Generally, we are using it to protect our internet-facing web applications. So if there are any security vulnerabilities in our applications, the solution can provide protection.
System Administrator at a insurance company with 1,001-5,000 employees
Provides good feedback for development and is easy to scale up
Pros and Cons
- "It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs."
- "The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product."
What is our primary use case?
How has it helped my organization?
It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs.
What is most valuable?
They have a sort of table that defines the functions of certain applications, ex. which function has the slowest or fastest response. This enables our in-house development team or vendors to review our application and fix the functions if necessary.
What needs improvement?
The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product.
Buyer's Guide
Fortinet FortiWeb
November 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
For how long have I used the solution?
I have been using FortiWeb for three years.
What do I think about the stability of the solution?
I think it's quite reliable so long as it's configured.
What do I think about the scalability of the solution?
As long as we accurately scale our requirements from the start, I think the solution is quite scalable and quite easy to scale up later on.
How are customer service and support?
They are quite helpful. But I think because our department is quite stable and configured correctly, we are rarely using the support. Everything works perfectly.
How was the initial setup?
I think it's quite complex because we need to know how the application works.
What about the implementation team?
We are using local support to configure the solutions for us. We also purchase local maintenance and support on top of the routine product support and updates. Because it is a
very specialized product, we need a very skillful person with expertise in the product to configure the solution for us.
What's my experience with pricing, setup cost, and licensing?
In a high availability cluster configuration, where the primary FortiGate is working and the secondary is a backup, Fortinet requires us to buy two licenses instead of one whether we are actually using it or not. With other products, you only purchase one license because we only use one license per instance.
What other advice do I have?
You need to accurately calculate the requirements of your infrastructure before implementing FortiWeb or any other web application firewall. Accuracy is very critical when scaling the product or the model that will be deployed on your infrastructure.
I would rate FortiWeb an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Infrastructure Manager with 201-500 employees
The learning mode of the appliance picks up on the pattern of SSL attacks
Pros and Cons
- "I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks."
- "We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
What is our primary use case?
We use it mostly to secure our web platform for things like Internet banking, email, and SMTP. It is for anything that is external coming into our internal network.
How has it helped my organization?
We were having a lot of probe attacks coming through from our external networks. Now, the traffic has to come through our firewall, then FortiWeb. Basically, FortiWeb acts like a second firewall for all our applications.
What is most valuable?
We have been using all the features and everything is nice.
I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks.
What needs improvement?
We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced.
We had trouble understanding it at first, but we got used to using it after six months. Then, it was simple to use.
For how long have I used the solution?
We have been using it for five years (since 2015).
What do I think about the stability of the solution?
We haven't had any issues with it so far.
What do I think about the scalability of the solution?
The scalability is okay. There hasn't been a need to upgrade. We have found something that can adapt to our environment and that we can use for a long period of time.
We plan to use the product for the next two years. There are no major upgrades planned anytime soon.
There are four users for the product (with two being from the security team).
How are customer service and technical support?
We have needed minimal support for the solution. The support has been okay.
Which solution did I use previously and why did I switch?
We did not have a solution that we previously used.
How was the initial setup?
It is complex to set up in learning mode. It takes a lot of time to learn the pattern of the web application before we put in the rule. The rule itself is a bit complex. We had to go by trial and error because there is nothing standard on the device.
The deployment took almost six hours to get up and running.
What about the implementation team?
We used a reseller. They helped us implement the device.
The reseller also does deployment and maintenance. For this, it takes about two of their staff and one or two of our staff internally. The staff will generally have experience in networking and firewalls with a background in security and port mapping.
What's my experience with pricing, setup cost, and licensing?
All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500.
Which other solutions did I evaluate?
Since we were using FortiGate firewall, we decided to look at FortiWeb. We also looked into several solutions, like Check Point and Palo Alto.
What other advice do I have?
The type of product you get depends on what you want to protect, how you want to protect it, and how many people will be accessing FortiWeb.
What we have now is working fine.
I would rate FortiWeb as an eight (out of 10).
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiWeb
November 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Sr. Systems Engineer at Kipepeo Solutions Ltd
Integrates well, excellent support, but reference architecture could improve
Pros and Cons
- "The most valuable feature of Fortinet FortiWeb is the ease of integration and configuration."
- "Fortinet FortiWeb could improve in reference architecture for different deployment scenarios."
What is our primary use case?
Fortinet FortiWeb was used to support mobile applications.
What is most valuable?
The most valuable feature of Fortinet FortiWeb is the ease of integration and configuration.
What needs improvement?
Fortinet FortiWeb could improve in reference architecture for different deployment scenarios.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately three years.
What do I think about the stability of the solution?
Fortinet FortiWeb is stable.
How are customer service and support?
The technical support from Fortinet FortiWeb is excellent.
Which solution did I use previously and why did I switch?
