Try our new research platform with insights from 80,000+ expert users
Blair Griffith-Barwell - PeerSpot reviewer
Principal Network Architect at a financial services firm with 201-500 employees
Real User
Top 10
Feb 23, 2023
It comes with several preconfigured rule sets and templates that make deploying new applications easier
Pros and Cons
  • "FortiWeb's ease of deployment is what we liked the most about it. Implementing FortiWeb was extremely fast and easy, which was a significant advantage. It comes with several preconfigured rule sets and templates."
  • "Another area for improvement is logging. When troubleshooting, the logs sometimes take a while to update. We've had people report that some things aren't logged if they're successful. It's a bit hit-and-miss. For example, sometimes people access one of our services, and it's successful, but we don't see that in the logs."

What is our primary use case?

We are a payment processor with infrastructure deployed across various environments, including AWS, on-prem, and various other environments. We are PCI Level One certified, and one of our requirements is WAF. FortiWeb is a tool we use to secure access to our public-facing applications and services.

Our environment is primarily cloud-based, and all of our services are AWS. We were in the process of migrating to the cloud when we implemented FortiWeb, but we still needed to maintain some on-premise infrastructure to serve different regions. We were happy with the solution after deploying it in the cloud, so we discussed the possibility of also using it with our on-premise applications based on the initial results. Many of those services are now moving to the cloud, so we won't deploy them on-premise anymore. 

We are using FortiWeb across multiple locations in London and Singapore, so we have WAF services sitting in front of applications across both sites. Our applications include various payment processing platforms, fraud prevention tools, and other related customer-facing services based in various locations within the AWS cloud.

A ten-person network team is responsible for administering FortiWeb. It's difficult to say precisely how many end-users there are because we provide this solution to third parties, but around 160 clients connect to the applications behind these services. Our clients are typically small or medium-sized enterprises.

How has it helped my organization?

FortiWeb provides an additional layer of security that we didn't have previously. We have a next-generation firewall deployed in our cloud infrastructure, but the WAF is the most external-facing piece. The WAF passes traffic to our internal next-generation firewalls.

We have also benefited from FortiWeb's load-balancing capabilities. FortiWeb enables us to load-balance without the need to take on an additional service. In most cases, we've been able to use load balancing provided by the AWS gateway. We have two servers with services deployed across multiple availability zones behind there. In addition to security, WAF allows us to load balance traffic across those servers in various availability zones without adding more load balancers.

FortiWeb streamlines tasks because we've eliminated other functions like load balancing. The API is also excellent. Someone on my team created an application that integrates with the API to quickly add new IP addresses without changing the templates. We've found it's helped us streamline some of our usual BAU tasks.

We already had a low false positive rate, but FortiWeb has lowered it further. Detections in our report tend to be accurate. We still get occasional false positives, but some of that probably relates to our custom-built applications. FortiWeb decreased our false positives by around 30 percent. 

We used to get a lot of alerts from our traditional firewall, but the number has declined significantly since deploying FortiWeb. It was a reduction of about 70 to 80 percent. The alerts coming from FortiWeb are helpful. They inform us of things that require action. We previously got many alerts from our public-facing services. We didn't have an efficient means of getting alerts. The same threat provided multiple alerts. That would keep going and could be overwhelming at times.

What is most valuable?

FortiWeb's ease of deployment is what we liked the most about it. Implementing FortiWeb was extremely fast and easy, which was a significant advantage. It comes with several preconfigured rule sets and templates. 

FortiWeb effectively addressed unknown threats. We get regular reports that we check. So far, we've had no issues at all. Around 99 percent of our public-facing infrastructure is restricted by source IP to our partners' networks, so our attack surface is restricted. WAF picked up and blocked any attacks before they can impact us. 

