We use FortiWeb as our web application firewall.
Fortinet Managed Rules for AWS WAF - API Security
Fortinet Inc.External reviews
External reviews are not included in the AWS star rating for the product.
It offers the level of security we need at a good price point
What is our primary use case?
How has it helped my organization?
FortiWeb provides the level of security we need at an excellent price point. It's easy to deploy and operationally efficient. FortiWeb enables us to streamline tasks. It's a robust solution that's effortless to configure. The AI and machine learning features help us block unknown threats.
We can bring our web applications online faster because FortiWeb shortens the time needed to bring any application into production. Compared to other application firewalls, FortiWeb has a smoother process for bringing applications online.
FortiWeb has few false positives. It's more accurate than other solutions, so we also see fewer alerts. FortiWeb has helped free up IT staff for other projects. You don't need to spend much time getting applications ready for the web, so IT staff can use this time to manage other things.
What is most valuable?
The AI engine and machine learning features distinguish FortiWeb from other solutions. It has a robust UI. FortiWeb is solidly accurate and provides excellent protection against zero-day attacks using machine learning. It appears to be effective because we've never experienced a breach from a zero-day attack.
We use almost all of the features, including analytics, malware detection, bot mitigation, and API discovery.
What needs improvement?
I think customers have the impression that FortiWeb is primarily for SMEs, but FortiWeb should work to expand its market share and adjust its branding. F5 and some other firewalls are easier to customize. FortiWeb could be more flexible and customizable. The documentation could also be improved because many of the advanced features aren't fully documented.
For how long have I used the solution?
We have used FortiWeb for around a year.
What do I think about the stability of the solution?
FortiWeb is highly stable. We haven't seen any bugs. The solution is reliable once configured properly.
What do I think about the scalability of the solution?
FortiWeb isn't difficult to scale.
How are customer service and support?
I rate Fortinet support six out of 10. The documentation and support need improvement.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used Citrix WAF and the F5. FortiWeb offers most of the same features at a better price.
How was the initial setup?
I have done on-prem, hybrid, and cloud deployments of FortiWeb. The deployment was straightforward for most features, but a few features require some customization and configuration in the console. That's where we ran into problems because the documentation isn't thorough in some areas.
It takes around three or four days to deploy FortiWeb for a simple website. It takes longer for a complex website, but it depends on the level of complexity. We deployed FortiWeb in-house with two people and some help from Fortinet support. It's deployed across multiple data centers and locations.
What was our ROI?
The price-performance ratio is good. The time to value is quick because it's easy to deploy and the ML engine doesn't take long to adjust and apply the correct rules.
What's my experience with pricing, setup cost, and licensing?
FortiWeb offers these services at a price that SME customers can afford, but it's also suitable for large enterprises. Still, they need to put in more work to gain a greater share of enterprise business because they face stiff competition in this segment from F5, Cloudflare, and some others.
What other advice do I have?
I rate Fortinet FortiWeb eight out of 10. FortiWeb is a suitable product for SMEs. I recommend a proof of concept before going forward with any project.
Awesome Network visibility
The Great AWS WAF
1. very less threat
2. Reduced attacks
3. protection from web-based malware sites.
Great Ruleset to Protect Application from OWASP top 10
This ruleset is an excellent tool that we can use on AWS WAF to protect Applications easily from OWASP top 10 attacks.