I have used many other solutions and I formally recommend NGINX. The challenge I have with NGINX is handing over the project to the end customer. The skillsets for managing NGINX as a WAF are a lot. This is what was drawing me towards F5. I wanted something that is seamless from end-to-end, for the customer.
The advantages of NGINX are that it's community-based, and you can get it anytime. Fortinet FortiWeb you have to go through a channel, there's an initial acquisition, and then the annual support which are things that we don't have to consider when we're dealing with NGINX.
How was the initial setup?
The initial setup of Fortinet FortiWeb was easy. The full implementation took approximately one week.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb depends from customer to customer because some customers are considering using other solutions, such as Imperva. The price of Fortinet FortiWeb sits well for the middle-sized customers that we deal with.
The price is based on our partner model, we are able to negotiate a good discount on GPR because we're also selling the firewall appliance.
What other advice do I have?
I rate Fortinet FortiWeb a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
GRC Security Consultant at Ionize
This flexible suite solves compliance problems but that comes at a cost
Pros and Cons
- "If I need something from tech support, I can get it answered within the hour."
- "Both the internal firewall management and the cloud can be managed by a single console."
- "It costs too much."
- "It is not entirely user-friendly."
What is our primary use case?
Normally I deal with on-premises installations. The firewalls are always on-prem for government departments. In a recent case, I was looking at a cloud solution because it was what the client preferred. So it was the Fortinet rules applied to an AWS solution. I was looking at the architecture around becoming an IRAP (Information Security Registered Assessors Program) certified program and I was looking at the AWS firewalls around how it would be able to comply with the ISM (International Safety Management) standards.
What is most valuable?
For me personally, the most valuable thing is that I like the fact that it is standardized so both internal firewall management and the cloud can be managed by the same company. Communication between the two works well and it can be a benefit. We can keep a single console to manage both.
What needs improvement?
User administrative controls could be a little bit better. I guess that would be the main thing. The usability within Fortinet could be a little bit easier on the users. But it is what it is.
The thing that was more difficult was not the tool itself but dealing with the logistics of the compliance issues. I was applying a standard set of rules to an AWS firewall. It served a purpose. The complex part of the solution was more of a compliance issue.
For how long have I used the solution?
We have been using Fortinet FortiWeb probably for over a year-and-a-half. Closer to two years.
What do I think about the scalability of the solution?
At this point in time, scalability seems to be fine. I mean, we are talking processing requests from all over Australia. It seems to be keeping up quite well. My impression of it at this stage is that it is very scalable. It is quite well suited for data management.
How are customer service and technical support?
I think judging our experience with technical support is a little bit unfair because I know all the local support people. I do go into the help desk when I have to, but I do know most of the teachers or technical support staff. I would rate them as being very responsive to customers. I have had no issues. If I need something I can get it answered within the hour. It is quite good.
How was the initial setup?
It was quite easy to do the initial setup and apply basic rules. Administratively, keeping an AWS firewall and applying the Fortinet rules made it quite simple for the difficulty level of this particular requirement.
What's my experience with pricing, setup cost, and licensing?
I think that ForiWeb is expensive for what they are offering. At the end of the day, when you sell a suite, compliance within the suite is easy to maintain. That is the good part. It is an expensive suite and it is an expensive solution, but it is a manageable one for an enterprise. It should just be cheaper for what they are offering in comparison to other tools on the market.
What other advice do I have?
My advice to people would be to evaluate the marketplace against your requirements and choose appropriately. Fortinet does operate at the enterprise level. It is listed on the Australian standard and it does carry Australia's approval for common criteria. So it does address the requirements needed for security for the assessments. Not every product can.
On a scale from one to ten (where one is the worst and ten is the best), I would rate this Fortinet solution as a seven-out-of-ten because of user administrative controls, usability, and price.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Executive Manager at a financial services firm with 1,001-5,000 employees
Has security profile but improvement is needed in ease of use
Pros and Cons
- "The solution's most valuable feature is its security profile."
- "The solution could improve its ease of use and add more advanced WAF features in future releases."
What is most valuable?
The solution's most valuable feature is its security profile.
What needs improvement?
The solution could improve its ease of use and add more advanced WAF features in future releases.
For how long have I used the solution?
I have been working with the product for more than five years.
Which solution did I use previously and why did I switch?
I've worked with both F5 and Fortinet and find F5 to be much better. F5 is easier to implement, more compatible with applications, and more robust and stable. Regarding securing applications behind the WAF, F5 generally provides better security.
How was the initial setup?
The solution's implementation is not complex and depends on the number and complexity of customers' applications.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiWeb's pricing is reasonable. Its licensing costs are yearly.
What other advice do I have?
