No more typing reviews! Try our Samantha, our new voice AI agent.

Fortinet FortiAppSec Cloud vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
5th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Fortinet FortiAppSec Cloud
Ranking in Web Application Firewall (WAF)
23rd
Average Rating
9.0
Reviews Sentiment
6.6
Number of Reviews
2
Ranking in other categories
CDN (11th), Distributed Denial-of-Service (DDoS) Protection (19th), API Security (16th), Dynamic Application Security Testing (DAST) (9th)
Fortinet FortiWeb
Ranking in Web Application Firewall (WAF)
2nd
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
121
Ranking in other categories
No ranking in other categories
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
reviewer2812593 - PeerSpot reviewer
CIO at a financial services firm with 51-200 employees
Advanced threat protection has reduced financial risk and improves application security visibility
The issue I have with Fortinet FortiAppSec Cloud is that the real-time analysis is not robust; I am unable to see all the logs of everything that happened, including what is passive. It only logs when there are suspicious activities, which means if something is not considered suspicious by Fortinet, I will not see the full picture. That is a disadvantage because it will not log unless it identifies an IOC or attacks, meaning I cannot see traffic information in a way that helps build more intelligence. The biggest issue I have with Fortinet FortiAppSec Cloud is that the logging is not as extensive as I would prefer. For instance, if there was an issue two days ago and Fortinet FortiAppSec Cloud did not mark it as a concern, I will not see any information about that, making it challenging to explain to customers if their request did not reach us. It hampers visibility from an API perspective. They need to enhance monitoring and logging to be more extensive and capture even passive activities. The AI integration in Fortinet FortiAppSec Cloud is still new. The generative models are good, but there is much work left to improve. It is not as intelligent as it could be; thus, enhancements around the AI co-assistant would be beneficial. Additionally, logging and monitoring need improvement as I can capture traffic and investigate offline on my Fortinet firewall, including full traffic view, but Fortinet FortiAppSec Cloud currently focuses only on security concerns, which does not give the complete picture.
HameedAhmed - PeerSpot reviewer
Joint Director at PAA
Security threats have been reduced through seamless deployment and strong integration with other tools
I have used Fortinet FortiWeb's integration features. We have easily integrated all of the applications with the product. Most of the applications we are using are in-house built. My technical team is looking after the best features. I have not used it extensively for maybe two and a half years. I have been involved in the installation, but I am not actually using the product. I work with it from time to time but not extensively. I would assess Fortinet FortiWeb's adaptive machine learning and artificial intelligence as having new patches installed regarding artificial intelligence, but when we bought it, I think the learning feature was there. Now they have installed artificial intelligence features through patches. We have a complete portfolio of Fortinet in our organization, including FortiMail, Fortinet FortiWeb, and FortiGate, along with multi-factor authentication. All of the products are from Fortinet. Fortinet tools integrate with each other and work in conjunction. I think Fortinet FortiWeb has helped us meet regulatory compliance because we are not a regulatory organization, but our sister organization is regulatory. We have regulatory compliance with the International Civil Aviation Authority, whose audit teams have checked our data center and these security products, and they are satisfied with us. The question about leveraging Fortinet FortiWeb's automated policy management does not pertain to my domain because I am not so technical, but I am in a management role now. My engineer is more technical than me. I would rate this product an eight point five out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The initial setup process is simple."
"It is a SaaS solution unlike much of the competition."
"This solution does a good job of preventing web application attacks, SQL injections, and cross-site scripting attacks."
"It's pretty convenient and pretty easy to set up and run. And then kind of for static content, it also offers caching."
"The impact of Cloudflare Web Application Firewall's integration with existing web technologies on our site's performance and security measures is quite great, actually."
"The security features are valuable. The particular feature we use is called OWASP."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"My favorite Fortinet device is the FortiGate next-gen firewall itself; it is a complete suite with intrusion prevention, intrusion detection, anti-malware, anti-DDoS, and SD-WAN functionalities."
"We have seen a reduction in incidents and a good return on investment from Fortinet FortiAppSec Cloud, with our return on investment around 60%."
"What we like about Fortinet FortiWeb is it has all the features. We use all of them, so we have to turn on all the options."
"The anti-defacement feature is very useful because it looks for web changes over time to protect pages."
"The GUI is user-friendly."
"It is cost-effective compared to other solutions."
"The ability to configure multiple policies for different requirements is a strong feature of Fortinet FortiWeb."
"With FortiWeb, the all-in-one license is one of the most beneficial features."
"Our customers find Fortinet FortiWeb much better than other solutions."
"The machine learning feature reduces the false positives."
 