FortiWeb is effortless to use and manage. The documentation is excellent, which is another huge advantage. The layout is logical and intuitive. You can create templates and reapply them to new applications, so we don't need to do a fresh configuration for each application. We have a template that represents our security benchmark. There are a few exceptions that we need to add for each application, but we can redeploy the security benchmark template for each new application that we create.

What needs improvement?

One area that needs improvement is using IP addresses within templates. If you allow an IP address to access an application, you should be able to leave a description of that. For example, we allow clients to access these services, and some are restricted to the IP address. When you add an IP, there's no way within the product to say what the IP address is. 

We need to maintain a separate external list because we need to remove any IP address associated with a client if they stop using our services. In many other products, you can create an object specifying that this IP address is for a client of this name or this service. You don't have this ability within FortiWeb. 

Another area for improvement is logging. When troubleshooting, the logs sometimes take a while to update. We've had people report that some things aren't logged if they're successful. It's a bit hit-and-miss. For example, sometimes people access one of our services, and it's successful, but we don't see that in the logs. 

Buyer's Guide
Fortinet FortiWeb
January 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,455 professionals have used our research since 2012.

For how long have I used the solution?

I've been using FortiWeb for around 18 months. 

What do I think about the stability of the solution?

FortiWeb is highly stable. I can't recall an instance when we've had any issues. Our services are used constantly. For example, we have a fraud prevention tool that various banks and FinTech companies access, and FortiWeb is deployed behind it. We've never had a problem with availability due to FortiWeb. The solution is 100 percent stable and available. 

What do I think about the scalability of the solution?

I'm satisfied with FortiWeb's scalability. It's always met the needs of our applications. We can deploy it in any application that we want to deploy behind. 

How are customer service and support?

I rate Fortinet support an eight out of ten. The technical support has gotten better. There were a few difficulties when we first raised some calls. It was a new product, and we weren't getting clarity on whether some of the actions we asked about were possible. Initially, the response was also a bit slow. We chalked that up to the fact that we were early adopters of the product. The support has improved since then, and we're happy with it today. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We didn't have a WAF solution, but we used Palo Alto Networks Next-Generation Firewalls. While these firewalls had many WAF capabilities, they weren't considered WAF products. 

Our main reason for deploying a WAF solution was to satisfy regulatory requirements. To get a PCI Level One certification, we need a WAF on some of these public-facing services. FortiWeb Cloud ticked all the boxes and met our requirements.

How was the initial setup?

I initially deployed a lot of the applications. It was so quick and easy. FortiWeb took about a week to deploy, including assessment and testing. We had to create a new environment. Much of our on-premise infrastructure was closed off in the past, so we required no WAF for regulatory compliance. 

To create this new environment, we onboarded some new services that were classified within the scope of PCI. They were deployed in the old way with firewalls. However, our QSA said we needed to have services behind the WAF, and we were being assessed in a week. We had to find and deploy a WAF before we were audited. 

I have a team, but I and one other engineer were involved in the deployment. After the setup, FortiWeb requires minimal maintenance, which is one aspect we like about it. We've occasionally had to open a support ticket for the odd bug that's come up. There's typically no maintenance on our end. I can't think of a time when we've had issues with availability from FortiWeb. 

What was our ROI?

It's hard to calculate an ROI monetarily.  Some of the services we provide based on FortiWeb are charged to the clients. I can't say much about it from that perspective. However, we've seen benefits from a time and resource perspective. Also, having a cloud-based WAF means we don't need to maintain the infrastructure, and we can quickly deploy new applications. We derive a massive value from the reusable templates. 

We also save money and resources because we don't need to deploy more EC2 instances or use additional products for load balancing and other functions. That's potentially an 80 percent reduction in those costs.  

What's my experience with pricing, setup cost, and licensing?

FortiWeb is transparent about how much each application costs. When you create an application, it will tell you the estimated cost. The licensing is clear, so we can see that we're getting a good value. 

We're satisfied with the price. Our organization sometimes questions if we're getting our money's worth, but we get a decent value from FortiWeb for the price. Everyone on our team and within the infrastructure area is happy with it.

