Try our new research platform with insights from 80,000+ expert users

Fortinet FortiWeb vs Rapid7 Metasploit comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiWeb
Average Rating
7.8
Number of Reviews
90
Ranking in other categories
Web Application Firewall (WAF) (4th)
Rapid7 Metasploit
Average Rating
7.6
Number of Reviews
18
Ranking in other categories
Vulnerability Management (19th)
 

Mindshare comparison

Fortinet FortiWeb and Rapid7 Metasploit aren’t in the same category and serve different purposes. Fortinet FortiWeb is designed for Web Application Firewall (WAF) and holds a mindshare of 8.4%, up 7.4% compared to last year.
Rapid7 Metasploit, on the other hand, focuses on Vulnerability Management, holds 1.9% mindshare, down 1.9% since last year.
Web Application Firewall (WAF)
Vulnerability Management
 

Featured Reviews

Kacem CHAMMALI - PeerSpot reviewer
Apr 1, 2024
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.
Aqeel Junaid - PeerSpot reviewer
Mar 14, 2024
Helps find vulnerabilities in a system to determine whether the system needs to be upgraded
I've been using Rapid7 Metasploit to create vulnerabilities and test exploits. I can create malicious Word documents through the Rapid7 Metasploit framework for testing purposes. I can create a backdoor through the solution to test a web server or a vulnerable machine The most valuable features…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the big advantages of using Fortinet FortiWeb is all the Fortinet family solutions use the same user interface and logic. This makes it easy to use, configure, manage, and understand if you have used one of their solutions before or are wanting to implement other Fortinet solutions in the future. Additionally, all Fortinet solutions can be managed with one application called FortiManager."
"The solution has a very simple deployment."
"The most valuable feature is the web application firewall (WAF)."
"This product is very user-friendly."
"If I need something from tech support, I can get it answered within the hour."
"Banks have to be compliant with PCI and other things, and FortiWeb is absolutely amazing in terms of providing these reports. Otherwise, they will have to spend a lot of time on them."
"The most valuable feature of this solution is Fail-Open."
"It's the extra security that is the most valuable feature. You have insight into your traffic. There are some great insights into what utilities hackers are trying to exploit. It blocks a lot of stuff from the internet."
"The most valuable feature for us is the support for testing Linux-based web server components."
"I don't have any other tools like it, and I always use it when I'm doing a pen test. Metasploit is a great solution for penetration testing,"
"The greatest advantage of Rapid7 Metasploit is that it is the only system that can directly exploit vulnerabilities on the Metasploit platform."
"Rapid7 Metasploit is a useful product."
"It is scalable. It's in line with our needs."
"It contains almost all the available exploits and payloads."
"It allows us to concentrate solely on identified vulnerabilities without the hassle of additional setup."
"The Search Engineering feature is good."
 

Cons

"The upgrade process could be a bit smoother."
"The false positives are annoying.​"
"Maybe the load balancing options could be enhanced."
"The tool's WAF or web application firewall area has certain aspects that can be improved."
"It would also be helpful if they could introduce easier reporting. It's good to have those reports that go to C-level management, and Fortinet does provide some graphs, but if they went into some more detail, that would be great."
"The initial setup in our data center was somewhat complex."
"The solution could offer more integration opportunities."
"I would like to see more improvements with respect to threat intelligence."
"It is necessary to add some training materials and a tutorial for beginners."
"The solution is not user-friendly and has room for improvement."
"Rapid7 Metasploit could be made easier for new users to learn."
"Rapid7 Metasploit can add a GUI feature because it is only available online."
"If your company's patch is not up to date, but you have other detection or defense solutions such as endpoint detection and response and antivirus software, the product exploit may not work effectively. This is because its exploit database update process is slow and not real-time. For zero-day vulnerabilities or new security threats, relying on Rapid7 Metasploit alone may not be effective."
"Metasploit cannot be installed on a machine with an antivirus."
"Better automation capabilities would be an improvement."
"The open-source version has reporting limitations. You need to develop these capabilities yourself. Built-in reporting is an excellent feature for penetration testing, but it isn't a must-have. The solution could also cover more vulnerabilities. Metasploit has around 10,000 exploits in its library, but more is always better."
 

Pricing and Cost Advice

"Due to the situation in Iran with the sanctions, the price of this solution is very expensive."
"Keep a loose margin between your actual bandwidth and the product sizing when using hardware appliances. Only virtual machines are upgradable to larger sizes."
"All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500."
"There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four. I have not encountered any additional costs on my projects involving Fortinet FortiWeb."
"There are no costs in addition to the standard licensing fees."
"The license cost depends on the size of the box or the size of the solution. It can go from €200 Euros to a few hundred thousand Euros a year depending on your size."
"The solution is very inexpensive when compared to F5 Advanced WAF and Avi Networks but offers the same benefits."
"It's an expensive solution, although there are no additional costs."
"The pricing structure involves a one-time purchase cost of approximately twenty thousand dollars or euros for all customers."
"I use the open-source version of this product. Pricing is not relevant."
"The great advantage with Rapid7 Metasploit, of course, is that it's free."
"We pay monthly. The pricing is reasonable."
"Rapid7 Metasploit is cheaper than Tenable.io Vulnerability Management."
"There are two versions available, one of which is the Pro version, and the other is the free version."
"Rapid7 Metasploit is an open-source solution."
"I have used the free version of Rapid7 Metasploit."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
42%
Computer Software Company
10%
Financial Services Firm
7%
Government
5%
Computer Software Company
18%
Financial Services Firm
10%
Manufacturing Company
10%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
FortiWeb is cheaper by over ten percent compared to other solutions like Barracuda and F5.
What needs improvement with Fortinet FortiWeb?
One area that needs improvement is the handling of SaaS downtime. When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well. ...
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What needs improvement with Rapid7 Metasploit?
Rapid7 Metasploit could be made easier for new users to learn.
 

Also Known As

No data available
Metasploit
 

Learn More

 

Overview

 

Sample Customers

Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Amazon Web Services (AWS), Microsoft, F5 and others in Web Application Firewall (WAF). Updated: October 2024.
814,649 professionals have used our research since 2012.