Cons

"The user interface is very simple and straightforward, but users need knowledge about DNS to accomplish tasks."
"We don't even use Cloudflare Bot Management because it's too expensive; you need to pay per request, and it's much cheaper to get one or two additional machines."
"The accuracy of the Cloudflare Web Application Firewall could be improved by reducing the number of false-negative alerts."
"The solution's learning curve can still be further reduced"
"We have noticed some latency when the call goes through the firewall. That could be improved."
"Cloudflare Web Application Firewall should include port forwarding features."
"I have experienced some difficulties with Cloudflare's support as a customer based in India."
"They have some limitations with third-party integrations."
"The issue I have with Fortinet FortiAppSec Cloud is that the real-time analysis is not robust; I am unable to see all the logs of everything that happened, including what is passive."
"Real-time traffic analysis has posed an issue for us because we did not see logs for legitimate traffic."
"The solution is rather complicated. If you know what to do, it's not bad, but it's complicated for a first time user to configure the solution. What I'd like to improve are the custom signatures."
"They can introduce a scaled-down version for the SMB market. It would be very competitive in the environment."
"The solution could improve by providing more integration with solutions other than the Fortinet family."
"For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting."
"We had one stability issue when I ran it once with Wireshark; it froze."
"It may be better if it were easier to create roles."
"Lacks functionalities that are available in other solutions."
"We would like the interface to be easier to use and more user-friendly. The interface needs to be enhanced."
 

Pricing and Cost Advice

"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"The solution is expensive."
"The annual licensing fee is $10,000 USD."
"It starts at $20 and can easily go up to $200 monthly"
"The solution's pricing option needs to be more transparent for enterprise clients."
"We pay $210 per month for CloudFlare WAF."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
Information not available
"FortiWeb is more expensive than some competing products."
"The solution gives us the best price to performance ratio."
"The price of Fortinet FortiWeb depends from customer to customer because some customers are considering using other solutions, such as Imperva. The price of Fortinet FortiWeb sits well for the middle-sized customers that we deal with."
"It is a cheap solution."
"The costs are standard. We pay around $1,600 yearly."
"Due to the situation in Iran with the sanctions, the price of this solution is very expensive."
"Keep a loose margin between your actual bandwidth and the product sizing when using hardware appliances. Only virtual machines are upgradable to larger sizes."
"The pricing is pretty good. We do pass a lot of traffic through our API servers. Something like 100 gigs of web traffic is a fair amount for reduced JSON API calls, but the cost is $50. For that peace of mind, we have thousands and thousands of customers that are protected by that $50, so it's a no-brainer."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Comms Service Provider
9%
Financial Services Firm
9%
Computer Software Company
7%
Construction Company
30%
Financial Services Firm
10%
Manufacturing Company
9%
Healthcare Company
8%
Manufacturing Company
9%
Financial Services Firm
8%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
No data available
By reviewers
Company SizeCount
Small Business60
Midsize Enterprise27
Large Enterprise36
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What needs improvement with Fortinet FortiAppSec Cloud?
Real-time traffic analysis has posed an issue for us because we did not see logs for legitimate traffic. A separate l...
What is your primary use case for Fortinet FortiAppSec Cloud?
Fortinet FortiAppSec Cloud is used as a WAF solution.
What advice do you have for others considering Fortinet FortiAppSec Cloud?
We are a customer running Fortinet FortiAppSec Cloud for both our organization and one for our customer. Three users ...
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing for Fortinet FortiWeb varies with different models having different prices. It depends on the requirement...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in Fortinet FortiWeb. The team was only from FortiGate itself. They are making new firm...
What is your primary use case for Fortinet FortiWeb?
Fortinet FortiWeb is very good as a web application solution. I have been working with Fortinet FortiWeb since 2020.
 

Also Known As

Cloudflare WAF
No data available
FortiWeb Web Application Firewall (WAF)
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Information Not Available
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Fortinet FortiAppSec Cloud vs. Fortinet FortiWeb and other solutions. Updated: April 2026.
893,244 professionals have used our research since 2012.