Try our new research platform with insights from 80,000+ expert users
CEO at a tech services company with 1-10 employees
MSP
Protects our customers' web infrastructure environment
Pros and Cons
  • "The most valuable feature is the web application firewall (WAF)."
  • "Fortinet FortiWeb has improved my organization by protecting our customer's web infrastructure environment."
  • "​Their support needs improvement."

How has it helped my organization?

Fortinet FortiWeb has improved my organization by protecting our customers' web infrastructure environment.

What is most valuable?

The most valuable feature is the web application firewall (WAF).

What needs improvement?

Their support needs improvement.

For how long have I used the solution?

More than five years.
Buyer's Guide
Fortinet FortiWeb
June 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

How are customer service and support?

I would rate their technical support as a nine out of 10.

Which solution did I use previously and why did I switch?

We previously used NetScaler.

How was the initial setup?

The initial setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable.

Which other solutions did I evaluate?

Not applicable.

What other advice do I have?

Evaluate this product against other vendors out there.

We were previously a partner.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
NetworkS4e03 - PeerSpot reviewer
Network System Administrator at a computer software company with 201-500 employees
Real User
Protected our web servers from outside attacks. Certificates were deleted when firmware was upgraded.
Pros and Cons
  • "We were able to protect our web servers from outside attacks."
  • "The false positives are annoying.​"
  • "I had some small problems when I was upgrading firmware. After the upgrade, some of my certificates were deleted.​"

How has it helped my organization?

We were able to protect our web servers from outside attacks. It has really helped us with publishing servers which were published on Microsoft Forefront TMG.

What is most valuable?

All of its feature are valuable to us. If you ask me which is the most valuable, it is the load balancing, then I would say the security features. Publishing OWA is also a good feature.

What needs improvement?

We started with FortiWeb400C, then we did an upgrade to FortiWeb 400D. I had some small problems when I was upgrading firmware. After the upgrade, some of my certificates were deleted.

The false positives are also annoying.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

We did not encounter with any stability issues.

What do I think about the scalability of the solution?

We did not encounter with any scalability issues.

How are customer service and technical support?

Fortinet technical support is really good. I would give them a nine out of 10.

Which solution did I use previously and why did I switch?

We did not use a WAF before. We used Microsoft TMG, but it is not a WAF.

How was the initial setup?

Initial setup is straightforward, and it is not too complex.

What's my experience with pricing, setup cost, and licensing?

It really pays off to buy licences for multiple years.

Which other solutions did I evaluate?

No.

What other advice do I have?

It is a really good product. It is worth using in your network.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partners.
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
June 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Technicae31f - PeerSpot reviewer
Technical Advisor at a tech services company with 51-200 employees
Real User
L-7 protection safeguards legacy servers/applications without changing application code
Pros and Cons
  • "Other than the additional security with exploit protection, we have simpler certificate handling, as we can keep internal servers using internal certificates continuously distributed and updated by Active Directory Group Policy, while the public certificates become updated only in a single place, FortiWeb itself."
  • "SSL Offloading simplifies the public certificate handling and brings additional protection features."
  • "L-7 protection makes possible to protect legacy/not up-to-date servers/applications without changing the application code."
  • "Centralized management of multiple devices, and GUI improvement, could reduce the learning curve."
  • "The interface could have the interdependent elements arranged sequentially and wizards that go through most common deployment actions."
  • "Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration."

How has it helped my organization?

Other than the additional security with exploit protection, we have simpler certificate handling, as we can keep internal servers using internal certificates continuously distributed and updated by Active Directory Group Policy, while the public certificates become updated only in a single place, FortiWeb itself.

What is most valuable?

SSL Offloading, as it simplifies the public certificate handling and brings additional protection features. 

Also, L-7 protection, as it makes possible to protect legacy/not up-to-date servers/applications without changing the application code.

What needs improvement?

