Try our new research platform with insights from 80,000+ expert users
PawanKumar10 - PeerSpot reviewer
Senior Manager at a computer software company with 201-500 employees
Reseller
Mar 13, 2023
A user-friendly solution that features excellent traffic filtering and reduced false positives
Pros and Cons
  • "The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities."
  • "We want to see more detailed logging, such as audit logging, as this would significantly enhance the solution's reporting. We currently get some information from logs, but more would be better."

What is our primary use case?

We use the solution as a web access firewall (WAF) to secure our applications and use URL mapping to ensure only traffic filtered through the WAF is allowed. 

The environment the product is used in is one project in our GCP, and we're located in the Western USA. Two members of the infrastructure team operate FortiWeb within our organization.

How has it helped my organization?

FortiWeb filters a lot of unwanted traffic, which is good for our organization, as it would negatively impact our reputation if this traffic weren't screened.

The solution helps us to streamline tasks as it features a user-friendly console, and we can apply the WAF to all the URLs required for our publicly available applications. The templates offer either advanced or extended protection for those URLs, and we can see insights for specific URLs, such as total hits and how many requests are being blocked and allowed.  

The FortiWeb Cloud also saved our organization time through machine learning, which analyses traffic based on IP origin and geographic region. This is one of the solution's better features and saved us significant time. 

We have seen time to value with the product. After implementation, we let the solution run for a month, then reconfigured a few policies and templates. Within three months, we were getting the desired results.  

What is most valuable?

The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities. 

The product is great for blocking unknown threats and attacks. We've had excellent results over the past two years, and the way it detects and filters traffic is outstanding.  

The FortiWeb Cloud is straightforward to use; with a basic overview of how to apply policies, create NAT rules, etc., it's easy. The console is user-friendly enough that anyone can create and apply policies. 

The solution also helped reduce our false positives by 20-25%. 

Our organization receives fewer alerts thanks to the solution, and we don't have to think about the security of the URLs for applications. We put the whole domain behind the WAF, and if it's configured correctly from the beginning, we spend minimal time making changes and get the precise results we need. Our alerts have been reduced by approximately 5%.  

What needs improvement?

We want to see more detailed logging, such as audit logging, as this would significantly enhance the solution's reporting. We currently get some information from logs, but more would be better.

Buyer's Guide
Fortinet FortiWeb
March 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
883,760 professionals have used our research since 2012.

For how long have I used the solution?

We've been using the solution for nearly two years. 

What do I think about the stability of the solution?

The solution is very stable. 

What do I think about the scalability of the solution?

The product is scalable; we can easily scale up and down as required. 

How was the initial setup?

I did the initial setup, which was very straightforward; the process includes putting an instance in the cloud and then adding the URLs of the domains to the template. The initial deployment took under two hours, but we needed to spend time reconfiguring the template later to reduce the number of false positives. One staff member can complete the setup, and it only requires basic knowledge.

Outside of updates and the initial reconfiguration, the solution requires minimal maintenance. 

What's my experience with pricing, setup cost, and licensing?

The pricing is average; the product is neither particularly expensive nor affordable. 

Regarding the price-performance ratio, the solution is definitely worth the money.

What other advice do I have?

I rate the tool nine out of ten. 

I advise anyone evaluating the solution to carry out a POC and recommend it overall.

We use the templates available in the Fortinet Web Cloud or WAF, which is sufficient to provide extended protection, traffic filtering, request blocking, and virus detection. 

Fortinet is our only WAF application because we've had excellent experiences with it. If any project requires security checks, we go with the solution.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Muhammad-Jahangir - PeerSpot reviewer
Senior Manager Tech Compliance at a financial services firm with 201-500 employees
Real User
Top 5
Nov 17, 2024
Reliable, effective web server protection with room for deployment expertise improvement
Pros and Cons
  • "FortiWeb has antivirus, web filtering, and application control features."
  • "The initial setup depends on familiarity with the product. It's manageable with the right expertise."

