We use FortiWeb Web Application Firewall for security features while working in the financial area.
External reviews
External reviews are not included in the AWS star rating for the product.
I have 2 project experiences using Fortinet Managed Rules for AWS WAF with API Gateway
Compliance: If your application needs to meet specific compliance requirements, such as PCI DSS or HIPAA, Fortinet Managed Rules can help you meet those requirements by providing a set of security rules and configurations that align with industry standards.
Simplified Implementation: Fortinet Managed Rules offer an easy-to-use solution for adding security to your applications. The rules are designed to integrate seamlessly with AWS API Gateway, making it convenient for .NET developers to implement and manage security measures without extensive manual configuration.
Time and Cost Savings: By leveraging Fortinet Managed Rules, you can save time and effort in implementing and maintaining custom security rules. The pre-configured rules provided by the service eliminate the need for you to create and manage complex rule sets from scratch, potentially reducing development and maintenance costs.
Overall, Fortinet Managed Rules for AWS WAF - API Gateway is solving security-related problems that can benefit .NET developers by providing an easy-to-use, pre-configured solution that enhances the security of their web applications running on AWS API Gateway, while also potentially saving time and cost.
Strict rules for adequate security
fortinet is good
Provides efficient integration features and has good scalability
What is our primary use case?
What is most valuable?
The product has good integration features.
What needs improvement?
The product's integration with Cisco needs improvement.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall for 30 years.
What do I think about the stability of the solution?
The platform's stability is good, with good assessment and low-level design.
What do I think about the scalability of the solution?
FortiWeb Web Application Firewall's scalability is good.
Which solution did I use previously and why did I switch?
I have used Palo Alto and Check Point before.
How was the initial setup?
The product is complicated to set up. The deployment time depends on the customer. Some customers have a deployment time of six to seven months, while others have a deployment time of two months. The process involves an assessment for a month, then a low-level design for another month.
What's my experience with pricing, setup cost, and licensing?
FortiWeb has a good presence because of its price.
What other advice do I have?
We are integrators with all the product certifications. We have a good team. We prefer assessment and low-level design before starting with the project.
I rate FortiWeb Web Application Firewall an eight out of ten.
AWS WAF managed services rules
A cost-effective firewall that remains stable while providing security to its users
What is our primary use case?
In my company, we use FortiWeb Web Application Firewall (WAF) for security.
What is most valuable?
FortiWeb is a small tool that can be used by those of our customers who use Fortinet FortiGate as their firewall. I will use Barracuda Email Protection for any customer who uses a firewall from a solution provider other than Fortinet FortiGate.
What needs improvement?
The product lacks features offered by enterprise-level firewall tools. The solution needs to offer more enterprise features like other brands.
It would be great if FortiWeb Web Application Firewall (WAF) had something like a wizard to allow for more integrations with other popular firewall products like Fortinet, Palo Alto, and so on.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall (WAF) for three years. I use the solution's latest version.
What do I think about the stability of the solution?
Stability-wise, I rate the solution a nine out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution an eight out of ten.
There are 2,000 users of the solution in my company.
How are customer service and support?
The solution's technical support was helpful and responsive. I rate the technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have previously used SonicWall.
How was the initial setup?
The initial setup was easy since it was possible to get remote support for the product.
The solution is deployed on-premises.
What's my experience with pricing, setup cost, and licensing?
It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee.
What other advice do I have?
There are five engineers needed for the maintenance of the solution.
If there is a requirement and one is already using a firewall from Fortinet, then it is easier to deploy FortiWeb Web Application Firewall (WAF). Overall, I rate the solution an eight out of ten.
A low-maintenance software with machine learning features aiding small-enterprise users
What is our primary use case?
In most cases, the customer uses WAF to protect web applications.
What is most valuable?
The machine learning on FortiWeb WAF is valuable. It is useful for new customers because it provides new signatures, and machine learning, which can help provide new information to customers about their websites.
What needs improvement?
WAF needs more signatures on FortiWeb and updates the database continuously to protect against new attacks. I hope the next release includes integration with the vulnerability scanner, a great feature of FortiWeb. If customers have vulnerability scanners, they can export the scan's result and post it to FortiWeb to patch completely.
For how long have I used the solution?
I have been working with FortiWeb WAF for four years. We are working with the latest version.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is not scalable. If you are running medium-sized hardware, you must upgrade and purchase new hardware. Fortinet has an issue with scalability at this point.
How are customer service and support?
I have received fantastic support.
How was the initial setup?
The initial setup and config are a piece of cake. The steps followed during deployment depend on the customer since not all customers have the same deployment phases. We guide deployment depending on the customer's needs. Most of the time I have deployed FortiWeb, it took one month. We needed to boot up vulnerability and configure security controls on each website. After that, the administrator on the customer's side will continue working with FortiWeb.
Maintenance is easy because WAF has a powerful view of logs.
