Try our new research platform with insights from 80,000+ expert users
Jishain-Ali - PeerSpot reviewer
Senior Security Consultant at a retailer with 10,001+ employees
Consultant
Top 20
An easy-to-deploy solution with machine learning features that reduce false positives
Pros and Cons
  • "The machine learning feature reduces the false positives."
  • "The documentation is poor."

What is most valuable?

The product has some unique features. The machine learning feature reduces the false positives. The tool detects zero-day attacks. It has an in-built antivirus, which most WAF tools do not have.

What needs improvement?

Advanced configurations require high skill. FortiWeb team should work on making it easier. The documentation is poor. The tool must provide advanced and robust DDoS protection.

For how long have I used the solution?

I have been using the solution for almost six years.

How are customer service and support?

The technical support is fine. The support team gives delayed responses if there is a complex issue.

Buyer's Guide
FortiWeb Web Application Firewall (WAF)
January 2025
Learn what your peers think about FortiWeb Web Application Firewall (WAF). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have worked with F5 Advanced WAF. It is a robust product and is suitable for complex environments. It is flexible. However, it depends on other solutions for inbuilt security and packet inspection.

How was the initial setup?

The initial setup is easy. It requires less intervention.

What's my experience with pricing, setup cost, and licensing?

I recommend the product to others. Overall, I rate the solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Andreas Lalos - PeerSpot reviewer
Director of Professional Services at Besecure
Real User
Top 5
Enhanced application protection with an extensive attack signature library
Pros and Cons
  • "FortiWeb has a very extensive library of known attack signatures, which makes the product fit for any environment, regardless if the customer uses Windows-specific or non-Windows-specific applications."
  • "For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting."

What is our primary use case?

FortiWeb is used for web application protection. It protects a web application against attacks targeting their web applications, such as cross-site scripting, SQL injection, and other common application-specific attacks.

How has it helped my organization?

FortiWeb allows the organization to operate efficiently without any downtime or serious security breach.

What is most valuable?

FortiWeb has a very extensive library of known attack signatures, which makes the product fit for any environment, regardless if the customer uses Windows-specific or non-Windows-specific applications. It also has a very low rate of false positives and incorporates other FortiGuard capabilities, such as detection of botnet traffic.

What needs improvement?

For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting. The product could offer better capabilities and analytics to pinpoint threat landscapes more efficiently.

For how long have I used the solution?

I have been working with FortiWeb for approximately four years, maybe more.

What do I think about the stability of the solution?

FortiWeb has proven to be very stable and does not introduce latency in the network.

What do I think about the scalability of the solution?

The product can scale according to the organization's traffic and architecture. It is available as a virtual appliance and a hardware appliance.

How are customer service and support?

Fortinet provides very good support, which I would rate as eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

At the moment, we are only working with Fortinet and not with other web application firewalls.

How was the initial setup?

Someone without prior experience with the product might find it challenging to deploy. However, Fortinet provides good online training to assist administrators.

What was our ROI?

The total cost of ownership should be calculated based on the actual protection it offers to the application. Deploying FortiWeb can save 20% to 30% of resources within the organization.

What's my experience with pricing, setup cost, and licensing?

FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapest solution. That said, it is worth the investment.

Which other solutions did I evaluate?

I have experience with other web application products.

What other advice do I have?

I'd rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Flag as inappropriate
PeerSpot user
Buyer's Guide
FortiWeb Web Application Firewall (WAF)
January 2025
Learn what your peers think about FortiWeb Web Application Firewall (WAF). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
CharlesFamisaran - PeerSpot reviewer
Head - System and Network Admin at Reliance Producers Cooperative
Real User
Top 10
Easy to setup, stable and scalable solution
Pros and Cons
  • "It is good for web tracking applications."
  • "There is room for improvement in pricing, and actually, the price is a bit higher because on the same terms I purchased, the support subscription is so high."

What is our primary use case?

My main use case is for security and routing.

What is most valuable?

It is good for web tracking applications.  

What needs improvement?

There is room for improvement in pricing, and actually, the price is a bit higher because on the same terms I purchased, the support subscription is so high.

For how long have I used the solution?

I've been using it for a long time. It has been more than three years now. 