What is our primary use case?

The primary use case involves using FortiWeb to protect web servers from various malicious activities by integrating it into a firewall with features like URL filtering and application control. Additionally, it was deployed to meet the requirements of PCI DSS.

How has it helped my organization?

FortiWeb has been helpful in securing our web servers effectively. Fortinet FortiWeb is reliable, providing seamless protection and peace of mind regarding the security of our web applications.

What is most valuable?

FortiWeb has antivirus, web filtering, and application control features. Being part of the next-generation firewall, it's highly effective in ensuring security. The capability to protect from malicious activities is significant, alongside other features like application control.

What needs improvement?

I cannot provide feedback on what needs improvement as I haven't used other solutions to compare it against and therefore cannot identify any areas lacking in FortiWeb. Overall, FortiWeb is reliable.

For how long have I used the solution?

It's been a year since I last used FortiWeb, while I previously configured and used it actively.

What do I think about the stability of the solution?

FortiWeb is reliable in terms of stability. There haven't been specific downtimes or technical issues with FortiWeb.

How are customer service and support?

We haven’t encountered issues necessitating contact with customer service for FortiWeb, implying stable support from Fortinet.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have no experience with other solutions.

How was the initial setup?

The initial setup depends on familiarity with the product. It's manageable with the right expertise. In cases of a simple application, setting up could be achieved in as little as one day.

What's my experience with pricing, setup cost, and licensing?

I can't determine the exact cost of licensing as it was part of a bundle that offered multiple features and licenses.

Which other solutions did I evaluate?

I have no experience with other solutions.

What other advice do I have?

I must emphasize the reliability.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
March 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
883,760 professionals have used our research since 2012.
Martin Janzsó - PeerSpot reviewer
Presales Consultant at a tech services company with 201-500 employees
Real User
Top 5
Sep 8, 2024
Has good integration with load-balancing applications
Pros and Cons
  • "The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
  • "Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees."

What is our primary use case?

Our company provides data center and cloud services as infrastructure providers. When customers need infrastructure like VMs or server allocation, we provide them with the vendor and offer services to operate, manage, implement, and integrate these security components.

What is most valuable?

The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection.

What needs improvement?

Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees.

For how long have I used the solution?

I have been using the product for four to five years. 

What do I think about the stability of the solution?

I rate the tool's stability a nine out of ten. 

What do I think about the scalability of the solution?

It's not good with normal perpetual licensing, but we can solve the problem using flex licensing. That's why I'd rate it nine out of ten. We're satisfied with it. Many of our customers, including small, medium, and enterprise businesses, use FortiWeb WAF.

How was the initial setup?

I rate the tool's deployment ease as seven out of ten. We have spent about 600 working hours to implement it. 

What's my experience with pricing, setup cost, and licensing?

The product provides very good prices to customers. The price is set well and offers great value for money.

What other advice do I have?

I rate the overall solution an eight out of ten. I advise others looking to use FortiWeb WAF to create deeper policy rules.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. msp
PeerSpot user
IgnitiusMolepo - PeerSpot reviewer
Senior IP Network Defense at a comms service provider with 10,001+ employees
Real User
Top 20
Feb 28, 2024
Protects internal applications and prevents target attacks
Pros and Cons
  • "The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats."
  • "We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version."

What is our primary use case?

The tool is a valuable web application that protects our internal mobile money application. It enforces policies, ensuring secure access for users connecting to the application. It complies with PCI DSS, safeguarding financial transactions and contributing to our revenue. The solution effectively addresses malware threats.

What is most valuable?

The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises.

You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary.

The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.

What needs improvement?

We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version. 

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the stability of the solution?

You may encounter problems if you don't have FortiAnalyzer. 

What do I think about the scalability of the solution?

My company has 11,000 users. 

How are customer service and support?

We've encountered several issues before, like the web and firmware's lack of responsiveness for 50 minutes. The Firewall, FortiWeb Manager firmware, and firmware updates must sync properly. We've addressed this, and our partners have helped resolve these issues.