Which other solutions did I evaluate?

I'm the network team lead, so I assessed and deployed FortiWeb. I looked at several options. I knew the Fortinet brand but was unfamiliar with FortiWeb WAF. After researching it, I recognized that it was potentially a product that we could use. I did a demo and found that it ticked all the boxes.

What other advice do I have?

I rate Fortinet FortiWeb a nine out of ten. I would definitely recommend the solution. FortiWeb is rich in security features and additional features like load balancing. It's one of the best products we use. 

It's easy and quick to deploy. The documentation is excellent. We are pleased with the product and see it as an integral part of deploying new applications in the cloud or on-premises efficiently.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Rio Wijaya Manalu - PeerSpot reviewer
Technical consultant at a retailer with 1-10 employees
Reseller
Top 5Leaderboard
Aug 12, 2024
Helpful to inspect traffic before a platform faces the internet
Pros and Cons
  • "Before a platform faces the internet, Fortinet FortiWeb inspects the traffic."
  • "The tool's WAF or web application firewall area has certain aspects that can be improved."

What is our primary use case?

Fortinet FortiWeb's use case is associated with WAF or web application firewall. Before a platform faces the internet, Fortinet FortiWeb inspects the traffic.

What is most valuable?

Fortinet FortiWeb is much cheaper compared to other solutions like the ones from F5 Networks, which have more capabilities. I think Fortinet FortiWeb is not as capable as F5 Networks, but it is cheaper. The key point for Fortinet FortiWeb is that when I give it to the customers, I see it is cheaper than F5 Networks.

All the players in the market are already using AI. In the AI area, I don't find any specific feature for Fortinet FortiWeb that is special compared to the other products in the market.

Fortinet FortiWeb's ML features are good, but they do not make the tool any special because all the products in the market, like F5 Networks, already use AI features. The AI feature does not make Fortinet FortiWeb any special.

What needs improvement?

The tool's WAF or web application firewall area has certain aspects that can be improved. I cannot find what features superficially can be improved in the WAF area of the tool.

Fortinet FortiWeb can be applicable for small or big networks. In my opinion, Fortinet FortiWeb can manage or improve its log management capabilities. As far as I know, FortiGate has a limit, which means it can be used for logging for seven days, and maybe it is because Fortinet wants to speed up the selling of another product called FortiAnalyzer. FortiAnalyzer is a device dedicated to logging analytic solutions. Fortinet may limit the capability of logging in Fortinet devices so that customers buy FortiAnalyzer for log analytics.

For how long have I used the solution?

I have been using Fortinet FortiWeb for three years. My company is a reseller of the solution.

What do I think about the scalability of the solution?

I don't know about the tool's scalability.

How are customer service and support?

I rate the technical support a nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I also use FortiAuthenticator.

How was the initial setup?

The product's initial setup phase can be somewhat complex depending on what software needs to be protected by Fortinet FortiWeb. If the web application is simple, the configuration can be made simple. If there is any specific need to protect the area in the web application, it is more tricky to configure Fortinet FortiWeb. It depends on what kind of web application needs to be protected by Fortinet FortiWeb. Overall, the tool's configuration is neither easy nor difficult.

What's my experience with pricing, setup cost, and licensing?

If one is cheap and ten is expensive, I rate the tool an eight.

What other advice do I have?

The product's document says that Forinet FortiWeb can detect zero-day attacks, but it needs more devices like FortiSandbox for help. Fortinet FortiWeb needs to be integrated with FortiSandbox. I think it is Fortinet's strategy to upsell other tools because Fortinet doesn't want to put the solution in one box or one device. If you want another feature, Fortinet wants you to buy another box.

