Fortinet Managed Rules for AWS WAF - API Gateway logo

    Fortinet Managed Rules for AWS WAF - API Gateway

    The Fortinet Managed Rules for AWS API Gateway is a comprehensive package for the best web application protection to help protect against the OWASP Top 10 web application threats, including SQLi/XSS attacks, General and Known Exploits, and Malicious Bots.

    Ratings and reviews

    4.2
    40 ratings
    2 star
    1 star
    35%
    60%
    5%
    0%
    0%
    10 AWS reviews
    |
    30 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (40)
    Łukasz T.

    My impressions on Fortinet Managed Rules for AWS WAF

    Reviewed on Sep 08, 2026
    Review provided by G2
    What do you like best about the product?
    I like how easy it is to deploy and manage the rules without having to build and maintain everything from scratch. It saves me time and makes AWS WAF management much simpler overall.
    What do you dislike about the product?
    The main downside is that some rules need fine-tuning to reduce false positives. It would also be helpful to have clearer, more detailed visibility into why specific requests are being blocked, along with easier customization options for individual rules.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF help protect our web applications from common attacks, without requiring us to manually create and maintain every security rule ourselves.
    Ekpono A.

    Fortinet WAF Simplifies Rule Management and Signature Testing

    Reviewed on Sep 07, 2026
    Review provided by G2
    What do you like best about the product?
    Thing I like most about Fortinet WAF is that it takes away manual management and maintenance of rules. The entire process of writing and testing WAF signatures
    What do you dislike about the product?
    It takes away the freedom to edit or add to the fine-tuned individual signature parameter, and the recurring subscription cost also puts pressure on our budget.
    What problems is the product solving and how is that benefiting you?
    1. It removes the need for continuous rule management for our team.
    2. We don’t have to manage dedicated infrastructure.
    3. Lastly, it saves time by keeping threat defence up to date.
    Ilario M.

    Intuitive and NIS2 Compliance with Fortinet WAF

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules for AWS WAF is very intuitive and that we can manage groups and users precisely thanks to its integration with Azure AD. Additionally, we are Fortinet partners and receive dedicated discounts, which is an added advantage.
    What do you dislike about the product?
    nothing in particular
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps me manage user access integrated with Azure AD, keeping us compliant with NIS2 regulations, and it's intuitive, allowing precise group and user management.
    Mohammed R.

    Good baseline WAF protection for teams without a security engineer

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    1.Fast to deploy — subscribe on Marketplace, attach to the existing web ACL, running same day

    2.No rule writing or tuning required to get OWASP Top 10 coverage FortiGuard Labs handles signature updates, so we're not chasing new CVEs

    3.Stays native to AWS — same console, CloudWatch metrics, sampled logs, Terraform workflow

    4.Rule groups are separable (OWASP, SQLi/XSS, bots, API), so we only pay for what we use

    5.COUNT mode let us validate against real traffic before blocking Strong coverage-to-effort ratio for a small team with no dedicated WAF engineer
    What do you dislike about the product?
    1.False positives on legitimate traffic (file uploads, rich-text fields, complex query strings) take trial and error to isolate

    2.Documentation is lighter than Fortinet's on-prem WAF products; limited guidance on which rule group to pick for a given workload
    What problems is the product solving and how is that benefiting you?
    1.Gave us real OWASP Top 10 coverage without anyone writing or maintaining rule logic — we simply didn't have the headcount for that

    2.FortiGuard handles signature updates, so new CVEs get covered faster than we could virtual-patch ourselves

    3.Satisfies the WAF control for compliance and customer security questionnaires with something documented and defensible
    Cristíano D.

    Custom rules that facilitate management and give full control of processes

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    Because it allows creating custom rules and having better control of all processes. This makes it easier to manage the platform. It is a great differentiator of the product.
    What do you dislike about the product?
    It allows improving performance and minimizing impact, depending on the platform being used. However, it has a significant price and the return on investment of the product, the support
    What problems is the product solving and how is that benefiting you?
    With AI, we can solve various problems and, thanks to its support for integrations, it facilitates the optimization of all the integrations we need to implement for what is to come.
    Ranjeet T.

    Efficient Security Management with Easy Setup

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    I like how Fortinet Managed Rules for AWS WAF helps me manage both my internal and public domain requests. It effectively stops unauthorized access and ensures only genuine requests reach the server. I appreciate its capability to monitor my payment system and protect my entire subdomains. The setup and configuration process is very easy, and I find the log analysis feature quite useful.
    What do you dislike about the product?
    Nothing
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to manage internal and public domain requests, stop unauthorized access, and protect subdomains. It monitors my payment system effectively. The setup and configuration are also very easy, making log analysis straightforward.
    Milan D.

