We use FortiWeb Web Application Firewall to protect websites from injection attacks.
Information Security Engineer at a tech services company with 201-500 employees
The solution blocks attacks from application layers and protects websites from injection attacks
Pros and Cons
- "FortiWeb Web Application Firewall blocks attacks from application layers and provides protection."
- "FortiWeb Web Application Firewall's signature database updates could be improved."
What is our primary use case?
What is most valuable?
FortiWeb Web Application Firewall blocks attacks from application layers and provides protection.
What needs improvement?
FortiWeb Web Application Firewall's signature database updates could be improved.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall for one year.
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate FortiWeb Web Application Firewall an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate FortiWeb Web Application Firewall a nine out of ten for scalability. Around 10 to 12 users use the solution in our organization.
How are customer service and support?
The solution’s customer support is not good.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup is easier than other products.
What about the implementation team?
It takes one week to deploy FortiWeb Web Application Firewall. As part of the deployment process, we create a FortiGate interface, connect FortiWeb to our website server, create virtual web servers in FortiWeb, and write some access control rules for protection purposes.
What's my experience with pricing, setup cost, and licensing?
FortiWeb Web Application Firewall's pricing is suited for small or medium organizations.
What other advice do I have?
FortiWeb Web Application Firewall is deployed on-cloud in our organization.
I recommend FortiWeb Web Application Firewall to other users because it helps block many attacks that come from the web and application layers. Using the solution to protect organizations from attacks is an easy process.
Overall, I rate FortiWeb Web Application Firewall a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Consultant at a computer software company with 51-200 employees
Reliable with a good sandbox feature and good protection against security threats
Pros and Cons
- "The solution has a good sandbox feature."
- "It can be better with web application firewalls."
What is our primary use case?
FortiWeb is an application firewall. We deployed it as a web application firewall for our 16-plus web applications. We integrate this with Fortigate and the FortiSandbox, and all the applications we are hosting in the data center.
How has it helped my organization?
With the feat of cyber attack, the most important thing we can do is protect the web application. We can protect it from attacks like DDoS. It's helping to maintain our cyber security posture.
What is most valuable?
The most valuable product feature is the web application firewall. It still includes the inline. Its mode of operation is great. It comes with four modes of operation, reverse proxy, two transplant nodes, and WCCP. One node is there for transplant, just to have one more. Any customer, based on their network of topology and deployment type, can choose it and have an easy deployment.
The solution has a good sandbox feature.
It is stable.
What needs improvement?
It can be better with web application firewalls.
It is already close to the best in class. This product is up to the mark right now.
For how long have I used the solution?
I've used the solution for around three years.
What do I think about the stability of the solution?
This is a stable, reliable solution. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
Capacity-wise, since there is hardware involved, it cannot scale too much. There are some technical limitations.
We have around 2,000 users right now.
We do not have plans to increase usage in the future.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
How easy or difficult the implementation is depends on the deployment type. It is very easy if you employ reverse proxy. However, it can be a little complex depending on what you need to do.
There was a team that helped deploy the solution, however, for maintenance, you only need one network security engineer.
What about the implementation team?
We used a third party to assist us with the setup.
What was our ROI?
We have witnessed an ROI. I'd rate the level of ROI we've seen a four out of five as it helps mitigate cyber attacks.
What's my experience with pricing, setup cost, and licensing?
I'd rate the pricing at a four out of five in terms of affordability.
Which other solutions did I evaluate?
I'm exploring two or three products right now. We did not evaluate anything before choosing this product.
What other advice do I have?
I highly recommend that any web application firewall be deployed in the IT infrastructure where companies host web applications. It should be there. Whatever you choose should integrate with a third-party load balancer.
I'd rate the solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiWeb
December 2025
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,310 professionals have used our research since 2012.
General Manager at a tech services company with 11-50 employees
Good reporting and a nice user interface but can be a bit expensive
Pros and Cons
- "It can scale well."
- "The upgrade process could be a bit smoother."
What is most valuable?
The reporting available is pretty great.
We find the configuration capabilities to be very good.
