

Fortinet FortiWeb and Check Point WAF both compete in the web application firewall category, with Fortinet FortiWeb having the upper hand due to its advanced integration capabilities and a strong focus on machine learning features.
Features: FortiWeb stands out with its machine learning capabilities, providing zero-day protection, API discovery, and granular access control. It is seamless when integrated with Fortinet's infrastructure and includes effective malware detection, bot mitigation, and load balancing. Check Point WAF leverages AI and behavior analysis for threat prevention. It offers zero-day protection, DDoS mitigation, and ensures ease of use with scalability and automated policy management.
Room for Improvement: Fortinet FortiWeb requires enhancements in customization, load balancing, support, and documentation. It is perceived as SME-centric, with a need for enterprise solutions. Check Point WAF can improve deployment simplicity, pricing models, reporting, and latency issues. Its reliance on AI sometimes reduces manual control and requires better support availability.
Ease of Deployment and Customer Service: Fortinet FortiWeb is well-suited to on-premises and hybrid setups, with beneficial integration within Fortinet's suite. It has mixed reviews on support, needing better documentation and response times. Check Point WAF serves cloud environments, offering easy maintenance and automation. It receives positive reviews for customer service, though its pricing is complex.
Pricing and ROI: Fortinet FortiWeb is competitively priced for SMEs with flexible licenses for various enterprise needs. It has a positive impact on ROI, reducing operational costs and securing applications. Check Point WAF, while more expensive, justifies its cost with comprehensive features and effectiveness in threat prevention, suited for mid to large enterprises with some users noting higher initial costs but long-term security benefits.
When we are attacked, we can understand how important the solution is.
When you migrate to the cloud, it feels like saving 90% of your time.
Most of the operations happen in the background, so I do not spend much time on it.
They need to increase the number of people for 24/7 support.
They were responsive even before we committed to buying their solution.
I also received full technical support, especially during the implementation.
Their support is truly exceptional when I compare it with similar large-sized companies.
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.
If I need to scale, I open a Whatsapp group with the director and the team, and we quickly proceed to do so.
They have sufficient resources, and there are no challenges from a scalability perspective.
Check Point CloudGuard WAF's scalability is very good.
You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
It is very stable.
It is very stable, never crashing or giving me an error that I can see.
I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.
We have not faced any significant issues during deployments.
The provider could improve by providing better guidance and support during the configuration process.
Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
A machine learning-based adaptive mode could help the WAF learn over time and auto-tune policies.
If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.
Fine-tuning is a room for improvement in Fortinet FortiWeb.
After the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer.
It is more expensive than f5, where we purchased everything as bundles, and Check Point costs more, but it is worth the money.
It is less costly than Cloudflare, Fortinet, and other vendors.
I know that its price is relatively expensive compared to other products but it gives benefits that are worth it.
For VM machines, the price increases based on CPU configurations of 2, 4, or 8 CPUs.
Most security products charge less at the time of purchase because of competition, but when we go to renewals, the prices become very high.
Fortinet FortiWeb is cost-effective compared to solutions like F5.
Upon implementation and evaluation with third-party penetration testing, it meets rigorous security standards required for dealing with financial institutions.
It can protect against zero-day attacks and hidden anomalies.
The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.
Fortinet FortiWeb has positively impacted my organization because most of our servers and applications are secure from hackers and other security threats.
Fortinet's pricing is way more competitive than Cisco or Palo Alto.
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiWeb | 4.4% |
| Check Point WAF (formerly CloudGuard WAF) | 2.0% |
| Other | 93.6% |

| Company Size | Count |
|---|---|
| Small Business | 56 |
| Midsize Enterprise | 23 |
| Large Enterprise | 36 |
| Company Size | Count |
|---|---|
| Small Business | 60 |
| Midsize Enterprise | 27 |
| Large Enterprise | 37 |
Check Point WAF offers a robust security framework with AI-driven threat detection and seamless integration, protecting applications and APIs in multi-cloud environments.
Effective in preemptively blocking threats through AI and machine learning, Check Point WAF reduces false positives and operational workload. Its integration capabilities and threat intelligence provide comprehensive protection against zero-day attacks, while centralized management facilitates cost-effective and insightful threat reporting.
What are the main features of Check Point WAF?Check Point WAF is employed in industries securing web applications and APIs, especially in multi-cloud environments. It effectively protects backend services, prevents unauthorized access, and monitors traffic, making it suitable for businesses with diverse infrastructures. It ensures compliance with security standards and adapts to fluctuating traffic patterns.
Fortinet FortiWeb provides advanced web application protection, using AI-driven threat detection and seamless integration with Fortinet products, ensuring robust security and easy management. It's favored for its scalability in protecting websites, mobile apps, and APIs from threats like SQL injection.
Fortinet FortiWeb offers robust web application security with features like machine learning-driven threat detection, load balancing, and OWASP protection. Its comprehensive security measures include web traffic filtering and DDoS protection, making it ideal for securing APIs and web servers. Cost-effectiveness and easy deployment further enhance its appeal as it serves banking, e-commerce, and industrial sectors. Areas needing enhancement include load balancing capabilities, comprehensive documentation, and improved support response times, addressing user-reported issues such as false positives and integration challenges. Documentation for cloud deployment is crucial for enhanced logging and performance stability.
What are Fortinet FortiWeb's Key Features?Companies across banking, e-commerce, and financial sectors implement Fortinet FortiWeb for its comprehensive security features in protecting web applications from SQL injection and cross-site scripting. Its use as a web application firewall provides essential protection and load-balancing capabilities, ensuring compliance with standards like PCI DSS in cloud environments and industrial settings.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.