Soroush-Enayati - PeerSpot reviewer
Network security engineer at freelancer
Real User
Top 10
Great machine learning, artificial intelligence and behaviour detection
Pros and Cons
  • "It helps us prevent attacks on servers."
  • "The initial setup is complex."

What is our primary use case?

It helps us prevent attacks on servers, and we deploy it on-premises.

What is most valuable?

There are many valuable features. It has machine learning, artificial intelligence, behaviour detection, and many other features capable of detecting web attacks.

What needs improvement?

The initial setup could be simplified.

For how long have I used the solution?

We have been using the solution for approximately ten years.

Buyer's Guide
Fortinet FortiWeb
March 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
765,386 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

We do not have experience with customer service and support.

How was the initial setup?

The initial setup is complex and takes between three to six months.

What about the implementation team?

We implemented the solution in-house.

What's my experience with pricing, setup cost, and licensing?

Fortinet FortiWeb has some types of licenses, and the main licenses refer to updating a signature and a pattern.

Which other solutions did I evaluate?

We evaluated machine learning and the main signatures about known attack signatures.

What other advice do I have?

I rate the solution a ten out of ten, and I recommend it for every organization with web services.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Pedro Andrade - PeerSpot reviewer
General Manager at Ip4u
Real User
Top 10
Good reporting and a nice user interface but can be a bit expensive
Pros and Cons
  • "It can scale well."
  • "The upgrade process could be a bit smoother."

What is most valuable?

The reporting available is pretty great.

We find the configuration capabilities to be very good. 

Technical support is helpful.

It's stable. 

It can scale well. 

I like the user interface. 

What needs improvement?

It's not the most popular option. Many clients prefer instead Citrix or Proxy Blue Coat. It might be a bit difficult to configure. 

The upgrade process could be a bit smoother. 

Sometimes the integration doesn't work on the first or second try.

The solution is a bit expensive. 

For how long have I used the solution?

We first installed the solution eight or nine years ago. We've used it for almost a decade. 

What do I think about the stability of the solution?

The solution is pretty stable. I'd rate it a three out of five in terms of stability. Sometimes the upgrades don't go as smoothly as we would like. 

What do I think about the scalability of the solution?

The solution is scalable. I'd rate it four out of five in terms of how easy it is to expand the product. 

How are customer service and support?

I can't complain about the technical support. They are pretty good. I found them to be helpful. However, it may depend on the engineer you get on the line. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup has a moderate level of difficulty.

We only need one person to deploy and maintain the product.

It takes about a week to have the entire solution set up.

What about the implementation team?

We install the solution for our clients. 

What was our ROI?

It's always difficult to measure ROI when it comes to security. It's always just a smart investment for a company.

What's my experience with pricing, setup cost, and licensing?

The product can be costly.

The licenses are paid annually. You do have several licensing choices. They don't have too much choice. However, their options are good. 

What other advice do I have?

We are not an end user. We are resellers.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
March 2024
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
765,386 professionals have used our research since 2012.
Manager at a construction company with 1-10 employees
Real User
Provides security and an easy setup, however scalability is a concern
Pros and Cons
  • "The most important feature of this solution is protection from attack."
  • "The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network."

What is our primary use case?

We use the solution to protect the various services of our site, E-commerce, file service, and download service.

What is most valuable?

The most important feature of this solution is protection from an attack.

What needs improvement?

The maintenance fee for this product could be improved and it needs to be easier to scale up. 

For how long have I used the solution?

I have been using the solution for four to five years. 

What do I think about the stability of the solution?

Stability is very important and yes, the product is stable.

What do I think about the scalability of the solution?

The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network.

How are customer service and support?

I would say technical support is good for this solution.

How was the initial setup?

Setup for this solution is easy, with one being easy and five being hard I would rate it a two out of five. Deployment took a few days. 

What's my experience with pricing, setup cost, and licensing?

We have between 100 and 200 users of the solution in our company. 

What other advice do I have?

I would rate the solution a six out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Commercial Manager at Natco Information technology
Real User
Top 10
Simple to set up with good technical support and the ability to scale
Pros and Cons
  • "We find that it is quite stable and reliable."
  • "The solution could offer more integration opportunities."

What is our primary use case?

We are primarily using the solution for our security applications as well as email and internet protection.

What is most valuable?

The product is very easy to use.

We find that it is quite stable and reliable. 

The solution can scale quite well.

The installation process is very simple. 

The technical support on offer is helpful.

What needs improvement?

The solution could offer more integration opportunities. 

For how long have I used the solution?

We started using the solution about five or so years ago. It's been a while at this point. 

What do I think about the stability of the solution?

The stability has been good over the years. It does not crash or freeze. There are no bugs or glitches. The performance is reliable. 

What do I think about the scalability of the solution?

The product does scale well. If a company needs to expand it, it can do so.

Some of our clients have over a hundred users. Others only have 50. the size of the setups varies. 

