FortiWeb is used for protecting against malicious activities, such as SQL injections, for outward-facing web forms.
BDM Fortinet & BDM Teamlead at a tech services company with 1,001-5,000 employees
Seamless integration and has enhanced security management
Pros and Cons
- "The most valuable features of FortiWeb include its dashboard and out-of-the-box integrations with other Fortinet products, which enhance its effectiveness."
- "There is room for improvement in the portability on multi-cloud environments."
What is our primary use case?
What is most valuable?
The most valuable features of FortiWeb include its dashboard and out-of-the-box integrations with other Fortinet products, which enhance its effectiveness. FortiWeb's position as part of the Fortinet platform makes it particularly beneficial for Fortinet customers, offering seamless integration and operational cost savings.
What needs improvement?
There is room for improvement in the portability on multi-cloud environments. Enhanced DDoS integration to make FortiWeb more unified with other Fortinet products could be beneficial.
For how long have I used the solution?
I have personally been working with FortiWeb for approximately two years.
Buyer's Guide
Fortinet FortiWeb
January 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,711 professionals have used our research since 2012.
What do I think about the stability of the solution?
I would rate the stability of FortiWeb as nine out of ten, indicating highly stable performance.
What do I think about the scalability of the solution?
I would rate the scalability of the product a seven out of ten. While it is multicloud-enabled, there is more automation in other products that may better suit complex environments.
How are customer service and support?
I would rate the customer service and support as nine out of ten.
How would you rate customer service and support?
Positive
What about the implementation team?
Our team, consisting of three certified Fortinet engineers, handles the deployment, although globally, Exclusive Networks has a large team of certified engineers.
What was our ROI?
Operational costs decrease when using FortiWeb within the Fortinet stack due to integrated assessments and security event management.
What's my experience with pricing, setup cost, and licensing?
I would rate the licensing cost as seven out of ten, considering it good value for money. The price is affordable and reasonable for the features offered.
Which other solutions did I evaluate?
We also work with other vendors such as F5, Proofpoint, and Palo Alto, however, Fortinet stands out for its holistic vision of cybersecurity.
What other advice do I have?
Overall, I would rate FortiWeb an eight out of ten for existing Fortinet customers due to its seamless integration and good value for money.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Vice President of Infrustructure at a tech services company with 51-200 employees
Enhanced security with comprehensive traffic inspection and some downtime automation needs
Pros and Cons
- "It allows specific IP whitelisting or even regional whitelisting, ensuring only whitelisted traffic from certain geographical regions can access the environment."
- "When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well."
What is our primary use case?
I use FortiWeb to protect all the domains in my organization. It safeguards my entire web segment. All the connections to my environment that do not come over VPN are protected by it, which is crucial as I work in the financial sector with a strong focus on security. FortiWeb stands in front of my environment, where either a firewall or WAF is used to inspect all inbound traffic.
How has it helped my organization?
It helps protect my organization by providing robust security measures for our web segment. By onboarding all my APIs and web applications onto FortiWeb, it ensures that traffic not coming through the firewall adheres to stringent security protocols. The SaaS model of FortiWeb also helps in managing latency effectively despite our users being in Nigeria while the infrastructure is based in Europe.
What is most valuable?
The features that I value most in FortiWeb include its inspection of traffic for Intrusion Prevention, Anti-Malware, and whitelisting capabilities. It allows specific IP whitelisting or even regional whitelisting, ensuring only whitelisted traffic from certain geographical regions can access the environment. These security features provide a comprehensive defense against malicious activities.
What needs improvement?
One area that needs improvement is the handling of SaaS downtime. When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well. Although measures like built-in redundancy and manual switching between data centers exist, there is room for improvement in making these transitions automatic without impacting the customer. Automating the migration without manual intervention would significantly enhance user experience during downtime. Additionally, being able to read non-flagged traffic for operational purposes could also be an area to improve.
For how long have I used the solution?
I have been using FortiWeb for about three years now.
What do I think about the stability of the solution?
The performance of FortiWeb is impressive because I use it as a SaaS-based solution, meaning it is not hosted inside my environment. Despite initial concerns about latency due to traffic redirection, it has performed well even with our users situated in Nigeria accessing infrastructure deployed in Europe.
How are customer service and support?
Their support is generally good, around a seven out of ten. They have a structured support system where you need to log into a platform to raise a case. For urgent issues, you need to raise a case and follow up with a phone call to escalate it to a higher priority. However, one downside is that getting immediate attention during emergencies can take up to thirty minutes or more.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting up the account is quick and can be done in thirty minutes to an hour if you know what you're doing. Onboarding applications are straightforward and can be completed in about ten minutes or less. Overall, the deployment can be completed in a matter of hours.
