Try our new research platform with insights from 80,000+ expert users

Fortinet FortiDDoS vs Fortinet FortiWeb comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
Fortinet FortiDDoS
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (11th)
Fortinet FortiWeb
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
96
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Mindshare comparison

Distributed Denial-of-Service (DDoS) Protection
Web Application Firewall (WAF)
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Yazan Omar - PeerSpot reviewer
An easy-to-use tool with great GUI
The product's initial setup phase was really easy. There is a lot of time involved in the testing phase and other processes related to the area of deployment, so it may take up to two weeks to deploy the solution. The solution is deployed on an on-premises model. One person is enough to take care of the deployment phase of the product. The person involved in the deployment phase needs to better understand topologies when dealing with Fortinet.
OcheEluma - PeerSpot reviewer
Enhanced security with comprehensive traffic inspection and some downtime automation needs
One area that needs improvement is the handling of SaaS downtime. When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well. Although measures like built-in redundancy and manual switching between data centers exist, there is room for improvement in making these transitions automatic without impacting the customer. Automating the migration without manual intervention would significantly enhance user experience during downtime. Additionally, being able to read non-flagged traffic for operational purposes could also be an area to improve.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is very good at mitigating threats."
"New and innovative way to protect the client's data."
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"I like Cloudflare's application gateway and DDoS protection."
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"The most valuable feature is its usability."
"The solution automatically detects and responds to certain types of traffic based on geolocation."
"It's very user-friendly."
"The product's initial setup phase was really easy."
"The protection resources and the support are valuable features of the solution."
"The equipment works very well, and I have not encountered any issues with it. It is a good solution for my company."
"The most valuable feature is the cloud DDoS scrubbing capability."
"The solution already has security profiles and it can protect from DDoS attacks and other kinds of attacks."
"Among its key features: Detects and mitigates DDoS attacks at L3 to L7; negligible to zero false-positives; Generates and sends reports without the need for an expensive third-party solution."
"The product allows the users to adjust the thresholds."
"I find the interface easy to use."
"Some of the threat detection analytics and the filtering capabilities they give us for filtering a certain type of information that we don't want coming into the site are its valuable features. The analytics are pretty good in terms of being able to see what threats have been detected and mitigated, where they're coming from, and things like that."
"I like FortiWeb's usability and ease of configuration. It's simple to configure rules and exceptions inside the attack log. We block everything by default. If something isn't working, we ask the system admin to adjust the template and add exceptions."
"Fortinet is a great SD-WAN player when it comes to security capabilities."
"FortiWeb offers machine learning in the latest product. This fixed many problems. There are no false negatives."
"Banks have to be compliant with PCI and other things, and FortiWeb is absolutely amazing in terms of providing these reports. Otherwise, they will have to spend a lot of time on them."
"It's stable and works efficiently against OWASP Top 10 attacks."
"The valuable feature of Fortinet FortiWeb vulnerability scanner"
"The AI-driven threat detection enhances protection capabilities, and the product is equipped with hardware acceleration, improving performance considerably."
 

Cons

"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"Eventually, things go sideways and require fixes when it would have been easier to prevent the issue initially."
"The analytics, basically the dashboard, doesn't have much to it."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"Cloudflare should add more documentation and pricing to the cloud version."
"The solution could be more user-friendly."
"I find that there have been issues in the past year with the solution hanging. It freezes often."
"The primary area for improvement is the on-premises capacity limit, currently fixed at 10 GB."
"All the thresholds that need to be configured should be included in the default so that user will not forget or misconfigure."
"The tool needs to focus more on the area of application traffic management, where it currently has some shortcomings."
"The only thing they need to do is to automate it. Today, you must create tools that do not require the use of an expert or anyone with special skills."
"I would like to see analytics, big data."
"Alerts and reporting features must be improved."
"The solution can be a little more user-friendly and it can be more affordable."
"It costs too much."
"The initial setup depends on familiarity with the product. It's manageable with the right expertise."
"No solution is 100% secure and the security could always be worked on."
"It can be better with web application firewalls."
"It would also be helpful if they could introduce easier reporting. It's good to have those reports that go to C-level management, and Fortinet does provide some graphs, but if they went into some more detail, that would be great."
"The upgrade process could be a bit smoother."
"Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration."
"The support side of things can be improved."
 

Pricing and Cost Advice

"The tool is a premium product, so it is very expensive."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"There are no additional costs beyond the standard licensing fees."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"That is one of the great features. I was able to access the majority of the features and services for free."
"The price of the solution is expensive."
"The product's pricing is minimal compared to other products."
"It's quite pricey."
"The product’s pricing needs improvement."
"The solution is reasonably priced."
"​It really pays off to buy licences for multiple years​."
"There are no costs in addition to the standard licensing fees."
"So far, I have been pretty pleased with the way it's priced and licensed. The way it's done makes it easy, especially for an organization like us, so I've been pleased with the way it's priced and licensed right now."
"If one is cheap and ten is expensive, I rate the tool an eight."
"​The pricing is reasonable."
"FortiWeb is more expensive than some competing products."
"FortiWeb can be purchased in VM mode for a lower price and the same features."
"Its subscription prices are cheaper, and it is not very expensive. From a price perspective, Fortinet is a very well-known security vendor. Subscriptions are very simple. They have a couple of licenses on an appliance, and that's it. The cost is not that big. One license is 40K, which they give with all the products. Another one includes the subscriptions for threat prevention, IPS, sandboxing, etc, which is more than enough."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Comms Service Provider
11%
Financial Services Firm
9%
Manufacturing Company
7%
Computer Software Company
12%
Manufacturing Company
11%
Financial Services Firm
8%
Comms Service Provider
7%
Computer Software Company
13%
Financial Services Firm
10%
Government
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What do you like most about Fortinet FortiDDoS?
The product's initial setup phase was really easy.
What is your experience regarding pricing and costs for Fortinet FortiDDoS?
Fortinet FortiDDoS offers lower costs compared to other solutions. The licensing costs are annually renewed.
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
The pricing for Fortinet FortiWeb varies with different models having different prices. It depends on the requirement...
What needs improvement with Fortinet FortiWeb?
There is room for improvement in Fortinet FortiWeb. The team was only from FortiGate itself. They are making new firm...
 

Also Known As

Cloudflare DNS
Fortinet DDoS, FortiDDos
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Black Gold Regional Schools, Amadeus Hospitality, Jefferson County, Chunghwa Telecom, City of Boroondara, Dimension Data
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Find out what your peers are saying about Cloudflare, Radware, NETSCOUT and others in Distributed Denial-of-Service (DDoS) Protection. Updated: August 2025.
865,384 professionals have used our research since 2012.