Listing Thumbnail

    Fortinet FortiWeb Web Application Firewall WAF VM (BYOL)

     Info
    Deployed on AWS
    AWS Free Tier
    FortiWeb web application firewall defends your web applications and APIs, leveraging AI-based machine learning that models your applications and APIs to block malicious anomalies, control bot traffic, and identify the most important threats.
    4.4

    Overview

    FortiWeb WAF defends your web applications and APIs using a multi-layered approach that intelligently and accurately protects your web applications from the OWASP Top 10 threats and more, without creating excess administrative overhead that can slow down deployment of your most critical line-of-business applications. Using AI-based machine learning, FortiWeb continuously and automatically models your application's behavior to:

    • Identify and block malicious behavior
    • Discover and protect exposed web APIs
    • Identify and control bot traffic
    • NEW identify attack patterns across your entire web application attack surface and aggregate them into security incidents across all FortiWeb and FortiWeb Cloud protected applications in a single Threat Analytics Dashboard (when you purchase the Advanced Bundle*) so that SOC analysts can focus on the threats that matter most. Combined with Fortinet Web Application Security Service from FortiGuard Labs, FortiWeb keeps your applications safe from vulnerability exploits, bots, malware uploads, DoS attacks, advanced persistent threats (APTs), and zero day attacks.

    Highlights

    • EFFECTIVE and ACCURATE protection that leverages machine learning to identify and block malicious behavior, discover and protect exposed web APIs, and identify and control bot traffic while minimizing the false positives that drive administrative overhead
    • INTEGRATED with FortiGate, FortiSandbox, and leading third-party vulnerability scanners for enhanced zero-day threat protection and virtual application patching
    • *NEW* ADVANCED THREAT ANALYTICS that help your SOC analysts focus on the threats that matter most by using the Threat Analytics Dashboard to identify attack patterns across all your cloud and on-prem deployments

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 8.0.4

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet FortiWeb Web Application Firewall WAF VM (BYOL)

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    BYOL, work directly with your Fortinet or Fortinet authorized channel account team.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    After deploying the instance, click on 'Manage in AWS Console' to see the running instance and public DNS address to continue the configuration of the FortiWeb-VM. Connect to the secured Web UI via the public DNS address: https://Public  DNS:8443. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of "admin" and the AWS Instance ID value as the password. The FortiWeb-VM Install and Configure guides are at https://docs.fortinet.com/document/fortiweb-public-cloud/latest/deploying-fortiweb-vm-on-aws-ec2/872945/creating-virtual-private-cloud-vpc . For the full FortiWeb Administrator Guide, please refer to Fortinet documentation: https://docs.fortinet.com/product/fortiweb 

    Support

    Vendor support

    ortinet FortiCare Support Services give you global support on a per-product basis. By subscribing to these services, you'll receive a timely response to any technical issue as well as complete visibility on ticket resolution progress. All FortiCare Support Services include firmware upgrades, access to the support portal and associated technical resources. FortiGuard Security Services include up-to-the minute threat intelligence delivered in real time to stop the latest threats.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.4
    30 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    63%
    37%
    0%
    0%
    0%
    0 AWS reviews
    |
    30 external reviews
    External reviews are from G2 .
    Mansi S.

    Robust Protection with Room for UI Improvement

    Reviewed on Feb 13, 2026
    Review provided by G2
    What do you like best about the product?
    I like the FortiAppSec Cloud's clean dashboard, which lets me quickly understand what’s happening without digging through endless logs. I also appreciate that I can log in and immediately see what types of attacks are being blocked, where traffic is coming from, and whether there are any unusual spikes. It's our security shield in front of our applications.
    What do you dislike about the product?
    The UI is clean overall, but sometimes when you're trying to troubleshoot something specific, you have to click around more than you'd like. A more straightforward log search or clearer explanations inside the dashboard would help. The UI is not customizable as well. I would love to see that option.
    What problems is the product solving and how is that benefiting you?
    I use FortiAppSec Cloud as a security shield for our web apps and APIs, providing deep visibility into traffic, reducing bot activity, preventing web attacks, and simplifying security reporting.
    Shiv A.