What do I think about the stability of the solution?

Stability is guaranteed stability. I'm okay with stability. I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten. 

How are customer service and support?

I am okay with the support. The support's subscription is high. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

pfSense is open-source and free, while FortiWeb is subscription-based. Both are manageable, but FortiWeb's features scale up connections per second, depending on the payment plan. 

How was the initial setup?

I would rate my experience with the initial setup a nine out of ten, where one is difficult, and ten is easy.

It took us two days to set up.

What about the implementation team?

I deployed it myself.  I just got a reference from the old system, and I configured it.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing a seven out of ten, where one is cheap and ten is expensive. 

What other advice do I have?

Overall, I would rate it a solid eight out of ten.  

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Martin Janzsó - PeerSpot reviewer
Presales Consultant at Invitech Kft.
Real User
Top 5
Has good integration with load-balancing applications
Pros and Cons
  • "The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
  • "Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees."

What is our primary use case?

Our company provides data center and cloud services as infrastructure providers. When customers need infrastructure like VMs or server allocation, we provide them with the vendor and offer services to operate, manage, implement, and integrate these security components.

What is most valuable?

The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection.

What needs improvement?

Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees.

For how long have I used the solution?

I have been using the product for four to five years. 

What do I think about the stability of the solution?

I rate the tool's stability a nine out of ten. 

What do I think about the scalability of the solution?

It's not good with normal perpetual licensing, but we can solve the problem using flex licensing. That's why I'd rate it nine out of ten. We're satisfied with it. Many of our customers, including small, medium, and enterprise businesses, use FortiWeb WAF.

How was the initial setup?

I rate the tool's deployment ease as seven out of ten. We have spent about 600 working hours to implement it. 

What's my experience with pricing, setup cost, and licensing?

The product provides very good prices to customers. The price is set well and offers great value for money.

What other advice do I have?

I rate the overall solution an eight out of ten. I advise others looking to use FortiWeb WAF to create deeper policy rules.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: msp
Flag as inappropriate
PeerSpot user
Senior Vice President Operations at Alackrity Consols
Real User
Top 20
Improves latency by optimizing traffic routing at an affordable price
Pros and Cons
  • "It improves latency by optimizing traffic routing."
  • "FortiWeb could have an inbound load balancing pack."

What is our primary use case?

We use the solution for branch optimization. Initially, it was all in MPLS, but they converted to the broadband network. Implementing it reduced the cost, and its redundancy was also better.

How has it helped my organization?

It improves latency by optimizing traffic routing. When a better link is available, it reroutes traffic through it. Additionally, MPLS helps reduce costs. Critical data can be prioritized on MPLS, while other data uses broadband connectivity, leading to better resource utilization. This setup supports load sharing, allowing multiple links to work simultaneously for improved performance.

What is most valuable?

From the web application perspective, it offers comprehensive features, including URL filtering and DNS protection. Additionally, FortiWeb provides SD-WAN capabilities, such as load sharing based on latency or packet drops. Its extensive feature set allows customers to choose and customize according to their needs and preferences.

What needs improvement?

FortiWeb could have an inbound load balancing pack. Currently, they don't have it, but they have the print product for that. It'll be better if they have it on the same product.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for three years.

What do I think about the scalability of the solution?

It is primarily for the enterprise environment segment. Even if one of the three links goes down, another link will appear to resolve the issue. FortiWeb primarily relies on its high availability features.

How are customer service and support?

We had a quick response from support since we have partnered with them. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was easy because we had training. Also, the FortiGate team provides good support. It took around around five to six days to complete. It is only a plug-and-play environment.

What's my experience with pricing, setup cost, and licensing?

The price is cheap compared to other products in the market. It costs 15-20% less than CheckPoint.

What other advice do I have?

It is more than a basic firewall. It includes various features for enhanced security, such as protection against threats and vulnerabilities specific to web applications. Depending on their roles and responsibilities, some people who work on EDS may also interact with FortiWeb WAF.

FortiWeb offers a comprehensive product suite for SOC integration, including automation and SIEM capabilities. It also offers a complete integration package, including physical components that ensure a consistent experience for internal and external teams.

It includes an analyzer that provides comprehensive visibility. It is designed to optimize costs while sending detailed analytics and other relevant data.

