Normally I deal with on-premises installations. The firewalls are always on-prem for government departments. In a recent case, I was looking at a cloud solution because it was what the client preferred. So it was the Fortinet rules applied to an AWS solution. I was looking at the architecture around becoming an IRAP (Information Security Registered Assessors Program) certified program and I was looking at the AWS firewalls around how it would be able to comply with the ISM (International Safety Management) standards.
GRC Security Consultant at Ionize
This flexible suite solves compliance problems but that comes at a cost
Pros and Cons
- "If I need something from tech support, I can get it answered within the hour."
- "Both the internal firewall management and the cloud can be managed by a single console."
- "It costs too much."
- "It is not entirely user-friendly."
What is our primary use case?
What is most valuable?
For me personally, the most valuable thing is that I like the fact that it is standardized so both internal firewall management and the cloud can be managed by the same company. Communication between the two works well and it can be a benefit. We can keep a single console to manage both.
What needs improvement?
User administrative controls could be a little bit better. I guess that would be the main thing. The usability within Fortinet could be a little bit easier on the users. But it is what it is.
The thing that was more difficult was not the tool itself but dealing with the logistics of the compliance issues. I was applying a standard set of rules to an AWS firewall. It served a purpose. The complex part of the solution was more of a compliance issue.
For how long have I used the solution?
We have been using Fortinet FortiWeb probably for over a year-and-a-half. Closer to two years.
Buyer's Guide
Fortinet FortiWeb
January 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the scalability of the solution?
At this point in time, scalability seems to be fine. I mean, we are talking processing requests from all over Australia. It seems to be keeping up quite well. My impression of it at this stage is that it is very scalable. It is quite well suited for data management.
How are customer service and support?
I think judging our experience with technical support is a little bit unfair because I know all the local support people. I do go into the help desk when I have to, but I do know most of the teachers or technical support staff. I would rate them as being very responsive to customers. I have had no issues. If I need something I can get it answered within the hour. It is quite good.
How was the initial setup?
It was quite easy to do the initial setup and apply basic rules. Administratively, keeping an AWS firewall and applying the Fortinet rules made it quite simple for the difficulty level of this particular requirement.
What's my experience with pricing, setup cost, and licensing?
I think that ForiWeb is expensive for what they are offering. At the end of the day, when you sell a suite, compliance within the suite is easy to maintain. That is the good part. It is an expensive suite and it is an expensive solution, but it is a manageable one for an enterprise. It should just be cheaper for what they are offering in comparison to other tools on the market.
What other advice do I have?
My advice to people would be to evaluate the marketplace against your requirements and choose appropriately. Fortinet does operate at the enterprise level. It is listed on the Australian standard and it does carry Australia's approval for common criteria. So it does address the requirements needed for security for the assessments. Not every product can.
On a scale from one to ten (where one is the worst and ten is the best), I would rate this Fortinet solution as a seven-out-of-ten because of user administrative controls, usability, and price.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Specialist at a financial services firm with 201-500 employees
Efficient, stable, and has good IP reputation features, but there are many false positive with the layer 7 attacks
Pros and Cons
- "It's stable and works efficiently against OWASP Top 10 attacks."
- "The Layer 7 DDoS attacks need improvement, it could be better."
What is our primary use case?
Fortinet FortiWeb is known for its web application firewalls. We are using it for preventing and detecting layer 7 attacks such as SQL injection.
We have several web applications in our organization and we use this solution to protect them against attacks.
What is most valuable?
It's stable and works efficiently against OWASP Top 10 attacks.
It's good at checking IP reputation and it's capable of detecting Layer 7 DDoS attacks.
Overall, it has many features.
What needs improvement?
The Layer 7 DDoS attacks need improvement, it could be better. When you compare it with the F5 solution, FortiWeb is weak in detecting the Layer 7 DDoS attacks. At times, it generates several false positives and there should be fewer.
In the next release, I would like to see better DDoS protection. It's an essential feature that should be included.
For how long have I used the solution?
I have been using Fortinet FortiWeb for more than five years.
We are using the 4000D model.
What do I think about the stability of the solution?
It's a stable solution and we run it 24/7. In the past five years, we have had four cases where there were some inconsistencies with the firmware. There are times where we experience crashes because of issues with the firmware.
What do I think about the scalability of the solution?
It's not easy to scale this solution. It has a determined throughput and if your throughput is more than it should be then you have to use another solution or purchase another FortiWeb model.
We have less than 10 people using this solution on a daily basis.
How are customer service and technical support?
We are not able to use international support because of US sanctions. We use a consultant to help us troubleshoot.
Which solution did I use previously and why did I switch?