Technical support is helpful.
It's stable.
It can scale well.
I like the user interface.
What needs improvement?
It's not the most popular option. Many clients prefer instead Citrix or Proxy Blue Coat. It might be a bit difficult to configure.
The upgrade process could be a bit smoother.
Sometimes the integration doesn't work on the first or second try.
The solution is a bit expensive.
For how long have I used the solution?
We first installed the solution eight or nine years ago. We've used it for almost a decade.
What do I think about the stability of the solution?
The solution is pretty stable. I'd rate it a three out of five in terms of stability. Sometimes the upgrades don't go as smoothly as we would like.
What do I think about the scalability of the solution?
The solution is scalable. I'd rate it four out of five in terms of how easy it is to expand the product.
How are customer service and support?
I can't complain about the technical support. They are pretty good. I found them to be helpful. However, it may depend on the engineer you get on the line.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup has a moderate level of difficulty.
We only need one person to deploy and maintain the product.
It takes about a week to have the entire solution set up.
What about the implementation team?
We install the solution for our clients.
What was our ROI?
It's always difficult to measure ROI when it comes to security. It's always just a smart investment for a company.
What's my experience with pricing, setup cost, and licensing?
The product can be costly.
The licenses are paid annually. You do have several licensing choices. They don't have too much choice. However, their options are good.
What other advice do I have?
We are not an end user. We are resellers.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network and Security Engineer at a financial services firm with 51-200 employees
Effective vulnerability scanner, highly stable, and low maintenance
Pros and Cons
- "The valuable feature of Fortinet FortiWeb vulnerability scanner"
- "Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company."
What is our primary use case?
We are using Fortinet FortiWeb to deliver service to our customers.
What is most valuable?
The valuable feature of Fortinet FortiWeb vulnerability scanner.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately 14 years.
What do I think about the stability of the solution?
The Fortinet FortiWeb is very stable.
What do I think about the scalability of the solution?
We did not have any problems with the scalability of Fortinet FortiWeb.
We have the development and network teams using the solution. It is approximately seven people in total.
How are customer service and support?
I did not use the support from Fortinet FortiWeb.
How was the initial setup?
The initial setup We Fortinet FortiWeb is straightforward. The full process of the deployment took approximately two weeks to 16 days.
What about the implementation team?
Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company.
What's my experience with pricing, setup cost, and licensing?
The license to use Fortinet FortiWeb is approximately $14,000.
I rate the price of Fortinet FortiWeb a four out of five.
What other advice do I have?
The solution does not require a lot of maintenance.
I would recommend this solution to others. If someone wants to use the internet with an application website or any other internet application, content filtering is very useful to filter all the requests that are coming to the server so that no one can hack or harm the system.
I rate Fortinet FortiWeb a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Specialist, IT Security at a financial services firm with 501-1,000 employees
Beneficial reports, reliable, and scalable
Pros and Cons
- "The most valuable feature of Fortinet FortiWeb is the reports and the AI-based features."
- "Fortinet FortiWeb could improve data integration."
What is most valuable?
The most valuable feature of Fortinet FortiWeb is the reports and the AI-based features.
What needs improvement?
Fortinet FortiWeb could improve data integration.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately six months.
What do I think about the stability of the solution?
Fortinet FortiWeb is a stable solution.
What do I think about the scalability of the solution?
The Fortinet FortiWeb is scalable.
We have three administrators using the solution and more than 300 end users using it.
How are customer service and support?
The support from Fortinet FortiWeb is good, but they could improve their response time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not use another solution prior to Fortinet FortiWeb.
How was the initial setup?
In the initial setup of Fortinet FortiWeb, we wanted to deploy it with WCCP mode, but we cannot do it because of the limitation with our Cisco ASA firewalls. It's difficult to integrate with FortiWeb. It is difficult to integrate Fortinet FortiWeb with other vendors other than Fortinet solutions. We cannot integrate it into our existing Cisco Firewall environment. We had to change the system to true transparent deployment mode.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb is expensive in our Ethiopian currency.
What other advice do I have?
