Fortinet FortiWeb has improved my organization by protecting our customers' web infrastructure environment.
CEO at a tech services company with 1-10 employees
Protects our customers' web infrastructure environment
Pros and Cons
- "The most valuable feature is the web application firewall (WAF)."
- "Fortinet FortiWeb has improved my organization by protecting our customer's web infrastructure environment."
- "Their support needs improvement."
How has it helped my organization?
What is most valuable?
The most valuable feature is the web application firewall (WAF).
What needs improvement?
Their support needs improvement.
For how long have I used the solution?
More than five years.
Buyer's Guide
Fortinet FortiWeb
December 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
How are customer service and support?
I would rate their technical support as a nine out of 10.
Which solution did I use previously and why did I switch?
We previously used NetScaler.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable.
Which other solutions did I evaluate?
Not applicable.
What other advice do I have?
Evaluate this product against other vendors out there.
We were previously a partner.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Products Specialist at a tech services company with 51-200 employees
Useful for integrating solutions but could have more customization
Pros and Cons
- "It's easy to use and allows us to integrate solutions together."
- "The solution could have more customization."
What is our primary use case?
We use Fortinet FortiWeb for our VPN. The solution is always updated to the latest version.
The solution is deployed on-premises.
What is most valuable?
It's easy to use and allows us to integrate solutions together.
What needs improvement?
The solution could have more customization.
For how long have I used the solution?
I have used this solution for one year.
What do I think about the stability of the solution?
It's very stable.
I would rate the stability as six out of ten.
What do I think about the scalability of the solution?
It's scalable.
I would rate the scalability as seven out of ten.
How are customer service and support?
Technical support is helpful and they respond quickly. I would rate them as eight out of ten.
How was the initial setup?
I would rate the setup as five out of ten.
What about the implementation team?
Our IT department implemented the solution.
What's my experience with pricing, setup cost, and licensing?
The cost isn't expensive.
What other advice do I have?
I would rate this solution as seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Fortinet FortiWeb
December 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
Information Security Expert at a financial services firm with 501-1,000 employees
It helps us protect our web and database servers from being penetrated from outside the office.
What is most valuable?
The most valuable features of the product are its IPS and VPN server.
How has it helped my organization?
The device is very handy and it helps us to protect our web and database servers from being penetrated from outside the office.
What needs improvement?
The antivirus and the IPS can be improved in the future.
For how long have I used the solution?
I have used it for about two years.
What do I think about the stability of the solution?
Fortunately, we have not yet encountered any stability issues!
What do I think about the scalability of the solution?
With the 600-C model, we had some scalability issues.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
Initial setup was very straightforward and simple.
What's my experience with pricing, setup cost, and licensing?
These devices, especially the 1500-D model, are really worth purchasing and using.
Which other solutions did I evaluate?
Before choosing this product, we evaluated many products such as Cisco, Juniper, Cyberoam, and Sophos.
What other advice do I have?
In my opinion, the FortiGate appliances, and especially the D series, are really powerful ones and worth providing for your network.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Technical Manager at a tech services company with 51-200 employees
Stable, simple to install, but more advanced features needed
Pros and Cons
- "The solution is stable."
- "The F5 solution has more features than Fortinet FortiWeb, such as multiple load balancing."
What is our primary use case?
We use Fortinet FortiWeb to protect our exchange terminal for mail security.
What needs improvement?
The F5 solution has more features than Fortinet FortiWeb, such as multiple load balancing.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately four years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I have approximately four clients using this solution.
How was the initial setup?
The installation is easy and straightforward, and the timeframe depends on the application
What about the implementation team?
We have one engineer that does the support of this solution.
Which other solutions did I evaluate?
I have evaluated F5 and Citrix.
What other advice do I have?
I would recommend this solution. I hope they are able to make some changes to compete with other solutions, such as F5 and Citrix.
I rate Fortinet FortiWeb a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Engineer : Cyber Security & Telecommunication at a tech services company with 11-50 employees
Reasonably priced and offers a good graphical user interface but need better integration capabilities
Pros and Cons
- "The initial setup is pretty straightforward."
- "The support side of things can be improved."
What is our primary use case?
We primarily used the solution as a POC to see how effective it is and so far we're happy with it.
We used it for protecting our web servers and the use of some web applications within a financial institution.
What is most valuable?
They have a very good graphical user interface.
The initial setup is pretty straightforward.
The solution is stable.
The scalability is pretty good.
We have found the pricing to be pretty reasonable.
What needs improvement?
During the POC we did encounter problems. For example, the integration with the HSM for storing keys was not ideal.
The downside is on the security side and is the firewall. When you look at the firewall, it doesn't do decryption and you have to depend on other third-party tools to do that. Or you would have to use another FortiGate product which makes things a little complicated. Today, people look for simplicity in terms of design. That's one downside to Fortinet's Firewall. The downside to FortiWeb is it had issues integrating with HSM. They fixed the issue, however, it took a long time to fix and it wasn't pleasant. I had to work with deadlines and I could not make the deadlines due to the slow timeline on their side.
For the firewall, when you deploy IPS, the IPS doesn't have visibility into encrypted traffic and 70% of traffic these days is encrypted, and that's the conservative figure of the actual percentage. If your IPS doesn't have that visibility, then it is not really doing the job that it has to do. In comparison, Palo Alto is the best firewall in terms of performance and has the technical specifications that we need.