Which solution did I use previously and why did I switch?

I tried to work with Cisco, but it wasn't working well. 

How was the initial setup?

FortiWeb Web Application Firewall's deployment is not complex. The setup involves connecting the switch and the firewall. Our main task is to redirect all traffic from the application to the website. The overall process can be completed in two weeks. Maintaining it isn't challenging, but the issue arises when the firmware becomes outdated; you must check and update it.

What about the implementation team?

FortiWeb Web Application Firewall helped us with the deployment. 

What other advice do I have?

I rate the overall solution a nine out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Simone F - PeerSpot reviewer
Director of IT at a tech services company with 11-50 employees
Real User
Mar 13, 2023
Is easy to configure and has pay-as-you-go pricing based on traffic, which is ideal for a start-up company
Pros and Cons
  • "I like FortiWeb's usability and ease of configuration. It's simple to configure rules and exceptions inside the attack log. We block everything by default. If something isn't working, we ask the system admin to adjust the template and add exceptions."
  • "We use Kubernetes, so I would like to have a plugin to configure FortiWeb Cloud automatically using Kubernetes Ingress. That would reduce the complexity of setting up an Ingress object in Kubernetes. Some competing solutions help you configure Ingress and Kubernetes automatically."

What is our primary use case?

We sell a SaaS product deployed on the Azure cloud platform using Kubernetes. We offer a bundle of cloud-based services. The Azure firewall solution is too expensive, so we need to find an alternative solution. 

We are currently testing FortiWeb in a QA environment and plan to deploy it on top of our SaaS product. We are about 95 percent covered now, but we still need to work out some technical details. I believe we will be ready to deploy it into production in the next few months. 

How has it helped my organization?

We currently are using Azure's WAF solution, but it is a little bit expensive for a startup project. The Azure firewall has limited configuration options that aren't helpful in our use case. FortiWeb is easier to configure and has pay-as-you-go pricing based on traffic, which is ideal for a startup company. Once our product starts having steadier traffic, switching to something with fixed pricing might make more sense. Currently, it's a risk for the company. 

It's too soon to say what other benefits we'll see from FortiWeb because we're still in the testing phase. We've watched some training presentations, and we're still working on a strategy for how we'll use the tool. Once we have a clear plan, we'll put it into development, configure the template, and deploy it into production when it's ready. 

it isn't in production. If the developers say a setting isn't working, we adjust the firewall rule, the goal is complete the template before going into production. 

What is most valuable?

I like FortiWeb's usability and ease of configuration. It's simple to configure rules and exceptions inside the attack log. We block everything by default. If something isn't working, we ask the system admin to adjust the template and add exceptions. I'm interested in the AI attack pattern-matching feature, but we haven't tested it yet. 

API is another feature that we haven't used in production, but I'm generally pleased that FortiWeb has this ability, and we can customize our application how we want. 

What needs improvement?

We use Kubernetes, so I would like to have a plugin to configure FortiWeb Cloud automatically using Kubernetes Ingress. That would reduce the complexity of setting up an Ingress object in Kubernetes. Some competing solutions help you configure Ingress and Kubernetes automatically. 

For how long have I used the solution?

We have been testing FortiWeb for the last four months. 

What do I think about the stability of the solution?

FortiWeb seems to be stable so far. 

What do I think about the scalability of the solution?

FortiWeb features automatic scaling because it's in the cloud, so scaling up is easy. 

How are customer service and support?

I rate Fortinet support an eight out of ten. We have only contacted them with a few questions, and they responded promptly. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

In recent years, we've spent money on various projects that required us to protect applications. We have the Azure firewall deployed, and we paid a third-party SOC company to monitor it for attacks. It didn't offer out-of-the-box complete protection easy to customize, so we configure it for watching threats and raised alerts, that's means additional effort. 

