- Firewall policy
IT Admin at a comms service provider with 1,001-5,000 employees
I set it up on my own. I'd like to see improvements in its internet and servers features.
What is most valuable?
What needs improvement?
- Internet
- Servers
For how long have I used the solution?
I have used it for a year and a half.
What do I think about the stability of the solution?
We had one stability issue when I ran it once with Wireshark; it froze.
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I have not encountered any scalability issues.
How are customer service and support?
I cannot rate technical support because I have not used it yet.
Which solution did I use previously and why did I switch?
How was the initial setup?
Initial setup was not that difficult. It was different to my previous solution; I could do it on my own.
Which other solutions did I evaluate?
Before choosing this product, I did not evaluate other options.
What other advice do I have?
- Be aware of logs.
- Does not compare with Check Point about finding policies.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Expert at a financial services firm with 501-1,000 employees
It helps us protect our web and database servers from being penetrated from outside the office.
What is most valuable?
The most valuable features of the product are its IPS and VPN server.
How has it helped my organization?
The device is very handy and it helps us to protect our web and database servers from being penetrated from outside the office.
What needs improvement?
The antivirus and the IPS can be improved in the future.
For how long have I used the solution?
I have used it for about two years.
What do I think about the stability of the solution?
Fortunately, we have not yet encountered any stability issues!
What do I think about the scalability of the solution?
With the 600-C model, we had some scalability issues.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
Initial setup was very straightforward and simple.
What's my experience with pricing, setup cost, and licensing?
These devices, especially the 1500-D model, are really worth purchasing and using.
Which other solutions did I evaluate?
Before choosing this product, we evaluated many products such as Cisco, Juniper, Cyberoam, and Sophos.
What other advice do I have?
In my opinion, the FortiGate appliances, and especially the D series, are really powerful ones and worth providing for your network.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
Security Expert at a tech services company
Next-gen firewall and built-in server load balancing. A BYOD feature is missing.
What is most valuable?
- UTM
- Ease of use
- Built-in server load balancing
- VPN
- Next-gen firewall features
How has it helped my organization?
It provides good security visibility.
What needs improvement?
A BYOD feature is missing; this could be a good add-on.
For how long have I used the solution?
I have used it for about 18 months.
What do I think about the stability of the solution?
I did not really encounter any stability issues; it performs well.
What do I think about the scalability of the solution?
I have not encountered any scalability issues in 18 months.
How are customer service and technical support?
Technical support is average; it could improve.
Which solution did I use previously and why did I switch?
We previously used Cisco PIX and ASA. We switched because there is no next-gen firewall in the Cisco portfolio.
How was the initial setup?
Initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Pricing is competitive. Licensing could get expensive as we add feature sets.
Which other solutions did I evaluate?
Before choosing this product, we evaluated Palo Alto, SonicWALL and Juniper.
What other advice do I have?
It is a good option, keeping in mind pricing and features.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at a local government with 501-1,000 employees
It’s an all-in-one solution that gives more Wi-Fi control capability.
What is most valuable?
- Routing
- Web filtering
- Wi-Fi control
How has it helped my organization?
It’s an all-in-one solution that lowers the cost of having multiple solutions. It gave us more Wi-Fi control capability.
What needs improvement?
- Logging
For how long have I used the solution?
We have been using this model for one year. We previously implemented earlier models for six years.
What do I think about the stability of the solution?
We have encountered very few stability problems. In six years, we had one device that need to be shipped back to Fortinet. We had HA set up at that location, so there was no down time.
We did not have a problem upgrading their firmware updates.
What do I think about the scalability of the solution?
Yes and no; you have to size it right before buying. The hardware on some models is not expandable, but you can easily turn software add-ons on and off.
How are customer service and technical support?
I’ll give them an 8/10 for technical support.
Which solution did I use previously and why did I switch?
We had a Cisco router and a Barracuda. We switched from that to a FortiGatefirewall and the Cisco Router. Finally, when the Cisco router was going bad, we replaced it with a FortiGate 100 for firewall and routing capability.
How was the initial setup?
Initial setup complexity depends on the network. The admin console is easy to use.