  • Centralized management of multiple devices, and GUI improvement, could reduce the learning curve. 
  • The interface could have the interdependent elements arranged sequentially and wizards that go through most common deployment actions. 
  • Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

No issues with scalability. (Actually, our traffic usually does not reach 50% of unit capacity).

How are customer service and technical support?

Good. Usually takes one day to get over all the assessment procedures to start to handle the issue.

Which solution did I use previously and why did I switch?

The previous vendor discontinued its product.

How was the initial setup?

A little bit complex, as understanding the GUI arrangement and terms took more time and effort than we expected.

What's my experience with pricing, setup cost, and licensing?

Keep a loose margin between your actual bandwidth and the product sizing when using hardware appliances. Only virtual machines are upgradable to larger sizes.

Which other solutions did I evaluate?

We acquired a Fortinet-based project, so we didn’t evaluate other ones.

What other advice do I have?

I rate it eight out of 10. I understand that a 10 is for products that not only execute smoothly but are also easy to use and manage, even when used on a multi-site corporation.

Take at least the Fortinet online course, or make sure that your reseller has experienced professionals.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user821967 - PeerSpot reviewer
Viznet Bilişim Hizmetleri
Real User
Auto Learn makes policy additions or deletions for my customers very simple​
Pros and Cons
  • "Auto Learn feature: Makes policy additions or deletions for my customers very simple​"
  • "HA Architecture needs improvement. I would improve it by working on AP HA."

How has it helped my organization?

Security.

What is most valuable?

  • Web application security features, because they are more effective
  • Stability 
  • Auto Learn feature: Makes policy additions or deletions for my customers very simple

What needs improvement?

HA Architecture. I would improve it by working on AP HA.

For how long have I used the solution?

Three to five years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

No issues with stability, with the true network topology.

How are customer service and technical support?

I am Fortinet expert, but L4 support is working very well.

Which solution did I use previously and why did I switch?

Previously used F5, NetScaler, Imperva. Other products feature LB WAFs, so a limited WAF feature. This product's primary feature is WAF. I chose this product because it prioritizes security.

How was the initial setup?

Very complex. More security features.

What's my experience with pricing, setup cost, and licensing?

Cheaper than others.

Which other solutions did I evaluate?

F5, NetScaler, Imperva and Squid.

What other advice do I have?

Here's how I would break down my rating of this product:

  • Session Management: 10 out of 10 
  • Security: 10 out of 10 
  • Stability: 10 out of 10
  • Health check feature: eight out of 10.

If your goal is security, FortiWeb is your best choice.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Technology Consultant at a tech services company with 11-50 employees
Consultant
Detection engine provides a high rate of exposure of web attacks
Pros and Cons
  • "High-performance and detection engines, provide a high rate of exposure of web attacks."
  • "FortiWeb is easy to operate with a reasonably high level of protection. FortiWeb provides multiple deployment options with a physical or virtual (FortiWeb-VM) appliance, and acts either as a reverse/transparent proxy or out-of-band. It is also available on AWS and Azure."
  • "Integration and learning about attacks. I would improve these areas by making FortiWeb integrate with other network technologies and feedback from multiple platforms."

How has it helped my organization?

Mitigation of attacks and thefts in an online banking platform.

What is most valuable?

High-performance and detection engines, because of their high rate of exposure of web attacks.

What needs improvement?

Integration and learning about attacks. I would improve these areas by making FortiWeb integrate with other network technologies and feedback from multiple platforms.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

The equipment is dimensioned as a function of servers traffic. To scale on the platform it is necessary to acquire superior models.

How is customer service and technical support?

Excellent.

How was the initial setup?

It was simple and functional.

What's my experience with pricing, setup cost, and licensing?

FortiWeb can be purchased in VM mode for a lower price and the same features.

Which other solutions did I evaluate?

The WAF module of F5 was evaluated.

What other advice do I have?

FortiWeb is easy to operate with a reasonably high level of protection. FortiWeb provides multiple deployment options with a physical or virtual (FortiWeb-VM) appliance, and acts either as a reverse/transparent proxy or out-of-band. It is also available on AWS and Azure.