I rate Fortinet FortiWeb a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Systems Engineer at a tech services company with 11-50 employees
Integrates well, excellent support, but reference architecture could improve
Pros and Cons
- "The most valuable feature of Fortinet FortiWeb is the ease of integration and configuration."
- "Fortinet FortiWeb could improve in reference architecture for different deployment scenarios."
What is our primary use case?
Fortinet FortiWeb was used to support mobile applications.
What is most valuable?
The most valuable feature of Fortinet FortiWeb is the ease of integration and configuration.
What needs improvement?
Fortinet FortiWeb could improve in reference architecture for different deployment scenarios.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately three years.
What do I think about the stability of the solution?
Fortinet FortiWeb is stable.
How are customer service and support?
The technical support from Fortinet FortiWeb is excellent.
Which solution did I use previously and why did I switch?
I have used many other solutions and I formally recommend NGINX. The challenge I have with NGINX is handing over the project to the end customer. The skillsets for managing NGINX as a WAF are a lot. This is what was drawing me towards F5. I wanted something that is seamless from end-to-end, for the customer.
The advantages of NGINX are that it's community-based, and you can get it anytime. Fortinet FortiWeb you have to go through a channel, there's an initial acquisition, and then the annual support which are things that we don't have to consider when we're dealing with NGINX.
How was the initial setup?
The initial setup of Fortinet FortiWeb was easy. The full implementation took approximately one week.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb depends from customer to customer because some customers are considering using other solutions, such as Imperva. The price of Fortinet FortiWeb sits well for the middle-sized customers that we deal with.
The price is based on our partner model, we are able to negotiate a good discount on GPR because we're also selling the firewall appliance.
What other advice do I have?
I rate Fortinet FortiWeb a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Manager at a construction company with 1-10 employees
Provides security and an easy setup, however scalability is a concern
Pros and Cons
- "The most important feature of this solution is protection from attack."
- "The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network."
What is our primary use case?
We use the solution to protect the various services of our site, E-commerce, file service, and download service.
What is most valuable?
The most important feature of this solution is protection from an attack.
What needs improvement?
The maintenance fee for this product could be improved and it needs to be easier to scale up.
For how long have I used the solution?
I have been using the solution for four to five years.
What do I think about the stability of the solution?
Stability is very important and yes, the product is stable.
What do I think about the scalability of the solution?
The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network.
How are customer service and support?
I would say technical support is good for this solution.
How was the initial setup?
Setup for this solution is easy, with one being easy and five being hard I would rate it a two out of five. Deployment took a few days.
What's my experience with pricing, setup cost, and licensing?
We have between 100 and 200 users of the solution in our company.
What other advice do I have?
I would rate the solution a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presale Engineer at a computer software company with 1,001-5,000 employees
Has excellent performance, pricing, and support services
Pros and Cons
- "The support services, performance, and pricing are all valuable features. The performance is excellent."
- "The initial setup process could be improved."
What is most valuable?
The support services, performance, and pricing are all valuable features. The performance is excellent.
What needs improvement?
The initial setup process could be improved.
For how long have I used the solution?
I've been working with this solution for two years.
It is deployed both on-premises and on the cloud.
What do I think about the scalability of the solution?
In general, we have small projects, so the scalability has been fine for our clients.
As for users, we have, in general, 50 to 100 clients.
How are customer service and support?
My colleagues at the network operations center have contacted technical support. I would rate technical support at eight on a scale from one to ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We sell and work with several options, but we feel comfortable with Fortinet FortiWeb because the performance and feedback are great.
How was the initial setup?
In general, the initial setup is easy, and I would rate it at four out of five.
What about the implementation team?
I deployed it myself.
What's my experience with pricing, setup cost, and licensing?
There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four.
I have not encountered any additional costs on my projects involving Fortinet FortiWeb.
What other advice do I have?
I sell or presell, and in general, the feedback is great. In fact, I think that Fortinet FortiWeb is number one in terms of performance.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
NetScaler
AWS WAF
Cloudflare Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Check Point CloudGuard WAF
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?


