What's my experience with pricing, setup cost, and licensing?
FortiWeb is cheaper by over ten percent compared to other solutions like Barracuda and F5.
Which other solutions did I evaluate?
I evaluated F5, Barracuda, and Cloudflare. FortiWeb stood out in terms of ease of use, management, and cost.
What other advice do I have?
I would recommend using Fortinet above any other tool. It is secure, cost-effective, and easy to use. The deployment and operational aspects are user-friendly.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiWeb
January 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,711 professionals have used our research since 2012.
Senior IP Network Defense at a comms service provider with 10,001+ employees
Protects internal applications and prevents target attacks
Pros and Cons
- "The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats."
- "We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version."
What is our primary use case?
The tool is a valuable web application that protects our internal mobile money application. It enforces policies, ensuring secure access for users connecting to the application. It complies with PCI DSS, safeguarding financial transactions and contributing to our revenue. The solution effectively addresses malware threats.
What is most valuable?
The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises.
You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary.
The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.
What needs improvement?
We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version.
For how long have I used the solution?
I have been using the product for three years.
What do I think about the stability of the solution?
You may encounter problems if you don't have FortiAnalyzer.
What do I think about the scalability of the solution?
My company has 11,000 users.
How are customer service and support?
We've encountered several issues before, like the web and firmware's lack of responsiveness for 50 minutes. The Firewall, FortiWeb Manager firmware, and firmware updates must sync properly. We've addressed this, and our partners have helped resolve these issues.
Which solution did I use previously and why did I switch?
I tried to work with Cisco, but it wasn't working well.
How was the initial setup?
FortiWeb Web Application Firewall's deployment is not complex. The setup involves connecting the switch and the firewall. Our main task is to redirect all traffic from the application to the website. The overall process can be completed in two weeks. Maintaining it isn't challenging, but the issue arises when the firmware becomes outdated; you must check and update it.
What about the implementation team?
FortiWeb Web Application Firewall helped us with the deployment.
What other advice do I have?
I rate the overall solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Pre-Sales at a comms service provider with 11-50 employees
Identifies potential DDoS attacks and suspicious domain activity
Pros and Cons
- "FortiWeb identified potential DDoS attacks and suspicious domain activity, showcasing the value of its machine-learning capabilities."
- "There could be ADC offering as well."
What is our primary use case?
My company is a Fortinet partner and specializes in FortiWeb. We often compete against cloud-native solutions like Azure Application Gateway WAF. We typically conduct proof-of-concept tests for potential clients. They are usually looking for API protection and bot mitigation, which FortiWeb excels at. We take responsibility for implementing and supporting the solution for our customers.
We also conduct simulation tests and review feedback from colleagues and customers. Customers often seek solutions for bottlenecks, especially regarding machine learning. We can do a detailed review of the WAF services and provide a report for the customer.
How has it helped my organization?
If a customer has a website, a firewall alone is not enough. While a firewall can act as an application firewall, it may not be sufficient. If we have a firewall at layer four and layer seven, and the customer needs protection against OWASP Top 10 vulnerabilities or requires IT audits, a web application firewall becomes crucial.
Additionally, if DDoS protection is a concern, it often comes integrated with WAF. For networking, some WAFs can even provide load-balancing functionality.
What is most valuable?
In my experience, we put my customer's website in monitor mode, not protect mode. So, we initially set up FortiWeb in monitor mode to avoid disruptions to the customer's website.
While in monitor mode, machine learning observed the web application. Once machine learning had enough data to analyze, we discussed unusual traffic patterns with the customer.
FortiWeb identified potential DDoS attacks and suspicious domain activity, showcasing the value of its machine-learning capabilities.
What needs improvement?
The price could be close to Imperva; Imperva is the number one firewall.
FortiWeb cannot do some kind of ADC solution, like load balancing. I hope they improve that.
I'm looking for the ADC solution, the load balancing solution. Because application firewalls with multiple line solutions do come with it. So, I think it should be integrated within FortiWeb WAF.
For how long have I used the solution?
I used it for two years. I started working with it when a client company moved their web application to the cloud (Azure or AWS) and needed protection. We implemented a FortiWeb solution as their WAF.
Which solution did I use previously and why did I switch?
I have used Check Point for email security.
What was our ROI?