We feel that FortiWeb is a better way to go than Azure Web Firewall in our scenario because FortiWeb has some advantages in pricing and features. It's easier to configure and maintain. Also, FortiWeb uses templates. 

How was the initial setup?

There was no initial setup because it's a SaaS solution. We only needed to configure it for our environment. The configuration was straightforward and only took a couple of hours. The only maintenance required is updating the templates. 

What was our ROI?

I would like to use the product based on our initial testing, so I think it's a sound investment. 

What's my experience with pricing, setup cost, and licensing?

We still don't know what the real cost will be because the pricing is based on traffic, and the solution isn't in production. However, we expect it to be cheaper than the Azure Web Firewall.

What other advice do I have?

I rate Fortinet FortiWeb an eight out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Director_45785 - PeerSpot reviewer
Director at a tech services company with 201-500 employees
Real User
Top 5Leaderboard
Jun 13, 2024
Helps block certain applications and websites to enhance user productivity and maintain application security
Pros and Cons
  • "FortiWeb Web Application Firewall helps us to block certain categories of browsing, such as weapons, and other inappropriate content on the client side. We have also blocked social media sites like TikTok and Facebook to enhance user productivity and maintain application security."
  • "We haven't faced any significant issues with FortiWeb Web Application Firewall. But they can lower the pricing, since it is a concern, especially in South Africa and the technical support, could be more responsive at times."

What is our primary use case?

The solution helps us to block certain applications and websites.

How has it helped my organization?

The use of FortiWeb Web Application Firewall, combined with Office 365 and Azure ID, has streamlined our VPN use and network security. With single sign-on, users only need to remember one process instead of two or three, which has improved our business security. 

What is most valuable?

FortiWeb Web Application Firewall helps us to block certain categories of browsing, such as weapons, and other inappropriate content on the client side. We have also blocked social media sites like TikTok and Facebook to enhance user productivity and maintain application security.             

What needs improvement?

We haven't faced any significant issues with FortiWeb Web Application Firewall. But they can lower the pricing, since it is a concern, especially in South Africa and the technical support, could be more responsive at times.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall of the past two years.

What do I think about the stability of the solution?

We have encountered some issues with the stability and would rate it an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten.

How are customer service and support?

The customer services is good but sometimes they are unresponsive.

Which solution did I use previously and why did I switch?

Before FortiWeb and Fortinet, we used to work with Sophos. We switched to Fortinet mainly due to better support and the availability of distributors in our country. In South Africa, Sophos lacked sufficient support and the resolution times for queries were often prolonged. With more vendors and better support, Fortinet has proven to be a more reliable choice.

How was the initial setup?

The deployment process of FortiWeb Web Application Firewall was easy. It took half an hour to be deployed.

What was our ROI?

FortiWeb Web Application Firewall has definitely helped with notifications of potential threats and vulnerabilities. It has impacted our operational costs by reducing them by 20%. This is mainly due to savings on bandwidth and infrastructure costs, as well as improved efficiency in handling potential threats.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing a four out of ten.

What other advice do I have?

FortiWeb should include log retention for 90 or 180 days built into the product, without requiring an additional license. Having to buy extra licenses for longer log retention is problematic and adds to the cost.

I would recommend FortiWeb to other users.

Overall, I would rate FortiWeb an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2106345 - PeerSpot reviewer
Security Specialist at a manufacturing company with 10,001+ employees
Real User
Mar 1, 2023
Cost-effective, easy to configure, and works very well as a single solution for multiple environments
Pros and Cons
  • "The ease of configuration is valuable. We have Azure WAF, we have OCI WAF, and we also have Cloud Armor for GCP, but their configuration isn't very easy. It's pretty simple in FortiWeb, and we can enable or configure whatever we want."
  • "The dashboards are not that configurable. Application-specific dashboards can be improved. If we have 50 applications, there should be something to see what's happening with these 50 applications. There could be a graph or a consolidated alert page where all alerts are inbuilt. They have other products that I can use, but this feature should be built into FortiWeb."

What is our primary use case?

