Try our new research platform with insights from 80,000+ expert users
Netwerk and Security Specialist at a healthcare company with 501-1,000 employees
Real User
Offers great insights into what utility hackers are trying to exploit and blocks a lot from the internet
Pros and Cons
  • "It's the extra security that is the most valuable feature. You have insight into your traffic. There are some great insights into what utilities hackers are trying to exploit. It blocks a lot of stuff from the internet."
  • "The solution is rather complicated. If you know what to do, it's not bad, but it's complicated for a first time user to configure the solution. What I'd like to improve are the custom signatures."

What is our primary use case?

We have our webmail, a private drop off solution, a video clip for our users to upload, and share company videos, all with FortiWeb.

What is most valuable?

It's the extra security that is the most valuable feature. You have insight into your traffic. There are some great insights into what utilities hackers are trying to exploit. It blocks a lot of stuff from the internet.

What needs improvement?

The solution is rather complicated. If you know what to do, it's not bad, but it's complicated for a first time user to configure the solution. What I'd like to improve are the custom signatures. If you want a good security solution, you have to get in kicking high for things that are getting blocked and you have to whitelist some signatures to make things work. It's a time-consuming thing to do. It would be nice to whitelist private IP ranges and see which signatures are hit and whitelist them automatically - which I think is possible to do. 

It would also be nice to have some extra security in the solution. I just upgraded to 6.0 and there were some security additions, but it would be nice to have some more and be able to configure them in the right way. Specifically, an updated security policy would be nice.

For how long have I used the solution?

I've been using the solution for 2.5 years.
Buyer's Guide
Fortinet FortiWeb
February 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's really stable. There was only one issue in the past two and a half years and with the help of the technical support from Fortinet, it was quickly fixed.

What do I think about the scalability of the solution?

We do have a small team but I think it's scalable. You can upgrade to a higher level, you can take it to a higher visibility mode. I think it's a very scalable solution. We have around 1,000 users using this solution.

How are customer service and support?

The technical support is very good.

How was the initial setup?

The initial setup was rather straightforward because we had some help setting up the unit in the first place. The initial setup, if you're using a VM, is really easy to roll out, if you know the Fortinet command line. It's not easy to configure an IP address and get it started. Then there was a rather steep learning curve in what you exactly have to do to have a really secure solution. It's rather easy to make it a reverse proxy and do nothing, but to get it monitoring in the right way, it takes some time. You have to think about it.

Deployment was a one-time setup. I think it took us about two days including one solution for configuring. For now, there is a new solution we need behind FortiWeb, and I think it takes about four to eight hours to set up. We require just one staff member for maintenance.

What's my experience with pricing, setup cost, and licensing?

You can set up licensing on a monthly or yearly basis. I'm not sure about pricing.

What other advice do I have?

Every external solution acceptable for work will use FortiWeb. We do have three or four FortiWeb solutions now and if there is anything we need to share through the internet, it's going to be through FortiWeb.

In terms of advice, I'd say take a good look at the support side of the help documents. There a very good document cycle on the Fortinet website. There's a lot of information. Get to know the solution.

I would rate this solution eight out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Soroush-Enayati - PeerSpot reviewer
Network security engineer at freelancer
Real User
Great machine learning, artificial intelligence and behaviour detection
Pros and Cons
  • "It helps us prevent attacks on servers."
  • "The initial setup is complex."

What is our primary use case?

It helps us prevent attacks on servers, and we deploy it on-premises.

What is most valuable?

There are many valuable features. It has machine learning, artificial intelligence, behaviour detection, and many other features capable of detecting web attacks.

What needs improvement?

The initial setup could be simplified.

For how long have I used the solution?

We have been using the solution for approximately ten years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

We do not have experience with customer service and support.

How was the initial setup?

The initial setup is complex and takes between three to six months.

What about the implementation team?

We implemented the solution in-house.

What's my experience with pricing, setup cost, and licensing?

Fortinet FortiWeb has some types of licenses, and the main licenses refer to updating a signature and a pattern.

Which other solutions did I evaluate?

We evaluated machine learning and the main signatures about known attack signatures.

What other advice do I have?

I rate the solution a ten out of ten, and I recommend it for every organization with web services.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
February 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
Pedro Andrade - PeerSpot reviewer
General Manager at Ip4u
Real User
Good reporting and a nice user interface but can be a bit expensive
Pros and Cons
  • "It can scale well."
  • "The upgrade process could be a bit smoother."

What is most valuable?

The reporting available is pretty great.

We find the configuration capabilities to be very good. 

Technical support is helpful.

It's stable. 

It can scale well. 

I like the user interface. 

What needs improvement?

It's not the most popular option. Many clients prefer instead Citrix or Proxy Blue Coat. It might be a bit difficult to configure. 

The upgrade process could be a bit smoother. 

Sometimes the integration doesn't work on the first or second try.

The solution is a bit expensive. 

For how long have I used the solution?

We first installed the solution eight or nine years ago. We've used it for almost a decade. 

What do I think about the stability of the solution?