Previously with another company, we used ModSecurity, which is an open-source solution. FortiWeb is better.
If I compare with F5 solutions, I would suggest F5.
How was the initial setup?
The initial setup was not easy but not exactly complex.
We maintain the system ourselves.
What about the implementation team?
We completed the initial setup ourselves and we had a consultant help us with some of the features. It was a hybrid implementation.
What's my experience with pricing, setup cost, and licensing?
It's an expensive solution, although there are no additional costs.
What other advice do I have?
In my opinion, F5 is the best solution in the world, whereas Fortinet FortiWeb would be second.
I have heard that Barracuda is a good solution, but I have not worked with it. In my experience, F5 is the better solution.
I would rate Fortinet FortiWeb a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiWeb
January 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Data Center Network Expert at TOSAN
User-friendly and makes it easy to find vulnerabilities
Pros and Cons
- "This product is very user-friendly."
- "FortiWeb needs to have support for the newest technology being used in web applications."
What is our primary use case?
We are using FortiWeb for publishing web services and some web applications.
What is most valuable?
The interface makes it easy to identify vulnerabilities.
The best features for us are the signature services. The devices uses signatures for identifying vulnerabilities in web applications.
This product is very user-friendly.
The security is very good.
What needs improvement?
FortiWeb needs to have support for the newest technology being used in web applications. For example, some companies have developed new features using the latest technology, but we are still waiting for Fortinet to support them.
For how long have I used the solution?
I have been using FortiWeb for between four and five years.
What do I think about the stability of the solution?
The stability is very good and we're fortunate that we haven't had any issues.
What do I think about the scalability of the solution?
We have had no issues with scalability.
How are customer service and technical support?
We are in Iran and working under sanctions, which means that we cannot buy new American products and cannot get support. Companies usually buy devices that are second hand, or from a third-party, neither of which have support.
That said, my impression is that the support is good for companies who are eligible to use it.
How was the initial setup?
The initial setup was not complex. Like all Fortinet devices, it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
Due to the situation in Iran with the sanctions, the price of this solution is very expensive.
Which other solutions did I evaluate?
The only other two web application firewall products that are available in my country are F5 and Imperva.
What other advice do I have?
This is a good product and I strongly recommend it, especially for companies in the banking industry.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Senior Specialist, IT Security at Ethiopia Commodity Exchange
Beneficial reports, reliable, and scalable
Pros and Cons
- "The most valuable feature of Fortinet FortiWeb is the reports and the AI-based features."
- "Fortinet FortiWeb could improve data integration."
What is most valuable?
The most valuable feature of Fortinet FortiWeb is the reports and the AI-based features.
What needs improvement?
Fortinet FortiWeb could improve data integration.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately six months.
What do I think about the stability of the solution?
Fortinet FortiWeb is a stable solution.
What do I think about the scalability of the solution?
The Fortinet FortiWeb is scalable.
We have three administrators using the solution and more than 300 end users using it.
How are customer service and support?
The support from Fortinet FortiWeb is good, but they could improve their response time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use another solution prior to Fortinet FortiWeb.
How was the initial setup?
In the initial setup of Fortinet FortiWeb, we wanted to deploy it with WCCP mode, but we cannot do it because of the limitation with our Cisco ASA firewalls. It's difficult to integrate with FortiWeb. It is difficult to integrate Fortinet FortiWeb with other vendors other than Fortinet solutions. We cannot integrate it into our existing Cisco Firewall environment. We had to change the system to true transparent deployment mode.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb is expensive in our Ethiopian currency.
What other advice do I have?
I rate Fortinet FortiWeb a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Software Engineer at a outsourcing company with 51-200 employees
Efficient threat prevention and reporting with strong ROI
Pros and Cons
- "The reporting and token system is good."
- "I see no room for improvement at the moment."
What is our primary use case?
We are studying ClearPass as a solution. I was requesting a comparison between Aruba ClearPass and FortiWeb Forti.
How has it helped my organization?
FortiWeb has been a helpful investment in our network.
What is most valuable?
The reporting and token system is good. The AI machine learning was qualified to block and report any suspicious activity.
What needs improvement?
I see no room for improvement at the moment.
For how long have I used the solution?
I have been familiar with FortiWeb for about three years now.
How are customer service and support?
The technical support is very helpful. I rate their technical support a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I only worked with similar solutions as a POC.
How was the initial setup?
The initial setup was easy.
What was our ROI?
FortiWeb has been a good investment, helping our network and providing a return on investment.
What's my experience with pricing, setup cost, and licensing?
The pricing of Fortinet FortiWeb is affordable and competitive.
What other advice do I have?
