No more typing reviews! Try our Samantha, our new voice AI agent.

Atomic ModSecurity Rules vs Fortinet FortiWeb Cloud WAF-as-a-Service comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
6th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Atomic ModSecurity Rules
Ranking in Web Application Firewall (WAF)
29th
Average Rating
9.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
No ranking in other categories
Fortinet FortiWeb Cloud WAF...
Ranking in Web Application Firewall (WAF)
21st
Average Rating
8.8
Reviews Sentiment
6.4
Number of Reviews
10
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 3.8%, down from 5.8% compared to the previous year. The mindshare of Atomic ModSecurity Rules is 0.8%, down from 1.0% compared to the previous year. The mindshare of Fortinet FortiWeb Cloud WAF-as-a-Service is 0.8%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
Cloudflare Web Application Firewall3.8%
Fortinet FortiWeb Cloud WAF-as-a-Service0.8%
Atomic ModSecurity Rules0.8%
Other94.6%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Vahid Babaey - PeerSpot reviewer
PhD Student at University of North Carolina at Charlott
Open rules have enabled me to secure web apps against obfuscated SQL injection and XSS attacks
The best feature Atomic ModSecurity Rules offers is the open source aspect. I believe that because it's open source, all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world. By accessing Atomic ModSecurity Rules, it has helped me significantly. Because of this open source feature, I am able to generate new rules and update the WAF and use this WAF in my research and also give it to other clients and customers to use the updated WAF. All of this is done just because of the open-source feature, because it can be updated.
NiteshSharma - PeerSpot reviewer
Pre Sales Architect at network techlab
Comprehensive web protection has secured public apps and supports advanced audit requirements
Fortinet FortiWeb Cloud WAF-as-a-Service has multiple valuable aspects. The WAF solution secures whatever public domains have been published by the public platform or internal servers exposed to public users. Firewalls have limitations, which is why I suggest using a WAF solution. The firewall provides the same features but in a limited edition. When discussing the SaaS platform or Layer 7 layer of security, you will receive multiple benefits. Firewalls have limitations with signatures, bot protection, and DOS protection. Fortinet FortiWeb Cloud WAF-as-a-Service is a dedicated WAF product that handles all DOS protection, bot protection, API security, endpoint connectivity, signature-based support, and top 10 OWASP support. Multiple features are available. AI and ML-based technology is available in almost every tool today. When discussing troubleshooting, there are AI models that will solve your problem and provide information. AI is helpful because it will give you proper information regarding errors and troubleshooting.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For us, the key feature of Cloudflare is DDoS protection and IP hiding, especially since we are a crypto company."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"This is a good product; it's reliable and scales well."
"In general, it's a very good product: the solution is very stable, the performance is great, the product offers very good scalability, the pricing is very reasonable, the installation is very straightforward and quite simple, and technical support has a very fast response time and is helpful."
"The Cloudflare Web Application Firewall's most valuable feature is its ease of configuration."
"It is a SaaS solution unlike much of the competition."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"The impact of Cloudflare Web Application Firewall's integration with existing web technologies on our site's performance and security measures is quite great, actually."
"The best feature Atomic ModSecurity Rules offers is the open source aspect, because all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world."
"The technical support is really good."
"Fortinet FortiWeb offers a variety of protections, including machine learning that helps protect web applications."
"I utilize Fortinet FortiWeb Cloud WAF-as-a-Service's AI-driven analytics, which is in the sixth generation of AI, and this is helping us protect against AI-based attacks, API-based attacks, and bot attacks."
"Regular updates are one of the aspects I appreciate about Fortinet FortiWeb Cloud WAF-as-a-Service, and it is provided by a leading brand in cybersecurity."
"Fortinet has created a holistic product that integrates features including AI and API protection, with straightforward automation and articulate reporting that even less experienced engineers can use easily."
"The initial setup is pretty easy, and it is easier than for the on-premises solution."
"Fortinet FortiWeb Cloud WAF-as-a-Service is a dedicated WAF product that handles all DOS protection, bot protection, API security, endpoint connectivity, signature-based support, and top 10 OWASP support."
"It is a secure tool."
 

Cons

"Support can be challenging at times."
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"Their documentation could be better. They don't have documentation that explains everything well."
"The blocked logs are difficult to read at times."
"The notification part could be improved. It's very much connected to Web Application Firewall, rate-limiting, and DDoS protection."
"The ModSecurity core rules need to be updated."
"The learning curve was steep initially."
"The user interface is very simple and straightforward, but users need knowledge about DNS to accomplish tasks."
"Additionally, I know that ModSecurity can block only SQL injection and XSS attacks, no more types of attacks."
"What I think could be improved in the future is the inclusion of runtime application self-protection, as RASP is currently not part of the program, but it would be beneficial if that could be added into the FortiAP-S Cloud product."
"It is expensive. Actually, it is expensive."
"The only thing I encountered was related to integration, mostly concerning translation."
"The usability of the interface could be improved as it is not user-friendly."
"The utilization of AI in Fortinet FortiWeb Cloud WAF-as-a-Service still needs to be upgraded and improved."
"While we find the solution to be really good overall, some improvements could be made to the alerting system, specifically around the health checks of endpoints."
"Fortinet FortiWeb Cloud WAF-as-a-Service could be improved with better logging capabilities, as many come with less spacing, necessitating a FortiSIM for enhanced functionality."
"I do not have any notes on improvement."
 

Pricing and Cost Advice

"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"It starts at $20 and can easily go up to $200 monthly"
"We pay $210 per month for CloudFlare WAF."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"It is not too pricey."
"The solution is expensive."
"The solution's pricing option needs to be more transparent for enterprise clients."
Information not available
Information not available
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
908,877 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Comms Service Provider
9%
Financial Services Firm
9%
Outsourcing Company
8%
Comms Service Provider
29%
Hospitality Company
12%
Construction Company
9%
Government
9%
Financial Services Firm
13%
Comms Service Provider
11%
Construction Company
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
No data available
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What needs improvement with Atomic ModSecurity Rules?
Atomic ModSecurity Rules can be improved by first studying and reading the structure of new obfuscated attacks, then ...
What is your primary use case for Atomic ModSecurity Rules?
My main use case for Atomic ModSecurity Rules is in my research, which tries to make websites secure against web atta...
What advice do you have for others considering Atomic ModSecurity Rules?
I would rate Atomic ModSecurity Rules nine out of ten. I chose nine out of ten because I have not studied other WAFs....
What is your experience regarding pricing and costs for Fortinet FortiWeb Cloud WAF-as-a-Service?
It is expensive. Actually, it is expensive. When discussing small organizations, I would not recommend it to them. I ...
What needs improvement with Fortinet FortiWeb Cloud WAF-as-a-Service?
Currently, I want to add that Fortinet FortiWeb Cloud WAF-as-a-Service is offering only two-factor authentication. I ...
What is your primary use case for Fortinet FortiWeb Cloud WAF-as-a-Service?
When discussing Fortinet FortiWeb Cloud WAF-as-a-Service, I always recommend it. Either I can recommend F5. Most user...
 

Also Known As

Cloudflare WAF
No data available
No data available
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Information Not Available
Information Not Available
Find out what your peers are saying about Imperva, Fortinet, F5 and others in Web Application Firewall (WAF). Updated: August 2026.
908,877 professionals have used our research since 2012.