


Fortinet FortiWeb and NGINX App Protect compete in web application protection. Fortinet FortiWeb is often favored for its integration with Fortinet products, while NGINX App Protect is praised for its customization capabilities.
Features: Fortinet FortiWeb is known for robust integration with Fortinet solutions, advanced application control, and zero-day protection. NGINX App Protect offers flexibility with its command-line control, auto-learning capabilities, and reverse proxy options.
Room for Improvement: Fortinet FortiWeb needs improvements in upgrade procedures, false positives handling, and third-party integration. Users also suggest enhanced DDoS protection. NGINX App Protect could improve its licensing model and boost bot protection and API security.
Ease of Deployment and Customer Service: Both solutions support various deployment modes, but Fortinet FortiWeb's support receives mixed feedback with calls for faster responses. NGINX App Protect is generally well-regarded in terms of customer service and support.
Pricing and ROI: Fortinet FortiWeb is seen as cost-effective, especially when bundled with Fortinet products. It offers good ROI and operational cost savings. NGINX App Protect is viewed as pricier and less flexible, impacting perceived value.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
Their support is truly exceptional when I compare it with similar large-sized companies.
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
The back-end development team is available, and if any issue arises, they will help us immediately by providing solutions when contacted.
They were quick and efficient when we had issues.
I would rate the customer support a 9 on a scale of 1 to 10.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
The scalability of NGINX App Protect is good and open source at its best.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
We have not faced any significant issues during deployments.
It is a quality solution, and I would rate its stability as eight out of ten.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
If the GUI includes notifications and improved logging capabilities that allow us to see traffic and store logs for six months, that would be very helpful.
Fine-tuning is a room for improvement in Fortinet FortiWeb.
After the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer.
There was more information from F5 regarding hardware requirements and specifications to deploy the service.
For now, I think NGINX App Protect is good, but maybe I would like to see the logging feature added.
The GUI and web GUI configuration could be improved to be easier to manage and use.
For VM machines, the price increases based on CPU configurations of 2, 4, or 8 CPUs.
Most security products charge less at the time of purchase because of competition, but when we go to renewals, the prices become very high.
Fortinet FortiWeb is cost-effective compared to solutions like F5.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
Fortinet FortiWeb has positively impacted my organization because most of our servers and applications are secure from hackers and other security threats.
Fortinet's pricing is way more competitive than Cisco or Palo Alto.
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
The most valuable feature is the ability to operate in a DevOps environment and to be configured through API and pipeline by the developers themselves.
Some threats like injection and running scripts, SQL injections, these all get stopped and rejected by the server.
Detecting bots and blocking IPs have proven effective for securing applications.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiWeb | 6.0% |
| Cloudflare Web Application Firewall | 4.7% |
| NGINX App Protect | 2.2% |
| Other | 87.1% |

| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 60 |
| Midsize Enterprise | 27 |
| Large Enterprise | 36 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 6 |
| Large Enterprise | 12 |
Cloudflare Web Application Firewall integrates DDoS protection, load balancing, and firewall capabilities. Its ease of use, configurability, and robust security measures make it a versatile choice for protecting web applications.
Cloudflare Web Application Firewall provides a comprehensive defense against threats with advanced reporting and robust security measures. It includes DNS integration, rate limiting, and extensive rule sets, all within a SaaS model that allows API configurability. Users value its caching, scalability, and pricing, although enhancements are needed in rate-limiting and third-party integration. Improvements in customer support, especially in India, real-time controls, and user documentation are also desired. Users seek a more intuitive dashboard, better log management, and improved alert systems, along with multitenancy capabilities and enhanced reporting.
What are the key features of Cloudflare Web Application Firewall?Cloudflare Web Application Firewall finds application in industries like banking and retail by acting as a comprehensive security gateway, managing authentication and authorization while protecting web applications from malicious Layer 7 traffic. It also implements load balancing, CDN, and zero-trust policies, supported by advanced reporting, analytics tools, and threat scoring to meet specific industry needs.
Fortinet FortiWeb provides advanced web application protection, using AI-driven threat detection and seamless integration with Fortinet products, ensuring robust security and easy management. It's favored for its scalability in protecting websites, mobile apps, and APIs from threats like SQL injection.
Fortinet FortiWeb offers robust web application security with features like machine learning-driven threat detection, load balancing, and OWASP protection. Its comprehensive security measures include web traffic filtering and DDoS protection, making it ideal for securing APIs and web servers. Cost-effectiveness and easy deployment further enhance its appeal as it serves banking, e-commerce, and industrial sectors. Areas needing enhancement include load balancing capabilities, comprehensive documentation, and improved support response times, addressing user-reported issues such as false positives and integration challenges. Documentation for cloud deployment is crucial for enhanced logging and performance stability.
What are Fortinet FortiWeb's Key Features?Companies across banking, e-commerce, and financial sectors implement Fortinet FortiWeb for its comprehensive security features in protecting web applications from SQL injection and cross-site scripting. Its use as a web application firewall provides essential protection and load-balancing capabilities, ensuring compliance with standards like PCI DSS in cloud environments and industrial settings.
NGINX App Protect offers comprehensive security features like auto-learning and bot protection. Its real-time threat detection and ease of integration make it suitable for web and mobile application security across on-premises, cloud, and container environments.
NGINX App Protect stands out with its adaptive machine learning, scalable deployment options, and robust API connectivity, offering Layer 7 DDoS protection and an OWASP-certified WAF. While it supports comprehensive traffic and security management, enhancements in platform integration, automation, and technical support could improve usability. The pricing model and policy management options could also see refinement. Commonly employed in securing web and mobile applications, it addresses threats including OWASP Top 10 vulnerabilities and DDoS attacks, while providing seamless integration with Kubernetes and CI/CD pipelines.
What are the key features of NGINX App Protect?NGINX App Protect finds broader use in sectors like banking and telecommunications, where it secures high-performance digital infrastructures. Its application spans perimeter security, load balancing, and acts as a reverse proxy in environments necessitating stringent security, high throughput, and robust management. The tool's adaptability facilitates its deployment alongside containers, ensuring compatibility with contemporary development practices.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.