Fortinet Managed Rules for AWS WAF - Complete OWASP Top 10 logo

    Fortinet Managed Rules for AWS WAF - Complete OWASP Top 10

    The Complete OWASP Top 10 Ruleset delivers comprehensive web application protection to protect against the OWASP Top 10 web application threats

    Ratings and reviews

    4.1
    73 ratings
    2 star
    1 star
    31%
    58%
    11%
    0%
    0%
    15 AWS reviews
    |
    58 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (73)
    Prateek M.

    Easy, Reliable AWS WAF Protection with Fortinet Managed Rules

    Reviewed on Aug 24, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Fortinet Managed Rules for AWS WAF is how easy it is to strengthen application security without having to build and maintain every rule manually. The managed rules provide broad coverage against common web application threats, are regularly updated to address emerging vulnerabilities, and integrate smoothly with AWS WAF. This saves time for security teams while providing reliable protection and reducing the effort required for ongoing rule management.
    What do you dislike about the product?
    One area that could be improved is the cost, especially for larger environments with multiple applications and AWS accounts. Some rules may also require tuning to reduce false positives and fit specific application requirements. More detailed documentation, clearer rule explanations, and easier troubleshooting would make it simpler to fine-tune the rules and understand why specific requests are being blocked.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect our web applications from common threats such as SQL injection, cross-site scripting, bots, and other malicious traffic without having to create and maintain all the security rules ourselves. The managed rules reduce the operational effort required for WAF management, improve our overall security posture, and help us respond to emerging threats more quickly. This allows our security team to focus more on higher-value security initiatives while maintaining consistent protection across AWS-hosted applications.
    shubham t.

    Robust Security with Easy Integration

    Reviewed on Aug 22, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules for AWS WAF enhances firewall protection, blocking threats before they reach the application and defending against common web attacks and known CVEs. I find the integration with AWS SNS really useful because it provides real-time updates to admins, letting them quickly respond to updates. Integrating Fortinet with AWS WAF is super easy, and the documentation is helpful.
    What do you dislike about the product?
    I think they have everything that is needed. I dont have any dislike points to be mentioned
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to enhance firewall protection, blocking threats and common web attacks before they reach my application. It provides robust safety against AI-driven threats, offers seamless AWS integration, and sends real-time updates for immediate action.
    Emmanuel N.

    Strong AWS Protection for EC2 and S3 with Proactive Security Controls

    Reviewed on Aug 21, 2026
    Review provided by G2
    What do you like best about the product?
    I like using it as one of the AWS services to protect what I run on AWS, such as applications deployed on EC2 and assets stored in an S3 bucket. It also helps me set up security measures in advance, before requests reach my apps.
    What do you dislike about the product?
    I’d say there’s something I dislike: if I had to, I would disconnect myself from the service and let requests hit my app through AWS WAF as a proxy for protection.
    What problems is the product solving and how is that benefiting you?
    This AWS WAF service helps me improve my cybersecurity measures by reducing suspicious requests to my applications hosted on AWS S3 bucket, where I keep sensitive assets.
    Accounting

    Out-of-the-Box OWASP Top 10 & Bot Coverage With Self-Updating Rules

    Reviewed on Aug 18, 2026
    Review provided by G2
    What do you like best about the product?
    Honestly the best part is not having to write my own rules — it just covers the OWASP Top 10 and bots out of the box, and the rules update themselves.
    What do you dislike about the product?
    Mainly the UI. Policy management isn't the most intuitive, and the reporting side could be a lot better.The dashboard could be simplerBit of a learning curve at the start too.
    What problems is the product solving and how is that benefiting you?
    Mainly blocking common web/API attacks like SQL injection and bots. The big win is I'm not writing or maintaining custom rules — it updates itself, scales automatically.
    Mohamed J.

    Managed Rules Feel Too Broad—False Positives and Limited Rule-Trigger Visibility

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best is the combination of **strong, continuously updated threat protection and ease of management**. Fortinet’s managed rules add protection against common web and API attacks, including OWASP Top 10 threats, SQL injection, XSS, known exploits, CVEs, and malicious bots, while the rules are regularly updated through FortiGuard Labs. This reduces the amount of time and effort required to maintain WAF rules manually.
    What do you dislike about the product?
    The main drawback is that managed rules can sometimes be **too broad or generate false positives**, requiring additional tuning and exclusions for specific applications. It would also be helpful to have more granular visibility into why a particular rule triggered and simpler customization options without increasing the management overhead.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF help reduce the effort required to protect our web applications and APIs from common threats such as SQL injection, XSS, and known exploits. The continuously updated rules reduce manual rule maintenance, improve our security coverage, and help our team respond to emerging threats more quickly while saving time on WAF management.
    Eddy Omar L.