What's my experience with pricing, setup cost, and licensing?
They have options for their licensing. Look at what you are going to use it for and purchase that way.
Which other solutions did I evaluate?
Before choosing this product, we did not evaluate other options. We had one of the smaller firewalls, and we upgraded to one of their bigger ones.
What other advice do I have?
Look at sizing. And if you are a 24/7/365 shop, get two for HA.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Support Engineer at a consumer goods company with 51-200 employees
You can set QoS according to application priority.
Valuable Features
- Security profiles with application control & web filtering. You can filter which applications are allowed or blocked inside your network, according to the port they are using. Web filtering - which can be applied to Skype for example, prevent botnets, and P2P - also is very helpful when you want to control what is allowed inside the network.
- QoS. You can set QoS according to application priority.
- Antivirus from end to end
- Remote and site-to-site VPN
Improvements to My Organization
We have minimized our expenses for internet security/antivirus in host-side products such as FortiClient installation, which has antimalware/web security/antivirus and protects the host from vulnerabilities while connected to the server.
Room for Improvement
I would like to see support for throughput up to 10 gbps and WAN support. Depending on your device’s design, I’d like to see throughput support up to 2 mbps for SSL, 3 mbps for IPS, and 1.5 mbps for applications. This might already be offered with newer versions.
I haven't used the latest release of device. From my current device perspective, reporting is good, but I want to see, in the future releases if they haven't done yet, is the total traffic alert (highest peak) that could receive on mobile or email. This is very helpful if you could set in required interval to monitor the total traffic that could feel the traffic in your hands.
Use of Solution
I have used it for five years.
Stability Issues
No issues encountered.
Scalability Issues
No issues encountered.
Customer Service and Technical Support
I rate the level of technical support 9/10.
Initial Setup
It was straightforward for minimal configuration and requirements, CLI for complex configuration.
Pricing, Setup Cost and Licensing
Pricing and licensing is good and it depends on what the business solution requires.
Other Advice
FortiNet shows me the health of the entire network. Evaluate how you would use FortiNet UTM. Look for the solution which fits your business infrastructure requirements such as VPNs, firewalls, application and web filtering, throughput, and most of all, which device which gives you the best performance.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Developer, Project Manager at a tech services company with 10,001+ employees
It makes our web site system work nice and smooth. The UI is a little complicated for new users.
What is most valuable?
- Firewall
- Load balancing
How has it helped my organization?
It makes our web site system work nice and smooth.
What needs improvement?
The UI is a little complicated for new users.
For how long have I used the solution?
I have been using it for over a year.
What do I think about the stability of the solution?
I have not yet encountered any stability issues.
What do I think about the scalability of the solution?
I have not yet encountered any scalability issues.
How are customer service and technical support?
I have even contacted technical support once.
Which solution did I use previously and why did I switch?
My web site used MS NLB service for load balancing and IPS firewall at first, but when our site's connection grew bigger, we discovered that we needed another solution. We chose FortiWeb after a little research into the market.
How was the initial setup?
Initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
The pricing is a little high.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineer at a financial services firm with 1,001-5,000 employees
At first, it helped us publish e-banking services, but we soon discovered it was an easy way to deploy other internal websites in an intranet style.
What is most valuable?
- FortiAnalyzer (SIEM) integration is useful for us because we collect in this device almost all the security events from the network. We are using exact URL (no default page, no home page) for our e-banking services for enterprises. Then we give a simple way to access the service to our customers using URL rewrite and redirect.
- Rewrite
- Redirect
- Proxy reverse mode
How has it helped my organization?
It helped us initially publish e-banking services, but after a few months, we discovered it was an easy way to deploy other internal websites, published in an intranet style.
What needs improvement?
I think Fortinet must make an effort in terms of upgrade procedures. There were some troubles upgrading from 5.2.x to 5.3.x, and the problem appeared again upgrading from 5.3.x to 5.5.x:
- Upgrading from 5.2.x to 5.3.x. Fortinet provides a script, but it doesn't work (they do not say anything about it). In some cases:
- If you are using the subnet 192.168.1.x in any interface, it assigns this network for management, which means it can't apply the configuration.
