Try our new research platform with insights from 80,000+ expert users

Fortinet FortiWeb vs NGINX App Protect comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.5
Number of Reviews
93
Ranking in other categories
Web Application Firewall (WAF) (4th)
NGINX App Protect
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
Web Application Firewall (WAF) (15th), Container Security (22nd), API Security (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.
Tomaz Sobczak - PeerSpot reviewer
Signature-based detection, DOS protection, and bot protection
NGINX App Protect is easier to automate and configure, or manage from an API. This is good for securing applications. However, it's not suitable for more complex tasks. NGINX App Protect positively impacted performance changes. There's a cache or it works like a proxy, so it can speed up applications. It can also offload some functions from servers, which NGINX can handle faster.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool is user-friendly."
"Centralized, full-featured DNS."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"The web application firewall brought us good security and a view of the accesses/blocks of the entire domain and subdomain that were accessed both by region (country) and IPs."
"From what I've seen so far, there are no negatives to report as of yet"
"Cloudflare allows us to self-host services such as Rocket.Chat and Node-RED, in high-availability mode, thanks to round robin DNS which allows us to share one hostname between our two locations."
"Smaller businesses have seen great ROI due to the low investment and strong performance."
"FortiWeb offers a good price for the marketplace. In the Sri Lankan market, it's hard to find high-end products that can match FortiWeb's pricing. For high-end solutions, the price is always extremely high."
"I like FortiWeb's usability and ease of configuration. It's simple to configure rules and exceptions inside the attack log. We block everything by default. If something isn't working, we ask the system admin to adjust the template and add exceptions."
"FortiGate is a stable product."
"It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs."
"The most valuable feature is ease of use."
"It is cost-effective compared to other solutions."
"We can block access using the IP address so no one can connect to our web server or website using the real IP."
"The most valuable feature of this solution is Fail-Open."
"It's very easy to deploy."
"The tool's most valuable feature is the OWASP certification. Additionally, the tool's ability to enforce strong passwords and OTP within minutes is impressive. With its analytics and recommendations, it is a very good solution."
"The tool is not complex and is very user-friendly."
"The most valuable feature of NGINX App Protect is its open source."
"NGINX App Protect has complete control over the HTTP session."
"I tested specific features and evaluated the solution against the Web Application Firewall. I conducted research to test different detection percentages. I did not use it directly for protection but for evaluation purposes."
"The most valuable feature of NGINX App Protect is the reverse proxy."
"The most valuable feature of NGINX App Protect is its flexibility."
 

Cons

"I would like Cloudflare to offer a dedicated account manager for large enterprise clients like us."
"Latencies are always a problem."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"It should confirm audit findings of the assigned area with auditees to ensure that the audit conclusions are based on an accurate understanding of the issues."
"There should be a specific price list for enterprise-level customers."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"The timing aspect can lead to it being considered overpriced. This is a particular concern we have with Cloudflare, as they may struggle with accurately detecting the client."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"The product's scalability could be better."
"A user interface or dashboard for troubleshooting is needed."
"It can be better with web application firewalls."
"When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it."
"F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented."
"I see no room for improvement at the moment."
"Fortinet FortiWeb could improve data integration."
"Its threat intelligence capabilities may not be as advanced as some competitors."
"The setup of NGINX App Protect is complex. The full process took one week to complete. Additionally, we had to change the network infrastructure platform which took one month."
"The product's user interface is an area with shortcomings as it can be quite confusing for users, making it an area where improvements are required."
"NGINX App Protect would be improved with integration with Shape and F5 WAF, which would make it easy for users to manage all their web application security with a single solution."
"NGINX App Protect could improve security."
"I encountered issues with NGINX App Protect while trying to upgrade custom rules."
"It's challenging if you need to go for a high throughput."
"Its technical support could be better."
"The integration of NGINX App Protect could improve."
 

Pricing and Cost Advice

"The cost primarily depends on the size of the organization."
"There are no additional costs beyond the standard licensing fees."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The price is reasonable."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"We don't have any issues with the price."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"When I use any other firewall, I have to take a license. It could be a perpetual license or subscription-based. In both cases, we have to pay some amount in advance, whereas in the case of FortiWeb, when using it as a service, I am paying half a dollar only for the domain name, and then I am paying based on the traffic or the number of requests."
"The pricing is average; the product is neither particularly expensive nor affordable."
"​The pricing is reasonable."
"There are no costs in addition to the standard licensing fees."
"The price of Fortinet FortiWeb is expensive in our Ethiopian currency."
"If one is very cheap and ten is very expensive, I rate the product price as three or four."
"The product is expensive. I rate the pricing a ten out of ten."
"The costs are standard. We pay around $1,600 yearly."
"NGINX is not expensive."
"There are not any additional costs we had to pay to use NGINX App Protect."
"There is a license needed to use NGINX App Protect."
"The price of NGINX App Protect is not much different from the products that fall under the leader category of Gartner Magic Quadrant."
"Our licensing costs are about $40,000 a year."
"The product's price is high."
"The licensing fees for this solution are pretty expensive for what it does, but there is no alternative."
"The price of NGINX App Protect is approximately $3,000 annually. All of our licenses are observed by a managed service partner."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
823,795 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
7%
Financial Services Firm
7%
Educational Organization
43%
Computer Software Company
9%
Financial Services Firm
8%
Government
4%
Computer Software Company
20%
Financial Services Firm
13%
Healthcare Company
6%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing of Fortinet FortiWeb is affordable and competitive.
What needs improvement with Fortinet FortiWeb?
I see no room for improvement at the moment.
What needs improvement with NGINX App Protect?
The product's price is high, making it an area of concern where improvements are required. The tool's licensing model...
 

Also Known As

Cloudflare DNS
No data available
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Information Not Available
Find out what your peers are saying about Fortinet FortiWeb vs. NGINX App Protect and other solutions. Updated: December 2024.
823,795 professionals have used our research since 2012.