The solution is pretty stable. I'd rate it a three out of five in terms of stability. Sometimes the upgrades don't go as smoothly as we would like. 

What do I think about the scalability of the solution?

The solution is scalable. I'd rate it four out of five in terms of how easy it is to expand the product. 

How are customer service and support?

I can't complain about the technical support. They are pretty good. I found them to be helpful. However, it may depend on the engineer you get on the line. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup has a moderate level of difficulty.

We only need one person to deploy and maintain the product.

It takes about a week to have the entire solution set up.

What about the implementation team?

We install the solution for our clients. 

What was our ROI?

It's always difficult to measure ROI when it comes to security. It's always just a smart investment for a company.

What's my experience with pricing, setup cost, and licensing?

The product can be costly.

The licenses are paid annually. You do have several licensing choices. They don't have too much choice. However, their options are good. 

What other advice do I have?

We are not an end user. We are resellers.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Manager at a construction company with 1-10 employees
Real User
Provides security and an easy setup, however scalability is a concern
Pros and Cons
  • "The most important feature of this solution is protection from attack."
  • "The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network."

What is our primary use case?

We use the solution to protect the various services of our site, E-commerce, file service, and download service.

What is most valuable?

The most important feature of this solution is protection from an attack.

What needs improvement?

The maintenance fee for this product could be improved and it needs to be easier to scale up. 

For how long have I used the solution?

I have been using the solution for four to five years. 

What do I think about the stability of the solution?

Stability is very important and yes, the product is stable.

What do I think about the scalability of the solution?

The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network.

How are customer service and support?

I would say technical support is good for this solution.

How was the initial setup?

Setup for this solution is easy, with one being easy and five being hard I would rate it a two out of five. Deployment took a few days. 

What's my experience with pricing, setup cost, and licensing?

We have between 100 and 200 users of the solution in our company. 

What other advice do I have?

I would rate the solution a six out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1406484 - PeerSpot reviewer
Jr. Engineer at a computer software company with 5,001-10,000 employees
Real User
Easy to install and maintain, with good technical support
Pros and Cons
  • "It is easy to install and to maintain."
  • "In terms of performance, it needs to be more robust."

What is our primary use case?

The primary use case of this solution is for security, on the periphery for the VPN.

What is most valuable?

It is easy to install and to maintain.

What needs improvement?

We are considering an upgrade to our firewall because our current version is not compatible with our FortiAnalyzer. As there is an incompatibility, we have been advised by Fortinet that an upgrade is necessary to avoid issues.

We believe this product will become obsolete.

It needs to better integrate with other platforms.

In terms of performance, it needs to be more robust. During the lockdown, we are connecting to a VPN and the connection should be faster, there should be RAM or more hardware. Also, it should include security features.

For how long have I used the solution?

I have been using Fortinet FortiWeb for two years.

What do I think about the stability of the solution?

This solution is stable and w have had no issues with its stability.

What do I think about the scalability of the solution?

It's a scalable product and we have plans to use it in the future.

We have approximately 1000 users in our organization.

How are customer service and technical support?

We are satisfied with technical support, we have not had any issues.

How was the initial setup?

The initial setup was straightforward, it was easy.

There were no issues and it was deployed in six months.

We have a team of 20 providing the IT infrastructure, including switching, firewalls, and maintenance.

What other advice do I have?

We have been using Fortinet for four years and internally we are using Cisco.

We would certainly recommend this product.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Network Security Planning at Ooredoo Kuwait
Reseller
Has a mechanism to detect all of your entries that aren't used and clean them up but they should have an antivirus option
Pros and Cons
  • "When we had Cisco we had around thirty thousand entries on our firewalls. Now we are down to three thousand. Fortinet has a mechanism to detect all of your entries which are not used, and it can clean it up."
  • "I would like to have an antivirus option."

What is our primary use case?

Our primary use case is as a firewall. We use a lot of Fortinet products. We have email security and FortiGate IPS. 

How has it helped my organization?

When we had Cisco we had around thirty thousand entries on our firewalls. Now we are down to three thousand. Fortinet has a mechanism to detect all of your entries which are not used, and it can clean it up.

What is most valuable?

The most valuable features are the access policies and how Fortinet gets the compilation done is really good.

What needs improvement?

I would like to have an antivirus option. 

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

Stability is very good. 

What do I think about the scalability of the solution?

We haven't had any issues with scalability. You can scale up easily. 

How are customer service and technical support?

Their technical support is good. 

Which solution did I use previously and why did I switch?

We previously used Cisco. We switched because all they are is a brand name. It was a failure. We gave it a year to improve the product and it didn't so we switched. 

How was the initial setup?

The initial setup was straightforward. The deployment didn't take much time. The support guys were really good. The transition from Cisco to Fortinet was a bit challenging but they had tools to make it easier. 

We require three staff for the deployment and maintenance. 

What about the implementation team?

We are the resellers. 

What other advice do I have?

