We use it for all our hosted web applications, so they are routed via FortiWave and Fortinet. We use both the network firewall and the application firewall. The whole infrastructure and everything else are protected. Fortinet protects the web infrastructure.
Cloud Architect/Solution Architect at a consultancy with 10,001+ employees
Provides good services and support at low cost
Pros and Cons
- "Deployment can be straightforward"
- "Its threat intelligence capabilities may not be as advanced as some competitors."
What is our primary use case?
What is most valuable?
There are very few specific things that are not present in cloud-native firewalls, like Azure Firewall or AWS Firewall. They lack many features, such as the ability to handle paths in requests larger than eight KB. For example, if you upload a document or the page size exceeds eight KB, you might face issues with AWS and other cloud-native firewalls. FortiWeb can handle requests of up to 10MB, providing this capability. It also has a very user-friendly UI. Even someone new to FortiWeb or any firewall system, with the right contextual knowledge, can configure it effectively. The support and documentation provided by Fortinet are generally sufficient for any team to manage infrastructure using Fortinet and FortiWeb.
What needs improvement?
Native cloud firewalls, like AWS WAF or Azure Firewall, have limitations compared to next-generation firewalls like Fortinet FortiWeb or other solutions. While AWS and Azure have security features, they are often tailored to their specific technologies and may lack some advanced capabilities in next-generation firewalls. This is why we sometimes opt for solutions like Fortinet, even in a cloud environment.
Fortinet FortiWeb has strengths, but there is room for improvement. For example, its threat intelligence capabilities may not be as advanced as some competitors. While Fortinet excels in many areas, it could enhance its advanced intelligence features. However, in terms of configuration, maintenance, and securing infrastructure, Fortinet remains a strong option.
For how long have I used the solution?
I have been using Fortinet FortiWeb as a partner for five to five years.
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the solution’s stability a seven out of ten.
What do I think about the scalability of the solution?
It is suitable for enterprises.
I rate the solution’s scalability as seven or eight out of ten.
How are customer service and support?
We have a procurement team and a support engagement team that is helping us with issues. They are maintaining the SLA and all those things.
How was the initial setup?
Deployment can be straightforward, like spinning up EC2 instances or Azure VMs with Fortinet, which can be a one-click process. The complexity arises from configuring Fortinet within your specific ecosystem. The configuration depends on the size and nature of your infrastructure, including the number of machines and appliances and the types of systems you are protecting, such as APIs, normal instances, or mobile applications. While deploying Fortinet itself might be quick, configuring it to fit your environment and security needs takes additional time and effort.
What other advice do I have?
Many other companies offer similar capabilities. We also use other solutions, but Fortinet FortiWeb has strong bot capabilities for threat protection and excellent geo-restriction features. It also handles malicious IP prevention and is easy to use. Our experience has been positive. We’ve only enabled the algorithms provided by FortiWeb and haven’t customized the configuration beyond what FortiWeb offers. The existing rules and features for FortiWeb are good.
If you need a next-generation firewall to meet industry and security demands, relying solely on native cloud firewalls like Azure Firewall, AWS Firewall, or Google Cloud Firewall may not be sufficient. These native firewalls often lack the advanced features to protect against various threats. It is advisable to consider solutions like Fortinet FortiWeb or Cloudflare to ensure robust protection.
It's a trade-off between price and the service you receive. If you're paying less for a solution that provides good services compared to a competitor where you might pay more for similar support and features, then Fortinet could be a viable option. It might be better if another solution, like Cloudflare, offers better value across multiple aspects such as service, cost, and support.
Overall, I rate the solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Manager at a tech services company with 501-1,000 employees
Used for web filtering purposes and has a user-friendly interface
Pros and Cons
- "The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS."
- "It would be good if the solution integrated with other solutions, like SAP."
What is our primary use case?
We use the solution for web filtering purposes. We use it to allow or block any application.
What is most valuable?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS. The solution's console is very user-friendly and very easy to manage. The solution has good stability and a user-friendly interface.
What needs improvement?
It would be good if the solution integrated with other solutions, like SAP.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall (WAF) for nine to ten years.
What do I think about the stability of the solution?
FortiWeb Web Application Firewall is a very stable solution.
I rate the solution’s stability ten out of ten.
What do I think about the scalability of the solution?
