Mostly we use FortiWeb for replacing reverse proxy from our systems and add some security features to it to protect the web portal we are providing to our customers. We use it to rewrite URLs and redirect FQDNs, et cetera, et cetera. That's the normal part.
Senior Technical Consultant at PROMOS consult
Good file security and redirect web traffic well but we had trouble with a few features
Pros and Cons
- "One main feature we are very happy about is file security and upload functionality."
- "The GUI could be better. It's limited."
What is our primary use case?
What is most valuable?
The main feature I like is the ability to redirect web traffic from a readable URL to a real URL. All the security features are good.
One main feature we are very happy about is file security and upload functionality. It will restrict the number of file types that can be uploaded to our portal and prevents any malware. It helps with security.
What needs improvement?
We had some trouble using some features. Maybe we understood it the wrong way when reading the manual. We had to implement some workarounds to help this problem.
The GUI could be better. It's limited.
For how long have I used the solution?
I've been using the solution for one year.
Buyer's Guide
Fortinet FortiWeb
December 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
There are no complaints on our side. The performance and stability are fine. We used to have a cluster of two appliances. Everything seems to be fine when we update the firmware. We haven't had any issues.
What do I think about the scalability of the solution?
The scalability may be slightly limited. We use hardware appliances. We need to buy appliances which have enough performance. You need to think about the sizing before you buy it. Scalability is not really possible with hardware.
We use it more and more. We are going to migrate all the connections which are directed to a proxy to the classification firewall.
How are customer service and support?
Normally, technical support is very good. All the tickets I opened have been solved in an average time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
It was the very first time that we used a web application firewall. We never used anything before.
How was the initial setup?
We had some difficulties at the beginning in terms of setting it up. It was a very new product for us. We never had web protection firewalls before. We had some support from our supplier, so we referred to the initial implementation to get it done with external support.
I'd rate the ease of implementation at a three out of five.
From a technical perspective, the deployment does not take a long time. Our problem internally was the organization and the planning as well as the communication with the other teams. That's what took so long. We started maybe one and a half years ago with the implementation and productive status was reached at the end of 2021. That's a long time. That said, one would say the management is at fault, not the actual technical staff.
At a cluster, so single point of failure, all this stuff, it kind of took around 24 hours to get it up. The offline time was very difficult, however.
We have two good people on staff that can handle deployment and maintenance. We are looking for another employee in the market, however, it's been very difficult to find someone.
What about the implementation team?
The implementation was done in-house with some help from our supplier.
What was our ROI?
We have not noted an ROI yet.
What's my experience with pricing, setup cost, and licensing?
We actually expanded our subscription for the next three years. I don't remember the exact price. It should be somewhere about 36,000 Euros. That's the cost for three years. It's moderately priced. I'd rate the general cost at a three out of five.
Which other solutions did I evaluate?
We thought about other options, however, since we had a very good experience with the FortiGate Firewall, I decided to buy FortiWeb. They operate well together.
What other advice do I have?
We are just customers and end-users.
Potential new users should compare different products from different vendors to make a decision on a web application firewall. It doesn't matter if it is FortiWeb, or F5, or something else, just take some time to compare.
I'd rate the solution six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
I.T. Manager at Pacific Cigarette Company
Visible ROI with the security the solution provides
Pros and Cons
- "The reason I recommend this product is because it guarantees that your network will be safe if it is set up properly and you fully utilize most of the functions."
- "I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted."
What is most valuable?
The features I found valuable were web filtering, reporting, and the dashboards. We use these features for controlling the traffic in our network, mainly for our security. This means that we can have policies there that allow or don't allow certain connections.
What needs improvement?
I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted.
For how long have I used the solution?
I have been using Fortinet FortiWeb for more than ten years.
What do I think about the stability of the solution?
The only instance where we have had issues with stability was a recent one where the solution was blocking some websites that we did not intend to block and which were even whitelisted in some instances.
Our partners explained that this happened because of an issue with the SSL setup. I'm not sure if they then sorted it out or if they just switched off that functionality.
But for the past 10 years that we've used it, that was the first error or problem that we ran into. Maybe it was just teething problems since we only deployed it end of last year.
What do I think about the scalability of the solution?