I recommend the solution for security.

I rate the solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Flag as inappropriate
PeerSpot user
Mahesh Patel - PeerSpot reviewer
Sr. Corporate Marketing Executive at a tech services company with 1-10 employees
Real User
Top 5
Helps users to secure their web-based applications
Pros and Cons
  • "The solution's technical support is good."
  • "I don't see any issues with the tool apart from the pricing aspect of the product. The price of the product is an area where improvements are required."

What is most valuable?

The most valuable feature of FortiWeb Web Application Firewall (WAF) that has proven to be the most effective in protecting web applications stems from the fact that the product recently launched a SaaS model, making it a cost-effective solution, which is a major reason why we selected it in our company.

What needs improvement?

I don't see any issues with the tool apart from the pricing aspect of the product. The price of the product is an area where improvements are required.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for a year. My company is a reseller of the solution.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution since it offers a SaaS model, which is why we can increase the bandwidth and number of applications in our company.

There are around 1,000 people in a company where our organization has provided FortiWeb Web Application Firewall (WAF).

Considering the IT side of the company, there are no plans to increase the usage of the product in the future.

How are customer service and support?

The solution's technical support is good. Compared to the previous year, Fortinet has taken a lot of steps to improve its support services. The response time of the support services offered by Fortinet is good, especially since the solution launched elite support for users. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have not used the products offered by Fortinet's competitors, but I know that most of the time, such tools can be available at a cheap price.

How was the initial setup?

My company has a team that is ready to help our customers implement the product.

There is a person in my company who knows about the technical team that takes care of the implementation part. I am a part of the marketing team, so the tool's implementation phase is something I don't know about.

What was our ROI?

In terms of ROI, the product helps secure applications and due to the security, there is less downtime when it comes to applications. From a security point, the tool uses cross-site scripting.

What's my experience with pricing, setup cost, and licensing?

The licensing cost of the product is pretty high compared to other OEMs in the market.

What other advice do I have?

As a marketing executive, I don't get to see any machine learning capabilities in the product.

My company only deals with solutions from Fortinet.

I recommend the product for pharma companies.

For administration and management of the product, there are two or three people in my company working in the core IT team.

From a marketing perspective, the product has been promoted enough in my region. My company has been promoting the product for the past 12 years.

The product offers information on the internet, and it can provide sufficient knowledge to employees who support the tool.

In terms of interface, the product is easy to use and is mostly connected to its own protocols,like FortiLink.

I rate the solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Flag as inappropriate
PeerSpot user
reviewer2314347 - PeerSpot reviewer
Network & Security Engineer at a tech services company with 51-200 employees
Real User
Top 10
A security solution for securing the Internet facing servers but lacks several security features

What is our primary use case?

We use the solution for securing the Internet-facing servers where you can do the  load balancing with the web appliance.

What needs improvement?

FortiWeb WAF lacks several security features compared to F5. F5 can incept the traffic to layer seven; FortiWeb can do it, too, but it is a tough process. We have to get support from Fortinet.

For how long have I used the solution?

I have been using FortiWeb as a partner for two years. We are using V7.2 of the solution.

What do I think about the stability of the solution?

Fortinet has many issues, like the zero-day attacks. Certain critical work vulnerabilities need to be immediately upgraded as an enterprise. You cannot initiate the upgrade anytime because it affects production. Usually, we schedule the upgrade. We do the configuration and scheduling of the updates. Fortinet is a 24/7 company that can release updates any time, regardless of the day of the week. FortiWeb WAF is a security solution that can be updated at any time, irrespective of the day of the week.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

On two recent occasions, I experienced delays in resolving technical issues with Fortiweb WAF, particularly when configuring explicit proxies on FortiGate firewalls. As a Fortinet partner, I was disappointed that our dedicated support channel was unavailable and that I could not obtain licenses or hardware assistance despite escalating to the country manager. Additionally, the technical support response times in the Middle East region have been inconsistent, with some areas providing excellent support while others have been unresponsive. This inconsistency has been particularly frustrating when dealing with urgent issues at remote sites. Overall, the support experience for Fortiweb WAF has been inconsistent and frustrating, particularly for Fortinet partners.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used Kemp before, but I also dislike the FortiWeb. I'm trying to move to F5 because F5 is very good.

