Try our new research platform with insights from 80,000+ expert users

Fortinet FortiWeb vs Rapid7 Metasploit comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.0
Cloudflare improves speed, security, and stability, leading to significant financial benefits with an ROI of 318% for businesses.
Sentiment score
7.3
Users experience significant cost savings, enhanced security, and efficient performance with easy deployment of Fortinet FortiWeb, despite some measurement challenges.
Sentiment score
7.6
Rapid7 Metasploit efficiently identifies system vulnerabilities, saving testing time and costs, offering significant ROI for first-time users.
WordPress security can be tricky, and that's where Cloudflare can be absolutely helpful for small businesses.
We have had ROI with the tool's use since it never gave us downtime and made us lose millions.
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
Metasploit has helped save time, especially with testing websites or VIPD projects.
The ROI can be very rapid for organizations using vulnerability assessment for the first time.
 

Customer Service

Sentiment score
7.2
Cloudflare's support is praised for responsiveness, though non-paying users and regions without local offices face challenges.
Sentiment score
6.8
Fortinet FortiWeb's customer support is inconsistent, praised for responsiveness but criticized for slow responses and varying regional satisfaction.
Sentiment score
7.7
Rapid7 Metasploit support varies, with mixed reviews on response time; commercial users generally report better experiences.
This would help us address issues promptly, especially during unforeseen events like DDoS attacks.
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
We'd like a dedicated account manager.
The expertise of engineers varies across different time zones, affecting the effectiveness of the support provided, especially during our daytime.
Rapid7 sometimes struggles with queries from non-security people, whereas Tenable is more patient.
The customer support is excellent
 

Scalability Issues

Sentiment score
8.2
Cloudflare efficiently handles increased traffic and growth, offering scalability, robust network performance, and seamless expansion for enterprises.
Sentiment score
7.2
Fortinet FortiWeb effectively scales, supporting thousands, though upfront sizing and hardware constraints are key for optimal performance.
Sentiment score
7.9
Opinions differ on Rapid7 Metasploit's scalability, with some praising its adaptability and others noting limitations, especially in automation.
I would rate the solution's scalability a ten out of ten since I didn't encounter any issues with it.
I rate its scalability a ten out of ten because I had no issues with it.
I rate the scalability a ten out of ten.
Metasploit can handle big projects and is already prepared for them.
Rapid7 Metasploit is highly scalable.
I would rate the scalability of Metasploit as an eight out of ten.
 

Stability Issues

Sentiment score
7.7
Cloudflare is generally stable and reliable, but occasional issues with downtime, speed, and DDoS protection are reported.
Sentiment score
7.9
Fortinet FortiWeb offers stable performance with rare issues, quickly resolved through support, ensuring reliable high-traffic management.
Sentiment score
8.1
Users praise Rapid7 Metasploit's stability and improvements, rating it 7-9 out of 10 while noting rare network issues.
For DDoS protection, I would not recommend Cloudflare.
I rate the solution’s stability an eight out of ten.
The service is very stable with no impacts during high-traffic periods.
We have not faced any significant issues during deployments.
I have never faced any technical issues or downtimes.
I find Metasploit to be very stable, and I would rate its stability as a nine out of ten.
 

Room For Improvement

Cloudflare needs analytics, threat insights, improved support, user-friendly dashboards, and simplified pricing, with consistent caching and security features.
Fortinet FortiWeb needs enhancements in throughput, cloud presence, integration, and user-friendly features to improve competitiveness and scalability.
Rapid7 Metasploit requires faster updates, improved GUI, better integration, enhanced support, updated database, and stronger evasion capabilities.
There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features.
Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor.
the ability to integrate with the on-site active directory instead of just AD through Azure AD
The cloud-based security service of Fortinet FortiWeb could be enhanced to match the level of providers like Cloudflare.
The database is not always updated with the latest vulnerabilities or zero-day exploits.
The time taken to fetch reports based on the number of events can be extensive.
Metasploit excels in vulnerability assessment, it could improve in vulnerability management.
 