We have multiple environments. Some applications are in Oracle Cloud, some are in Azure, some are in GCP, and some are on-prem. We wanted a single solution for web applications, and that's why we chose FortiWeb. In the case of the cloud, we don't even have to manage it. It's a managed service from Fortinet.

How has it helped my organization?

We have not been using it for a very long time. It has only been eight months, and so far, there have been two main benefits. The first benefit is that if I have an on-prem solution, I can buy their hardware and deploy it, but the configuration is the same. If I have a cloud, I can use FortiWeb as a service or as a virtual machine. It depends on requirements, but the configuration remains the same. The configuration doesn't change. We have a lot of global parts and a lot of teams are working on it, so it gets easy to communicate and verify the configuration and create a baseline.

Costing is another benefit. The cost is based on the traffic. If an application is used, we pay for it, but if it's not used, we don't have to pay for it. With other solutions, we have to buy the solution, and then we have to purchase or take licenses. If they aren't used, we are just burning money without any use.

We are using anomaly detection and bot mitigation. In terms of anomaly detection, it is able to find the behavior. We have some applications where normal users are logging from India, and if the behavior changes, it gives us an alert, but in terms of bot mitigation, I haven't found much.

It's easy to use. I don't have to do any changes in my environment. For example, if I use Azure WAF, I have to use a traffic gateway, load balancer, or something similar, whereas, with FortiWeb, I don't have to change any architecture. I just have to change my DNS entry. That's it. If I'm able to change my DNS entry, FortiWeb works.

Adding new applications is also quite easy. You just add the application and change the DNS settings, and you are good to go. Whether you want to block or unblock, or you want the learning mode or protection mode, you can enable or disable it with just one click, and you are good to go. Most of the settings are already there if you want to tweak them. It has a GUI. You must have to click here and there. The documentation is also good. If I don't know something, their documentation is quite helpful. A lot of people are using Fortinet, so YouTube videos and articles are also available.

The configuration part is easy. The configuration and implementation process is streamlined. We don't have to change anything. We don't have to follow 10 processes. It's a single process with which everybody is familiar. Manpower and manhours are saved because a lot of discussions are avoided. It also helps us in creating a baseline. We now have a baseline of what we need. So, from an instant response point of view, it's easy for us because we are getting the same results out of it.

It has reduced false positives. As compared to my old solution, there is at least a 17% to 18% reduction.

It has reduced the number of alerts that our organization receives. There is a 50% to 60% reduction in alerts.

It has saved us time. We were spending around three to four days setting up our old solution, whereas now, we are spending a maximum of four hours.

What is most valuable?

The ease of configuration is valuable. We have Azure WAF, we have OCI WAF, and we also have Cloud Armor for GCP, but their configuration isn't very easy. It's pretty simple in FortiWeb, and we can enable or configure whatever we want.

Its cost is also good. If I'm using an application for 15 days, I pay only for 15 days.

FortiWeb is good for blocking unknown threats and attacks. I've done a PoC with Azure WAF and OCI WAF, and in comparison, FortiWeb is quite good.

What needs improvement?

The dashboards are not that configurable. Application-specific dashboards can be improved. If we have 50 applications, there should be something to see what's happening with these 50 applications. There could be a graph or a consolidated alert page where all alerts are inbuilt. They have other products that I can use, but this feature should be built into FortiWeb.

Reporting could also be better. There should be inbuilt reports that we can use to present on how it is benefiting and other things. We should be able to get reports in PDF or other common formats.

For how long have I used the solution?

It has been around eight months.

What do I think about the stability of the solution?

Its stability is good. Stability-wise, there aren't any major differences among Azure WAF, OCI WAF, Google Cloud Armor, and Fortinet FortiWeb.

What do I think about the scalability of the solution?

If I'm using FortiWeb as a service, I don't have to care about scaling because everything is taken care of by Fortinet. From a scaling point of view, I don't have to do anything. If it's on-premises, we already know how many users are going to use it, and we can decide on the model accordingly. So far, we haven't had to scale it up for any project.