How was the initial setup?

FortiWeb comes with an IP address. You need to log into the web console, and you can do it with the CLI using the console cable. You have to go in; it will initially give you a setup wizard and configure the hostname, interfaces, etc. The setup is relatively easy, but when it comes to advanced deployments. Kemp is a relatively affordable and capable solution. Fortiweb WAF offered all the features, making Kemp less appealing for enterprise-level applications. Kemp is suitable for smaller or regional websites, but it may not be as robust for global deployments.

Additionally, I could not locate the virtual domain feature in Fortiweb WAF. This feature would allow me to assign different domain names to a single website based on the user's location. Fortiweb WAF presented EDS as a workaround, but the process was overly complex and inconvenient.

Firstly, expect load balancing and a web application firewall for the same product Fortinet is offering. Start by booting up the device and use FortiWeb to connect the file by application firewall. There's a default IP address without any password. You log in, and then it shows your initial setup wizard. The wizard helps you set up the host names, Fortinet account, FortiCloud account, etc. After that, you start setting up your physical servers; then you give a virtual server, which will be a point. In a network with a firewall and port forwarding, the FortiWeb WAF device can act as a load balancer and a security gateway. It can receive traffic from the firewall, decrypt SSL/TLS traffic, inspect traffic for layer seven vulnerabilities, and then forward traffic to the appropriate internal server based on load-balancing algorithms and application-specific information provided by the servers. The FortiWeb WAF can monitor server health and performance and automatically switch traffic away from unhealthy servers.

Deployment depends on how much complexity you want to add to the product. If the customer requirement is easy, you may deploy it in one day. For example, I was working on a project with around 16 servers. Each server has a different data source; one server gives the back end, whereas the other provides the front end. That was a complex deployment. It will take around four to five days to deploy if you want to go deeper into it.

What was our ROI?

We have achieved 70% ROI.

What's my experience with pricing, setup cost, and licensing?

FortiWeb is expensive. F5 is also very expensive, but it is value for money.

What other advice do I have?

The solution’s maintenance and UI are easy, but some features are hidden. Their quality assurance needs to work. We used to have the upgrades and patches every month or 15 days, but now they are coming every week too. We have vulnerability.

The product needs to get more mature.

Overall, I rate the solution a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Syarul Idzuddin Adzmi - PeerSpot reviewer
Operation Director at Digital Pulse Sdn Bhd
Real User
Top 5
A cost-effective firewall that remains stable while providing security to its users
Pros and Cons
  • "The initial setup was easy since it was possible to get remote support for the product."
  • "The product lacks features offered by enterprise-level firewall tools."

What is our primary use case?

In my company, we use FortiWeb Web Application Firewall (WAF) for security.

What is most valuable?

FortiWeb is a small tool that can be used by those of our customers who use Fortinet FortiGate as their firewall. I will use Barracuda Email Protection for any customer who uses a firewall from a solution provider other than Fortinet FortiGate.

What needs improvement?

The product lacks features offered by enterprise-level firewall tools. The solution needs to offer more enterprise features like other brands.

It would be great if FortiWeb Web Application Firewall (WAF) had something like a wizard to allow for more integrations with other popular firewall products like Fortinet, Palo Alto, and so on.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for three years. I use the solution's latest version.

What do I think about the stability of the solution?

Stability-wise, I rate the solution a nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution an eight out of ten.

There are 2,000 users of the solution in my company.

How are customer service and support?

The solution's technical support was helpful and responsive. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have previously used SonicWall.

How was the initial setup?

The initial setup was easy since it was possible to get remote support for the product.

The solution is deployed on-premises.

What's my experience with pricing, setup cost, and licensing?

It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee.

What other advice do I have?

There are five engineers needed for the maintenance of the solution.

If there is a requirement and one is already using a firewall from Fortinet, then it is easier to deploy FortiWeb Web Application Firewall (WAF). Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Buyer's Guide
Download our free FortiWeb Web Application Firewall (WAF) Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free FortiWeb Web Application Firewall (WAF) Report and get advice and tips from experienced pros sharing their opinions.