Setup Cost

Cloudflare offers flexible pricing with plans for small businesses to enterprises, balancing cost with comprehensive features and protection.
Fortinet FortiWeb offers competitive, cost-effective pricing with flexible options, appealing to enterprises for value, transparency, and performance.
Rapid7 Metasploit's pricing includes a one-time fee and annual support, viewed as intermediate compared to alternatives.
That's where Cloudflare shines for smaller businesses – it's ten times cheaper than Akamai.
I find it to be cheap.
It's cost-effective, but I think they should have a custom pricing model for enterprise customers based on the features you use.
Fortinet FortiWeb is cost-effective compared to solutions like F5.
The cost is approximately $15 per device.
Metasploit is cheaper than Nessus and offers a more robust community edition that provides a good experience for studying Metasploit.
 

Valuable Features

Cloudflare offers caching, DDoS protection, and CDN services, enhancing website speed and security with intuitive interface and global reach.
Fortinet FortiWeb offers advanced security features with seamless integration, intuitive interface, and enhanced threat detection using AI and machine learning.
Rapid7 Metasploit offers automated penetration testing with extensive module support, integration features, and versatility for security professionals.
Our scenario consisted of two web servers in different allocations to control access demands, and the load balancer did the job as expected, bringing security and stability to access points.
For me, the valuable feature is DDoS protection.
The most valuable features of the solution are performance and security.
The machine learning-based threat detection is significant, as it uses a learning method that eases the configuration burden, making it very useful.
Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place.
The most valuable features of Metasploit include its powerful capabilities for exploitation and scanning.
When I compare Metasploit with Nessus, I find that Metasploit is faster and it does not burden the system as much.
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Fortinet FortiWeb
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
95
Ranking in other categories
Web Application Firewall (WAF) (5th)
Rapid7 Metasploit
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
21
Ranking in other categories
Vulnerability Management (20th)
 

Mindshare comparison

Web Application Firewall (WAF)
Vulnerability Management
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.
Mani Bommisetty - PeerSpot reviewer
Comprehensive insights with robust vulnerability detection and streamlined alert management
Rapid7 has a significant advantage in providing a clear picture of my environment. It provides insight and incident detection response capabilities. When deployed with the same agent in servers or endpoints, it identifies vulnerabilities and monitors data transmission to external sources. Rapid7 offers comprehensive features within one platform, eliminating the need to integrate multiple tools to see all alerts in one place.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
17%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
8%
Educational Organization
42%
Computer Software Company
8%
Financial Services Firm
7%
Government
5%
Computer Software Company
18%
Financial Services Firm
11%
Manufacturing Company
10%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
Fortinet FortiWeb is cost-effective compared to solutions like F5. It offers strong performance for the price, provid...
What needs improvement with Fortinet FortiWeb?
The cloud-based security service of Fortinet FortiWeb could be enhanced to match the level of providers like Cloudfla...
What do you like most about Rapid7 Metasploit?
I use Rapid7 Metasploit for payload generation and Post-Exploitation.
What is your experience regarding pricing and costs for Rapid7 Metasploit?
Metasploit is cheaper than Nessus and offers a more robust community edition that provides a good experience for stud...
What needs improvement with Rapid7 Metasploit?
While Metasploit excels in vulnerability assessment, it could improve in vulnerability management. Nessus currently h...
 

Also Known As

Cloudflare DNS
No data available
Metasploit
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
City of Corpus Christi, Diebold, Lumenate, Nebraska Public Power District, Prairie North Regional Health, Apptio, Automation Direct, Bob's Stores, Cardinal Innovations Healthcare Solutions, Carnegie Mellon University
Find out what your peers are saying about Amazon Web Services (AWS), F5, Microsoft and others in Web Application Firewall (WAF). Updated: March 2025.
849,686 professionals have used our research since 2012.