Fortinet FortiWeb Web Application Firewall WAF (PAYG)
Firewall protection has secured our customer portal and provides long-term peace of mind
What is our primary use case?
I use the solution as a firewall for our customer portal.
How has it helped my organization?
The solution provides peace of mind with website protection.
What is most valuable?
The solution offers IP Protection, which I find very valuable.
What needs improvement?
There is room for improvement in providing better access to updates, more seamless renewals, and the ability to rename objects.
For how long have I used the solution?
I have used the solution for 12 years.
Which solution did I use previously and why did I switch?
I did not use any previous solutions.
How was the initial setup?
Inital setup was fairly involved, requiring multiple sessions with Fortinet support.
What's my experience with pricing, setup cost, and licensing?
It is probably best to bring your own license (BYOL).
Which other solutions did I evaluate?
I did not consider any alternate solutions.
What other advice do I have?
The renewals are not seamless, and although updates are advertised via email from AWS, actual software updates require contacting support for access.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Easy-to-Implement AppSec with Strong Signature Detection, Bot Protection, and Cloud Integration
Its Signature based detection and Advanced Bot protection defn needs a praise.
Synthetic Testing, Fabric Connector options really put forti's Appsec in driver position.
Its very easy implementation, to use and configuration and integration with cloud (AWS & Azure market place pfferings) comes in handy.
Reporting is some what limited which we got to knwo during our training and it pretty much remained the same today.
Because of its powerful and multi option features, it covers all ur firewall needs not just for our application but DNS, ELB's nd other API security needs as part of our hybrid security strategy
Streamlines Web Security but Needs UI Enhancements
Secure, User-Friendly with Great Support, Minor Lag Issues
Robust Protection with Room for UI Improvement
Strong Security but Initial Setup Woes
Centralized Threat Management, Easy Setup
Robust WAF Security and Bot Mitigation in a Single Console
Easy Web and API Security at Scale
No big problems reported so far, but the product could be a bit more user-friendly and have better reporting.
Integration with existing infrastructure has improved efficiency and centralized management
What is our primary use case?
The main use case for Fortinet FortiWeb is handling huge amounts of data from the customer side when they lack proper data structure. Customers request a solution that can manage large volumes of data and classify it, which is the primary reason they select Web Application Firewalls.
Additionally, they seek to protect and separate applications within their network between production and non-production environments, as well as define bandwidth allocation for approved applications and restrict forbidden ones.
What is most valuable?
Fortinet does not have the best Web Application Firewall in the world, but they do have interoperable systems. From the customer side, especially if they are already buying FortiGates, firewalls, mail, proxy, and other solutions, it becomes much easier for them to purchase Fortinet FortiWeb. This is because there is one technical support team and a single point of contact from the vendor side when they need technical expertise.
The main benefits provided to users who already have other Fortinet solutions include better economics and easier maintenance due to unified technical support and a convenient single point of contact. Updates are much easier because Fortinet has one operating system for all their products. If the customer buys a manager as the central console of the whole system, they can operate all systems from one console and deploy all updates, renewals, or other changes.
What needs improvement?
Fortinet can improve their technical support, especially the response time. There appears to be an issue with their SLA. When a customer opens a ticket, it is picked up within one or two hours. However, after the customer submits a specific question and requests troubleshooting help from Fortinet support, it takes at least three to five days to provide a proper answer. The response time from the support team is an area that requires improvement.
For how long have I used the solution?
We are a distributor and I continue to work with Fortinet solutions as a reseller distributor.
What do I think about the stability of the solution?
I have not received any complaints or reports of issues from our partners or our technical team regarding stability. Perhaps three or four years ago there was an incident at a customer site in Serbia, but that was not related to Fortinet. The issue was related to network segmentation because they could not reach all logs from their network. The problem was not from Fortinet but from the Cisco ASA, not the switch.
What do I think about the scalability of the solution?
For scalability on a scale from one to ten, Fortinet FortiWeb is very scalable and it is easy to improve the bandwidth and the system. You can add additional boxes that combine together to achieve a bigger throughput for investigation and research.
How was the initial setup?
I have not received any complaints from the partner side regarding troubles or issues with implementation. The implementation of Fortinet FortiWeb and WAF into the Fortinet ecosystem proceeded very smoothly.
What about the implementation team?
That is a question for the technical part of my team and is not within my area of responsibility.
What other advice do I have?
We primarily sell Fortinet's flagship model, which is FortiGate, their next-generation firewall. After that, we sell switches, wireless devices, and solutions such as mail, web protection, and EDR. These are the most sold products in Serbia from Fortinet's portfolio.
We have recently closed a deal in Serbia with Fortinet FortiWeb.
The documentation is excellent, particularly the implementation manual. The pricing is very competitive compared to most vendors producing similar solutions. When comparing Fortinet FortiWeb to F5 BIG-IP, which is their matching solution, Fortinet FortiWeb uses smaller boxes while meeting the same technical specifications. This automatically makes Fortinet FortiWeb cheaper than F5. F5 is considered the most sold vendor in this area for Web Application Firewalls globally, and Fortinet FortiWeb offers better pricing in comparison. I would rate this product a ten out of ten.