For security products, from my experience, customers will compare costs if they have been attacked. They may consider insurance. If you provide more protection, the return on investment is the compromise to use the application.
What's my experience with pricing, setup cost, and licensing?
This product offers two pricing options: a standard package and an advanced package. The advanced package includes credential stuffing protection, while the standard package includes automatic application learning, bot mitigation, and web application protection.
If you simply need to protect your website, the standard package is sufficient. However, if you need credential stuffing protection, the advanced package is necessary. This is the key difference between the two packages.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Specialist at a manufacturing company with 10,001+ employees
Cost-effective, easy to configure, and works very well as a single solution for multiple environments
Pros and Cons
- "The ease of configuration is valuable. We have Azure WAF, we have OCI WAF, and we also have Cloud Armor for GCP, but their configuration isn't very easy. It's pretty simple in FortiWeb, and we can enable or configure whatever we want."
- "The dashboards are not that configurable. Application-specific dashboards can be improved. If we have 50 applications, there should be something to see what's happening with these 50 applications. There could be a graph or a consolidated alert page where all alerts are inbuilt. They have other products that I can use, but this feature should be built into FortiWeb."
What is our primary use case?
We have multiple environments. Some applications are in Oracle Cloud, some are in Azure, some are in GCP, and some are on-prem. We wanted a single solution for web applications, and that's why we chose FortiWeb. In the case of the cloud, we don't even have to manage it. It's a managed service from Fortinet.
How has it helped my organization?
We have not been using it for a very long time. It has only been eight months, and so far, there have been two main benefits. The first benefit is that if I have an on-prem solution, I can buy their hardware and deploy it, but the configuration is the same. If I have a cloud, I can use FortiWeb as a service or as a virtual machine. It depends on requirements, but the configuration remains the same. The configuration doesn't change. We have a lot of global parts and a lot of teams are working on it, so it gets easy to communicate and verify the configuration and create a baseline.
Costing is another benefit. The cost is based on the traffic. If an application is used, we pay for it, but if it's not used, we don't have to pay for it. With other solutions, we have to buy the solution, and then we have to purchase or take licenses. If they aren't used, we are just burning money without any use.
We are using anomaly detection and bot mitigation. In terms of anomaly detection, it is able to find the behavior. We have some applications where normal users are logging from India, and if the behavior changes, it gives us an alert, but in terms of bot mitigation, I haven't found much.
It's easy to use. I don't have to do any changes in my environment. For example, if I use Azure WAF, I have to use a traffic gateway, load balancer, or something similar, whereas, with FortiWeb, I don't have to change any architecture. I just have to change my DNS entry. That's it. If I'm able to change my DNS entry, FortiWeb works.
Adding new applications is also quite easy. You just add the application and change the DNS settings, and you are good to go. Whether you want to block or unblock, or you want the learning mode or protection mode, you can enable or disable it with just one click, and you are good to go. Most of the settings are already there if you want to tweak them. It has a GUI. You must have to click here and there. The documentation is also good. If I don't know something, their documentation is quite helpful. A lot of people are using Fortinet, so YouTube videos and articles are also available.
The configuration part is easy. The configuration and implementation process is streamlined. We don't have to change anything. We don't have to follow 10 processes. It's a single process with which everybody is familiar. Manpower and manhours are saved because a lot of discussions are avoided. It also helps us in creating a baseline. We now have a baseline of what we need. So, from an instant response point of view, it's easy for us because we are getting the same results out of it.
It has reduced false positives. As compared to my old solution, there is at least a 17% to 18% reduction.
It has reduced the number of alerts that our organization receives. There is a 50% to 60% reduction in alerts.
It has saved us time. We were spending around three to four days setting up our old solution, whereas now, we are spending a maximum of four hours.
What is most valuable?
The ease of configuration is valuable. We have Azure WAF, we have OCI WAF, and we also have Cloud Armor for GCP, but their configuration isn't very easy. It's pretty simple in FortiWeb, and we can enable or configure whatever we want.
Its cost is also good. If I'm using an application for 15 days, I pay only for 15 days.
FortiWeb is good for blocking unknown threats and attacks. I've done a PoC with Azure WAF and OCI WAF, and in comparison, FortiWeb is quite good.
What needs improvement?
The dashboards are not that configurable. Application-specific dashboards can be improved. If we have 50 applications, there should be something to see what's happening with these 50 applications. There could be a graph or a consolidated alert page where all alerts are inbuilt. They have other products that I can use, but this feature should be built into FortiWeb.
