


Fortinet FortiWeb and Prisma Cloud by Palo Alto Networks compete in the field of web application security and cloud security. Based on feature offerings, Fortinet FortiWeb seems to have the upper hand with its integration capabilities and comprehensive web application security features.
Features: Fortinet FortiWeb stands out with features like application control, SSL offloading, and advanced machine learning capabilities for threat detection. Additionally, it excels in virtual patching and server load balancing, alongside its seamless integration within Fortinet's security ecosystem. On the other hand, Prisma Cloud provides extensive cloud security posture management, focusing on workload protection and data security across multi-cloud environments. Its automated forensics and dynamic identity management enhance its functionality for cloud-centric enterprises.
Room for Improvement: Fortinet FortiWeb could improve by boosting hardware robustness, enhancing threat intelligence, and supporting modern applications. Its SaaS offerings and integration with external platforms could also expand. Prisma Cloud could optimize automation, refine UI usability, and focus more on API security. Considerations on flexible pricing models could cater better to smaller enterprises.
Ease of Deployment and Customer Service: Fortinet FortiWeb is noted for its deployment across hybrid and cloud environments, although on-premise setups can be complex. It has an extensive support network that receives varied feedback based on location. Prisma Cloud benefits from seamless hybrid cloud integration and generally positive support services but could enhance onboarding processes to improve support efficiency further.
Pricing and ROI: Fortinet FortiWeb offers cost-effective solutions within its subscription model, especially when combined with other Fortinet products, providing tangible ROI through infrastructure cost savings. Prisma Cloud, while considered premium, justifies its pricing with comprehensive cloud capabilities, structured around scalable service usage. Its pricing may deter smaller organizations, although it appeals significantly to larger enterprises with cloud-first strategies.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
It eliminates the need for additional hardware, making it a financially and technically sound investment.
Reputation and data security are the two most important things to a financial institution.
We may have prevented a security breach with remediation of the findings.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
Their support is truly exceptional when I compare it with similar large-sized companies.
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.
They can respond with technical documentation or pass on the case to the next level because it requires the development of a new feature or changing a feature due to a bug.
Anywhere we raise a tech case, they revert back within an hour.
I would give them 10 out of 10.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
Scalability-wise, I rate the solution a nine out of ten.
We haven't had any issues scaling the solution.
There aren't any limits to Prisma Cloud's scalability.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
We have not faced any significant issues during deployments.
I would rate it a ten out of ten for stability.
Most of the time, when the client requires data, it is not available.
The cloud environment is dynamic, so the tool must be dynamic.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.
Fine-tuning is a room for improvement in Fortinet FortiWeb.
After the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer.
Prisma Cloud is an excellent tool.
We could have deployed the runtime monitoring with Prisma Cloud by Palo Alto Networks, but within our organization at our company, it was very difficult to find who would be the owner for the alerts.
Even though documentation was available, it took a while for a new person to understand what integration meant, what will be achieved after the integration, or how the integration needed to be done on the Azure or AWS side.
For VM machines, the price increases based on CPU configurations of 2, 4, or 8 CPUs.
Most security products charge less at the time of purchase because of competition, but when we go to renewals, the prices become very high.
Fortinet FortiWeb is cost-effective compared to solutions like F5.
The cost was not on the higher side.
If you are using a single tool like Prisma Cloud, with a single license, you can monitor all environments, such as Google Cloud, Azure, AWS, and Oracle Cloud.
Prisma's price is pretty high, but it's a good product, and you get what you paid for, especially if you're working in a containerized environment.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
Fortinet FortiWeb has positively impacted my organization because most of our servers and applications are secure from hackers and other security threats.
Fortinet's pricing is way more competitive than Cisco or Palo Alto.
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
It provides a single pane of glass.
If I want to check how many of my S3s have encryption, I can write a Lambda function in Prisma Cloud and get that report.