Every location with 200 to 300 people has installed the FortiWeb Web Application Firewall.
I rate the solution a nine out of ten for scalability.
How are customer service and support?
Our experience with the solution's technical support has been good. We promptly get support from the technical support team.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup is easy and can be done in a few hours.
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a nine or ten out of ten.
What other advice do I have?
I would recommend FortiWeb Web Application Firewall to other users because it is a good product.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
Network & Security Engineer at a tech services company with 51-200 employees
A security solution for securing the Internet facing servers but lacks several security features
What is our primary use case?
We use the solution for securing the Internet-facing servers where you can do the load balancing with the web appliance.
What needs improvement?
FortiWeb WAF lacks several security features compared to F5. F5 can incept the traffic to layer seven; FortiWeb can do it, too, but it is a tough process. We have to get support from Fortinet.
For how long have I used the solution?
I have been using FortiWeb as a partner for two years. We are using V7.2 of the solution.
What do I think about the stability of the solution?
Fortinet has many issues, like the zero-day attacks. Certain critical work vulnerabilities need to be immediately upgraded as an enterprise. You cannot initiate the upgrade anytime because it affects production. Usually, we schedule the upgrade. We do the configuration and scheduling of the updates. Fortinet is a 24/7 company that can release updates any time, regardless of the day of the week. FortiWeb WAF is a security solution that can be updated at any time, irrespective of the day of the week.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
On two recent occasions, I experienced delays in resolving technical issues with Fortiweb WAF, particularly when configuring explicit proxies on FortiGate firewalls. As a Fortinet partner, I was disappointed that our dedicated support channel was unavailable and that I could not obtain licenses or hardware assistance despite escalating to the country manager. Additionally, the technical support response times in the Middle East region have been inconsistent, with some areas providing excellent support while others have been unresponsive. This inconsistency has been particularly frustrating when dealing with urgent issues at remote sites. Overall, the support experience for Fortiweb WAF has been inconsistent and frustrating, particularly for Fortinet partners.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have used Kemp before, but I also dislike the FortiWeb. I'm trying to move to F5 because F5 is very good.
How was the initial setup?
FortiWeb comes with an IP address. You need to log into the web console, and you can do it with the CLI using the console cable. You have to go in; it will initially give you a setup wizard and configure the hostname, interfaces, etc. The setup is relatively easy, but when it comes to advanced deployments. Kemp is a relatively affordable and capable solution. Fortiweb WAF offered all the features, making Kemp less appealing for enterprise-level applications. Kemp is suitable for smaller or regional websites, but it may not be as robust for global deployments.
Additionally, I could not locate the virtual domain feature in Fortiweb WAF. This feature would allow me to assign different domain names to a single website based on the user's location. Fortiweb WAF presented EDS as a workaround, but the process was overly complex and inconvenient.
Firstly, expect load balancing and a web application firewall for the same product Fortinet is offering. Start by booting up the device and use FortiWeb to connect the file by application firewall. There's a default IP address without any password. You log in, and then it shows your initial setup wizard. The wizard helps you set up the host names, Fortinet account, FortiCloud account, etc. After that, you start setting up your physical servers; then you give a virtual server, which will be a point. In a network with a firewall and port forwarding, the FortiWeb WAF device can act as a load balancer and a security gateway. It can receive traffic from the firewall, decrypt SSL/TLS traffic, inspect traffic for layer seven vulnerabilities, and then forward traffic to the appropriate internal server based on load-balancing algorithms and application-specific information provided by the servers. The FortiWeb WAF can monitor server health and performance and automatically switch traffic away from unhealthy servers.
Deployment depends on how much complexity you want to add to the product. If the customer requirement is easy, you may deploy it in one day. For example, I was working on a project with around 16 servers. Each server has a different data source; one server gives the back end, whereas the other provides the front end. That was a complex deployment. It will take around four to five days to deploy if you want to go deeper into it.
What was our ROI?
We have achieved 70% ROI.
What's my experience with pricing, setup cost, and licensing?
FortiWeb is expensive. F5 is also very expensive, but it is value for money.
What other advice do I have?
The solution’s maintenance and UI are easy, but some features are hidden. Their quality assurance needs to work. We used to have the upgrades and patches every month or 15 days, but now they are coming every week too. We have vulnerability.
The product needs to get more mature.
