Try our new research platform with insights from 80,000+ expert users
AhmedIsmael - PeerSpot reviewer
Network & Telecom Manager at a retailer with 1,001-5,000 employees
Real User
Easy to use, and the all-in-license covers all of the features
Pros and Cons
  • "The most valuable feature is ease of use."
  • "I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device."

What is our primary use case?

I am using FortiWeb as a web application firewall and as a load balancer for HTTP applications. 

What is most valuable?

The most valuable feature is ease of use.

It has an all-in-one license, unlike F5 where you need separate licenses for the antivirus, IP reputation, denial of service attacks, etc. With FortiWeb, the all-in-one license is one of the most beneficial features.

What needs improvement?

I would like to see the Application Delivery Control (ADC) and Web Application Firewall (WAF) combined in one device. For example, if I have one device that costs $2,600 USD then it can have two licenses, where it can operate as a load balancer as well as a WAF.

For how long have I used the solution?

We have been using FortiWeb for three years.

Buyer's Guide
Fortinet FortiWeb
June 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

This is a good solution, stability-wise.

What do I think about the scalability of the solution?

FortiWeb is a scalable product and we have about 3,000 users.

That said, we need to purchase a model with more capacity because this is a small one, and our business has expanded in the past three years.

How are customer service and support?

We have been in contact with technical support and we are satisfied with them.

Which solution did I use previously and why did I switch?

We did not use another similar solution before choosing FortiWeb.

How was the initial setup?

The initial setup is straightforward.

Any FortiWeb deployment needs about two weeks because when it is first implemented, in phase one, machine learning takes place. It is needed because every application needs some customization. FortiWeb needs approximately two weeks to build this profile. After that, an expert will do some fine-tuning on the profile and the appliance will start to work.

What about the implementation team?

During the deployment, we used a system integrator, but after that, we can manage it by ourselves. Our network team has seven people including one technician, one manager, and five administrators.

What's my experience with pricing, setup cost, and licensing?

There are no licensing costs.

What other advice do I have?

In summary, this is a good product and I can recommend it for others.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Information Security Consultant at Future Telecom
Real User
Integrates very well and easy to use, configure, and manage
Pros and Cons
  • "The customers are very happy with this solution because of two things. First, the IPS integration with a web application is very tightly done on Fortinet. Second, the ease of use is there. The management interface or the GUI interface is very easy to use, configure, and manage. These are the two main valuable features. It supports integration with other Fortinet products. It also integrates very well with the firewall and sandboxing technology. They already have enough integration with different technologies. They have got a complete tech intelligence view of the whole product."
  • "They could improve their support a little bit for faster response time."

What is our primary use case?

We have deployed a couple of projects for our customers to protect their online e-commerce systems. They have web-based applications for online ordering, for example, for online ordering from a hypermarket. It seems to be a very good solution. We have replaced the existing Barracuda devices of a customer. We deal with the latest version of Fortinet FortiWeb.

What is most valuable?

The customers are very happy with this solution because of two things. First, the IPS integration with a web application is very tightly done on Fortinet. Second, the ease of use is there. The management interface or the GUI interface is very easy to use, configure, and manage. These are the two main valuable features.

It supports integration with other Fortinet products. It also integrates very well with the firewall and sandboxing technology. They already have enough integration with different technologies. They have got a complete tech intelligence view of the whole product. 

What needs improvement?

They could improve their support a little bit for faster response time. 

For how long have I used the solution?

I have been using Fortinet FortiWeb for two years.

What do I think about the stability of the solution?

It is very stable.

What do I think about the scalability of the solution?

It is very scalable. The web application firewall is protecting the web servers in an organization from outside to inside. It probably has more than 1,000 users.

How are customer service and technical support?

Their technical support needs a little bit of improvement in terms of faster response time.

How was the initial setup?

The initial setup is very straightforward. It took about 30 to 40 minutes for one web application for default settings. If you want to go with complex settings, then it would probably take three to four days to understand the application backend and everything else.

What about the implementation team?

We used a system integrator. One Admin is more than enough to deploy and maintain it. It is very stable and easy to configure and deploy.

What's my experience with pricing, setup cost, and licensing?

Its subscription prices are cheaper, and it is not very expensive. From a price perspective, Fortinet is a very well-known security vendor.

Subscriptions are very simple. They have a couple of licenses on an appliance, and that's it. The cost is not that big. One license is 40K, which they give with all the products. Another one includes the subscriptions for threat prevention, IPS, sandboxing, etc, which is more than enough.

What other advice do I have?

Fortinet FortiWeb is rated as one of the top WAF devices in many of the independent research reports. Our customers find Fortinet FortiWeb much better than other solutions. 

We plan to continue using this solution if an opportunity is there. It depends on the customer's requirements. If a customer is going for an online e-commerce website, we would always recommend going with Fortinet FortiWeb. 

