We are using Fortinet FortiWeb to deliver service to our customers.
Network and Security Engineer at ONB
Effective vulnerability scanner, highly stable, and low maintenance
Pros and Cons
- "The valuable feature of Fortinet FortiWeb vulnerability scanner"
- "Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company."
What is our primary use case?
What is most valuable?
The valuable feature of Fortinet FortiWeb vulnerability scanner.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately 14 years.
What do I think about the stability of the solution?
The Fortinet FortiWeb is very stable.
Buyer's Guide
Fortinet FortiWeb
May 2025

Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We did not have any problems with the scalability of Fortinet FortiWeb.
We have the development and network teams using the solution. It is approximately seven people in total.
How are customer service and support?
I did not use the support from Fortinet FortiWeb.
How was the initial setup?
The initial setup We Fortinet FortiWeb is straightforward. The full process of the deployment took approximately two weeks to 16 days.
What about the implementation team?
Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company.
What's my experience with pricing, setup cost, and licensing?
The license to use Fortinet FortiWeb is approximately $14,000.
I rate the price of Fortinet FortiWeb a four out of five.
What other advice do I have?
The solution does not require a lot of maintenance.
I would recommend this solution to others. If someone wants to use the internet with an application website or any other internet application, content filtering is very useful to filter all the requests that are coming to the server so that no one can hack or harm the system.
I rate Fortinet FortiWeb a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Manager at a construction company with 1-10 employees
Provides security and an easy setup, however scalability is a concern
Pros and Cons
- "The most important feature of this solution is protection from attack."
- "The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network."
What is our primary use case?
We use the solution to protect the various services of our site, E-commerce, file service, and download service.
What is most valuable?
The most important feature of this solution is protection from an attack.
What needs improvement?
The maintenance fee for this product could be improved and it needs to be easier to scale up.
For how long have I used the solution?
I have been using the solution for four to five years.
What do I think about the stability of the solution?
Stability is very important and yes, the product is stable.
What do I think about the scalability of the solution?
The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network.
How are customer service and support?
I would say technical support is good for this solution.
How was the initial setup?
Setup for this solution is easy, with one being easy and five being hard I would rate it a two out of five. Deployment took a few days.
What's my experience with pricing, setup cost, and licensing?
We have between 100 and 200 users of the solution in our company.
What other advice do I have?
I would rate the solution a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiWeb
May 2025

Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Senior Analyst at a financial services firm with 1,001-5,000 employees
20 Gbps appliance throughput makes it useful for large enterprise deployment and also meets future requirements. Product support is a major concern.
What is most valuable?
In my opinion, the following features of FortiWeb 4000E are the most valuable & were appreciated during all my previous engagements:
- 20 Gbps appliance throughput makes it useful for large enterprise deployment and also meets future requirements.
- Easy integration with various Fortinet products such as FortiSandbox for APT detection.
- ASIC (Application Specific Integrated Circuit) provides quick SSL offloading and doesn’t choke the user requests.
How has it helped my organization?
- Operations overhead (administration and escalation management) has been brought down, as Fortinet provides flexible and customizable reporting options with the FortiAnalyzer appliance for logging and reporting.
- Rule creation and fine tuning are easy, as compared to its competitors.
- Product has provided adequate assurance to organization’s PCI DSS program.
What needs improvement?
Product support is a major concern; if FortiWeb wants to become a market leader, then it must provide better after-sales services.
The automatic policy learning feature also needs some improvement, as using this feature leads to more false positives.
Integration with other cloud-based DDoS protection services such as CloudFlare, Arbor, Akamai, etc., is also a limitation.
For how long have I used the solution?
It’s been almost one year since we started using this solution.
What do I think about the scalability of the solution?
The FortiWeb 4000E appliance comes with 20 Gbps throughput, 2X2 TB HDD and unlimited licensing. (Yes, you got it correct.) This adds value to the organization and meets its current and future requirements.
How are customer service and technical support?
As I wrote in my previous comments, FortiWeb needs to invest and improve its tech support services due to limited skills in market. Critical- and high-severity issues usually take more time for resolution.
Which solution did I use previously and why did I switch?
We were using Imperva as our WAF solution, which is also a market leader (as per Gartner Magic Quadrant) and provides lots of flexibility and cloud integration options. However, due to high cost, the organization decided to switch to Fortinet Fortiweb.
How was the initial setup?
Selecting the appropriate deployment topology is a major task. Initial configuration settings are little difficult to implement but overall management is easy.
FortiWeb provides a wide variety of deployment options such as
- Reverse proxy
- Inline transparent
- True transparent proxy
- Offline sniffing
- WCCP (Web Cache Communication Protocol)
What's my experience with pricing, setup cost, and licensing?
Pricing and licensing are USP of this solution; deploying an appliance provides in-house control and flexibility. A dedicated 4000E appliance is appropriate for large enterprises, while Fortinet also provides a VM-based solution, which is perfect for small and medium enterprises.
Which other solutions did I evaluate?