    Ready-to-Use Security Rules That Simplify API Protection

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    It’s a library of preconfigured, ready-to-use signatures and rules that makes security protections extremely easy to deploy and maintain. These rules are updated regularly to ensure up-to-date security. To be specific they help to secure API from injection attacks (CSS. CEVs, etc)
    What do you dislike about the product?
    Rules can become complex to set up, and the UI doesn’t really help, which makes management and enrolling new personnel difficult. Also, these rules can only be applied to WAS apps/services.
    What problems is the product solving and how is that benefiting you?
    It helped us harden our API by applying a preconfigured OWASP Top 10 ruleset. As a result, we were able to align with security standards and best practices, making our API connections/integrations and management more secure. Also, performance was not impacted.
    Youcef E.

    Set-and-Forget Security with Auto-Updating Rules

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules for AWS WAF protects our web apps against OWASP Top 10 attacks, including SQL injection, XSS, and bot attacks. The managed rulesets save us from writing custom rules manually, and layering them with rate limiting and geo-blocking enhances security. I appreciate that it blocks attacks at the edge without the need for manual rule upkeep, and we no longer have to write and update signatures ourselves. The automatic handling of new CVEs allows our developers to stay focused on features while security remains current. I love the 'set and forget' threat protection with rules updating automatically, requiring zero manual patching. The initial setup was smooth, taking under 30 minutes and attaching to the ALB in the AWS console without needing any config files, and it worked out of the box.
    What do you dislike about the product?
    I occasionally experience false positives, where some legitimate traffic gets flagged, especially with multi-step web apps. Additionally, I feel the logging could be more granular. Another concern is the pricing, which jumps at certain request volume tiers.
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to protect web apps from attacks like SQL injection without manual rule upkeep. It saves time by auto-updating rules, allowing my team to focus on development while maintaining current security.
    Marketing and Advertising

    Reliable protection with minimal maintenance

    Reviewed on Aug 11, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules provide strong, continuously updated protection against common web threats without requiring me to manually maintain a large set of WAF rules. The integration with AWS WAF is straightforward, and Fortinet’s threat intelligence makes it a good low-maintenance security layer.
    What do you dislike about the product?
    The main downside is the limited visibility and control compared with custom AWS WAF rules. Troubleshooting false positives can sometimes be difficult, and the documentation could provide more detail about exactly why specific requests are blocked.
    What problems is the product solving and how is that benefiting you?
    It helps protect our web applications from common attacks and malicious traffic without requiring us to build and maintain every WAF rule ourselves. This reduces the operational overhead for the team and gives us an additional security layer that is easy to integrate with our existing AWS infrastructure.
    Fairose Al Mahdhi

    Managed rules have strengthened web security and reduce manual protection effort for internal sites

    Reviewed on Jul 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Fortinet Managed Rules for AWS WAF is to protect our internal intranet sites and to publish some load as we are using it there.

    Regarding my main use case, ease of adoption, rule training, and cost model are vital because it is a managed rule group inside AWS WAF, meaning you do not get the FortiWeb full feature set. A learning-based positive security model without detailed app layer analytics and dashboarding means you need to make it there. When teams move to full FortiWeb cloud, they transition to self-managed FortiWeb.

    What is most valuable?

    The best features Fortinet Managed Rules for AWS WAF offers are real-time protection against OWASP Top Ten threats, FortiGuard threat intelligence, and automatic rule updates without manual maintenance, which leads to low false positives and easy integration with AWS WAF. What stands out most is the combination of continuously updated threat intelligence and managed protections, helping secure web applications with minimal operational effort.

    Fortinet Managed Rules for AWS WAF has positively impacted my organization by improving overall web application security by blocking common attacks such as SQL injections and XSS for traffic before they reach the application. It reduced the workload of the security team through automatic updates, improved compliance, and minimized the risk of downtime caused by web-based attacks. Overall, it strengthened our security posture while reducing operational effort.

    The automatic rule updates have reduced the operational effort for our team because we did not need to manually track new web vulnerabilities and update WAF signatures. For example, when new CVEs or emerging web attacks are released, Fortinet automatically updates the managed rule group, FortiGuard, which saves us time, ensures faster protection, and allows the team to focus on network operations instead of continuously tuning WAF rules.

    What needs improvement?

    Overall, Fortinet Managed Rules for AWS WAF is a solid solution, but it could be improved with more granular customization of managed rules, better visibility into why specific requests are blocked, more detailed reporting and analytics, and tighter integration with SIEM and SOAR platforms for incident response, which would add value. These improvements would make troubleshooting and security operations more efficient.

    Besides better rule customization and reporting, I would prefer to see a more intuitive management interface with easier policy tuning and clearer dashboards. Improved integration with third-party SIEM/SOAR and DevSecOps tools would streamline security operations. Faster support for newly discovered threats and more detailed documentation with deployment best practices would also help organizations adopt and manage the solution more effectively.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for seven years.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    The scalability of Fortinet Managed Rules for AWS WAF has been very good because it is built on AWS WAF, which scales automatically with application traffic without requiring additional infrastructure. As our traffic increased, we did not experience any major performance issues, and the managed rule continues to provide consistent protections. The automatic updates and cloud-native architecture made it easy to support growth with minimal operational effort.

    How are customer service and support?

    The customer support for Fortinet Managed Rules for AWS WAF is very good. Whenever we had an issue, they solved it immediately.