I would rate Fortinet FortiWeb an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Fortinet FortiWeb
June 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
GRC Security Consultant at Ionize
Consultant
This flexible suite solves compliance problems but that comes at a cost
Pros and Cons
  • "If I need something from tech support, I can get it answered within the hour."
  • "Both the internal firewall management and the cloud can be managed by a single console."
  • "It costs too much."
  • "It is not entirely user-friendly."

What is our primary use case?

Normally I deal with on-premises installations. The firewalls are always on-prem for government departments. In a recent case, I was looking at a cloud solution because it was what the client preferred. So it was the Fortinet rules applied to an AWS solution. I was looking at the architecture around becoming an IRAP (Information Security Registered Assessors Program) certified program and I was looking at the AWS firewalls around how it would be able to comply with the ISM (International Safety Management) standards.  

What is most valuable?

For me personally, the most valuable thing is that I like the fact that it is standardized so both internal firewall management and the cloud can be managed by the same company. Communication between the two works well and it can be a benefit. We can keep a single console to manage both.  

What needs improvement?

User administrative controls could be a little bit better. I guess that would be the main thing. The usability within Fortinet could be a little bit easier on the users. But it is what it is.  

The thing that was more difficult was not the tool itself but dealing with the logistics of the compliance issues. I was applying a standard set of rules to an AWS firewall. It served a purpose. The complex part of the solution was more of a compliance issue.  

For how long have I used the solution?

We have been using Fortinet FortiWeb probably for over a year-and-a-half. Closer to two years.  

What do I think about the scalability of the solution?

At this point in time, scalability seems to be fine. I mean, we are talking processing requests from all over Australia. It seems to be keeping up quite well. My impression of it at this stage is that it is very scalable. It is quite well suited for data management.  

How are customer service and technical support?

I think judging our experience with technical support is a little bit unfair because I know all the local support people. I do go into the help desk when I have to, but I do know most of the teachers or technical support staff. I would rate them as being very responsive to customers. I have had no issues. If I need something I can get it answered within the hour. It is quite good.  

How was the initial setup?

It was quite easy to do the initial setup and apply basic rules. Administratively, keeping an AWS firewall and applying the Fortinet rules made it quite simple for the difficulty level of this particular requirement.  

What's my experience with pricing, setup cost, and licensing?

I think that ForiWeb is expensive for what they are offering. At the end of the day, when you sell a suite, compliance within the suite is easy to maintain. That is the good part. It is an expensive suite and it is an expensive solution, but it is a manageable one for an enterprise. It should just be cheaper for what they are offering in comparison to other tools on the market.  

What other advice do I have?

My advice to people would be to evaluate the marketplace against your requirements and choose appropriately. Fortinet does operate at the enterprise level. It is listed on the Australian standard and it does carry Australia's approval for common criteria. So it does address the requirements needed for security for the assessments. Not every product can.  

On a scale from one to ten (where one is the worst and ten is the best), I would rate this Fortinet solution as a seven-out-of-ten because of user administrative controls, usability, and price.  

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer890208 - PeerSpot reviewer
Information Security Specialist at a financial services firm with 201-500 employees
Real User
Efficient, stable, and has good IP reputation features, but there are many false positive with the layer 7 attacks
Pros and Cons
  • "It's stable and works efficiently against OWASP Top 10 attacks."
  • "The Layer 7 DDoS attacks need improvement, it could be better."

What is our primary use case?

Fortinet FortiWeb is known for its web application firewalls. We are using it for preventing and detecting layer 7 attacks such as SQL injection.

We have several web applications in our organization and we use this solution to protect them against attacks.

What is most valuable?

It's stable and works efficiently against OWASP Top 10 attacks.

It's good at checking IP reputation and it's capable of detecting Layer 7 DDoS attacks.

Overall, it has many features.

What needs improvement?

The Layer 7 DDoS attacks need improvement, it could be better. When you compare it with the F5 solution, FortiWeb is weak in detecting the Layer 7 DDoS attacks. At times, it generates several false positives and there should be fewer.

In the next release, I would like to see better DDoS protection. It's an essential feature that should be included.

For how long have I used the solution?

I have been using Fortinet FortiWeb for more than five years.

We are using the 4000D model.

What do I think about the stability of the solution?

It's a stable solution and we run it 24/7. In the past five years, we have had four cases where there were some inconsistencies with the firmware. There are times where we experience crashes because of issues with the firmware.

What do I think about the scalability of the solution?

It's not easy to scale this solution. It has a determined throughput and if your throughput is more than it should be then you have to use another solution or purchase another FortiWeb model.

We have less than 10 people using this solution on a daily basis.

How are customer service and technical support?

We are not able to use international support because of US sanctions. We use a consultant to help us troubleshoot.

Which solution did I use previously and why did I switch?

Previously with another company, we used ModSecurity, which is an open-source solution. FortiWeb is better.

If I compare with F5 solutions, I would suggest F5.

How was the initial setup?

The initial setup was not easy but not exactly complex.

We maintain the system ourselves.

What about the implementation team?

