Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Senior Information Security Engineer with 1,001-5,000 employees
Vendor
Aug 31, 2016
With Layer 7 server load balancing, it makes decisions based on the content of messages. It also can offload slow connections from the upstream servers.

What is most valuable?

  • Web services signature: Helped us on secure key exchange, authentication and integrity of the transmissions.
  • Virtual patching: We publish many web services through FortiWeb. We are able to quickly resolve vulnerabilities.
  • Layer 7 server load balancing: The device made smart decisions based on the content of messages. Also, with compression and encryption, it can offload slow connections from the upstream servers. That greatly improved performance.
  • Zero-day protection
  • Advance correlation
  • URL rewriting and content rewriting

How has it helped my organization?

Before FortiWeb deployment, we were using a combination of commercial and open-source products. It was a hassle for the administrators, due to which some areas were unintentionally overlooked and caused many problems. With FortiWeb, we got a one-box solution for internet and internet security, which reduced the time required of the administrators and improved visibility at the larger scale.

What needs improvement?

Usually patches and version upgrades are really buggy, so we usually wait about one month for a stable release to upgrade. They need to improve the new version/patch delivery mechanism. For example, if a patch fixes one functionality for web services but also causes some other functionality failure.

For how long have I used the solution?

I have been using it since 2014.

Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.

What do I think about the stability of the solution?

In the first few months, we had some issues but with a custom patch, we are good.

What do I think about the scalability of the solution?

No scalability problems so far.

How are customer service and support?

I rate technical support 8.5/10.

Which solution did I use previously and why did I switch?

We were using combination of solutions, due to our organisation's policies. Due to lack of visibility, administrative issues and response times, we shifted.

How was the initial setup?

We had a complex environment, with multiple offices across the globe with all the data in and out from our HQ.

What's my experience with pricing, setup cost, and licensing?

At the time of deployment, and still now, the price was considerable less than other solutions and varies according to license type.

Which other solutions did I evaluate?

We also evaluated Cisco and McAfee.

What other advice do I have?

It is a great product, but be careful with version upgrades.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Director with 51-200 employees
Vendor
Top 20
Aug 31, 2016
Other firewalls are just as good, but this product is at a much better price point.

What is most valuable?

We use them for VPN, standard layer 4, web filtering, anti-malware and DLP – they are used as our perimeter firewall solution.

How has it helped my organization?

I would not say it has improved how we function because I think that other leading vendors firewalls are as good. However, I do think that FortiGate can do it at a much better price point than, for example, Cisco ASA or Palo Alto.

What needs improvement?

The CLI could be improved by removing all default syntax from the config. The debugging of crypto VPN is not as informative as other vendors’ firewalls. The GUI is also not as good as some vendors, but overall as a package and considering price, it still provides value for money.

For how long have I used the solution?

I first used the Fortinet solutions in 2005 when it was version 2 & 3; since then, it has matured a lot and is much better. I would definitely recommend it, primarily on value for money. For the newer versions, I have been using 1000C and 300D, with FortiGate VM01 firewalls running a mix of software versions 5.4 and 5.2 for almost two years.

What do I think about the stability of the solution?

I did not encounter any stability issues.

What do I think about the scalability of the solution?

FortiManager is required for scalable managing of multiple devices, but we do not have enough to need that. I think that the logging could be better but for that, FortiAnalyzer is recommended, which we do not have.

How are customer service and technical support?

We have not needed to use Fortinet TAC.

Which solution did I use previously and why did I switch?

This solution replaced some old Juniper ISG firewalls that were EoL; nobody in the company had Juniper SRX experience and the choice was made for Fortinet before I started at the company.

How was the initial setup?

Initial setup for what we need to use it is very straightforward. There are certain features (such as TACACS) where you need to use CLI, but most things can be done with the GUI.

What's my experience with pricing, setup cost, and licensing?

Very competitive; Fortinet would always be an option for a perimeter firewall for me if I were needing new kit. I would always include it in any quotes and options, although depending on the requirements, I might decide to choose something else.

Which other solutions did I evaluate?

I have used firewalls that I find easier to manage, configure and troubleshoot. However, the Fortinet firewalls are pretty good, and in terms of value for money, they are outstanding.

Pros: Cost for performance, very feature rich, GUI is pretty good.