Reporting could also be better. There should be inbuilt reports that we can use to present on how it is benefiting and other things. We should be able to get reports in PDF or other common formats.
For how long have I used the solution?
It has been around eight months.
What do I think about the stability of the solution?
Its stability is good. Stability-wise, there aren't any major differences among Azure WAF, OCI WAF, Google Cloud Armor, and Fortinet FortiWeb.
What do I think about the scalability of the solution?
If I'm using FortiWeb as a service, I don't have to care about scaling because everything is taken care of by Fortinet. From a scaling point of view, I don't have to do anything. If it's on-premises, we already know how many users are going to use it, and we can decide on the model accordingly. So far, we haven't had to scale it up for any project.
How are customer service and support?
I've not contacted them for FortiWeb. We are also using Fortinet firewalls for which I've taken their help.
Which solution did I use previously and why did I switch?
We had our own solution. We called it SecOps. It had something from RedHat and something from OPNsense. We built it that way. We were using that. We switched to FortiWeb because of two reasons. The first reason was the cost, and the second thing was that we wanted a single solution that can be implemented everywhere. We are from R&D. We decide on a solution, and then our product team implements it. When we have multiple tools, operations and maintenance become quite a headache because every tool has its own learning curve. All tools are not the same.
How was the initial setup?
We have on-premises as well as public cloud environments. We have Azure, OCI, and GCP.
Its initial setup is straightforward. It takes a little bit more time the first time because we have to set up the subscription, etc. Next time, it takes only around four hours.
What about the implementation team?
We implemented it in-house. We are a global team, so a lot of people were involved. From the R&D side, at least five to six people were involved.
In terms of maintenance, when it's on-prem, some sort of maintenance is required in terms of firmware upgrades. We also follow ISO standards, so we have to do maintenance. We have a requirement to check everything once a month, but FortiWeb doesn't take much time.
What was our ROI?
We have been using it only for eight months, so I need more time to see its price-performance ratio, but it's worth the money. I'm getting what I'm paying for.
There are time savings. Previously, we were spending four to five days setting up our SecOps solution, whereas now, we are spending only four hours.
What's my experience with pricing, setup cost, and licensing?
When I use any other firewall, I have to take a license. It could be a perpetual license or subscription-based. In both cases, we have to pay some amount in advance, whereas in the case of FortiWeb, when using it as a service, I am paying half a dollar only for the domain name, and then I am paying based on the traffic or the number of requests. In every organization, there are some applications that are heavily used, and there are some applications that are not heavily used. So, why go with a yearly, three-yearly, or five-yearly plan when you can just pay based on the traffic that WAF is processing? Previously, for each project, the cost was $800 to $1,000 per application. Now, it's $100 to $120. For some of the applications, there is a 90% reduction, and for some of the applications, there is a 50% reduction. We're paying only $500 to $600.
Which other solutions did I evaluate?
We checked OCI WAF, Microsoft Azure WAF, Google Cloud Armor, and Fortinet FortiWeb. We also checked other WAF solutions such as Akamai and CloudFlare but didn't do a PoC with them. We did a PoC with OCI WAF, Microsoft Azure WAF, Google Cloud Armor, and Fortinet FortiWeb.
We went for Fortinet FortiWeb because we wanted a single solution that can be implemented anywhere. If we use Azure WAF, it would be hard to use in GCP. We have to create a connection between both, whereas we can implement Fortinet FortiWeb on any cloud. If we have on-prem applications, we can implement FortiWeb hardware as a solution. In some places, we have strict requirements. If it's a VMware data center, they also have the FortiWeb VM solution. If we want to use Docker images, they also provide Docker images. We can just use a single tool. We are not dependent on multiple tools.
What other advice do I have?
Every team has different requirements, but if you need an easy solution that can be deployed in a very short time, FortiWeb is the right one. It doesn't need too much expertise when you're initially configuring it, and even if you're testing it, the cost is quite low. It's good even for small projects.
It has the API gateway functionality, but we aren't using that. We are also not using API discovery and API security. I've enabled machine learning, but we have not used it a lot. We are in the exploring phase.
Overall, I'd rate Fortinet FortiWeb an eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Manager Data Servicers at a financial services firm with 1,001-5,000 employees
Secures APIs with effective protection against web threats
Pros and Cons
- "It is cost-effective compared to other solutions."
- "They could integrate some kind of machine learning and AI facilities to automate workflows."
What is our primary use case?
We use FortiWeb to connect external APIs to our on-prem data center solutions.
What is most valuable?