How are customer service and support?

I've not contacted them for FortiWeb. We are also using Fortinet firewalls for which I've taken their help.

Which solution did I use previously and why did I switch?

We had our own solution. We called it SecOps. It had something from RedHat and something from OPNsense. We built it that way. We were using that. We switched to FortiWeb because of two reasons. The first reason was the cost, and the second thing was that we wanted a single solution that can be implemented everywhere. We are from R&D. We decide on a solution, and then our product team implements it. When we have multiple tools, operations and maintenance become quite a headache because every tool has its own learning curve. All tools are not the same.

How was the initial setup?

We have on-premises as well as public cloud environments. We have Azure, OCI, and GCP. 

Its initial setup is straightforward. It takes a little bit more time the first time because we have to set up the subscription, etc. Next time, it takes only around four hours.

What about the implementation team?

We implemented it in-house. We are a global team, so a lot of people were involved. From the R&D side, at least five to six people were involved.

In terms of maintenance, when it's on-prem, some sort of maintenance is required in terms of firmware upgrades. We also follow ISO standards, so we have to do maintenance. We have a requirement to check everything once a month, but FortiWeb doesn't take much time.

What was our ROI?

We have been using it only for eight months, so I need more time to see its price-performance ratio, but it's worth the money. I'm getting what I'm paying for.

There are time savings. Previously, we were spending four to five days setting up our SecOps solution, whereas now, we are spending only four hours.

What's my experience with pricing, setup cost, and licensing?

When I use any other firewall, I have to take a license. It could be a perpetual license or subscription-based. In both cases, we have to pay some amount in advance, whereas in the case of FortiWeb, when using it as a service, I am paying half a dollar only for the domain name, and then I am paying based on the traffic or the number of requests. In every organization, there are some applications that are heavily used, and there are some applications that are not heavily used. So, why go with a yearly, three-yearly, or five-yearly plan when you can just pay based on the traffic that WAF is processing? Previously, for each project, the cost was $800 to $1,000 per application. Now, it's $100 to $120. For some of the applications, there is a 90% reduction, and for some of the applications, there is a 50% reduction. We're paying only $500 to $600.

Which other solutions did I evaluate?

We checked OCI WAF, Microsoft Azure WAF, Google Cloud Armor, and Fortinet FortiWeb. We also checked other WAF solutions such as Akamai and CloudFlare but didn't do a PoC with them. We did a PoC with OCI WAF, Microsoft Azure WAF, Google Cloud Armor, and Fortinet FortiWeb.

We went for Fortinet FortiWeb because we wanted a single solution that can be implemented anywhere. If we use Azure WAF, it would be hard to use in GCP. We have to create a connection between both, whereas we can implement Fortinet FortiWeb on any cloud. If we have on-prem applications, we can implement FortiWeb hardware as a solution. In some places, we have strict requirements. If it's a VMware data center, they also have the FortiWeb VM solution. If we want to use Docker images, they also provide Docker images. We can just use a single tool. We are not dependent on multiple tools.

What other advice do I have?

Every team has different requirements, but if you need an easy solution that can be deployed in a very short time, FortiWeb is the right one. It doesn't need too much expertise when you're initially configuring it, and even if you're testing it, the cost is quite low. It's good even for small projects.

It has the API gateway functionality, but we aren't using that. We are also not using API discovery and API security. I've enabled machine learning, but we have not used it a lot. We are in the exploring phase.

Overall, I'd rate Fortinet FortiWeb an eight out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Blair Griffith-Barwell - PeerSpot reviewer
Principal Network Architect at a financial services firm with 201-500 employees
Real User
Top 5
Feb 23, 2023
It comes with several preconfigured rule sets and templates that make deploying new applications easier
Pros and Cons
  • "FortiWeb's ease of deployment is what we liked the most about it. Implementing FortiWeb was extremely fast and easy, which was a significant advantage. It comes with several preconfigured rule sets and templates."
  • "Another area for improvement is logging. When troubleshooting, the logs sometimes take a while to update. We've had people report that some things aren't logged if they're successful. It's a bit hit-and-miss. For example, sometimes people access one of our services, and it's successful, but we don't see that in the logs."