What's my experience with pricing, setup cost, and licensing?
Fortinet has a single license, and it's easy to deploy the license and doesn't take time to retrieve it. WAF is just plug-and-play, unlike other vendors. WAF wins this point. FortiWeb WAF is priced well for customers compared to other vendors' solutions.
Which other solutions did I evaluate?
I also work with F5 Networks. The comparison is a little bit complicated. Depending on the customer's needs, we do not recommend deploying F5 in a small environment. F5 needs a lot of administrators and an IT department. On the other hand, Fortinet will be better in this situation. We need a few people to support WAF. Otherwise, both vendors are perfect.
What other advice do I have?
If you plan to deploy FortiWeb, you must have the right device to achieve high availability. I rate FortiWeb WAF a ten out of ten.
The solution blocks attacks from application layers and protects websites from injection attacks
What is our primary use case?
We use FortiWeb Web Application Firewall to protect websites from injection attacks.
What is most valuable?
FortiWeb Web Application Firewall blocks attacks from application layers and provides protection.
What needs improvement?
FortiWeb Web Application Firewall's signature database updates could be improved.
For how long have I used the solution?
I have been using FortiWeb Web Application Firewall for one year.
What do I think about the stability of the solution?
I rate FortiWeb Web Application Firewall an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate FortiWeb Web Application Firewall a nine out of ten for scalability. Around 10 to 12 users use the solution in our organization.
How are customer service and support?
The solution’s customer support is not good.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup is easier than other products.
What about the implementation team?
It takes one week to deploy FortiWeb Web Application Firewall. As part of the deployment process, we create a FortiGate interface, connect FortiWeb to our website server, create virtual web servers in FortiWeb, and write some access control rules for protection purposes.
What's my experience with pricing, setup cost, and licensing?
FortiWeb Web Application Firewall's pricing is suited for small or medium organizations.
What other advice do I have?
FortiWeb Web Application Firewall is deployed on-cloud in our organization.
I recommend FortiWeb Web Application Firewall to other users because it helps block many attacks that come from the web and application layers. Using the solution to protect organizations from attacks is an easy process.
Overall, I rate FortiWeb Web Application Firewall a nine out of ten.
Better than other API gateways as kong
It offers the level of security we need at a good price point
What is our primary use case?
We use FortiWeb as our web application firewall.
How has it helped my organization?
FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient. FortiWeb enables us to streamline tasks. It's a robust solution that's effortless to configure. The AI and machine learning features help us block unknown threats.
We can bring our web applications online faster because FortiWeb shortens the time needed to bring any application into production. Compared to other application firewalls, FortiWeb has a smoother process for bringing applications online.
FortiWeb has few false positives. It's more accurate than other solutions, so we also see fewer alerts. FortiWeb has helped free up IT staff for other projects. You don't need to spend much time getting applications ready for the web, so IT staff can use this time to manage other things.
What is most valuable?
The AI engine and machine learning features distinguish FortiWeb from other solutions. It has a robust UI. FortiWeb is solidly accurate and provides excellent protection against zero-day attacks using machine learning. It appears to be effective because we've never experienced a breach from a zero-day attack.
We use almost all of the features, including analytics, malware detection, bot mitigation, and API discovery.
What needs improvement?
I think customers have the impression that FortiWeb is primarily for SMEs, but FortiWeb should work to expand its market share and adjust its branding. F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented.
For how long have I used the solution?
We have used FortiWeb for around a year.
What do I think about the stability of the solution?
FortiWeb is highly stable. We haven't seen any bugs. The solution is reliable once configured properly.
What do I think about the scalability of the solution?
FortiWeb isn't difficult to scale.
How are customer service and support?
I rate Fortinet support six out of 10. The documentation and support need improvement.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used Citrix WAF and the F5. FortiWeb offers most of the same features at a better price.
How was the initial setup?
I have done on-prem, hybrid, and cloud deployments of FortiWeb. The deployment was straightforward for most features, but a few features require some customization and configuration in the console. That's where we ran into problems because the documentation isn't thorough in some areas.
It takes around three or four days to deploy FortiWeb for a simple website. It takes longer for a complex website, but it depends on the level of complexity. We deployed FortiWeb in-house with two people and some help from Fortinet support. It's deployed across multiple data centers and locations.
What was our ROI?
The price-performance ratio is good. The time to value is quick because it's easy to deploy and the ML engine doesn't take long to adjust and apply the correct rules.
What's my experience with pricing, setup cost, and licensing?
FortiWeb offers these services at a price that SME customers can afford, but it's also suitable for large enterprises. Still, they need to put in more work to gain a greater share of enterprise business because they face stiff competition in this segment from F5, Cloudflare, and some others.
What other advice do I have?
I rate Fortinet FortiWeb eight out of 10. FortiWeb is a suitable product for SMEs. I recommend a proof of concept before going forward with any project.