We use FortiWeb for extended protection profiles to mitigate SQL injection and other web application threats. It is effective against web application threats and helps with our API protection and load balancing.
Additionally, it is cost-effective compared to other solutions.
What needs improvement?
They could integrate some kind of machine learning and AI facilities to automate workflows. We need to update regular patches frequently, and it requires regular installation and testing of these patches.
For how long have I used the solution?
We have been working with FortiWeb for almost five years.
What do I think about the stability of the solution?
It is stable for us, showing good performance in handling web security.
What do I think about the scalability of the solution?
I would rate its scalability at six because we have to increase our CPU and memory capacities, as it is confined to CPU and memories.
How are customer service and support?
I would rate the customer service and technical support between eight and nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is easy to manage.
What was our ROI?
It helps us save costs, about 20% to 30%.
What's my experience with pricing, setup cost, and licensing?
In comparison to other solutions, the price is reasonable.
What other advice do I have?
FortiWeb is suitable for medium-scale companies. I recommend using this solution.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at a government with 5,001-10,000 employees
Offers good integration capabilities with other security tools
Pros and Cons
- "The product's initial setup phase was straightforward, and since our company didn't have any problems with it, we didn't encounter many problems with the tool."
- "Though the reporting is a nice aspect associated with the tool, I feel that it has certain shortcomings and can be made better."
What is our primary use case?
I use the solution in my company, as we mostly load some web applications at our data center and use it to ensure that the web pages are properly secured.
What is most valuable?
Actually, most of the features of the tool are really good, but I would like to emphasize the importance of its machine learning features, as it can be implemented smoothly in Fortinet FortiWeb, and it is very helpful for our company.
What needs improvement?
Though the reporting is a nice aspect associated with the tool, I feel that it has certain shortcomings and can be made better. The reporting part can provide more information and be more specific.
Fortinet FortiWeb's admin guide could offer more, like, examples or features on how to implement the tool. It can provide information on how a user can make use of it in different usages, and that can help a lot. The admin guide is satisfactory, and it meets our company's needs.
Actually, my company would like it if the product could implement scanning attachments for exchange for assets or exchange needs. The aforementioned area consists of the feature that my company wants to apply, but it is not supported in Fortinet yet. My company needs the product to support us in the aforementioned area, and it can help us a lot by providing a layer of security that can check files and attachments in emails and other stuff, which would be great.
For how long have I used the solution?
I have been using Fortinet FortiWeb for three years. I am an end user of the solution.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten.
In terms of stability, it is a good solution that is easy to use and has many features and resources. The support offered by the product is good, especially since the support team responds on time, keeps you informed, and even follows up. Generally, it is a good solution to have and use.
My company has not experienced any downtime while using the product.
What do I think about the scalability of the solution?
In our company, we have not implemented the product on a large scale.
Around 2,000 people per month use the product in our company.
Every single day, the tool is used to host web applications.
If our company needs to implement more hosted web servers, we will use Fortinet FortiWeb, but if not, then it will remain at the current number. Increasing the use of the tool is not my decision, and I just accommodate the needs of the organization.
How are customer service and support?
The solution's technical support is good. When my company faced some problems with the product, I found the solution's support team to be very supportive and helpful. I rate the technical support a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
On a scale of one to ten, where one is difficult and ten is easy, I rate the product's initial setup phase as eight or nine.
The product's initial setup phase was straightforward, and since our company didn't have any problems with it, we didn't encounter many problems with the tool. Maybe our company encountered some problems with the product's setup because we used to use it to set up the servers or stuff, which took time, but now Fortinet FortiWeb handles everything smoothly and easily.
The solution is deployed on an on-premises version.
The solution can be deployed in a week.
What was our ROI?
If my company did not have Fortinet FortiWeb, then I believe that we would have had to host some of the services in an external data center with extra fees and there we would have had to pay for the web services, but we don't need that anymore because now, we have an on-prem web service that can promote us to be able to host as much as we need of web services.
On a scale of one to ten, where one is zero percent and ten is a hundred percent, I rate the ROI as an eight.
What's my experience with pricing, setup cost, and licensing?
If one is very cheap and ten is very expensive, I rate the product price as three or four. The tool is cost-effective and offers value for money. I didn't mean it was very expensive. The price is fixed, but some features need an extra license.
Which other solutions did I evaluate?
My company was considering F5, but you actually went for Fortinet FortiWeb after considering the cost aspect.
What other advice do I have?
My company doesn't specifically host e-commerce platforms since we offer mainly government services.