Cons: Debugging is not as good as I find Cisco ASA. CLI is overly complicated by all syntax showing in the configuration. The GUI is not as nice as CheckPoint or Palo Alto.

What other advice do I have?

Evaluate the product first and compare it to what you are used to and what you want. It provides very good value for money, but if the budget were there, I would probably choose another vendor in certain circumstances.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
PeerSpot user
Senior Analyst at a financial services firm with 1,001-5,000 employees
Real User
Aug 30, 2016
20 Gbps appliance throughput makes it useful for large enterprise deployment and also meets future requirements. Product support is a major concern.

What is most valuable?

In my opinion, the following features of FortiWeb 4000E are the most valuable & were appreciated during all my previous engagements:

  • 20 Gbps appliance throughput makes it useful for large enterprise deployment and also meets future requirements.
  • Easy integration with various Fortinet products such as FortiSandbox for APT detection.
  • ASIC (Application Specific Integrated Circuit) provides quick SSL offloading and doesn’t choke the user requests.

How has it helped my organization?

  • Operations overhead (administration and escalation management) has been brought down, as Fortinet provides flexible and customizable reporting options with the FortiAnalyzer appliance for logging and reporting.
  • Rule creation and fine tuning are easy, as compared to its competitors.
  • Product has provided adequate assurance to organization’s PCI DSS program.

What needs improvement?

Product support is a major concern; if FortiWeb wants to become a market leader, then it must provide better after-sales services.

The automatic policy learning feature also needs some improvement, as using this feature leads to more false positives.

Integration with other cloud-based DDoS protection services such as CloudFlare, Arbor, Akamai, etc., is also a limitation.

For how long have I used the solution?

It’s been almost one year since we started using this solution.

What do I think about the scalability of the solution?

The FortiWeb 4000E appliance comes with 20 Gbps throughput, 2X2 TB HDD and unlimited licensing. (Yes, you got it correct.) This adds value to the organization and meets its current and future requirements.

How are customer service and technical support?

As I wrote in my previous comments, FortiWeb needs to invest and improve its tech support services due to limited skills in market. Critical- and high-severity issues usually take more time for resolution.

Which solution did I use previously and why did I switch?

We were using Imperva as our WAF solution, which is also a market leader (as per Gartner Magic Quadrant) and provides lots of flexibility and cloud integration options. However, due to high cost, the organization decided to switch to Fortinet Fortiweb.

How was the initial setup?

Selecting the appropriate deployment topology is a major task. Initial configuration settings are little difficult to implement but overall management is easy.

FortiWeb provides a wide variety of deployment options such as

  • Reverse proxy
  • Inline transparent
  • True transparent proxy
  • Offline sniffing
  • WCCP (Web Cache Communication Protocol)

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are USP of this solution; deploying an appliance provides in-house control and flexibility. A dedicated 4000E appliance is appropriate for large enterprises, while Fortinet also provides a VM-based solution, which is perfect for small and medium enterprises.

Which other solutions did I evaluate?

We did PoCs for other WAF products such as Citrix, F5 and Barracuda before finalizing on FortiWeb for our enterprise, which satisfied enterprise requirements.

What other advice do I have?

Thorough review of architecture is required. It’s recommended to get it deployed by authorized FortiWeb vendors. Attention to the rules is a must. Otherwise, it might lead to lots of false positives.

Fortinet WAF can also be integrated with SIEM, which could be beneficial for centralized monitoring.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2379189 - PeerSpot reviewer
Manager at a manufacturing company with 201-500 employees
Real User
Top 20
Jun 5, 2024
Transparent, easy to use, and integrates well with the existing security infrastructure
Pros and Cons
  • "The solution is transparent and smooth."
  • "The price is a little higher than the competitors."

What is our primary use case?

We use the solution in our headquarters. We have some agents outside our company.

What is most valuable?

The solution is transparent and smooth. So far, the tool has integrated well with our existing security infrastructure.

What needs improvement?

The price is a little higher than the competitors.

For how long have I used the solution?

I have been using the solution for more than five years.

How are customer service and support?

The technical support team is okay.

What about the implementation team?

We have a consultant who gives us advice about the implementation.

What other advice do I have?