Overall, the most valuable features for us in Prisma Cloud are those that provide visibility, ensure compliance with regulations, and help us align our on-premises servers and cloud environments with mandated security standards.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiWeb | 6.0% |
| Cloudflare Web Application Firewall | 4.7% |
| Prisma Cloud by Palo Alto Networks | 2.0% |
| Other | 87.3% |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 60 |
| Midsize Enterprise | 27 |
| Large Enterprise | 36 |
| Company Size | Count |
|---|---|
| Small Business | 37 |
| Midsize Enterprise | 22 |
| Large Enterprise | 56 |
Cloudflare Web Application Firewall integrates DDoS protection, load balancing, and firewall capabilities. Its ease of use, configurability, and robust security measures make it a versatile choice for protecting web applications.
Cloudflare Web Application Firewall provides a comprehensive defense against threats with advanced reporting and robust security measures. It includes DNS integration, rate limiting, and extensive rule sets, all within a SaaS model that allows API configurability. Users value its caching, scalability, and pricing, although enhancements are needed in rate-limiting and third-party integration. Improvements in customer support, especially in India, real-time controls, and user documentation are also desired. Users seek a more intuitive dashboard, better log management, and improved alert systems, along with multitenancy capabilities and enhanced reporting.
What are the key features of Cloudflare Web Application Firewall?Cloudflare Web Application Firewall finds application in industries like banking and retail by acting as a comprehensive security gateway, managing authentication and authorization while protecting web applications from malicious Layer 7 traffic. It also implements load balancing, CDN, and zero-trust policies, supported by advanced reporting, analytics tools, and threat scoring to meet specific industry needs.
Fortinet FortiWeb provides advanced web application protection, using AI-driven threat detection and seamless integration with Fortinet products, ensuring robust security and easy management. It's favored for its scalability in protecting websites, mobile apps, and APIs from threats like SQL injection.
Fortinet FortiWeb offers robust web application security with features like machine learning-driven threat detection, load balancing, and OWASP protection. Its comprehensive security measures include web traffic filtering and DDoS protection, making it ideal for securing APIs and web servers. Cost-effectiveness and easy deployment further enhance its appeal as it serves banking, e-commerce, and industrial sectors. Areas needing enhancement include load balancing capabilities, comprehensive documentation, and improved support response times, addressing user-reported issues such as false positives and integration challenges. Documentation for cloud deployment is crucial for enhanced logging and performance stability.
What are Fortinet FortiWeb's Key Features?Companies across banking, e-commerce, and financial sectors implement Fortinet FortiWeb for its comprehensive security features in protecting web applications from SQL injection and cross-site scripting. Its use as a web application firewall provides essential protection and load-balancing capabilities, ensuring compliance with standards like PCI DSS in cloud environments and industrial settings.
Prisma Cloud by Palo Alto Networks provides comprehensive cloud-native security solutions. It covers dynamic workload identity, automated forensics, and multi-cloud protection, ensuring robust security across diverse cloud platforms.
Prisma Cloud delivers advanced capabilities for managing cloud security across AWS, Azure, and GCP platforms. It offers dynamic workload identity creation, real-time monitoring, and seamless integration into CI/CD pipelines. With automation, centralized dashboards, and enhanced visibility, users effectively manage security misconfigurations and vulnerabilities. While optimizing cloud environments through runtime protection and compliance, Prisma Cloud faces challenges with its navigation, pricing, and limited automation capabilities. Users seek improvements in API security, role-based access controls, and documentation quality, emphasizing the need for enhanced customization and reporting features.
What are the important features of Prisma Cloud?
What benefits or ROI should users consider in reviews?
Industries like finance and telecom rely on Prisma Cloud for managing cloud security posture and container security. Teams utilize its capabilities across hybrid and multi-cloud settings to ensure compliance and robust threat protection. Features like misconfiguration detection and runtime monitoring are critical in promoting security objectives in these sectors.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.