What is our primary use case?

We are a payment processor with infrastructure deployed across various environments, including AWS, on-prem, and various other environments. We are PCI Level One certified, and one of our requirements is WAF. FortiWeb is a tool we use to secure access to our public-facing applications and services.

Our environment is primarily cloud-based, and all of our services are AWS. We were in the process of migrating to the cloud when we implemented FortiWeb, but we still needed to maintain some on-premise infrastructure to serve different regions. We were happy with the solution after deploying it in the cloud, so we discussed the possibility of also using it with our on-premise applications based on the initial results. Many of those services are now moving to the cloud, so we won't deploy them on-premise anymore. 

We are using FortiWeb across multiple locations in London and Singapore, so we have WAF services sitting in front of applications across both sites. Our applications include various payment processing platforms, fraud prevention tools, and other related customer-facing services based in various locations within the AWS cloud.

A ten-person network team is responsible for administering FortiWeb. It's difficult to say precisely how many end-users there are because we provide this solution to third parties, but around 160 clients connect to the applications behind these services. Our clients are typically small or medium-sized enterprises.

How has it helped my organization?

FortiWeb provides an additional layer of security that we didn't have previously. We have a next-generation firewall deployed in our cloud infrastructure, but the WAF is the most external-facing piece. The WAF passes traffic to our internal next-generation firewalls.

We have also benefited from FortiWeb's load-balancing capabilities. FortiWeb enables us to load-balance without the need to take on an additional service. In most cases, we've been able to use load balancing provided by the AWS gateway. We have two servers with services deployed across multiple availability zones behind there. In addition to security, WAF allows us to load balance traffic across those servers in various availability zones without adding more load balancers.

FortiWeb streamlines tasks because we've eliminated other functions like load balancing. The API is also excellent. Someone on my team created an application that integrates with the API to quickly add new IP addresses without changing the templates. We've found it's helped us streamline some of our usual BAU tasks.

We already had a low false positive rate, but FortiWeb has lowered it further. Detections in our report tend to be accurate. We still get occasional false positives, but some of that probably relates to our custom-built applications. FortiWeb decreased our false positives by around 30 percent. 

We used to get a lot of alerts from our traditional firewall, but the number has declined significantly since deploying FortiWeb. It was a reduction of about 70 to 80 percent. The alerts coming from FortiWeb are helpful. They inform us of things that require action. We previously got many alerts from our public-facing services. We didn't have an efficient means of getting alerts. The same threat provided multiple alerts. That would keep going and could be overwhelming at times.

What is most valuable?

FortiWeb's ease of deployment is what we liked the most about it. Implementing FortiWeb was extremely fast and easy, which was a significant advantage. It comes with several preconfigured rule sets and templates. 

FortiWeb effectively addressed unknown threats. We get regular reports that we check. So far, we've had no issues at all. Around 99 percent of our public-facing infrastructure is restricted by source IP to our partners' networks, so our attack surface is restricted. WAF picked up and blocked any attacks before they can impact us. 

FortiWeb is effortless to use and manage. The documentation is excellent, which is another huge advantage. The layout is logical and intuitive. You can create templates and reapply them to new applications, so we don't need to do a fresh configuration for each application. We have a template that represents our security benchmark. There are a few exceptions that we need to add for each application, but we can redeploy the security benchmark template for each new application that we create.

What needs improvement?

One area that needs improvement is using IP addresses within templates. If you allow an IP address to access an application, you should be able to leave a description of that. For example, we allow clients to access these services, and some are restricted to the IP address. When you add an IP, there's no way within the product to say what the IP address is. 

We need to maintain a separate external list because we need to remove any IP address associated with a client if they stop using our services. In many other products, you can create an object specifying that this IP address is for a client of this name or this service. You don't have this ability within FortiWeb. 