We did PoCs for other WAF products such as Citrix, F5 and Barracuda before finalizing on FortiWeb for our enterprise, which satisfied enterprise requirements.
What other advice do I have?
Thorough review of architecture is required. It’s recommended to get it deployed by authorized FortiWeb vendors. Attention to the rules is a must. Otherwise, it might lead to lots of false positives.
Fortinet WAF can also be integrated with SIEM, which could be beneficial for centralized monitoring.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at a insurance company with 1,001-5,000 employees
Provides good feedback for development and is easy to scale up
Pros and Cons
- "It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs."
- "The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product."
What is our primary use case?
Generally, we are using it to protect our internet-facing web applications. So if there are any security vulnerabilities in our applications, the solution can provide protection.
How has it helped my organization?
It offers some feedback and suggestions that guide our system development while helping our vendors to update their applications and fix any issues or bugs.
What is most valuable?
They have a sort of table that defines the functions of certain applications, ex. which function has the slowest or fastest response. This enables our in-house development team or vendors to review our application and fix the functions if necessary.
What needs improvement?
The dashboard evaluating the performance of each application connected to the web app's firewall is quite helpful, but the tool is only available in application performance management. So I think if Fortinet could better integrate that particular feature, it would add a lot of value to the product.
For how long have I used the solution?
I have been using FortiWeb for three years.
What do I think about the stability of the solution?
I think it's quite reliable so long as it's configured.
What do I think about the scalability of the solution?
As long as we accurately scale our requirements from the start, I think the solution is quite scalable and quite easy to scale up later on.
How are customer service and technical support?
They are quite helpful. But I think because our department is quite stable and configured correctly, we are rarely using the support. Everything works perfectly.
How was the initial setup?
I think it's quite complex because we need to know how the application works.
What about the implementation team?
We are using local support to configure the solutions for us. We also purchase local maintenance and support on top of the routine product support and updates. Because it is a
very specialized product, we need a very skillful person with expertise in the product to configure the solution for us.
What's my experience with pricing, setup cost, and licensing?
In a high availability cluster configuration, where the primary FortiGate is working and the secondary is a backup, Fortinet requires us to buy two licenses instead of one whether we are actually using it or not. With other products, you only purchase one license because we only use one license per instance.
What other advice do I have?
You need to accurately calculate the requirements of your infrastructure before implementing FortiWeb or any other web application firewall. Accuracy is very critical when scaling the product or the model that will be deployed on your infrastructure.
I would rate FortiWeb an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Advisor at a tech services company with 51-200 employees
L-7 protection safeguards legacy servers/applications without changing application code
Pros and Cons
- "Other than the additional security with exploit protection, we have simpler certificate handling, as we can keep internal servers using internal certificates continuously distributed and updated by Active Directory Group Policy, while the public certificates become updated only in a single place, FortiWeb itself."
- "SSL Offloading simplifies the public certificate handling and brings additional protection features."
- "L-7 protection makes possible to protect legacy/not up-to-date servers/applications without changing the application code."
- "Centralized management of multiple devices, and GUI improvement, could reduce the learning curve."
- "The interface could have the interdependent elements arranged sequentially and wizards that go through most common deployment actions."
- "Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration."
How has it helped my organization?
Other than the additional security with exploit protection, we have simpler certificate handling, as we can keep internal servers using internal certificates continuously distributed and updated by Active Directory Group Policy, while the public certificates become updated only in a single place, FortiWeb itself.
What is most valuable?
SSL Offloading, as it simplifies the public certificate handling and brings additional protection features.
Also, L-7 protection, as it makes possible to protect legacy/not up-to-date servers/applications without changing the application code.
What needs improvement?
- Centralized management of multiple devices, and GUI improvement, could reduce the learning curve.
- The interface could have the interdependent elements arranged sequentially and wizards that go through most common deployment actions.
- Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No issues with scalability. (Actually, our traffic usually does not reach 50% of unit capacity).
How are customer service and technical support?
Good. Usually takes one day to get over all the assessment procedures to start to handle the issue.
Which solution did I use previously and why did I switch?
The previous vendor discontinued its product.
How was the initial setup?
A little bit complex, as understanding the GUI arrangement and terms took more time and effort than we expected.
What's my experience with pricing, setup cost, and licensing?
Keep a loose margin between your actual bandwidth and the product sizing when using hardware appliances. Only virtual machines are upgradable to larger sizes.
Which other solutions did I evaluate?
We acquired a Fortinet-based project, so we didn’t evaluate other ones.
What other advice do I have?
I rate it eight out of 10. I understand that a 10 is for products that not only execute smoothly but are also easy to use and manage, even when used on a multi-site corporation.
Take at least the Fortinet online course, or make sure that your reseller has experienced professionals.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Information Security Leader at a government
It has helped us prevent exploitation of vulnerabilities while we are working on code. Signatures are basic and prone to firing false positives.
What is most valuable?
- It supports OWASP top 10.