    Which solution did I use previously and why did I switch?

    Fortinet Managed Rules for AWS WAF is our first time using it with AWS WAF.

    What about the implementation team?

    I was not directly involved in the purchasing process of Fortinet Managed Rules for AWS WAF; the subscription was handled through our procurement cloud team. My role focused on deployment, configurations, and tuning the security aspects.

    What was our ROI?

    There is a positive return on investment because the managed rules reduced manual administration and improved protection against common attacks.

    When I mention reducing personnel, I mean my team spends less time managing web security now, not that we reduced the headcount. Since the managed rules are updated automatically, we spend less time creating and maintaining WAF rules manually, allowing the team to focus on higher value tasks such as security monitoring, incident response, and infrastructure improvements, which is helpful for our team to reduce spending.

    What's my experience with pricing, setup cost, and licensing?

    The pricing was reasonable considering the automatic updates, FortiGuard threat intelligence, and reduced operational effort.

    What other advice do I have?

    Overall, Fortinet Managed Rules for AWS WAF is a strong solution providing effective protection against common web threats while benefiting from FortiGuard threat intelligence and reduced operational effort through automatic rule updates.

    My advice to others looking into using Fortinet Managed Rules for AWS WAF is that we hardly open support cases. I would rate this solution an 8 out of 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Rohit Racharla

    Security rules have protected parcel lockers from attacks and now need smarter AI-driven threat detection

    Reviewed on May 19, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We are using Fortinet Managed Rules for AWS WAF for one of our front-end applications called the lockers application, where it will be interacted with our postmen in Belgium. For that application to protect against hackers and bots, we are using these WAF rules.

    Currently, I have used Fortinet Managed Rules for AWS WAF in the AWS service provider for cloud. We have integrated this in the WAF for the locker application, which is an end customer application, and we receive around thousands to hundreds of thousands of requests coming to our application. Since this is publicly exposed, we are using it to make our application more secure and robust without any downtime or security attacks.

    What is most valuable?

    Fortinet Managed Rules for AWS WAF is mainly used for controlling the use of bots and hackers, and tracking geolocation rules and source IP behaviors, which is very helpful in our application and organization from a security perspective.

    The main features include integration with AWS, Azure, and Google Cloud. Additionally, it helps protect against OWASP Top 10 vulnerabilities, helps prevent data breaching, and ensures regulatory compliance.

    Fortinet Managed Rules for AWS WAF has positively impacted us. We were not having financial losses because our application, the lockers, is where citizens place their parcels. Someone could potentially try to manipulate those devices. To protect against such security risks and penalties, this solution helped notify us about what is coming to our application from a hacker's perspective and how they are trying to exploit the application. To mitigate these things, it has been helpful for us.

    Since using Fortinet Managed Rules for AWS WAF, financial losses have gradually decreased. Because this is a customer-facing environment where citizens of Belgium use the lockers to place their parcels, we were able to mitigate this risk. Additionally, whenever a hacker was trying to exploit the system and asking for a bounty, that threat was completely eliminated. These two things are very valuable for our application to mitigate.

    What needs improvement?

    Fortinet Managed Rules for AWS WAF should have AI-driven threat detection to reduce false positives, and the UI should be improved. Additionally, improvements should be made to the logging methods and web application protection. It should also be more effective for modern environments, and as the world evolves along with AI, it should evolve with an AI-driven architecture as well.

    We are emerging in the AI space, and Fortinet Managed Rules for AWS WAF should be AI compatible as well. I am not certain whether it is AI compatible, as I have not used that particular service. I suggest enhancing it for more AI-driven applications.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for the last one year.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    Fortinet Managed Rules for AWS WAF was easily scaled without any issues. We did not have to monitor anything, but it scaled directly.

    How are customer service and support?

    The customer support for Fortinet Managed Rules for AWS WAF was very prompt. Whenever assistance was needed, there was always an engineer available to help us. I really appreciate their support.

    Which solution did I use previously and why did I switch?

    I have not used any other services. I am directly using Fortinet Managed Rules for AWS WAF only.

    How was the initial setup?

    I purchased Fortinet Managed Rules for AWS WAF through the AWS Marketplace, which is the only option available.

    Since it is present in AWS, the cost of Fortinet Managed Rules for AWS WAF is not high, and my customer is also happy with the cost and the work it is doing. At the integration level, it is a click and use solution.

    What was our ROI?

    For return on investment, since we are protecting our application from Layer 7 attacks and deadly attacks, Fortinet Managed Rules for AWS WAF helps us prevent data breaches and protects against hackers trying to exploit the lockers or someone trying to steal parcels from the lockers. For that, it has been very helpful.

    Which other solutions did I evaluate?

    I checked F5 and Imperva before choosing Fortinet Managed Rules for AWS WAF. Comparing all those options, I made the decision to use Fortinet.

    What other advice do I have?

    I would rate Fortinet Managed Rules for AWS WAF a seven out of ten. I highly recommend others to try Fortinet Managed Rules for AWS WAF and see how exactly these managed rules are working.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)