The product has been in the WAF business for a long time. Its maturity cannot be compared to other alternatives. Based on my experience with Fortinet FortiWeb, I'd recommend it in specific cases, especially if you have a limited budget. It can meet basic requirements. However, other vendors have better features and support. I rate the overall product a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Aug 9, 2024
Flag as inappropriateCyber Security Engineer at Mudra Electronics limited
Has a user-friendly dashboard, but its technical support services need improvement
Pros and Cons
- "The product has a very user-friendly dashboard."
- "The product's scalability could be better."
What is our primary use case?
We use FortiWeb for protecting web applications.
What is most valuable?
The product has a very user-friendly dashboard.
What needs improvement?
The software's support services could be better compared to Sophos.
What do I think about the scalability of the solution?
The product's scalability could be better compared to Sophos.
How are customer service and support?
It is challenging to communicate with the FortiWeb's support team.
Which solution did I use previously and why did I switch?
We use Sophos as well.
How was the initial setup?
FortiWeb's configuration process is more difficult than Sophos. I rate the process a one out of ten.
What's my experience with pricing, setup cost, and licensing?
The product is expensive. I rate the pricing a ten out of ten.
What other advice do I have?
I rate FortiWeb a five out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network & Telecom Manager at a retailer with 1,001-5,000 employees
Easy to use, and the all-in-license covers all of the features
Pros and Cons
- "The most valuable feature is ease of use."
- "I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device."
What is our primary use case?
I am using FortiWeb as a web application firewall and as a load balancer for HTTP applications.
What is most valuable?
The most valuable feature is ease of use.
It has an all-in-one license, unlike F5 where you need separate licenses for the antivirus, IP reputation, denial of service attacks, etc. With FortiWeb, the all-in-one license is one of the most beneficial features.
What needs improvement?
I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device. For example, if I have one device that costs $2,600 USD then it can have two licenses, where it can operate as a load balancer as well as a WAF.
For how long have I used the solution?
We have been using FortiWeb for three years.
What do I think about the stability of the solution?
This is a good solution, stability-wise.
What do I think about the scalability of the solution?
FortiWeb is a scalable product and we have about 3,000 users.
That said, we need to purchase a model with more capacity because this is a small one, and our business has expanded in the past three years.
How are customer service and technical support?
We have been in contact with technical support and we are satisfied with them.
Which solution did I use previously and why did I switch?
We did not use another similar solution before choosing FortiWeb.
How was the initial setup?
The initial setup is straightforward.
Any FortiWeb deployment needs about two weeks because when it is first implemented, in phase one, machine learning takes place. It is needed because every application needs some customization. FortiWeb needs approximately two weeks to build this profile. After that, an expert will do some fine-tuning on the profile and the appliance will start to work.
What about the implementation team?
During the deployment, we used a system integrator, but after that, we can manage it by ourselves. Our network team has seven people including one technician, one manager, and five administrators.
What's my experience with pricing, setup cost, and licensing?
There are no licensing costs.
What other advice do I have?
In summary, this is a good product and I can recommend it for others.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Tech Manager at Global tec
Problematic licensing requires upgrades at scale with additional expense for advanced features
Pros and Cons
- "FortiWeb offers machine learning in the latest product. This fixed many problems. There are no false negatives."
- "Fortinet FortiWeb is not scalable. You'll need more budget to change the hardware."
What is our primary use case?
We are partners with Fortinet. We specialize in power customers. We use many products like FortiGate, FortiWeb, FortiAnalyzer, FortiSIEM, and FortiSandbox.
All the FortiGate products are new, even the Fortinet switches we are selling to our customers. We also install and configure the network for our customers.
How has it helped my organization?
With this product, you can secure all the Fortinet products together. I'm an entrepreneur. Most people fail in the publication of a firewall.
What is most valuable?
FortiWeb offers machine learning in the latest product. Before that, there was an auto-learning feature. This fixed many problems. There are no false negatives now.
Fortinet FortiWeb now has artificial intelligence and machine learning.
What needs improvement?
What I would like to see improved in Fortinet FortiWeb will probably be included in the next release. The legal feature needs better step-by-step use of the form.
We use the FortiGate guidebook for step-by-step instructions. But the FortiWeb guidebook is only is a demonstration kit which is not enough for a new installation.
What do I think about the stability of the solution?
FortiWeb is a stable solution.
What do I think about the scalability of the solution?
Fortinet FortiWeb is not scalable. There is a model and a license if you want to use it. You'll need more budget to change the hardware. FortiWeb is not scalable on the same plan.
How was the initial setup?
The initial setup is not simple for all the products. Some Fortinet products vary, but overall it is straightforward.
What other advice do I have?
In the version of Fortinet FortiWeb that we have, it does not include the scanner. We cannot access every feature. If you have all the popular products, you can use the system perfectly to connect everything.
Fortinet can improve the security firebase in support for HTTPS and the CPU with additional configurations. On a scale from 1 to 10, I would rate Fortinet FortiWeb a two.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
F5 Advanced WAF
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?
- When evaluating Web Application Security, what aspect do you think is the most important to look for?