My impression is that it's quite scalable because I know they have different sizes. In one of our organizations, we had fewer users, so we're using a smaller one, which was a 60-day or something like that. And then when you are using it for a bigger organization, they also have that type of device for many users.
They'll ask you how many users are going to be governed by this firewall. So when we had fewer users, we got a smaller firewall. And then when we expanded and had many more users, we got a bigger one. It's quite scalable I think.
How are customer service and support?
Their technical support is good. They'll jump onto the occasion. When you submit a log report or you request some support, they quickly respond. I would rate them a ten. Very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to Fortinet, we used Netgear, but this was a long time ago. I think this was 15 years ago.
How was the initial setup?
The initial setup was not straightforward. You need an expert to set it up with you and to configure it for you. I think the more you work with it, the better accustomed you are to it. The initial setup did not take longer than a week.
The deployment was done in a team of three people.
What about the implementation team?
We implemented it with a third party, and they're the ones who always then deploy and implement it for us. The deployment didn't take more than a week.
What was our ROI?
I would say that the ROI is visible because we are happy with the security it provides.
What's my experience with pricing, setup cost, and licensing?
The pricing is a bit high. It is not a cheap product.
What other advice do I have?
The reason I recommend this product is because it guarantees that your network will be safe if it is set up properly and you fully utilize most of the functions.
Overall, I would rate FortiWeb solution a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiWeb
December 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
Senior Information Security Consultant at Future Telecom
Integrates very well and easy to use, configure, and manage
Pros and Cons
- "The customers are very happy with this solution because of two things. First, the IPS integration with a web application is very tightly done on Fortinet. Second, the ease of use is there. The management interface or the GUI interface is very easy to use, configure, and manage. These are the two main valuable features. It supports integration with other Fortinet products. It also integrates very well with the firewall and sandboxing technology. They already have enough integration with different technologies. They have got a complete tech intelligence view of the whole product."
- "They could improve their support a little bit for faster response time."
What is our primary use case?
We have deployed a couple of projects for our customers to protect their online e-commerce systems. They have web-based applications for online ordering, for example, for online ordering from a hypermarket. It seems to be a very good solution. We have replaced the existing Barracuda devices of a customer. We deal with the latest version of Fortinet FortiWeb.
What is most valuable?
The customers are very happy with this solution because of two things. First, the IPS integration with a web application is very tightly done on Fortinet. Second, the ease of use is there. The management interface or the GUI interface is very easy to use, configure, and manage. These are the two main valuable features.
It supports integration with other Fortinet products. It also integrates very well with the firewall and sandboxing technology. They already have enough integration with different technologies. They have got a complete tech intelligence view of the whole product.
What needs improvement?
They could improve their support a little bit for faster response time.
For how long have I used the solution?
I have been using Fortinet FortiWeb for two years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is very scalable. The web application firewall is protecting the web servers in an organization from outside to inside. It probably has more than 1,000 users.
How are customer service and technical support?
Their technical support needs a little bit of improvement in terms of faster response time.
How was the initial setup?
The initial setup is very straightforward. It took about 30 to 40 minutes for one web application for default settings. If you want to go with complex settings, then it would probably take three to four days to understand the application backend and everything else.
What about the implementation team?
We used a system integrator. One Admin is more than enough to deploy and maintain it. It is very stable and easy to configure and deploy.
What's my experience with pricing, setup cost, and licensing?
Its subscription prices are cheaper, and it is not very expensive. From a price perspective, Fortinet is a very well-known security vendor.
Subscriptions are very simple. They have a couple of licenses on an appliance, and that's it. The cost is not that big. One license is 40K, which they give with all the products. Another one includes the subscriptions for threat prevention, IPS, sandboxing, etc, which is more than enough.
What other advice do I have?
Fortinet FortiWeb is rated as one of the top WAF devices in many of the independent research reports. Our customers find Fortinet FortiWeb much better than other solutions.
We plan to continue using this solution if an opportunity is there. It depends on the customer's requirements. If a customer is going for an online e-commerce website, we would always recommend going with Fortinet FortiWeb.
I would rate Fortinet FortiWeb an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Data Center Network Expert at TOSAN
User-friendly and makes it easy to find vulnerabilities
Pros and Cons
- "This product is very user-friendly."