I would rate it a seven out of ten. A seven and not a ten because of the antivirus issue. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
PeerSpot user
Senior Information Security Engineer with 1,001-5,000 employees
Vendor
With Layer 7 server load balancing, it makes decisions based on the content of messages. It also can offload slow connections from the upstream servers.

What is most valuable?

  • Web services signature: Helped us on secure key exchange, authentication and integrity of the transmissions.
  • Virtual patching: We publish many web services through FortiWeb. We are able to quickly resolve vulnerabilities.
  • Layer 7 server load balancing: The device made smart decisions based on the content of messages. Also, with compression and encryption, it can offload slow connections from the upstream servers. That greatly improved performance.
  • Zero-day protection
  • Advance correlation
  • URL rewriting and content rewriting

How has it helped my organization?

Before FortiWeb deployment, we were using a combination of commercial and open-source products. It was a hassle for the administrators, due to which some areas were unintentionally overlooked and caused many problems. With FortiWeb, we got a one-box solution for internet and internet security, which reduced the time required of the administrators and improved visibility at the larger scale.

What needs improvement?

Usually patches and version upgrades are really buggy, so we usually wait about one month for a stable release to upgrade. They need to improve the new version/patch delivery mechanism. For example, if a patch fixes one functionality for web services but also causes some other functionality failure.

For how long have I used the solution?

I have been using it since 2014.

What do I think about the stability of the solution?

In the first few months, we had some issues but with a custom patch, we are good.

What do I think about the scalability of the solution?

No scalability problems so far.

How are customer service and technical support?

I rate technical support 8.5/10.

Which solution did I use previously and why did I switch?

We were using combination of solutions, due to our organisation's policies. Due to lack of visibility, administrative issues and response times, we shifted.

How was the initial setup?

We had a complex environment, with multiple offices across the globe with all the data in and out from our HQ.

What's my experience with pricing, setup cost, and licensing?

At the time of deployment, and still now, the price was considerable less than other solutions and varies according to license type.

Which other solutions did I evaluate?

We also evaluated Cisco and McAfee.

What other advice do I have?

It is a great product, but be careful with version upgrades.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Analyst at a financial services firm with 1,001-5,000 employees
Real User
20 Gbps appliance throughput makes it useful for large enterprise deployment and also meets future requirements. Product support is a major concern.

What is most valuable?

In my opinion, the following features of FortiWeb 4000E are the most valuable & were appreciated during all my previous engagements:

  • 20 Gbps appliance throughput makes it useful for large enterprise deployment and also meets future requirements.
  • Easy integration with various Fortinet products such as FortiSandbox for APT detection.
  • ASIC (Application Specific Integrated Circuit) provides quick SSL offloading and doesn’t choke the user requests.

How has it helped my organization?

  • Operations overhead (administration and escalation management) has been brought down, as Fortinet provides flexible and customizable reporting options with the FortiAnalyzer appliance for logging and reporting.
  • Rule creation and fine tuning are easy, as compared to its competitors.
  • Product has provided adequate assurance to organization’s PCI DSS program.

What needs improvement?

Product support is a major concern; if FortiWeb wants to become a market leader, then it must provide better after-sales services.

The automatic policy learning feature also needs some improvement, as using this feature leads to more false positives.

Integration with other cloud-based DDoS protection services such as CloudFlare, Arbor, Akamai, etc., is also a limitation.

For how long have I used the solution?

It’s been almost one year since we started using this solution.

What do I think about the scalability of the solution?

The FortiWeb 4000E appliance comes with 20 Gbps throughput, 2X2 TB HDD and unlimited licensing. (Yes, you got it correct.) This adds value to the organization and meets its current and future requirements.

How are customer service and technical support?

As I wrote in my previous comments, FortiWeb needs to invest and improve its tech support services due to limited skills in market. Critical- and high-severity issues usually take more time for resolution.

Which solution did I use previously and why did I switch?

We were using Imperva as our WAF solution, which is also a market leader (as per Gartner Magic Quadrant) and provides lots of flexibility and cloud integration options. However, due to high cost, the organization decided to switch to Fortinet Fortiweb.

How was the initial setup?

Selecting the appropriate deployment topology is a major task. Initial configuration settings are little difficult to implement but overall management is easy.

FortiWeb provides a wide variety of deployment options such as

  • Reverse proxy
  • Inline transparent
  • True transparent proxy
  • Offline sniffing
  • WCCP (Web Cache Communication Protocol)

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are USP of this solution; deploying an appliance provides in-house control and flexibility. A dedicated 4000E appliance is appropriate for large enterprises, while Fortinet also provides a VM-based solution, which is perfect for small and medium enterprises.

Which other solutions did I evaluate?

We did PoCs for other WAF products such as Citrix, F5 and Barracuda before finalizing on FortiWeb for our enterprise, which satisfied enterprise requirements.

What other advice do I have?

Thorough review of architecture is required. It’s recommended to get it deployed by authorized FortiWeb vendors. Attention to the rules is a must. Otherwise, it might lead to lots of false positives.

Fortinet WAF can also be integrated with SIEM, which could be beneficial for centralized monitoring.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.