Try our new research platform with insights from 80,000+ expert users

FortiWeb Web Application Firewall (WAF) vs Sucuri comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
FortiWeb Web Application Fi...
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
23
Ranking in other categories
Web Application Firewall (WAF) (16th)
Sucuri
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
6
Ranking in other categories
Web Application Firewall (WAF) (22nd), Distributed Denial-of-Service (DDoS) Protection (14th), Domain Name System (DNS) Security (12th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
IgnitiusMolepo - PeerSpot reviewer
Protects internal applications and prevents target attacks
The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises. You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary. The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.
David Shlingbaum - PeerSpot reviewer
Simple solution and good WAF
Sucuri could provide help for specific security alerts in-line instead of requiring users to search for it in the help section. Users get errors or EBAs, and if they want to read about it, they need to find it in the help section of the site. It would be more helpful to allow users to see more information and tips immediately from within the alert.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The technical support is good."
"The most valuable feature is its usability."
"The UI is good."
"The attacker won't have details since my public IP is anonymous. It offers us good privacy."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"The overall experience with Cloudflare is positive, with a rating of eight out of ten."
"The features of Cloudflare were found to be more beneficial and led to the decision to utilize it over other options."
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
"The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats."
"FortiWeb Web Application Firewall helps us to block certain categories of browsing, such as weapons, and other inappropriate content on the client side. We have also blocked social media sites like TikTok and Facebook to enhance user productivity and maintain application security."
"The product's initial setup phase was easy."
"The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS."
"It improves latency by optimizing traffic routing."
"The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature."
"The platform's stability is good."
"The initial setup was very easy."
"I use it as a WAF, which is basically a web firewall to monitor and block traffic to our web server."
"The most valuable part is the analytics and visualization."
"Domain name scanning since it allows us to scan all our domain names and determine whether it has malware or if is reported as phishing."
"It significantly eases the workload and streamlines the initial setup required to protect a website."
"The initial setup was straightforward. Straight forward because the plugin can simply be installed and then it does its job. It's not complex, there is no learning curve. The online scan is simple, you put in the website address and the scan gives us a report on the browser itself. It's simple to use."
 

Cons

"There are some issues with the CDN services."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"There should be a specific price list for enterprise-level customers."
"DNS Management."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"If they improve on the placement of their data centers, it would be better. I'm living in a remote area. I would like to connect to them without any kind of lag."
"The tool needs to improve caching of servers. The product needs to include PFX certificate as well."
"WAF needs more signatures on FortiWeb and updates the database continuously to protect against new attacks."
"FortiWeb Web Application Firewall needs to improve its performance."
"There is room for improvement in pricing, and actually, the price is a bit higher because on the same terms I purchased, the support subscription is so high."
"The product lacks features offered by enterprise-level firewall tools."
"The product is complicated to set up."
"The tool's price and performance are areas of concern where improvements are required."
"Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees."
"There could be ADC offering as well."
"The main improvement I would like to see is support for .NET applications. If they could include this feature, I would include more sites in the protection."
"Sucuri could provide help for specific security alerts in-line instead of requiring users to search for it in the help section."
"In terms of improvement, the cost factor is always there."
"Confident score: Currently it does not have one and there are cases that most websites flagged are false-positives."
"It would greatly benefit customers if they implemented an online chat or messaging system for quicker assistance."
"I would rate this solution an eight out of ten. The reason is that we have found sometimes customers or Google saying that there is something wrong with the website but Sucuri says that the site is clean so we do have to look at the site manually which means that the Sucuri scan does not pick up anything and everything."
 

Pricing and Cost Advice

"That is one of the great features. I was able to access the majority of the features and services for free."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"I give the price a five out of ten."
"The price of the solution is expensive."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"We are using the free version."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"FortiWeb has a good presence because of its price."
"This product offers two pricing options: a standard package and an advanced package."
"The licensing cost of the product is pretty high compared to other OEMs in the market."
"It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee."
"The product provides very good prices to customers. The price is set well and offers great value for money."
"FortiWeb Web Application Firewall is not expensive."
"I would rate the pricing a four out of ten."
"The tool is really expensive."
"I’d simply say it’s really worth it."
"It stands out as a more cost-effective option compared to other cloud-based security services like Cloudflare or JetPass."
"Sucuri offers different plans, both the standard plan and an advanced plan. So there are different plans to choose from."
"The ROI has been very good. Because of the solution, I have a tax break. The site developers were not always experienced people. We used to pay more for cleaning up the site when it was infected. Now, we have peace of mind knowing that the solution will clean up the site and that we won't have to go through the unnecessary process of restoring it from a backup. The protection on the WAF and the measures for backups have also prevented our site from going down."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
17%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
16%
Financial Services Firm
13%
Manufacturing Company
10%
Comms Service Provider
8%
Educational Organization
42%
Computer Software Company
9%
Manufacturing Company
7%
Real Estate/Law Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapes...
What needs improvement with FortiWeb Web Application Firewall (WAF)?
There are some issues pertaining to the migration. If some of my customers want to migrate from F5 to Fortinet Firewa...
What do you like most about Sucuri?
The initial setup was very easy.
What is your experience regarding pricing and costs for Sucuri?
The pricing is very reasonable. Sucuri offer other features as an add-on, such as backup, but these have an additiona...
What needs improvement with Sucuri?
The main improvement I would like to see is support for .NET applications. If they could include this feature, I woul...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
The Loft Salon, Tom McFarlin, WPBeginner, Taylor Town, Everything Everywhere, Financial Ducks in a Row, Chubstr, Real Advice Gal, Sujan Patel, Wallao, List25, School the World
Find out what your peers are saying about FortiWeb Web Application Firewall (WAF) vs. Sucuri and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.