- "FortiWeb needs to have support for the newest technology being used in web applications."
What is our primary use case?
We are using FortiWeb for publishing web services and some web applications.
What is most valuable?
The interface makes it easy to identify vulnerabilities.
The best features for us are the signature services. The devices uses signatures for identifying vulnerabilities in web applications.
This product is very user-friendly.
The security is very good.
What needs improvement?
FortiWeb needs to have support for the newest technology being used in web applications. For example, some companies have developed new features using the latest technology, but we are still waiting for Fortinet to support them.
For how long have I used the solution?
I have been using FortiWeb for between four and five years.
What do I think about the stability of the solution?
The stability is very good and we're fortunate that we haven't had any issues.
What do I think about the scalability of the solution?
We have had no issues with scalability.
How are customer service and technical support?
We are in Iran and working under sanctions, which means that we cannot buy new American products and cannot get support. Companies usually buy devices that are second hand, or from a third-party, neither of which have support.
That said, my impression is that the support is good for companies who are eligible to use it.
How was the initial setup?
The initial setup was not complex. Like all Fortinet devices, it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
Due to the situation in Iran with the sanctions, the price of this solution is very expensive.
Which other solutions did I evaluate?
The only other two web application firewall products that are available in my country are F5 and Imperva.
What other advice do I have?
This is a good product and I strongly recommend it, especially for companies in the banking industry.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Information Security Officer at State Audit Office
Flexible, easy to learn and configure, and has almost everything that a web application firewall needs
Pros and Cons
- "It is a good product. We have just blocked everything coming from some geographical locations or certain countries, and it has been working very efficiently when I look at logs, events, and incidents generated from the system. It is generating very good analytic reports about it. This is the most valuable thing about this solution. It has load balancing and almost everything that a web application firewall needs. It is very flexible and easy to learn and configure. It can be easily learned and configured by using the information available on different channels such as YouTube."
- "When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it."
What is our primary use case?
We have been testing FortiWeb in our environment. We have it on virtual machines. We used it to block requests from some geographical locations or certain countries. It is very important for us because many attack attempts, logs, and events were generated from those geographical locations. Our country has some political difficulties in the region with other countries.
What is most valuable?
It is a good product. We have just blocked everything coming from some geographical locations or certain countries, and it has been working very efficiently when I look at logs, events, and incidents generated from the system. It is generating very good analytic reports about it. This is the most valuable thing about this solution.
It has load balancing and almost everything that a web application firewall needs. It is very flexible and easy to learn and configure. It can be easily learned and configured by using the information available on different channels such as YouTube.
What needs improvement?
When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it.
For how long have I used the solution?
I have been using this solution for three months.
What do I think about the stability of the solution?
Based on what I know and see during the testing mode, it is stable. There has been no major incident. It has not stopped during this time.
What do I think about the scalability of the solution?
It is flexible and scalable. We have about 400 employees, and all of them are using this solution.
How are customer service and technical support?
We don't have any experience with international support. The local guys from our partner High Tech Solutions are so educated and professionals that we didn't have any need to use international support. They are doing well and are available all the time. They are always ready to help and support whether it is a working hour or not.
What about the implementation team?
We have one System Admin who works on the configuration and an InfoSec officer who looks into events, incidents, and logs and analyzes them. So, we have two people. We also have our head of the department, and we are responsible and accountable to him.
Which other solutions did I evaluate?
We have also tested other products such as Imperva and F5, and the most number of likes were for F5 and FortiWeb.
What other advice do I have?
We like the product, but we haven't yet decided to purchase it because we don't have the budget for now. We will express our preferences towards FortiWeb to our top management, and it will be decided by them. We will suggest to them that it is a good product.
I would rate Fortinet FortiWeb a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Software Engineer at a outsourcing company with 51-200 employees
Efficient threat prevention and reporting with strong ROI
Pros and Cons
- "The reporting and token system is good."
- "I see no room for improvement at the moment."
What is our primary use case?
We are studying ClearPass as a solution. I was requesting a comparison between Aruba ClearPass and FortiWeb Forti.
How has it helped my organization?
FortiWeb has been a helpful investment in our network.
What is most valuable?
The reporting and token system is good. The AI machine learning was qualified to block and report any suspicious activity.