    Strong Security but Initial Setup Woes

    Reviewed on Feb 11, 2026
    Review provided by G2
    What do you like best about the product?
    I think the automatic security and centralized dashboard in FortiAppSec Cloud are pretty good. It's easy to integrate with Fabric, which is helpful, and it's pretty fast and easy to deploy and scale. The automatic security reduces manual rule tuning, and the centralized dashboard improves visibility and response time. The Fabric integration allows automated threat sharing across network and application layers, which improves both security posture and operational efficiency and also improves application latency.
    What do you dislike about the product?
    The initial configuration and setup for complex rules can be tricky, which is challenging for first-time users. Also, the UI and UX could be improved, particularly with richer incident storytelling like timeline-based views and smarter risk scoring. Sometimes, there's a bit of performance issue during peak traffic, and there's a lack of detailing in incident reports.
    What problems is the product solving and how is that benefiting you?
    I use FortiAppSec Cloud to reduce bot traffic, prevent API abuse, and protect from DDoS attacks and credential stuffing. It reduces manual rule management, improves visibility, and enhances security posture and operational efficiency.
    Manav S.

    Centralized Threat Management, Easy Setup

    Reviewed on Feb 11, 2026
    Review provided by G2
    What do you like best about the product?
    I use FortiAppSec Cloud to secure and monitor our web applications and APIs. It helps us detect vulnerabilities, manage security policies, and maintain visibility into potential threats in our cloud environment. FortiAppSec Cloud centralizes monitoring, improves alerting, and helps us respond to risks more efficiently. One of the best features is its centralized board and control center, which offers a consolidated view of application health, threat activity, and policy status in one place. This allows me to quickly see recent alerts, traffic patterns, and any flagged vulnerabilities from a single screen. The initial setup was pretty easy.
    What do you dislike about the product?
    I think the personalized UI could be improved. I would like to be able to change the data into a format I like, including the color scheme.
    What problems is the product solving and how is that benefiting you?
    I use FortiAppSec Cloud to secure and monitor our web applications and APIs, centralizing monitoring and improving alerting. It solves the problem of requiring multiple tools and manual effort. I appreciate the consolidated view of application health, threat activity, and policy status from a single dashboard.
    Information Technology and Services

    Robust WAF Security and Bot Mitigation in a Single Console

    Reviewed on Feb 10, 2026
    Review provided by G2
    What do you like best about the product?
    I evaluated it for WAF solution & liked it's security, bot mitigation measures, & everything security under single console. I particularly liked how it's designed to handle coming of age security threats, with agentic AI proliferation.
    What do you dislike about the product?
    I felt there are improvements possible in it's overall UI/UX experience & onboarding flows, making it a li'll more intuitive & performant will help smoothen the experience
    What problems is the product solving and how is that benefiting you?
    I like the strong AI driven security approach in its solution & offerings, allowing teams to focus on business problems, modernize their infrastructure with least worries about it's security.
    Ritika K.

    Easy Web and API Security at Scale

    Reviewed on Feb 09, 2026
    Review provided by G2
    What do you like best about the product?
    The ease of use and the way it can protect applications and APIs effectively while aggregating all logs into one system that requires little maintenance.
    What do you dislike about the product?
    Greater reporting and analytics capabilities (more customization, flexibility). Would help with visibility/troubleshooting.

    No big problems reported so far, but the product could be a bit more user-friendly and have better reporting.
    What problems is the product solving and how is that benefiting you?
    FortiAppSec Cloud offers an answer to the problem of securing web applications and APIs against modern threats, including OWASP Top 10 attacks, bots, and abuse – without increasing operational complexity. To that end, it helps us in mitigating risk, simplifying security administration and increasing visibility of apps.
    View all reviews