As you can see, the attack types are mapped to OWASP top 10. The policy creation always follows the procedure:
- Create first the objects needed.
- Assemble the policy.
- The GUI interface is intuitive. I have never needed to use the CLI
- It has good reports.It is easy to manage.
How has it helped my organization?
The portal has a lot of vulnerabilities, which are not easy to solve quickly. The device has helped us to prevent exploitation of them while we are working on the code.
What needs improvement?
The signatures are very basic and prone to firing false positives. For example, FortiWeb detects this string as an attack because it detects "perl" in it:
User-Agent: Mozilla/5.0 (compatible; PaperLiBot/2.1; https://support.paper.li/entries/20023257-what-is-paper-li)
This is a false positive. If the signature was more complex, that would not occur.
For how long have I used the solution?
I have been using it for four years.
What do I think about the stability of the solution?
I have not encountered any stability issues, but it always consumes a lot of memory.
How are customer service and technical support?
Technical support is 7/10. We had a pair of cases without solution; one URL-rewriting related and another one Lync Enterprise-related. In both cases, we had to search for alternate solutions.
Which solution did I use previously and why did I switch?
ISA Server was working as a reverse proxy, but it lacks web attack prevention. Also, because the platform is dedicated and the OS is hardened.
How was the initial setup?
It has an auto-learn module that makes it easy to establish the first policy, after which you can customize it. It is straightforward to configure the FortiWeb. We have encountered that it is especially difficult to work with URL rewriting, because of regular expressions.
What's my experience with pricing, setup cost, and licensing?
Price and licensing is fine; it is one of the cheapest solutions and does its job.
Which other solutions did I evaluate?
We also evaluated F5 and Imperva. Fortinet won because of its price. It has done its work for the last four years; the only problem that I have seen is the high false-positives rate which prevents us from focusing on the real attacks.
What other advice do I have?
It has a good quality/price relationship. The web vulnerability scan module is useless.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Jr. Engineer at a computer software company with 5,001-10,000 employees
Easy to install and maintain, with good technical support
Pros and Cons
- "It is easy to install and to maintain."
- "In terms of performance, it needs to be more robust."
What is our primary use case?
The primary use case of this solution is for security, on the periphery for the VPN.
What is most valuable?
It is easy to install and to maintain.
What needs improvement?
We are considering an upgrade to our firewall because our current version is not compatible with our FortiAnalyzer. As there is an incompatibility, we have been advised by Fortinet that an upgrade is necessary to avoid issues.
We believe this product will become obsolete.
It needs to better integrate with other platforms.
In terms of performance, it needs to be more robust. During the lockdown, we are connecting to a VPN and the connection should be faster, there should be RAM or more hardware. Also, it should include security features.
For how long have I used the solution?
I have been using Fortinet FortiWeb for two years.
What do I think about the stability of the solution?
This solution is stable and w have had no issues with its stability.
What do I think about the scalability of the solution?
It's a scalable product and we have plans to use it in the future.
We have approximately 1000 users in our organization.
How are customer service and technical support?
We are satisfied with technical support, we have not had any issues.
How was the initial setup?
The initial setup was straightforward, it was easy.
There were no issues and it was deployed in six months.
We have a team of 20 providing the IT infrastructure, including switching, firewalls, and maintenance.
What other advice do I have?
We have been using Fortinet for four years and internally we are using Cisco.
We would certainly recommend this product.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network Security Planning at Ooredoo Kuwait
Has a mechanism to detect all of your entries that aren't used and clean them up but they should have an antivirus option
Pros and Cons
- "When we had Cisco we had around thirty thousand entries on our firewalls. Now we are down to three thousand. Fortinet has a mechanism to detect all of your entries which are not used, and it can clean it up."
- "I would like to have an antivirus option."
What is our primary use case?
Our primary use case is as a firewall. We use a lot of Fortinet products. We have email security and FortiGate IPS.
How has it helped my organization?
When we had Cisco we had around thirty thousand entries on our firewalls. Now we are down to three thousand. Fortinet has a mechanism to detect all of your entries which are not used, and it can clean it up.
What is most valuable?
The most valuable features are the access policies and how Fortinet gets the compilation done is really good.
What needs improvement?
I would like to have an antivirus option.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
Stability is very good.
What do I think about the scalability of the solution?
We haven't had any issues with scalability. You can scale up easily.
How are customer service and technical support?
Their technical support is good.
Which solution did I use previously and why did I switch?
We previously used Cisco. We switched because all they are is a brand name. It was a failure. We gave it a year to improve the product and it didn't so we switched.
How was the initial setup?
The initial setup was straightforward. The deployment didn't take much time. The support guys were really good. The transition from Cisco to Fortinet was a bit challenging but they had tools to make it easier.
We require three staff for the deployment and maintenance.
What about the implementation team?
We are the resellers.
What other advice do I have?
I would rate it a seven out of ten. A seven and not a ten because of the antivirus issue.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.

Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
F5 Advanced WAF
NetScaler
Cloudflare Web Application Firewall
Imperva Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?