What needs improvement?
I see no room for improvement at the moment.
For how long have I used the solution?
I have been familiar with FortiWeb for about three years now.
How are customer service and support?
The technical support is very helpful. I rate their technical support a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I only worked with similar solutions as a POC.
How was the initial setup?
The initial setup was easy.
What was our ROI?
FortiWeb has been a good investment, helping our network and providing a return on investment.
What's my experience with pricing, setup cost, and licensing?
The pricing of Fortinet FortiWeb is affordable and competitive.
What other advice do I have?
I recommend FortiWeb to others. I wish there were more integration with Azure systems.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Nov 15, 2024
Flag as inappropriatePresale Engineer at a computer software company with 1,001-5,000 employees
Has excellent performance, pricing, and support services
Pros and Cons
- "The support services, performance, and pricing are all valuable features. The performance is excellent."
- "The initial setup process could be improved."
What is most valuable?
The support services, performance, and pricing are all valuable features. The performance is excellent.
What needs improvement?
The initial setup process could be improved.
For how long have I used the solution?
I've been working with this solution for two years.
It is deployed both on-premises and on the cloud.
What do I think about the scalability of the solution?
In general, we have small projects, so the scalability has been fine for our clients.
As for users, we have, in general, 50 to 100 clients.
How are customer service and support?
My colleagues at the network operations center have contacted technical support. I would rate technical support at eight on a scale from one to ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We sell and work with several options, but we feel comfortable with Fortinet FortiWeb because the performance and feedback are great.
How was the initial setup?
In general, the initial setup is easy, and I would rate it at four out of five.
What about the implementation team?
I deployed it myself.
What's my experience with pricing, setup cost, and licensing?
There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four.
I have not encountered any additional costs on my projects involving Fortinet FortiWeb.
What other advice do I have?
I sell or presell, and in general, the feedback is great. In fact, I think that Fortinet FortiWeb is number one in terms of performance.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
IT Infrastructure Manager with 201-500 employees
The learning mode of the appliance picks up on the pattern of SSL attacks
Pros and Cons
- "I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks."
- "We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
What is our primary use case?
We use it mostly to secure our web platform for things like Internet banking, email, and SMTP. It is for anything that is external coming into our internal network.
How has it helped my organization?
We were having a lot of probe attacks coming through from our external networks. Now, the traffic has to come through our firewall, then FortiWeb. Basically, FortiWeb acts like a second firewall for all our applications.
What is most valuable?
We have been using all the features and everything is nice.
I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks.
What needs improvement?
We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced.
We had trouble understanding it at first, but we got used to using it after six months. Then, it was simple to use.
For how long have I used the solution?
We have been using it for five years (since 2015).
What do I think about the stability of the solution?
We haven't had any issues with it so far.
What do I think about the scalability of the solution?
The scalability is okay. There hasn't been a need to upgrade. We have found something that can adapt to our environment and that we can use for a long period of time.
We plan to use the product for the next two years. There are no major upgrades planned anytime soon.
There are four users for the product (with two being from the security team).
How are customer service and technical support?
We have needed minimal support for the solution. The support has been okay.
Which solution did I use previously and why did I switch?
We did not have a solution that we previously used.
How was the initial setup?
It is complex to set up in learning mode. It takes a lot of time to learn the pattern of the web application before we put in the rule. The rule itself is a bit complex. We had to go by trial and error because there is nothing standard on the device.
The deployment took almost six hours to get up and running.
What about the implementation team?
We used a reseller. They helped us implement the device.
The reseller also does deployment and maintenance. For this, it takes about two of their staff and one or two of our staff internally. The staff will generally have experience in networking and firewalls with a background in security and port mapping.
What's my experience with pricing, setup cost, and licensing?
All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500.
Which other solutions did I evaluate?
Since we were using FortiGate firewall, we decided to look at FortiWeb. We also looked into several solutions, like Check Point and Palo Alto.
What other advice do I have?
The type of product you get depends on what you want to protect, how you want to protect it, and how many people will be accessing FortiWeb.
What we have now is working fine.
I would rate FortiWeb as an eight (out of 10).
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
F5 Advanced WAF
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?
- When evaluating Web Application Security, what aspect do you think is the most important to look for?