The security part has been satisfactory till now, and we haven't faced any problems yet.
FortiGate FortiWeb's features that have been most effective in mitigating web-based threats are possible because of the signatures. My company doesn't need to enforce a lot of policies or stuff. Fortinet FortiWeb has a lot of internal databases that can help you, and you can use whatever platform you are hosting your web applications through whichever software you use. it can build up a web protection profile that matches your needs, making it a very helpful tool.
Speaking about how machine learning features enhance our security posture, I would say that some aspects of the website are not normally clear for our company, and machine learning helps in such areas. It just traces the normal usage of the web applications along with the websites or links most users visit while also checking which URLs are mostly used, after which the tool differentiates between the normal usage and any abnormalities, based on which it builds the model that can be used to improve the security. Sometimes, a person cannot do things manually and is not sure about all the aspects of our web applications because many are not developers. Machine learning comes into the picture because one may not know all the stuff associated with the product.
A team of four or five people is enough to deploy the tool. Maintaining the tool is actually not a very big task and not many people are required for it.
The integration capabilities of the product with other security tools have benefited our company's security strategy as it sits smoothly in our network. The tool doesn't cause any problems with the integration part.
I would recommend that users use the tool's high availability. With the tool, one box is not enough, so there is a need to have a cluster of two boxes. Users need to measure their needs regarding the logging process and everything else, including processing. Even before starting to use it, we have to set up everything, or you would be confused about how to use the tool in the future, and it would be difficult to figure out how much retention log retention we would need in our company. It is important to set up everything related to the users' needs so that they don't need to change a lot of settings in the future.
I rate the tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Technology Officer at a tech services company with 51-200 employees
It offers the level of security we need at a good price point
Pros and Cons
- "FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient."
- "F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented."
What is our primary use case?
We use FortiWeb as our web application firewall.
How has it helped my organization?
FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient. FortiWeb enables us to streamline tasks. It's a robust solution that's effortless to configure. The AI and machine learning features help us block unknown threats.
We can bring our web applications online faster because FortiWeb shortens the time needed to bring any application into production. Compared to other application firewalls, FortiWeb has a smoother process for bringing applications online.
FortiWeb has few false positives. It's more accurate than other solutions, so we also see fewer alerts. FortiWeb has helped free up IT staff for other projects. You don't need to spend much time getting applications ready for the web, so IT staff can use this time to manage other things.
What is most valuable?
The AI engine and machine learning features distinguish FortiWeb from other solutions. It has a robust UI. FortiWeb is solidly accurate and provides excellent protection against zero-day attacks using machine learning. It appears to be effective because we've never experienced a breach from a zero-day attack.
We use almost all of the features, including analytics, malware detection, bot mitigation, and API discovery.
What needs improvement?
I think customers have the impression that FortiWeb is primarily for SMEs, but FortiWeb should work to expand its market share and adjust its branding. F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented.
For how long have I used the solution?
We have used FortiWeb for around a year.
What do I think about the stability of the solution?
FortiWeb is highly stable. We haven't seen any bugs. The solution is reliable once configured properly.
What do I think about the scalability of the solution?
FortiWeb isn't difficult to scale.
How are customer service and support?
I rate Fortinet support six out of 10. The documentation and support need improvement.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used Citrix WAF and the F5. FortiWeb offers most of the same features at a better price.
How was the initial setup?
I have done on-prem, hybrid, and cloud deployments of FortiWeb. The deployment was straightforward for most features, but a few features require some customization and configuration in the console. That's where we ran into problems because the documentation isn't thorough in some areas.
It takes around three or four days to deploy FortiWeb for a simple website. It takes longer for a complex website, but it depends on the level of complexity. We deployed FortiWeb in-house with two people and some help from Fortinet support. It's deployed across multiple data centers and locations.
What was our ROI?
The price-performance ratio is good. The time to value is quick because it's easy to deploy and the ML engine doesn't take long to adjust and apply the correct rules.
What's my experience with pricing, setup cost, and licensing?
FortiWeb offers these services at a price that SME customers can afford, but it's also suitable for large enterprises. Still, they need to put in more work to gain a greater share of enterprise business because they face stiff competition in this segment from F5, Cloudflare, and some others.
What other advice do I have?
I rate Fortinet FortiWeb eight out of 10. FortiWeb is a suitable product for SMEs. I recommend a proof of concept before going forward with any project.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
NetScaler
AWS WAF
Cloudflare Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Check Point CloudGuard WAF
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?



