I recommend FortiWeb to others. I wish there were more integration with Azure systems.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Nov 15, 2024
Flag as inappropriateSales manager at Xxx
A cost-effective solution for web security but lacks stability
Pros and Cons
- "Fortinet FortiWeb is priced well."
- "The product’s stability could be improved."
What is our primary use case?
We use the solution for the office in Oracle.
What is most valuable?
Fortinet FortiWeb is priced well.
What needs improvement?
The product’s stability could be improved.
For how long have I used the solution?
I have been using Fortinet FortiWeb for one year. We are using the latest version of the solution.
What do I think about the stability of the solution?
The product’s stability is normal. I rate it six out of ten.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
The initial setup depends on technical knowledge.
What's my experience with pricing, setup cost, and licensing?
The solution is cheaper compared with other solutions. It has a yearly license.
What other advice do I have?
Overall, I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Senior Cyber Security Engineer at a tech services company with 201-500 employees
A competitively priced and stable solution
Pros and Cons
- "The deployment was very easy."
- "The documentation for the machine learning could be better."
What is our primary use case?
The version we are using is not old, but neither is it up to date.
We implement FortiWeb to block incoming attacks to our network and web applications.
We use complex authentication rules and forms, in addition to the solution, for protection. We also do caching with static websites and compression.
What is most valuable?
I would say that machine learning is the most valuable upgrade from 5.8, both before and after 5.9.
What needs improvement?
The documentation for the machine learning could be better. They do not provide proper documentation explaining how the solution works or how to configure it. A good, valid KB article would be helpful.
It is difficult to configure the machine learning and get it up and running. We put in a week of learning mode and then place it in our production. The machine and data learning is a pain point. I work with different clients. The machine-learning algorithm doesn't learn all the URL patterns.
It would be nice to see certain software changes in order to add some kind of betterment with machine learning.
What do I think about the stability of the solution?
As a hardware device, the solution is very stable. This is true when compared with other web application firewalls.
What do I think about the scalability of the solution?
Hardware is not very shareable, as increasing capacity would require the use of a different one. But there is good scalability when it comes to WAF, SaaS and cloud solutions. The CPU cores and RAM memory capacity can always stand improvement.
How are customer service and technical support?
From the time a ticket is created, technical support takes a while to respond, especially when compared with Cisco. In this area it is not so great.
How was the initial setup?
The deployment was very easy. Since it concerns hardware, one only need plug in the firewall and bring it up by connecting the device. It is pretty easy and not time consuming. The deployment takes, perhaps, one hour. But, the configuration and machine learning are important.
What's my experience with pricing, setup cost, and licensing?
The license can be renewed on an annual or tri-annual basis. The price is competitive.
What other advice do I have?
The solution protects a web server with more than 1,000 users making use of the solution.
The solution is good. It has a preferable price, stability and security, all which recommend it to other users. My only issue is with the machine learning.
I rate Fortinet FortiWeb as an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
Sr. Systems Engineer at Kipepeo Solutions Ltd
Integrates well, excellent support, but reference architecture could improve
Pros and Cons
- "The most valuable feature of Fortinet FortiWeb is the ease of integration and configuration."
- "Fortinet FortiWeb could improve in reference architecture for different deployment scenarios."
What is our primary use case?
Fortinet FortiWeb was used to support mobile applications.
What is most valuable?
The most valuable feature of Fortinet FortiWeb is the ease of integration and configuration.
What needs improvement?
Fortinet FortiWeb could improve in reference architecture for different deployment scenarios.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately three years.
What do I think about the stability of the solution?
Fortinet FortiWeb is stable.
How are customer service and support?
The technical support from Fortinet FortiWeb is excellent.
Which solution did I use previously and why did I switch?
I have used many other solutions and I formally recommend NGINX. The challenge I have with NGINX is handing over the project to the end customer. The skillsets for managing NGINX as a WAF are a lot. This is what was drawing me towards F5. I wanted something that is seamless from end-to-end, for the customer.
The advantages of NGINX are that it's community-based, and you can get it anytime. Fortinet FortiWeb you have to go through a channel, there's an initial acquisition, and then the annual support which are things that we don't have to consider when we're dealing with NGINX.
How was the initial setup?
The initial setup of Fortinet FortiWeb was easy. The full implementation took approximately one week.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb depends from customer to customer because some customers are considering using other solutions, such as Imperva. The price of Fortinet FortiWeb sits well for the middle-sized customers that we deal with.
The price is based on our partner model, we are able to negotiate a good discount on GPR because we're also selling the firewall appliance.
What other advice do I have?
I rate Fortinet FortiWeb a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
F5 Advanced WAF
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?