I would advise requesting a PoC test with a learning policy.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user818139 - PeerSpot reviewer
Security Consultant at a tech services company with 11-50 employees
Consultant
Give us built-in security templates, strong threat intelligence, and is AV integrated
Pros and Cons
  • "Also, if you serve files or you accept files with your server, Fortiweb has built-in antivirus. The Fortinet product family also provides good IP intelligence (botnet C&C, etc.)."
  • "Built-in security templates, AV integrated, strong threat intelligence."

    How has it helped my organization?

    With other vendors you need to go through a learning period. With FortiWeb you can just apply a high-security profile and move on. It's very easy to reduce false positives.

    What is most valuable?

    • Built-in security templates
    • AV integrated
    • Strong threat intelligence

    Also, if you serve files or you accept files with your server, Fortiweb has built-in antivirus. The Fortinet product family also provides good IP intelligence (botnet C&C, etc.).

    Requires very little effort to add device to topology or replace existing WAF device with FortiWeb.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    No issues with stability.

    What do I think about the scalability of the solution?

    No issues with scalability.

    How are customer service and technical support?

    Eight out of 10.

    Which solution did I use previously and why did I switch?

    F5, A10, KEMP.

    How was the initial setup?

    It's very easy.

    What other advice do I have?

    Be sure to look at industry reviews, they have good knowledge about threat intelligence.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    Security Consultant at Accenture
    Real User
    It has provided stability to applications. The hardware is not sturdy.

    What is most valuable?

    Application delivery is strong.

    How has it helped my organization?

    It has provided stability to applications.

    What needs improvement?

    The hardware does not measure up. Fortinet does not have sturdy hardware.

    For how long have I used the solution?

    I have been using it for three years.

    Which solution did I use previously and why did I switch?

    My client was using it when we took over operation of the project.

    What's my experience with pricing, setup cost, and licensing?

    The price is not too low and it’s not too high.

    Which other solutions did I evaluate?

    I did not evaluate other options. This product was already implemented.

    What other advice do I have?

    Check the market before implementing it... because I didn’t get the chance to do so.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user389823 - PeerSpot reviewer
    Head of Security at a tech company with 1,001-5,000 employees
    Vendor
    If a customer has a web portal that frequently experiences attacks, FortiWeb blocks all negative traffic.

    What is most valuable?

    • SSL offloading
    • Unlimited number of protected servers
    • Load balancing

    How has it helped my organization?

    If a customer has a web portal that frequently experiences attacks, FortiWeb blocks all negative traffic.

    What needs improvement?

    It would be great if FortiWeb could provide web forms like Microsoft TMG. (For example, OWA Exchange portal or SharePoint portal.) Many of our customers are looking forward to this functionality.

    For how long have I used the solution?

    I don’t use it, but as a partner of Fortinet, I implement it at customers’ sites. Our customers have been using it for about two years.

    What do I think about the stability of the solution?

    One of our customers recently experienced a stability problem. The customer has two FortiWeb appliances in an HA cluster (A-P). Something happened and both FortiWeb units became MASTER. Only a reboot of one of the units helped them. We opened a ticket.

    What do I think about the scalability of the solution?

    I have not encountered any scalability issues.

    How are customer service and technical support?

    Sometimes technical support is very slow, but sometimes they work very fast. So I will rate it 5/10.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    Initial setup is not very complex. But if we have problems with configuration, we ask support.

    What's my experience with pricing, setup cost, and licensing?

    We always recommend the full bundle, but sometimes we offer a budget-conscious solution for the customer.

    Which other solutions did I evaluate?

    Before choosing this product, I did not evaluate other options.

    What other advice do I have?

    Look at the PRICE and the PERFORMANCE.

    Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a Fortinet partner.
    PeerSpot user
    Buyer's Guide
    Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2025
    Buyer's Guide
    Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.