Try our new research platform with insights from 80,000+ expert users

Cloudflare Web Application Firewall vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Cloudflare Web Application ...
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
23
Ranking in other categories
Web Application Firewall (WAF) (7th)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
95
Ranking in other categories
Web Application Firewall (WAF) (5th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
SachidDoshi - PeerSpot reviewer
Offers a huge signature repository and is superiorly effective in mitigating DDoS attacks
The solution's learning curve can still be further reduced, which presently stands at two or three months. The product has a custom rule set that users can modify and manifest as needed. The vendor can probably shorten the learning curve using cutting-edge technologies like AI. The solution provider can also work around the web applications and identify the toolset that needs to be implemented to deploy the solution in less time. The vendor has launched a SASE product that can function with Cloudflare Web Application Firewall, but many improvements are needed in terms of features, such as the web filtering feature, and CASB has not yet been added.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"The most valuable features of the solution are performance and security."
"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"Centralized, full-featured DNS."
"I like Cloudflare's application gateway and DDoS protection."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"We extensively use the solution every day. The solution is very stable; we haven’t seen any glitches."
"It is configurable via API."
"Cloudflare is cheaper compared to Azure WAF, which I have considered before."
"Cloudflare WAF provides protection through rules and functionalities like Cloudflare's SDRAP."
"The setup process is very simple for me."
"The rate limiting features and customizations in terms of URL match and applying policies are valuable to me."
"Technical support has a very fast response time and they are helpful."
"The product has improved our security posture by blocking bad actors."
"If I need something from tech support, I can get it answered within the hour."
"It is a stable product."
"What we like about Fortinet FortiWeb is it has all the features. We use all of them, so we have to turn on all the options."
"SSL Offloading simplifies the public certificate handling and brings additional protection features."
"FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient."
"All the features that FortiGate contains are very suitable for our business. We work with other products in Fortinet, FortiWeb, FortiSandbox, FortiMail, and FortiCache. We use all UTM features like self-encryption, encryption, all UTM features."
"FortiWeb is easy to operate with a reasonably high level of protection. FortiWeb provides multiple deployment options with a physical or virtual (FortiWeb-VM) appliance, and acts either as a reverse/transparent proxy or out-of-band. It is also available on AWS and Azure."
"The valuable feature of Fortinet FortiWeb vulnerability scanner"
 

Cons

"I would like Cloudflare to offer a dedicated account manager for large enterprise clients like us."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"The analytics, basically the dashboard, doesn't have much to it."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"Support response time could be improved."
"The solution could be more user-friendly."
"Integration involving API with other products could be more user-friendly."
"Cloudflare Web Application Firewall should improve visibility for a customer."
"The learning curve was steep initially."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"The blocked logs are difficult to read at times."
"Its stability could be better."
"The ModSecurity core rules need to be updated."
"The solution's learning curve can still be further reduced"
"The platform's control features related to real-time authentication and response time need improvement."
"For advanced users, it would be really useful to have access and the ability to manipulate packets. If we can access and manipulate the contents of packets, even encrypted packets... that would be powerful. Since we're looking at packets arriving at our network, we would have the private key to access those packets and their information."
"Its threat intelligence capabilities may not be as advanced as some competitors."
"New releases and old releases have some bugs, some features do not work as good as we want but every new release the Fortinet team fixes up problems."
"Another area for improvement is logging. When troubleshooting, the logs sometimes take a while to update. We've had people report that some things aren't logged if they're successful. It's a bit hit-and-miss. For example, sometimes people access one of our services, and it's successful, but we don't see that in the logs."
"HA Architecture needs improvement. I would improve it by working on AP HA."
"Centralized management of multiple devices, and GUI improvement, could reduce the learning curve."
"Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company."
"Fortinet FortiWeb needs to improve the way it's configured. Common services like publishing exchange should be done in one click only."
 

Pricing and Cost Advice

"So far I use free tier and happy with it. You can subscribe to business package if needed."
"There are no additional costs beyond the standard licensing fees."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"We are using the free version."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The product's pricing is cheap."
"The annual licensing fee is $10,000 USD."
"It is not too pricey."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"The solution's pricing option needs to be more transparent for enterprise clients."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"It starts at $20 and can easily go up to $200 monthly"
"The solution is expensive."
"Due to the situation in Iran with the sanctions, the price of this solution is very expensive."
"The solution is cheaper compared with other solutions. It has a yearly license."
"If one is cheap and ten is expensive, I rate the tool an eight."
"There are no licensing costs."
"Previously, for each project, the cost was $800 to $1,000 per application. Now, it's $100 to $120. For some of the applications, there is a 90% reduction, and for some of the applications, there is a 50% reduction. We're paying only $500 to $600."
"The price of Fortinet FortiWeb is reasonable. This is one of the key factors of why we use this solution."
"The solution is a bit expensive when compared to other products."
"FortiWeb offers these services at a price that SME customers can afford, but it's also suitable for large enterprises. Still, they need to put in more work to gain a greater share of enterprise business because they face stiff competition in this segment from F5, Cloudflare, and some others."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
17%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
8%
Educational Organization
22%
Computer Software Company
14%
Financial Services Firm
8%
Manufacturing Company
6%
Educational Organization
42%
Computer Software Company
8%
Financial Services Firm
7%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Cloudflare Web Application Firewall?
The product has a valuable security control functionality.
What is your experience regarding pricing and costs for Cloudflare Web Application Firewall?
Cloudflare is cheaper compared to Azure WAF, which I have considered before.
What needs improvement with Cloudflare Web Application Firewall?
The product can improve by having more multitenancy capability, which is currently not available. This improvement wo...
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
Fortinet FortiWeb is cost-effective compared to solutions like F5. It offers strong performance for the price, provid...
What needs improvement with Fortinet FortiWeb?
The cloud-based security service of Fortinet FortiWeb could be enhanced to match the level of providers like Cloudfla...
 

Also Known As

Cloudflare DNS
Cloudflare WAF
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
crunchbase, udacity, marketo, okcupid, zendesk
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Cloudflare Web Application Firewall vs. Fortinet FortiWeb and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.