I rate the tool an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
January 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,455 professionals have used our research since 2012.
Martin Ellmann - PeerSpot reviewer
Chief Executive Officer at a tech services company with 11-50 employees
Real User
Top 5
Aug 19, 2024
Provides users with ease of policy configuration and good integration capabilities
Pros and Cons
  • "The product's initial setup phase was easy."
  • "The tool's price and performance are areas of concern where improvements are required."

What is our primary use case?

I use the solution in my company to make web applications more secure because we have a special portal or web interface that we have to make secure for cybersecurity and different accesses. We found that FortiWeb Web Application Firewall (WAF) works fine for such use cases.

What is most valuable?

The tool's most valuable feature is the web access it offers. We control every access, like who goes in and what they do.

What needs improvement?

The tool's price and performance are areas of concern where improvements are required.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for three years.

What do I think about the stability of the solution?

It is a 100 percent stable solution. Stability-wise, I rate the solution a ten out of ten.

What do I think about the scalability of the solution?

My company has three customers using the tool. One of the customers has 1,00,000 users.

How are customer service and support?

My company manages the technical support with around four people, so it is not a complex process for us to handle. In general, the tool's support team is friendly.

How was the initial setup?

The product's initial setup phase was easy.

The solution's deployment needs a bit of time because we have to discuss it with the deployment team, which consists of software. The project keeps growing and changing daily, so if the people involved in the deployment make new software, we have to change something. It is an easy process and can be managed in around two weeks by one person.

What's my experience with pricing, setup cost, and licensing?

The tool is really expensive. In our company, we could do a lot more, but the price is always a point covering areas like why we need one, whether it is important to discuss, why it is so expensive and so on.

Speaking about the licensing model, people need to opt for a subscription-based model. My company likes to have a subscription for at least three or five years because, otherwise, you have to renew the license. Managing the licensing part for one person can also be very complex.

What other advice do I have?

The solution helps protect our company's web applications against common threats up to 99 percent. We feel very safe with the tool.

Speaking about how the tool has effectively mitigated web security threats for an application, I would say that it is an application behind the web portal, so there are about a hundred or thousand people who can access a website. If it is a sensitive application, and we have to watch every access to it to make it really safe, that is the reason why we need WAF on the application.

My company doesn't use AI with the tool.

I recommend the product to others. I would say that others need to have it if they have a shopping website or something similar. I know it is hard to sell because we find it quite hard whenever my company tries to do so.

The solution offers 100 percent integration with other Fortinet security products.

The ease of policy configuration in the tool is okay.

I rate the tool a nine to ten out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
PawanKumar10 - PeerSpot reviewer
Senior Manager at a computer software company with 201-500 employees
Reseller
Mar 13, 2023
A user-friendly solution that features excellent traffic filtering and reduced false positives
Pros and Cons
  • "The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities."
  • "We want to see more detailed logging, such as audit logging, as this would significantly enhance the solution's reporting. We currently get some information from logs, but more would be better."

What is our primary use case?

We use the solution as a web access firewall (WAF) to secure our applications and use URL mapping to ensure only traffic filtered through the WAF is allowed. 

The environment the product is used in is one project in our GCP, and we're located in the Western USA. Two members of the infrastructure team operate FortiWeb within our organization.

How has it helped my organization?

FortiWeb filters a lot of unwanted traffic, which is good for our organization, as it would negatively impact our reputation if this traffic weren't screened.

The solution helps us to streamline tasks as it features a user-friendly console, and we can apply the WAF to all the URLs required for our publicly available applications. The templates offer either advanced or extended protection for those URLs, and we can see insights for specific URLs, such as total hits and how many requests are being blocked and allowed.  

The FortiWeb Cloud also saved our organization time through machine learning, which analyses traffic based on IP origin and geographic region. This is one of the solution's better features and saved us significant time. 

We have seen time to value with the product. After implementation, we let the solution run for a month, then reconfigured a few policies and templates. Within three months, we were getting the desired results.  

What is most valuable?

The policies and the filtering are the most valuable features, especially traffic, URL, and application filtering. The solution is excellent at detecting vulnerabilities. 