The support side of things can be improved. They need to quickly tend to issues and resolve them as soon as possible. Those are the expectations.
For how long have I used the solution?
We've only used FortiWeb for a POC.
What do I think about the stability of the solution?
The stability of the product has been good. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. When you look at the specs and if you do what they say in the specs, in terms of ensuring that you're not overlooking anything, it's a good product.
What do I think about the scalability of the solution?
The solution can scale. That's not a problem at all.
How are customer service and support?
Technical support could be more responsive. They need to address issues faster. I'm not completely happy with the level of support we receive.
How was the initial setup?
Generally, the solution is easy to set up. It's not overly complex.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty good if you look at other top options in this space. They are reasonable.
Which other solutions did I evaluate?
I've also looked at Palo Alto, and it has the specifications that we need, however, the pricing is quite high.
What other advice do I have?
Our company is a Fortinet partner.
I'd rate the solution at a seven out of ten.
In terms of functionality, it does a perfect job, however, when you have to integrate with third-party tools, that's where you might have issues. Going forward, maybe what Fortinet needs to do is to ensure that they don't have integration issues with the other big vendors that are common in terms of what's deployed out there. Someone might want FortiWeb, however, for example in my case where a bank needed to integrate that with Jamalt or HSM for description, they have to do their homework.
When you're dealing with financial clients, they need to have seamless integration and not to have these challenges where it would take time to fix as an issue. That should be figured out pre-deployment. Companies in banking can't wait for clients to point out that this is an issue. They have to attend to it beforehand and resolve issues to meet expectations.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Network System Administrator at a computer software company with 201-500 employees
Protected our web servers from outside attacks. Certificates were deleted when firmware was upgraded.
Pros and Cons
- "We were able to protect our web servers from outside attacks."
- "The false positives are annoying."
- "I had some small problems when I was upgrading firmware. After the upgrade, some of my certificates were deleted."
How has it helped my organization?
We were able to protect our web servers from outside attacks. It has really helped us with publishing servers which were published on Microsoft Forefront TMG.
What is most valuable?
All of its feature are valuable to us. If you ask me which is the most valuable, it is the load balancing, then I would say the security features. Publishing OWA is also a good feature.
What needs improvement?
We started with FortiWeb400C, then we did an upgrade to FortiWeb 400D. I had some small problems when I was upgrading firmware. After the upgrade, some of my certificates were deleted.
The false positives are also annoying.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
We did not encounter with any stability issues.
What do I think about the scalability of the solution?
We did not encounter with any scalability issues.
How are customer service and technical support?
Fortinet technical support is really good. I would give them a nine out of 10.
Which solution did I use previously and why did I switch?
We did not use a WAF before. We used Microsoft TMG, but it is not a WAF.
How was the initial setup?
Initial setup is straightforward, and it is not too complex.
What's my experience with pricing, setup cost, and licensing?
It really pays off to buy licences for multiple years.
Which other solutions did I evaluate?
No.
What other advice do I have?
It is a really good product. It is worth using in your network.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partners.
Security Consultant at a tech services company with 11-50 employees
Give us built-in security templates, strong threat intelligence, and is AV integrated
Pros and Cons
- "Also, if you serve files or you accept files with your server, Fortiweb has built-in antivirus. The Fortinet product family also provides good IP intelligence (botnet C&C, etc.)."
- "Built-in security templates, AV integrated, strong threat intelligence."
How has it helped my organization?
With other vendors you need to go through a learning period. With FortiWeb you can just apply a high-security profile and move on. It's very easy to reduce false positives.
What is most valuable?
- Built-in security templates
- AV integrated
- Strong threat intelligence
Also, if you serve files or you accept files with your server, Fortiweb has built-in antivirus. The Fortinet product family also provides good IP intelligence (botnet C&C, etc.).
Requires very little effort to add device to topology or replace existing WAF device with FortiWeb.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No issues with scalability.
How are customer service and technical support?
Eight out of 10.
Which solution did I use previously and why did I switch?
F5, A10, KEMP.
How was the initial setup?
It's very easy.
What other advice do I have?
Be sure to look at industry reviews, they have good knowledge about threat intelligence.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Admin at a comms service provider with 1,001-5,000 employees
I set it up on my own. I'd like to see improvements in its internet and servers features.
What is most valuable?
- Firewall policy
What needs improvement?
- Internet
- Servers
For how long have I used the solution?
I have used it for a year and a half.
What do I think about the stability of the solution?
We had one stability issue when I ran it once with Wireshark; it froze.
What do I think about the scalability of the solution?
I have not encountered any scalability issues.
How are customer service and technical support?
I cannot rate technical support because I have not used it yet.
Which solution did I use previously and why did I switch?
How was the initial setup?
Initial setup was not that difficult. It was different to my previous solution; I could do it on my own.
Which other solutions did I evaluate?
Before choosing this product, I did not evaluate other options.
What other advice do I have?
- Be aware of logs.
- Does not compare with Check Point about finding policies.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
F5 Advanced WAF
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?
- When evaluating Web Application Security, what aspect do you think is the most important to look for?