure multiple policies for different requirements is a strong feature of Fortinet FortiWeb."
"When it comes to blocking unknown threats and attacks, I would give it the highest score possible. We first started using AWS and its Web Application Firewalls. That was okay, but it was quite a manual process to keep it up to date, whereas Fortinet is always up to date, and the default rules or the modules that you can turn on are very easy to use."
"Other than the additional security with exploit protection, we have simpler certificate handling, as we can keep internal servers using internal certificates continuously distributed and updated by Active Directory Group Policy, while the public certificates become updated only in a single place, FortiWeb itself."
"The most valuable feature is the web application firewall (WAF)."
"The GUI makes it easy to scale in terms of learning and utilization."
"FortiWeb's ease of deployment is what we liked the most about it. Implementing FortiWeb was extremely fast and easy, which was a significant advantage. It comes with several preconfigured rule sets and templates."
"The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities."
 

Cons

"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"If they improve on the placement of their data centers, it would be better. I'm living in a remote area. I would like to connect to them without any kind of lag."
"The documentation could improve for Cloudflare DNS."
"The solution could be more user-friendly."
"Cloudflare should add more documentation and pricing to the cloud version."
"I think the APIs are a little bit hard for us to work with. The APIs could be more open so that we could integrate better with our SolarWinds or our monitoring solution."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"I would like to see improved features in the F5 Advanced WAF solution, especially with a focus on enabling Kubernetes fully."
"The reporting portion of F5 Advance WAF is not great. They need to work out something better, as it is very basic. You only see the top IPs, I think there is more they can offer."
"The BIG-IQ is supposed to centralize the management for all of the boxes but it's not very effective."
"You have to buy another module with an extra license, to have the authentication feature."
"The GUI interface can be confusing due to similar-looking tabs for policy building, traffic learning, and event logs."
"For me, an area for improvement in F5 Advanced WAF is the reporting as it isn't so clear. The vendor needs to work on the reporting capability of the solution. What I'd like to see in the next release of F5 Advanced WAF is threat intelligence to protect your web application, particularly having that capability out-of-the-box, and not needing to pay extra for it, similar to what's offered in FortiWeb, for example, any request that originates from a malicious IP will be blocked automatically by FortiWeb. F5 Advanced WAF should have the intelligence for blocking malicious IPs, or automatically blocking threats included in the license, instead of making it an add-on feature that users have to pay for apart from the standard licensing fees."
"F5 Advanced WAF could improve the reporting. It's a bit difficult to populate, them. If you're not so familiar with the functions, such as where to find the logs and other settings."
"Users would like to have an additional IP intelligence license to handle this within WAF itself without needing to engage with the SOC team."
"The interface could have the interdependent elements arranged sequentially and wizards that go through most common deployment actions."
"We use Kubernetes, so I would like to have a plugin to configure FortiWeb Cloud automatically using Kubernetes Ingress. That would reduce the complexity of setting up an Ingress object in Kubernetes. Some competing solutions help you configure Ingress and Kubernetes automatically."
"We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
"They could integrate some kind of machine learning and AI facilities to automate workflows."
"We have had problems with deployments where we've had to contact technical support to resolve them."
"FortiWeb does not exist in a cloud-based form. Its only available for deployment as a virtual appliance on AWS and Azure IaaS platforms. Because of the trend to WAF environments, it would be good to have it as a SaaS. Also, FortiWeb would be more competitive if it combined WAF and DDoS protection."
"Their documentation is fairly complete, but it's sometimes a little bit difficult to search for exactly what you're looking for to resolve an issue. There have been times when we've gone to try to search for areas that we needed to get information on, and it has not always been extremely clear exactly how a particular thing needs to be set up."
"It costs too much."
 

Pricing and Cost Advice

"So far I use free tier and happy with it. You can subscribe to business package if needed."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The pricing is too high."
"The cost is slightly above average."
"The way we deployed it, I would rate it a four out of five in terms of pricing."
"F5 Advanced WAF is not a cost-effective solution. Although they are attempting to reduce prices with their VE and cloud options, they are more expensive than other solutions. The solution is more expensive on average."
"Licensing fees for this solution are paid on a yearly basis."
"There is a perpetual license that comes with your hardware. There is also an additional fee for support."
"It's more expensive than other solutions and depending on the modules, there can be additional fees."
"After buying the program, you just pay for the support every year."
"The pricing is pretty good. We do pass a lot of traffic through our API servers. Something like 100 gigs of web traffic is a fair amount for reduced JSON API calls, but the cost is $50. For that peace of mind, we have thousands and thousands of customers that are protected by that $50, so it's a no-brainer."
"The pricing is in the middle. I would rate the pricing a five out of ten. It feels like a justified cost for the features."
"FortiWeb can be purchased in VM mode for a lower price and the same features."
"There are no costs in addition to the standard licensing fees."
"The maintenance fee for this product could be improved."
"We are on an annual license for this solution and the price is approximately €100."
"The license cost depends on the size of the box or the size of the solution. It can go from €200 Euros to a few hundred thousand Euros a year depending on your size."
"It is fine now. We had to earlier negotiate the price."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
825,399 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
7%
Computer Software Company
15%
Financial Services Firm
15%
Government
8%
Manufacturing Company
6%
Educational Organization
43%
Computer Software Company
9%
Financial Services Firm
8%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about F5 Advanced WAF?
It's a fairly easy-to-use and user-friendly tool. My administrators and team also like its ability to customize the r...
What is your experience regarding pricing and costs for F5 Advanced WAF?
The pricing and support service levels affect response times from customer service, depending on whether the support ...
What needs improvement with F5 Advanced WAF?
The main improvement needed is related to IP intelligence. Once we start receiving traffic from repetitive IP address...
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing of Fortinet FortiWeb is affordable and competitive.
What needs improvement with Fortinet FortiWeb?
I see no room for improvement at the moment.
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
MAXIMUS, Vivo, American Systems, Bangladesh Post Office, City Bank
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about F5 Advanced WAF vs. Fortinet FortiWeb and other solutions. Updated: December 2024.
825,399 professionals have used our research since 2012.