Another area for improvement is logging. When troubleshooting, the logs sometimes take a while to update. We've had people report that some things aren't logged if they're successful. It's a bit hit-and-miss. For example, sometimes people access one of our services, and it's successful, but we don't see that in the logs. 

For how long have I used the solution?

I've been using FortiWeb for around 18 months. 

What do I think about the stability of the solution?

FortiWeb is highly stable. I can't recall an instance when we've had any issues. Our services are used constantly. For example, we have a fraud prevention tool that various banks and FinTech companies access, and FortiWeb is deployed behind it. We've never had a problem with availability due to FortiWeb. The solution is 100 percent stable and available. 

What do I think about the scalability of the solution?

I'm satisfied with FortiWeb's scalability. It's always met the needs of our applications. We can deploy it in any application that we want to deploy behind. 

How are customer service and support?

I rate Fortinet support an eight out of ten. The technical support has gotten better. There were a few difficulties when we first raised some calls. It was a new product, and we weren't getting clarity on whether some of the actions we asked about were possible. Initially, the response was also a bit slow. We chalked that up to the fact that we were early adopters of the product. The support has improved since then, and we're happy with it today. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We didn't have a WAF solution, but we used Palo Alto Networks Next-Generation Firewalls. While these firewalls had many WAF capabilities, they weren't considered WAF products. 

Our main reason for deploying a WAF solution was to satisfy regulatory requirements. To get a PCI Level One certification, we need a WAF on some of these public-facing services. FortiWeb Cloud ticked all the boxes and met our requirements.

How was the initial setup?

I initially deployed a lot of the applications. It was so quick and easy. FortiWeb took about a week to deploy, including assessment and testing. We had to create a new environment. Much of our on-premise infrastructure was closed off in the past, so we required no WAF for regulatory compliance. 

To create this new environment, we onboarded some new services that were classified within the scope of PCI. They were deployed in the old way with firewalls. However, our QSA said we needed to have services behind the WAF, and we were being assessed in a week. We had to find and deploy a WAF before we were audited. 

I have a team, but I and one other engineer were involved in the deployment. After the setup, FortiWeb requires minimal maintenance, which is one aspect we like about it. We've occasionally had to open a support ticket for the odd bug that's come up. There's typically no maintenance on our end. I can't think of a time when we've had issues with availability from FortiWeb. 

What was our ROI?

It's hard to calculate an ROI monetarily.  Some of the services we provide based on FortiWeb are charged to the clients. I can't say much about it from that perspective. However, we've seen benefits from a time and resource perspective. Also, having a cloud-based WAF means we don't need to maintain the infrastructure, and we can quickly deploy new applications. We derive a massive value from the reusable templates. 

We also save money and resources because we don't need to deploy more EC2 instances or use additional products for load balancing and other functions. That's potentially an 80 percent reduction in those costs.  

What's my experience with pricing, setup cost, and licensing?

FortiWeb is transparent about how much each application costs. When you create an application, it will tell you the estimated cost. The licensing is clear, so we can see that we're getting a good value. 

We're satisfied with the price. Our organization sometimes questions if we're getting our money's worth, but we get a decent value from FortiWeb for the price. Everyone on our team and within the infrastructure area is happy with it.

Which other solutions did I evaluate?

I'm the network team lead, so I assessed and deployed FortiWeb. I looked at several options. I knew the Fortinet brand but was unfamiliar with FortiWeb WAF. After researching it, I recognized that it was potentially a product that we could use. I did a demo and found that it ticked all the boxes.

What other advice do I have?

I rate Fortinet FortiWeb a nine out of ten. I would definitely recommend the solution. FortiWeb is rich in security features and additional features like load balancing. It's one of the best products we use. 

It's easy and quick to deploy. The documentation is excellent. We are pleased with the product and see it as an integral part of deploying new applications in the cloud or on-premises efficiently.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.