How are customer service and technical support?

We've had a good experience with technical support. They are helpful and responsive. We're quite satisfied with the level of service they provide. 

Which solution did I use previously and why did I switch?

We also currently use Cisco for some security and protection.

How was the initial setup?

We found the initial setup to be easy. It's straightforward. It's not complex or difficult at all. A company shouldn't have any issues with the setup at all.

The installation and deployment process is fast. It doesn't take more than a day.

We have two engineers on staff that can handle deployment and maintenance. 

What about the implementation team?

We have a team in-house that can manage it. We don't need the assistance of outside integrators or consultants. 

What's my experience with pricing, setup cost, and licensing?

We have a yearly subscription that we renew annually.

What other advice do I have?

We're using the latest version of the solution. I cannot speak to the exact version number, as I don't have it on hand. 

We're a company that helps implement this product for clients. 

At this time, I'd rate the product at an eight out of ten. We've largely been very satisfied with its capabilities. 

I'd recommend the product to other users and companies. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Information Security Officer at State Audit Office
Real User
Flexible, easy to learn and configure, and has almost everything that a web application firewall needs
Pros and Cons
  • "It is a good product. We have just blocked everything coming from some geographical locations or certain countries, and it has been working very efficiently when I look at logs, events, and incidents generated from the system. It is generating very good analytic reports about it. This is the most valuable thing about this solution. It has load balancing and almost everything that a web application firewall needs. It is very flexible and easy to learn and configure. It can be easily learned and configured by using the information available on different channels such as YouTube."
  • "When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it."

What is our primary use case?

We have been testing FortiWeb in our environment. We have it on virtual machines. We used it to block requests from some geographical locations or certain countries. It is very important for us because many attack attempts, logs, and events were generated from those geographical locations. Our country has some political difficulties in the region with other countries. 

What is most valuable?

It is a good product. We have just blocked everything coming from some geographical locations or certain countries, and it has been working very efficiently when I look at logs, events, and incidents generated from the system. It is generating very good analytic reports about it. This is the most valuable thing about this solution. 

It has load balancing and almost everything that a web application firewall needs. It is very flexible and easy to learn and configure. It can be easily learned and configured by using the information available on different channels such as YouTube.

What needs improvement?

When we look at the incident reports in the dashboard, they are available for a maximum duration of 24 hours. They should provide more time for the analysis and increase the duration of the availability of these reports. Currently, it gives the options for 5 minutes, 1 hour, and 24 hours. It would be excellent if there are more options for a longer time period. It may be configurable, but I don't know how to do it.

For how long have I used the solution?

I have been using this solution for three months. 

What do I think about the stability of the solution?

Based on what I know and see during the testing mode, it is stable. There has been no major incident. It has not stopped during this time.

What do I think about the scalability of the solution?

It is flexible and scalable. We have about 400 employees, and all of them are using this solution. 

How are customer service and technical support?

We don't have any experience with international support. The local guys from our partner High Tech Solutions are so educated and professionals that we didn't have any need to use international support. They are doing well and are available all the time. They are always ready to help and support whether it is a working hour or not.

What about the implementation team?

We have one System Admin who works on the configuration and an InfoSec officer who looks into events, incidents, and logs and analyzes them. So, we have two people. We also have our head of the department, and we are responsible and accountable to him.

Which other solutions did I evaluate?

We have also tested other products such as Imperva and F5, and the most number of likes were for F5 and FortiWeb.

What other advice do I have?

We like the product, but we haven't yet decided to purchase it because we don't have the budget for now. We will express our preferences towards FortiWeb to our top management, and it will be decided by them. We will suggest to them that it is a good product.

I would rate Fortinet FortiWeb a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Dino R - PeerSpot reviewer
System Administrator at a insurance company with 1,001-5,000 employees
Real User
Top 20
Provides good feedback for development and is easy to scale up
Pros and Cons
  • "It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs."
  • "The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product."

What is our primary use case?

Generally, we are using it to protect our internet-facing web applications. So if there are any security vulnerabilities in our applications, the solution can provide protection.

How has it helped my organization?

It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs.

What is most valuable?

They have a sort of table that defines the functions of certain applications, ex. which function has the slowest or fastest response. This enables our in-house development team or vendors to review our application and fix the functions if necessary. 

What needs improvement?

The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product.

For how long have I used the solution?

I have been using FortiWeb for three years.

What do I think about the stability of the solution?

I think it's quite reliable so long as it's configured. 

What do I think about the scalability of the solution?

As long as we accurately scale our requirements from the start, I think the solution is quite scalable and quite easy to scale up later on.

How are customer service and technical support?

They are quite helpful. But I think because our department is quite stable and configured correctly, we are rarely using the support. Everything works perfectly.

How was the initial setup?

I think it's quite complex because we need to know how the application works.  

What about the implementation team?