- If you use LDAP authentication, the new field "realm" appears empty, the configuration doesn't work, and you have to manually change it.
- Upgrading from 5.3.x to 5.5.x:
- Some changes are introduced, then it requires fully formatting the device and configuring it manually (copy/paste pieces of configuration).
- Once again, if you are using the subnet 192.168.1.x in any interface, it assigns this network for management, which means it can't apply the configuration.
For how long have I used the solution?
I have used it for three years.
What do I think about the stability of the solution?
It really is a powerful WAF; more than one year running with no stability issues.
What do I think about the scalability of the solution?
We did not have to scale our web servers; we just added new servers without any issue.
How are customer service and technical support?
The support is good, but they need more experts, because sometimes they take too much time to provide solutions.
Which solution did I use previously and why did I switch?
Fortinet was the first brand we thought about, because we had been using FortiGate for a few years, and we thought they had some common architecture.
How was the initial setup?
The initial setup was very easy. We use the proxy reverse schema; I think it is the best for almost all situations. The last firmware 5.5.x permits customers to deploy in different configurations in the same box.
What's my experience with pricing, setup cost, and licensing?
I think FortiWeb is the best WAF in terms of cost/benefit. Licensing is similar to other Fortinet products; 100% clear with no surprises.
Which other solutions did I evaluate?
For new projects this year, we evaluated Imperva and Barracuda. The latter can be a good option for entry-level deployments, but is hard to surpass Fortinet products.
What other advice do I have?
I advise being careful with the upgrade procedures. Also, it is a good idea to use Fortinet for a 60-day trial. That way, you can do a lot of testing on your own before deploying it. Using the VM (virtual machine) you can save a lot of time, can do proofs of concept and avoid opening tickets asking basics questions.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Leader at a government
It has helped us prevent exploitation of vulnerabilities while we are working on code. Signatures are basic and prone to firing false positives.
What is most valuable?
- It supports OWASP top 10.
As you can see, the attack types are mapped to OWASP top 10. The policy creation always follows the procedure:
- Create first the objects needed.
- Assemble the policy.

- The GUI interface is intuitive. I have never needed to use the CLI
- It has good reports.It is easy to manage.
How has it helped my organization?
The portal has a lot of vulnerabilities, which are not easy to solve quickly. The device has helped us to prevent exploitation of them while we are working on the code.
What needs improvement?
The signatures are very basic and prone to firing false positives. For example, FortiWeb detects this string as an attack because it detects "perl" in it:
User-Agent: Mozilla/5.0 (compatible; PaperLiBot/2.1; https://support.paper.li/entries/20023257-what-is-paper-li)
This is a false positive. If the signature was more complex, that would not occur.
For how long have I used the solution?
I have been using it for four years.
What do I think about the stability of the solution?
I have not encountered any stability issues, but it always consumes a lot of memory.
How are customer service and technical support?
Technical support is 7/10. We had a pair of cases without solution; one URL-rewriting related and another one Lync Enterprise-related. In both cases, we had to search for alternate solutions.
Which solution did I use previously and why did I switch?
ISA Server was working as a reverse proxy, but it lacks web attack prevention. Also, because the platform is dedicated and the OS is hardened.
How was the initial setup?
It has an auto-learn module that makes it easy to establish the first policy, after which you can customize it. It is straightforward to configure the FortiWeb. We have encountered that it is especially difficult to work with URL rewriting, because of regular expressions.
What's my experience with pricing, setup cost, and licensing?
Price and licensing is fine; it is one of the cheapest solutions and does its job.
Which other solutions did I evaluate?
We also evaluated F5 and Imperva. Fortinet won because of its price. It has done its work for the last four years; the only problem that I have seen is the high false-positives rate which prevents us from focusing on the real attacks.
What other advice do I have?
It has a good quality/price relationship. The web vulnerability scan module is useless.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
NetScaler
AWS WAF
Cloudflare Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Check Point CloudGuard WAF
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?














This review seems to apply to Fortinet's Fortigate firewalls instead of Fortiweb (Web Application Firewall).