Overall, I rate the product a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Md. Al Imran Chowdhury - PeerSpot reviewer
Cyber Security Analyst at a tech consulting company with 501-1,000 employees
Real User
Top 5Leaderboard
Oct 14, 2023
An useer-friendly solution with easy configuration
Pros and Cons
  • "The tool's HTTP traffic, website fixing, and blocking are fantastic. It is user-friendly with easy configuration."
  • "FortiWeb Web Application Firewall needs to improve its performance."

What is most valuable?

The tool's HTTP traffic, website fixing, and blocking are fantastic. It is user-friendly with easy configuration. 

What needs improvement?

FortiWeb Web Application Firewall needs to improve its performance. 

What do I think about the scalability of the solution?

FortiWeb Web Application Firewall is scalable. 

How are customer service and support?

The tool's tech support is good. 

How was the initial setup?

The tool's installation is straightforward. 

What's my experience with pricing, setup cost, and licensing?

FortiWeb Web Application Firewall is not expensive. 

What other advice do I have?

I rate the solution an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Oche Eluma - PeerSpot reviewer
Network Security Architect at a tech services company with 51-200 employees
Real User
Sep 28, 2023
Helps us to view all of our logs on one platform
Pros and Cons
  • "The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature."
  • "The technical support team is bad."

What is our primary use case?

I have a multi-cloud environment. I have a production workload in Nigeria, with some data centers in Continental Europe and in the East US in multiple regions.

We have two different public clouds, AWS and Azure. Because of how Fortinet works, we connect to our customers via a remote access VPN.

What is most valuable?

The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature. 

Emails can be configured, and text messages can be sent via the mobile app. 

It is a cheap solution. 

What needs improvement?

The user interface can be improved. Also, there are authentication failures that need improvement in the next release. 

For how long have I used the solution?


How are customer service and support?

The technical support team is bad. 

How would you rate customer service and support?

Neutral

What other advice do I have?

I would rate the overall solution a eight out of ten due to the support and user interface issues. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1495404 - PeerSpot reviewer
Jefe de Venta Especialista de Seguridad Informatica at a tech services company with 51-200 employees
Real User
Feb 20, 2021
Stable and the support in Peru is good
Pros and Cons
  • "FortiGate is a stable product."
  • "We have had problems with deployments where we've had to contact technical support to resolve them."

What is our primary use case?

We are a solution provider and I work in the sales team. We resell the Fortinet brand, including the firewall and other solutions.

I have experience with both using and configuration of Fortinet products.

What needs improvement?

We have had problems with deployments where we've had to contact technical support to resolve them.

For how long have I used the solution?

I have been working with Fortinet FortiWeb for five or six years.

What do I think about the stability of the solution?

FortiGate is a stable product.

How are customer service and technical support?

I have a good relationship with the support teams in Peru, and we are well-supported.

We have not needed support to assist with deployment, but we have worked with them for troubleshooting problems.

Which solution did I use previously and why did I switch?

I am familiar with solutions from other vendors, but the majority of my knowledge is of Fortinet products.

How was the initial setup?

We have not had any problems with deployment.

What about the implementation team?

We have a network team that deploys this solution for different clients. We have three engineers in charge of deployment and maintenance.

What other advice do I have?

I would rate this solution a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2588226 - PeerSpot reviewer
Senior Software Engineer at a outsourcing company with 51-200 employees
Real User
Top 20
Nov 15, 2024
Efficient threat prevention and reporting with strong ROI
Pros and Cons
  • "The reporting and token system is good."
  • "I see no room for improvement at the moment."

What is our primary use case?

We are studying ClearPass as a solution. I was requesting a comparison between Aruba ClearPass and FortiWeb Forti.

How has it helped my organization?

FortiWeb has been a helpful investment in our network.

What is most valuable?

The reporting and token system is good. The AI machine learning was qualified to block and report any suspicious activity.

What needs improvement?

I see no room for improvement at the moment.

For how long have I used the solution?

I have been familiar with FortiWeb for about three years now.

How are customer service and support?

The technical support is very helpful. I rate their technical support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I only worked with similar solutions as a POC.

How was the initial setup?

The initial setup was easy.

What was our ROI?

FortiWeb has been a good investment, helping our network and providing a return on investment.

What's my experience with pricing, setup cost, and licensing?

The pricing of Fortinet FortiWeb is affordable and competitive.

What other advice do I have?

I recommend FortiWeb to others. I wish there were more integration with Azure systems.

I'd rate the solution ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.