Overall, I rate the solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Sales manager at a manufacturing company with 5,001-10,000 employees
A cost-effective solution for web security but lacks stability
Pros and Cons
- "Fortinet FortiWeb is priced well."
- "The product’s stability could be improved."
What is our primary use case?
We use the solution for the office in Oracle.
What is most valuable?
Fortinet FortiWeb is priced well.
What needs improvement?
The product’s stability could be improved.
For how long have I used the solution?
I have been using Fortinet FortiWeb for one year. We are using the latest version of the solution.
What do I think about the stability of the solution?
The product’s stability is normal. I rate it six out of ten.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
The initial setup depends on technical knowledge.
What's my experience with pricing, setup cost, and licensing?
The solution is cheaper compared with other solutions. It has a yearly license.
What other advice do I have?
Overall, I rate the solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Operation Director at a tech services company with 1-10 employees
A cost-effective firewall that remains stable while providing security to its users
Pros and Cons
- "The initial setup was easy since it was possible to get remote support for the product."
- "The product lacks features offered by enterprise-level firewall tools."
What is our primary use case?
In my company, we use FortiWeb Web Application Firewall (WAF) for security.
What is most valuable?
FortiWeb is a small tool that can be used by those of our customers who use Fortinet FortiGate as their firewall. I will use Barracuda Email Protection for any customer who uses a firewall from a solution provider other than Fortinet FortiGate.
What needs improvement?
The product lacks features offered by enterprise-level firewall tools. The solution needs to offer more enterprise features like other brands.
It would be great if FortiWeb Web Application Firewall (WAF) had something like a wizard to allow for more integrations with other popular firewall products like Fortinet, Palo Alto, and so on.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall (WAF) for three years. I use the solution's latest version.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution an eight out of ten.
There are 2,000 users of the solution in my company.
How are customer service and support?
The solution's technical support was helpful and responsive. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have previously used SonicWall.
How was the initial setup?
The initial setup was easy since it was possible to get remote support for the product.
The solution is deployed on-premises.
What's my experience with pricing, setup cost, and licensing?
It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee.
What other advice do I have?
There are five engineers needed for the maintenance of the solution.
If there is a requirement and one is already using a firewall from Fortinet, then it is easier to deploy FortiWeb Web Application Firewall (WAF). Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
I.T. Manager at a agriculture with 501-1,000 employees
Visible ROI with the security the solution provides
Pros and Cons
- "The reason I recommend this product is because it guarantees that your network will be safe if it is set up properly and you fully utilize most of the functions."
- "I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted."
What is most valuable?
The features I found valuable were web filtering, reporting, and the dashboards. We use these features for controlling the traffic in our network, mainly for our security. This means that we can have policies there that allow or don't allow certain connections.
What needs improvement?
I know that we have run into some issues with an SSL certificate and how it functions. Sometimes this breaks connectivity or just limits certain websites that are whitelisted.
For how long have I used the solution?
I have been using Fortinet FortiWeb for more than ten years.
What do I think about the stability of the solution?
The only instance where we have had issues with stability was a recent one where the solution was blocking some websites that we did not intend to block and which were even whitelisted in some instances.
Our partners explained that this happened because of an issue with the SSL setup. I'm not sure if they then sorted it out or if they just switched off that functionality.
But for the past 10 years that we've used it, that was the first error or problem that we ran into. Maybe it was just teething problems since we only deployed it end of last year.
What do I think about the scalability of the solution?
My impression is that it's quite scalable because I know they have different sizes. In one of our organizations, we had fewer users, so we're using a smaller one, which was a 60-day or something like that. And then when you are using it for a bigger organization, they also have that type of device for many users.
They'll ask you how many users are going to be governed by this firewall. So when we had fewer users, we got a smaller firewall. And then when we expanded and had many more users, we got a bigger one. It's quite scalable I think.
How are customer service and support?
Their technical support is good. They'll jump onto the occasion. When you submit a log report or you request some support, they quickly respond. I would rate them a ten. Very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to Fortinet, we used Netgear, but this was a long time ago. I think this was 15 years ago.
How was the initial setup?
The initial setup was not straightforward. You need an expert to set it up with you and to configure it for you. I think the more you work with it, the better accustomed you are to it. The initial setup did not take longer than a week.
The deployment was done in a team of three people.
What about the implementation team?