We are using local support to configure the solutions for us. We also purchase local maintenance and support on top of the routine product support and updates. Because it is a
very specialized product, we need a very skillful person with expertise in the product to configure the solution for us.

What's my experience with pricing, setup cost, and licensing?

In a high availability cluster configuration, where the primary FortiGate is working and the secondary is a backup, Fortinet requires us to buy two licenses instead of one whether we are actually using it or not. With other products, you only purchase one license because we only use one license per instance.

What other advice do I have?

You need to accurately calculate the requirements of your infrastructure before implementing FortiWeb or any other web application firewall. Accuracy is very critical when scaling the product or the model that will be deployed on your infrastructure. 

I would rate FortiWeb an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
AhmedIsmael - PeerSpot reviewer
Network & Telecom Manager at a retailer with 1,001-5,000 employees
Real User
Easy to use, and the all-in-license covers all of the features
Pros and Cons
  • "The most valuable feature is ease of use."
  • "I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device."

What is our primary use case?

I am using FortiWeb as a web application firewall and as a load balancer for HTTP applications. 

What is most valuable?

The most valuable feature is ease of use.

It has an all-in-one license, unlike F5 where you need separate licenses for the antivirus, IP reputation, denial of service attacks, etc. With FortiWeb, the all-in-one license is one of the most beneficial features.

What needs improvement?

I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device. For example, if I have one device that costs $2,600 USD then it can have two licenses, where it can operate as a load balancer as well as a WAF.

For how long have I used the solution?

We have been using FortiWeb for three years.

What do I think about the stability of the solution?

This is a good solution, stability-wise.

What do I think about the scalability of the solution?

FortiWeb is a scalable product and we have about 3,000 users.

That said, we need to purchase a model with more capacity because this is a small one, and our business has expanded in the past three years.

How are customer service and technical support?

We have been in contact with technical support and we are satisfied with them.

Which solution did I use previously and why did I switch?

We did not use another similar solution before choosing FortiWeb.

How was the initial setup?

The initial setup is straightforward.

Any FortiWeb deployment needs about two weeks because when it is first implemented, in phase one, machine learning takes place. It is needed because every application needs some customization. FortiWeb needs approximately two weeks to build this profile. After that, an expert will do some fine-tuning on the profile and the appliance will start to work.

What about the implementation team?

During the deployment, we used a system integrator, but after that, we can manage it by ourselves. Our network team has seven people including one technician, one manager, and five administrators.

What's my experience with pricing, setup cost, and licensing?

There are no licensing costs.

What other advice do I have?

In summary, this is a good product and I can recommend it for others.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Infrastructure Manager with 201-500 employees
Real User
The learning mode of the appliance picks up on the pattern of SSL attacks
Pros and Cons
  • "I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks."
  • "We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."

What is our primary use case?

We use it mostly to secure our web platform for things like Internet banking, email, and SMTP. It is for anything that is external coming into our internal network.

How has it helped my organization?

We were having a lot of probe attacks coming through from our external networks. Now, the traffic has to come through our firewall, then FortiWeb. Basically, FortiWeb acts like a second firewall for all our applications.

What is most valuable?

We have been using all the features and everything is nice. 

I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks. 

What needs improvement?

We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced. 

We had trouble understanding it at first, but we got used to using it after six months. Then, it was simple to use.

For how long have I used the solution?

We have been using it for five years (since 2015). 

What do I think about the stability of the solution?

We haven't had any issues with it so far. 

What do I think about the scalability of the solution?

The scalability is okay. There hasn't been a need to upgrade. We have found something that can adapt to our environment and that we can use for a long period of time.

We plan to use the product for the next two years. There are no major upgrades planned anytime soon.

There are four users for the product (with two being from the security team).

How are customer service and technical support?

We have needed minimal support for the solution. The support has been okay.

Which solution did I use previously and why did I switch?

We did not have a solution that we previously used.

How was the initial setup?

It is complex to set up in learning mode. It takes a lot of time to learn the pattern of the web application before we put in the rule. The rule itself is a bit complex. We had to go by trial and error because there is nothing standard on the device.

The deployment took almost six hours to get up and running.

What about the implementation team?

We used a reseller. They helped us implement the device. 

The reseller also does deployment and maintenance. For this, it takes about two of their staff and one or two of our staff internally. The staff will generally have experience in networking and firewalls with a background in security and port mapping.

What's my experience with pricing, setup cost, and licensing?

All our Fortinet pricing is bundled together for different products, like FortiGate, FortiAnalyzer, and FortiWeb. FortiWeb, by itself, is probably around $2,500 to $3,500.

Which other solutions did I evaluate?

Since we were using FortiGate firewall, we decided to look at FortiWeb. We also looked into several solutions, like Check Point and Palo Alto.

What other advice do I have?

The type of product you get depends on what you want to protect, how you want to protect it, and how many people will be accessing FortiWeb.

What we have now is working fine.

I would rate FortiWeb as an eight (out of 10).

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.