The product is great for blocking unknown threats and attacks. We've had excellent results over the past two years, and the way it detects and filters traffic is outstanding.  

The FortiWeb Cloud is straightforward to use; with a basic overview of how to apply policies, create NAT rules, etc., it's easy. The console is user-friendly enough that anyone can create and apply policies. 

The solution also helped reduce our false positives by 20-25%. 

Our organization receives fewer alerts thanks to the solution, and we don't have to think about the security of the URLs for applications. We put the whole domain behind the WAF, and if it's configured correctly from the beginning, we spend minimal time making changes and get the precise results we need. Our alerts have been reduced by approximately 5%.  

What needs improvement?

We want to see more detailed logging, such as audit logging, as this would significantly enhance the solution's reporting. We currently get some information from logs, but more would be better.

For how long have I used the solution?

We've been using the solution for nearly two years. 

What do I think about the stability of the solution?

The solution is very stable. 

What do I think about the scalability of the solution?

The product is scalable; we can easily scale up and down as required. 

How was the initial setup?

I did the initial setup, which was very straightforward; the process includes putting an instance in the cloud and then adding the URLs of the domains to the template. The initial deployment took under two hours, but we needed to spend time reconfiguring the template later to reduce the number of false positives. One staff member can complete the setup, and it only requires basic knowledge.

Outside of updates and the initial reconfiguration, the solution requires minimal maintenance. 

What's my experience with pricing, setup cost, and licensing?

The pricing is average; the product is neither particularly expensive nor affordable. 

Regarding the price-performance ratio, the solution is definitely worth the money.

What other advice do I have?

I rate the tool nine out of ten. 

I advise anyone evaluating the solution to carry out a POC and recommend it overall.

We use the templates available in the Fortinet Web Cloud or WAF, which is sufficient to provide extended protection, traffic filtering, request blocking, and virus detection. 

Fortinet is our only WAF application because we've had excellent experiences with it. If any project requires security checks, we go with the solution.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
reviewer2078280 - PeerSpot reviewer
CTO at a tech services company with 11-50 employees
MSP
Feb 7, 2023
People can run a pen test on our system whenever they like and we'll pass with flying colors
Pros and Cons
  • "When it comes to blocking unknown threats and attacks, I would give it the highest score possible. We first started using AWS and its Web Application Firewalls. That was okay, but it was quite a manual process to keep it up to date, whereas Fortinet is always up to date, and the default rules or the modules that you can turn on are very easy to use."
  • "It would also be helpful if they could introduce easier reporting. It's good to have those reports that go to C-level management, and Fortinet does provide some graphs, but if they went into some more detail, that would be great."

What is our primary use case?

We use it in front of AWS Web Application Firewalls for our web-based management console, as well as for all of our API services for our Windows agents.

How has it helped my organization?

Being a data protection company, we have to meet a lot of specific requirements for customers. When people would say, "Our standard practice is to do a pen test against your outward-facing servers," there was always a little bit of worry in the back of my mind: "Oh, man, is there something that I've forgotten about?" But nowadays, I don't have that at all. I know that it's all configured and running well. I know that people can run a pen test whenever they like and we'll pass with flying colors.

It can take a little bit of time if you want to be very particular about the traffic that you allow. FortiWeb is very configurable and that can take a little bit of time if you do want to be that particular. But apart from that, we don't really touch it much these days except if we get an email to say there's been a node attack. In that case, we might just want to check on things. But in general, once it has been configured, we can forget about that side of things and just get on with all of our other normal tasks.

Machine learning could be a little bit of a buzzword, but that's the whole advantage of using a cloud-based platform. You get the benefits of another site seeing an attack and Fortinet works out if traffic should be filtered or not. It's great all around.