    Strong, Low-Maintenance Protection for AWS Workloads

    Reviewed on Aug 30, 2026
    Review provided by G2
    What do you like best about the product?
    The biggest advantage is the combination of strong security coverage and ease of management. The preconfigured rules make it much easier to protect AWS workloads against common threats such as SQL injection, XSS, and known exploits without having to build and maintain everything from scratch. The integration with AWS WAF is straightforward, and the managed updates help keep protection aligned with new threats. Overall, it saves time while providing an additional layer of security for web applications and APIs.
    What do you dislike about the product?
    The main downside is that the rules can sometimes require tuning to avoid false positives, especially for applications with custom traffic patterns. It would also be helpful to have more detailed documentation and clearer guidance for fine-tuning rules for specific workloads. Pricing can also become a consideration as the number of protected resources grows.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect our web applications and APIs from common attacks without having to create and maintain WAF rules ourselves. It provides consistent security coverage against threats like SQL injection, XSS, and other known exploits while reducing the time we spend on security rule management. This lets our team focus more on application and infrastructure work while still maintaining a strong security posture.
    Subigya G.

    OP: AWS WAF | Know the real power

    Reviewed on Aug 30, 2026
    Review provided by G2
    What do you like best about the product?
    The main reason we use Fortinet's managed rules is how easily they plug into our existing AWS setup to cover core security risks like SQL injection and cross-site scripting. Building and updating custom WAF rules by hand takes way too much time, so having Fortinet's team handle the threat intelligence and signature updates behind the scenes saves a massive headache. It gives our public-facing APIs a solid baseline defense right out of the box without forcing us to spend hours tweaking custom logic every time a new vulnerability drops.
    What do you dislike about the product?
    The biggest issue is dealing with false positives when you first turn the rules on. If you jump straight to blocking mode, legitimate traffic or unusual API payloads will definitely get caught and blocked. You end up having to run everything in Count mode for a while, dig through CloudWatch logs, and set up override rules to fix the false alarms before you can actually enforce blocks. Another downside is the lack of visibility into the actual underlying rule logic. Because the signatures are proprietary black boxes, troubleshooting why a specific request got flagged takes more time than it should. On top of that, cost can accumulate quickly if you are running these rules across high-traffic Application Load Balancers, since AWS charges for rule evaluations alongside the subscription cost.
    What problems is the product solving and how is that benefiting you?
    It solves the hassle of keeping web endpoints and open APIs safe from bad traffic, web scrapers, and common attack vectors without forcing us to build or patch security rules by hand. Because Fortinet handles threat signatures automatically, new vulnerabilities are covered right away, saving us from constantly checking security advisories just to tweak firewall settings. The biggest win for us is cut-down workload. We get solid, hands-off security built right into our cloud setup, which lets us put our time toward building features instead of sifting through network logs to craft custom filter rules. It simply gives us a dependable safety net for our web apps without adding extra day-to-day maintenance.
    敏熙 .

    FortiGuard-Powered Managed Rules That Stop SQLi and XSS with Zero Added Latency

    Reviewed on Aug 29, 2026
    Review provided by G2
    What do you like best about the product?
    The automated threat intelligence powered by FortiGuard Labs is the biggest win for our team. We use the Fortinet OWASP Top 10 and Known Bad Inputs/Bots Rulesets on our public-facing ALBs. Instead of constantly monitoring new CVEs and manually writing complex regex rules in-house, the rule sets are updated automatically in the background. It effectively neutralizes SQLi, XSS, and automated vulnerability scanner probes without adding latency to our applications.
    What do you dislike about the product?
    While the protection is robust, diagnosing occasional false positives can be challenging due to the 'black-box' nature of managed rules. When a legitimate multi-step API request containing complex JSON payloads gets blocked, AWS WAF logs show the rule group and rule ID, but not the exact string or parameter that triggered the match. We have to spend extra time cross-referencing logs and writing custom label-based exception rules. It would be a huge improvement if Fortinet/AWS could provide more granular trigger explanations or context directly in the logs to speed up root-cause analysis.
    What problems is the product solving and how is that benefiting you?
    Before implementing Fortinet Managed Rules, our security team struggled with manually tracking new CVEs and writing custom regex rules for our AWS WAF, which consumed 6–8 engineering hours each week and left a window of vulnerability during zero-day events. By switching to Fortinet Managed Rules, we now have automated, continuously updated threat intelligence applied directly to our CloudFront and ALB distributions. This has eliminated the operational overhead of rule maintenance, cut our vulnerability triage time by roughly 70%, and ensured our public-facing APIs are consistently shielded against OWASP Top 10 threats and automated exploit probes.
    Anonymous

    Saves Time with Effective Web Attack Coverage

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate the simplicity of usage for Fortinet Managed Rules for AWS WAF. It doesn't need much maintenance and does its job simply, which is really crucial as we are a small team of developers. It saves us time because we don't have to deal with keeping up with signature updates, and it helps manage the noise from the internet that isn't always a direct threat but can use up unnecessary capacity. I like that we can apply the group rule only where it makes sense, rather than globally, which saved a lot of time and pain.
    What do you dislike about the product?
    I find the rules confusing as I don't always know why something was blocked. I get an ID and label but have to infer the intent. Also, I think the documentation is pretty thin, which could definitely be improved.
    What problems is the product solving and how is that benefiting you?
    I save time with Fortinet Managed Rules for AWS WAF, avoiding signature management. It simplifies usage with minimal maintenance and allows rule application only where needed, reducing unnecessary resource use.
    Recommendations to others considering the product:
    Consider enhancing the documentation to provide clearer explanations of rule actions and intents. This could help users better understand why certain actions are taken and improve overall user experience.