We implemented it with a third party, and they're the ones who always then deploy and implement it for us. The deployment didn't take more than a week.
What was our ROI?
I would say that the ROI is visible because we are happy with the security it provides.
What's my experience with pricing, setup cost, and licensing?
The pricing is a bit high. It is not a cheap product.
What other advice do I have?
The reason I recommend this product is because it guarantees that your network will be safe if it is set up properly and you fully utilize most of the functions.
Overall, I would rate FortiWeb solution a nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Architect/Solution Architect at a consultancy with 10,001+ employees
Out-of-the-box tools are abundant but the solution lacks an interface for troubleshooting
Pros and Cons
- "The solution is easy to configure and deploy."
- "A user interface or dashboard for troubleshooting is needed."
What is our primary use case?
Our company uses the solution to provide firewall and web security services to our customers around the globe.
Our use cases are on the back end for banks and the financial sector where we automate monitoring and deployment.
We do not have a portal, so are limited to a maximum of 3,000 users. We currently have 2,000 users and three maintenance technicians.
In the future, we will add front-end service.
Depending on our client's needs, we pair the solution with other business applications.
What is most valuable?
The solution is easy to configure and deploy.
There is a richness in the rules and out-of-the-box tools that is not available with native firewall solutions.
What needs improvement?
A user interface or dashboard for troubleshooting is needed so technicians without knowledge of the network or common hardware can visualize the environment.
Accounts should be set up in the user's name, not the company's name.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
The solution is stable and I rate it an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable and I rate it a ten out of ten.
How was the initial setup?
The initial setup was a bit complex for us because we were new to the solution.
Technical support helped and trained us so we now handle setups with ease.
What about the implementation team?
We worked with the solution's technical support for our initial implementation but our internal team now handles setup and implementation for customers.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit expensive when compared to other products.
Which other solutions did I evaluate?
There are many security constraints that cannot be fulfilled by native cloud firewalls such as Azure and AWS.
For example, AWS has a limitation of 8GB with regard to request values.
We recommend the solution and its next-generation capabilities including ease of configuration, code being contained within the IIC engine, how templates and terraforms are handled, and superior wave and firewall security.
We are continually conducting research on next-generation firewalls because the solution can be a bit expensive.
What other advice do I have?
I use solution a lot and recommend it with a rating of seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Easy to use with a nice interface and good support
Pros and Cons
- "The support is quite good."
- "Sometimes, even if you follow the documentation, it doesn't work as expected."
What is our primary use case?
We primarily view the VPN net and use the WAF as our web protection.
What is most valuable?
The interface is very straightforward and easy to use.
It's stable.
The support is quite good.
We found the initial setup pretty simple.
What needs improvement?
Sometimes, even if you follow the documentation, it doesn't work as expected.
The solution can be a bit pricey.
For how long have I used the solution?
I've used the solution for about one year, or maybe a bit more than that.
What do I think about the stability of the solution?
Sometimes it is not as stable as it could be. We've had some issues. Sometimes the loading will be disrupted for no apparent reason. It might be due to the WAF.
What do I think about the scalability of the solution?
We have not tested the scalability of the product.
We have two people working on the solution right now.
It's possible that we will scale the solution in the future. There is the potential that we will use it on another project.
How are customer service and support?
We have contacted support for reliability issues, and they have been able to resolve everything within a matter of hours. They are very quick.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used F5. F5 needs a bit of a higher skill set. It takes some experience to operate.
How was the initial setup?
The implementation took about two months. It's not so hard to set everything up. It's easier than, for example, F5, to set up.
In terms of maintenance, for WAF, I need about three people to handle various tasks.
What about the implementation team?
We hired a consultant to assist us during the setup. The consultant helped my people learn the process so we could become self-sufficient.
What was our ROI?
We have not seen any ROI at this time.
What's my experience with pricing, setup cost, and licensing?
The solution is a little expensive. I'd rate it a three out of five in terms of affordability.
I cannot speak to the exact price we pay for the product.
Which other solutions did I evaluate?
We didn't really look into other options as my boss is pretty well versed in other options. However, we are always looking into comparisons.
What other advice do I have?
We are using the latest version of the solution.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
NetScaler
AWS WAF
Cloudflare Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Check Point CloudGuard WAF
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?