Before this, we had our AWS Web Application Firewalls. The process would be to look at our web servers and see if there was any suspicious-looking traffic that had gotten to those web servers through the AWS firewalls, and then we would adjust the AWS firewalls accordingly to filter that out. We might even have had to write new code to stop things at the server level. FortiWeb has saved us hundreds of hours.

I'm quite particular about what I allow into our network. There were some false positives as we were configuring everything the way that I wanted it, but I can't even remember the last time someone had an issue with a false positive because we had it set too securely. With the machine learning and getting the benefit of traffic that is going to many different sites, Fortinet is able to know which traffic is legit and which isn't. As a result, we get fewer false positives.

Although the number of alerts is not that relevant for us, FortiWeb has definitely reduced the overall stress levels, especially at the management level. It's good to be able to present a report to C-level executives saying, "This is the amount of traffic that we've had coming in, and this is what has been blocked by Fortinet." We're able to show them that it is benefiting the business.

In addition, it has helped free up our infrastructure team, as they don't have to look after the AWS Web Application Firewalls.

What is most valuable?

When it comes to blocking unknown threats and attacks, I would give it the highest score possible. We first started using AWS and its Web Application Firewalls. That was okay, but it was quite a manual process to keep it up to date, whereas Fortinet is always up to date, and the default rules or the modules that you can turn on are very easy to use.

Overall, the solution is extremely easy to use. It's all very step-by-step. We just tell it what DNS records to approve and it sets up an SSL certificate. And then, all traffic just starts flowing through Fortinet and then straight over to us. Our network is quite secure, so we have allowed individual IPs that are listed by Fortinet so that we're not just blanket-accepting everything. It's enabling our web servers to be more secure by only allowing Fortinet, instead of the whole world, like we used to.

Also, if you want to diagnose something, rather than outright blocking it, you can just log it so you can see what's happening.

You can go through the audit trail as well. There might be a situation where it will prompt you to block everyone's traffic from a specific IP.

In terms of FortiWeb's advanced modules, we have two main, different Fortinet applications. One is for our web-based stuff and the other is for our Windows agents, which is all API traffic. We use different sets of the modules, or the advanced features, but across both, we use pretty much everything.

What needs improvement?

At the moment, it's very easy to see if an attack has come in, and what they've done. What I would like to see is that they turn on all logging so that we can even see legitimate traffic. But still, that's a very minimal issue.

It would also be helpful if they could introduce easier reporting. It's good to have those reports that go to C-level management, and Fortinet does provide some graphs, but if they went into some more detail, that would be great. Then I wouldn't have to do it myself.

For how long have I used the solution?

I have been using FortiWeb for two to three years.

What do I think about the stability of the solution?

The stability is a 10 out of 10. We haven't had any issues.

What do I think about the scalability of the solution?

We have thousands of customers that use our platform around the world. All of them go through Fortinet. We also have a few thousand Windows agents that all go through Fortinet. With the load balancing inside Fortinet, we're able to scale up our servers and Fortinet can always handle the traffic.

How are customer service and support?

I haven't had to contact support much. These days, people don't really like contacting support. I have needed to do it on one or two occasions and they have been very helpful. It was by email and I got the answers that I needed straight away.

But the fact that I haven't had to contact support speaks to the ease of use of the system itself.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We just had web servers on the internet and the AWS Web Application Firewalls in front of them. I wasn't happy with those, so I added Fortinet in front of them. We still use AWS, but Fortinet is the first line.

We switched because I'm very paranoid. I'm big on security. Working in IT for many years, Fortinet was always a trusted name in routers, so I thought I'd give the FortiWeb web application firewalls a go and I haven't looked back.

How was the initial setup?

The initial setup was a piece of cake, done step-by-step. We just had to add some DNS entries and that was about it. It tells you exactly what you need to do. I didn't need to contact support or ask for any help.

There were a lot of additional modules that I wanted to check out and that took a little bit of time. But getting a basic setup running was very quick.

There is no maintenance involved.

What was our ROI?