We completed the initial setup ourselves and we had a consultant help us with some of the features. It was a hybrid implementation.

What's my experience with pricing, setup cost, and licensing?

It's an expensive solution, although there are no additional costs.

What other advice do I have?

In my opinion, F5 is the best solution in the world, whereas Fortinet FortiWeb would be second.

I have heard that Barracuda is a good solution, but I have not worked with it. In my experience, F5 is the better solution.

I would rate Fortinet FortiWeb a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Data Center Network Expert at TOSAN
Real User
User-friendly and makes it easy to find vulnerabilities
Pros and Cons
  • "This product is very user-friendly."
  • "FortiWeb needs to have support for the newest technology being used in web applications."

What is our primary use case?

We are using FortiWeb for publishing web services and some web applications.

What is most valuable?

The interface makes it easy to identify vulnerabilities.

The best features for us are the signature services. The devices uses signatures for identifying vulnerabilities in web applications.

This product is very user-friendly.

The security is very good.

What needs improvement?

FortiWeb needs to have support for the newest technology being used in web applications. For example, some companies have developed new features using the latest technology, but we are still waiting for Fortinet to support them.

For how long have I used the solution?

I have been using FortiWeb for between four and five years.

What do I think about the stability of the solution?

The stability is very good and we're fortunate that we haven't had any issues.

What do I think about the scalability of the solution?

We have had no issues with scalability.

How are customer service and technical support?

We are in Iran and working under sanctions, which means that we cannot buy new American products and cannot get support. Companies usually buy devices that are second hand, or from a third-party, neither of which have support.

That said, my impression is that the support is good for companies who are eligible to use it.

How was the initial setup?

The initial setup was not complex. Like all Fortinet devices, it is user-friendly.

What's my experience with pricing, setup cost, and licensing?

Due to the situation in Iran with the sanctions, the price of this solution is very expensive.

Which other solutions did I evaluate?

The only other two web application firewall products that are available in my country are F5 and Imperva.

What other advice do I have?

This is a good product and I strongly recommend it, especially for companies in the banking industry.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Cyber Security Engineer at Mudra Electronics limited
Real User
Top 5
Has a user-friendly dashboard, but its technical support services need improvement
Pros and Cons
  • "The product has a very user-friendly dashboard."
  • "The product's scalability could be better."

What is our primary use case?

We use FortiWeb for protecting web applications.

What is most valuable?

The product has a very user-friendly dashboard.

What needs improvement?

The software's support services could be better compared to Sophos.

What do I think about the scalability of the solution?

The product's scalability could be better compared to Sophos.

How are customer service and support?

It is challenging to communicate with the FortiWeb's support team.

Which solution did I use previously and why did I switch?

We use Sophos as well.

How was the initial setup?

FortiWeb's configuration process is more difficult than Sophos. I rate the process a one out of ten.

What's my experience with pricing, setup cost, and licensing?

The product is expensive. I rate the pricing a ten out of ten.

What other advice do I have?

I rate FortiWeb a five out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Soroush-Enayati - PeerSpot reviewer
Network security engineer at freelancer
Real User
Great machine learning, artificial intelligence and behaviour detection
Pros and Cons
  • "It helps us prevent attacks on servers."
  • "The initial setup is complex."

What is our primary use case?

It helps us prevent attacks on servers, and we deploy it on-premises.

What is most valuable?

There are many valuable features. It has machine learning, artificial intelligence, behaviour detection, and many other features capable of detecting web attacks.

What needs improvement?

The initial setup could be simplified.

For how long have I used the solution?

We have been using the solution for approximately ten years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

We do not have experience with customer service and support.

How was the initial setup?

The initial setup is complex and takes between three to six months.

What about the implementation team?

We implemented the solution in-house.

What's my experience with pricing, setup cost, and licensing?

Fortinet FortiWeb has some types of licenses, and the main licenses refer to updating a signature and a pattern.

Which other solutions did I evaluate?

We evaluated machine learning and the main signatures about known attack signatures.

What other advice do I have?

I rate the solution a ten out of ten, and I recommend it for every organization with web services.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
willie.Na. - PeerSpot reviewer
System Engineer at Trans Business Machines Ltd
Real User
Easy to scale in terms of learning and utilization with a user-friendly GUI
Pros and Cons
  • "The GUI makes it easy to scale in terms of learning and utilization."
  • "Lacks functionalities that are available in other solutions."

What is our primary use case?

We use this product for load balancing and for their firewall. We are partners with Fortinet. 

What is most valuable?

I like that the GUI makes it easy to scale in terms of learning and utilization.
We chose this solution based on the online training and materials they offered. It's easily available on the web. 

What needs improvement?

There are specific functionalities that I'd like to see improve and that would basically bring it into line with what is being offered by solutions such as F5 and Imperva.

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

This is a stable solution. 

How was the initial setup?

The initial setup is straightforward, the deployment took us about two hours. We currently have 16 users. 

What other advice do I have?

I rate this solution seven out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros sharing their opinions.