What is our primary use case?
When discussing Fortinet FortiWeb Cloud WAF-as-a-Service, I always recommend it. Either I can recommend F5. Most users require security via SSL, so I recommend Fortinet FortiWeb Cloud WAF-as-a-Service because you can get bot security, DOS protection, signature-based technology, and certification. You will receive all Layer 7 security. That is why I recommended Fortinet FortiWeb Cloud WAF-as-a-Service.
Whatever publicly accessible applications exist, they should use the WAF solution. People in banking, marketing, and finance are only using the WAF solution. If it is a mid or small company, they do not require a WAF solution because they do not have a public platform and are not publishing that application. For enterprise level, I can recommend a WAF solution or a firewall.
What is most valuable?
Fortinet FortiWeb Cloud WAF-as-a-Service has multiple valuable aspects. The WAF solution secures whatever public domains have been published by the public platform or internal servers exposed to public users. Firewalls have limitations, which is why I suggest using a WAF solution. The firewall provides the same features but in a limited edition. When discussing the SaaS platform or Layer 7 layer of security, you will receive multiple benefits.
Firewalls have limitations with signatures, bot protection, and DOS protection. Fortinet FortiWeb Cloud WAF-as-a-Service is a dedicated WAF product that handles all DOS protection, bot protection, API security, endpoint connectivity, signature-based support, and top 10 OWASP support. Multiple features are available.
AI and ML-based technology is available in almost every tool today. When discussing troubleshooting, there are AI models that will solve your problem and provide information. AI is helpful because it will give you proper information regarding errors and troubleshooting.
What needs improvement?
Currently, I want to add that Fortinet FortiWeb Cloud WAF-as-a-Service is offering only two-factor authentication. I want them to provide SAML authentication. If it gets SAML authentication or something similar, that would be good for us.
For how long have I used the solution?
I have started using it in 2023.
What do I think about the stability of the solution?
I would rate the stability as eight to nine.
What do I think about the scalability of the solution?
Currently, I have found some issues, but otherwise it is a good product.
It is easily deployed. You need to do a next, next step. Either you can put the domain name and IP and proceed to the next step. It auto checks everything, and you need to install the certificate. That is all.
How are customer service and support?
Sometimes it is difficult to connect with FortiGate teams because there are rotational shifts. Sometimes in the morning I am connected to someone, and in the evening, I do not get support from them because they start in the next stage. There are some challenges, but not significant ones.
How would you rate customer service and support?
How was the initial setup?
When discussing customizable security rules in Fortinet FortiWeb Cloud WAF-as-a-Service, it is definitely helpful for finance or banking sectors because for audit purposes, whatever points will be opening from the other side, in the WAF solution, I can fix and fulfill that concern raised by the audit team.
What's my experience with pricing, setup cost, and licensing?
It is expensive. Actually, it is expensive. When discussing small organizations, I would not recommend it to them. I always choose the enterprise because it is expensive.
I just recommend Fortinet FortiWeb Cloud WAF-as-a-Service because it is very expensive. In the SaaS platform, I can pay monthly, and if it is required, I can enable it. If it is not required, I can disable it.
Which other solutions did I evaluate?
Regarding my preference for Fortinet compared to other vendors, I should give preference to the WAF solution. My first preference is F5. My second preference is Akamai. My third preference is Imperva. My fourth preference is Fortinet FortiWeb Cloud WAF-as-a-Service.
I am speaking about the technical capabilities and not price. When discussing the WAF solution, the price will be the same or matchable. Some may be higher or lower.
What other advice do I have?
When discussing real-time threat intelligence impact, there is no comparison with Palo Alto because Palo Alto is giving a lot of real-time visibility. There is no comparison between the other products.
I have not tested the automated threat detection feature. However, I will get the information from your side, and I will definitely test and update you in the next call. I would rate this review as eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other