We haven't been hacked. I don't know what price tag you'd put on that.

I'm very security conscious, but at the same time, I can be somewhat cheap and I will only spend money if I think it's worthy or providing the value that it should. At no point have I thought of getting rid of Fortinet.

We saw value from it immediately. We were uncertain about how AWS Web Application Firewalls were protecting us. We weren't that confident, because we couldn't really see what was happening. Management was kind of uneasy as a result. As soon as we had this implemented, we could see the stats and a few graphs. Immediately, that peace of mind was had by all.

What's my experience with pricing, setup cost, and licensing?

The pricing is pretty good. We do pass a lot of traffic through our API servers. Something like 100 gigs of web traffic is a fair amount for reduced JSON API calls, but the cost is $50. For that peace of mind, we have thousands and thousands of customers that are protected by that $50, so it's a no-brainer.

Which other solutions did I evaluate?

I had a look around, but I didn't test anything else. Fortinet was the first one that I did testing with and it met all my criteria, so I figured, "Why waste time looking at some others when this does the job?"

What other advice do I have?

I recommend it to everyone. Because we're a data protection company, we have a lot of people who want to do pen testing against us, and I'm very confident that we're protected because of Fortinet.

If you're looking for a very comprehensive web application firewall, which is both simple to set up and also has a huge number of features to turn on, features that can give you some added protection for specific needs, give Fortinet a go. It's worth your time, and it won't take much time either.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Muhammad-Jahangir - PeerSpot reviewer
Senior Manager Tech Compliance at a financial services firm with 201-500 employees
Real User
Top 10
Nov 17, 2024
Reliable, effective web server protection with room for deployment expertise improvement
Pros and Cons
  • "FortiWeb has antivirus, web filtering, and application control features."
  • "The initial setup depends on familiarity with the product. It's manageable with the right expertise."

What is our primary use case?

The primary use case involves using FortiWeb to protect web servers from various malicious activities by integrating it into a firewall with features like URL filtering and application control. Additionally, it was deployed to meet the requirements of PCI DSS.

How has it helped my organization?

FortiWeb has been helpful in securing our web servers effectively. Fortinet FortiWeb is reliable, providing seamless protection and peace of mind regarding the security of our web applications.

What is most valuable?

FortiWeb has antivirus, web filtering, and application control features. Being part of the next-generation firewall, it's highly effective in ensuring security. The capability to protect from malicious activities is significant, alongside other features like application control.

What needs improvement?

I cannot provide feedback on what needs improvement as I haven't used other solutions to compare it against and therefore cannot identify any areas lacking in FortiWeb. Overall, FortiWeb is reliable.

For how long have I used the solution?

It's been a year since I last used FortiWeb, while I previously configured and used it actively.

What do I think about the stability of the solution?

FortiWeb is reliable in terms of stability. There haven't been specific downtimes or technical issues with FortiWeb.

How are customer service and support?

We haven’t encountered issues necessitating contact with customer service for FortiWeb, implying stable support from Fortinet.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have no experience with other solutions.

How was the initial setup?

The initial setup depends on familiarity with the product. It's manageable with the right expertise. In cases of a simple application, setting up could be achieved in as little as one day.

What's my experience with pricing, setup cost, and licensing?

I can't determine the exact cost of licensing as it was part of a bundle that offered multiple features and licenses.

Which other solutions did I evaluate?

I have no experience with other solutions.

What other advice do I have?

I must emphasize the reliability.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Martin Janzsó - PeerSpot reviewer
Presales Consultant at a tech services company with 201-500 employees
Real User
Top 5
Sep 8, 2024
Has good integration with load-balancing applications
Pros and Cons
  • "The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
  • "Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees."

What is our primary use case?

Our company provides data center and cloud services as infrastructure providers. When customers need infrastructure like VMs or server allocation, we provide them with the vendor and offer services to operate, manage, implement, and integrate these security components.

What is most valuable?

The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection.

What needs improvement?

Regarding areas for improvement, the documentation needs work. We had issues with a customer because the documentation didn't clearly show which devices can connect with FortiWeb WAF, leading to misconfiguration and difficult meetings. We also need deeper technical support - finding who's responsible for technical aspects is challenging. Hungary has a good Fortinet office with strong sales and pre-sales employees.

For how long have I used the solution?

I have been using the product for four to five years. 

What do I think about the stability of the solution?

I rate the tool's stability a nine out of ten. 

What do I think about the scalability of the solution?

It's not good with normal perpetual licensing, but we can solve the problem using flex licensing. That's why I'd rate it nine out of ten. We're satisfied with it. Many of our customers, including small, medium, and enterprise businesses, use FortiWeb WAF.

How was the initial setup?

I rate the tool's deployment ease as seven out of ten. We have spent about 600 working hours to implement it. 

What's my experience with pricing, setup cost, and licensing?

The product provides very good prices to customers. The price is set well and offers great value for money.

What other advice do I have?

I rate the overall solution an eight out of ten. I advise others looking to use FortiWeb WAF to create deeper policy rules.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. msp
PeerSpot user
Aung Min Oo - PeerSpot reviewer
Director at a tech services company with 11-50 employees
Real User
Top 5
Jan 15, 2024
A tool to protect websites from malware and adware attacks that needs to improve its scalability
Pros and Cons
  • "The product is easy to configure."
  • "FortiWeb Web Application Firewall (WAF) needs to update its attack prevention database."

What is our primary use case?

I use the solution for some of my company's clients who want to protect their websites from malware and adware attacks.

How has it helped my organization?

From a benefit perspective, FortiWeb Web Application Firewall (WAF) protects the customers’ websites, which are used to communicate with the audience or clients.

What is most valuable?

I am not sure about what I like in the solution because I think most of the customers ask for the product whenever they want a WAF tool for any of their projects. After our company had a discussion with one of our local teams, we sold it by providing the features of the FortiWeb Web Application Firewall (WAF) that our customers like, as we mostly follow the customer requirements. Our company sells FortiWeb Web Application Firewall (WAF) if it meets our customers' requirements.

What needs improvement?

To deal with zero-day attacks, FortiWeb Web Application Firewall (WAF) needs to expand and update its database since it is one of the areas where the tool currently lacks. In short, FortiWeb Web Application Firewall (WAF) needs to update its attack prevention database.

In FortiWeb Web Application Firewall (WAF), there is a substantial amount of improvement required in the scalability area.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for less than a year.

What do I think about the stability of the solution?

Stability-wise, I rate the solution a seven out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a five out of ten.

My company only has two customers who use FortiWeb Web Application Firewall (WAF). My company wants to sell the tool to medium and large-sized businesses with 500 or more users.

How was the initial setup?

The solution is deployed on an on-premises model.

Sometimes, the product's deployment takes over one or two days because customers need to check their requirements and then may want some features. In general, it takes a minimum of two or three days to deploy the product.

What's my experience with pricing, setup cost, and licensing?

Compared to the other products in the market, FortiWeb Web Application Firewall (WAF) is a reasonably priced product, but sometimes people may consider it a bit expensive. I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price.

What other advice do I have?

The product is easy to configure.

I have a separate team of three engineers in the company to manage FortiWeb Web Application Firewall (WAF).

Based on my experience and the comments from our company's customers who use the solution, I can say that FortiWeb Web Application Firewall (WAF) is a good product. Our company's customers who use the solution like it since they have been using it for about a year without any bad opinions or comments about it.

Feature-wise, FortiWeb Web Application Firewall (WAF) needs to add more functionalities. Some of the customers who use it want it to have more features, but we cannot find any in the tool presently. I can say what kind of features are required right now in the product. One customer who may want 20 features in the tool may get only 15 features that comply with the customer's requirements.

I rate the overall tool a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.