We are using FortiWeb for publishing web services and some web applications.
Data Center Network Expert at TOSAN
User-friendly and makes it easy to find vulnerabilities
Pros and Cons
- "This product is very user-friendly."
- "This is a good product and I strongly recommend it, especially for companies in the banking industry."
- "FortiWeb needs to have support for the newest technology being used in web applications."
- "FortiWeb needs to have support for the newest technology being used in web applications."
What is our primary use case?
What is most valuable?
The interface makes it easy to identify vulnerabilities.
The best features for us are the signature services. The devices uses signatures for identifying vulnerabilities in web applications.
This product is very user-friendly.
The security is very good.
What needs improvement?
FortiWeb needs to have support for the newest technology being used in web applications. For example, some companies have developed new features using the latest technology, but we are still waiting for Fortinet to support them.
For how long have I used the solution?
I have been using FortiWeb for between four and five years.
Buyer's Guide
Fortinet FortiWeb
March 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability is very good and we're fortunate that we haven't had any issues.
What do I think about the scalability of the solution?
We have had no issues with scalability.
How are customer service and support?
We are in Iran and working under sanctions, which means that we cannot buy new American products and cannot get support. Companies usually buy devices that are second hand, or from a third-party, neither of which have support.
That said, my impression is that the support is good for companies who are eligible to use it.
How was the initial setup?
The initial setup was not complex. Like all Fortinet devices, it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
Due to the situation in Iran with the sanctions, the price of this solution is very expensive.
Which other solutions did I evaluate?
The only other two web application firewall products that are available in my country are F5 and Imperva.
What other advice do I have?
This is a good product and I strongly recommend it, especially for companies in the banking industry.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Network Security Engineer at a computer software company with 5,001-10,000 employees
User-friendly, stable and efficiently secure VMs and applications
Pros and Cons
- "We use it to secure VMs and applications. It protects against DDoS attacks. It's very user-friendly."
- "There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support."
What is our primary use case?
I initially deployed it for my company, but now I administrate it for a client.
What is most valuable?
We use it to secure VMs and applications in Azure. It protects against DDoS attacks.
It's very user-friendly.
What needs improvement?
There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support.
In future releases, I would like to see added antivirus features that provide user-based activity indicators. For example, if a user downloads a large number of files or connects frequently, the WAF could flag this activity for investigation.
For how long have I used the solution?
I have been using it for three months now.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable product.
How are customer service and support?
For some initial issues. It's good, but not during the first year. FortiWeb could improve response time and first-level support clarity.
How would you rate customer service and support?
Positive
What about the implementation team?
The first implementation with an expert took two hours. My solo attempt took three weeks.
What other advice do I have?
Take time to test it thoroughly. Consider buying an existing solution if needed.
Overall, I would rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Fortinet FortiWeb
March 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
Cyber Security Engineer at Mudra Electronics limited
Has a user-friendly dashboard, but its technical support services need improvement
Pros and Cons
- "The product has a very user-friendly dashboard."
- "The product's scalability could be better."
What is our primary use case?
We use FortiWeb for protecting web applications.
What is most valuable?
The product has a very user-friendly dashboard.
What needs improvement?
The software's support services could be better compared to Sophos.
What do I think about the scalability of the solution?
The product's scalability could be better compared to Sophos.
How are customer service and support?
It is challenging to communicate with the FortiWeb's support team.
Which solution did I use previously and why did I switch?
We use Sophos as well.
How was the initial setup?
FortiWeb's configuration process is more difficult than Sophos. I rate the process a one out of ten.
What's my experience with pricing, setup cost, and licensing?
The product is expensive. I rate the pricing a ten out of ten.
What other advice do I have?
I rate FortiWeb a five out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network security engineer at freelancer
Great machine learning, artificial intelligence and behaviour detection
Pros and Cons
- "It helps us prevent attacks on servers."
- "There are many valuable features; it has machine learning, artificial intelligence, behaviour detection, and many other features capable of detecting web attacks."
- "The initial setup is complex."
- "The initial setup is complex and takes between three to six months."
What is our primary use case?
It helps us prevent attacks on servers, and we deploy it on-premises.
What is most valuable?
There are many valuable features. It has machine learning, artificial intelligence, behaviour detection, and many other features capable of detecting web attacks.
What needs improvement?
The initial setup could be simplified.
For how long have I used the solution?
We have been using the solution for approximately ten years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
We do not have experience with customer service and support.
How was the initial setup?
The initial setup is complex and takes between three to six months.
What about the implementation team?
We implemented the solution in-house.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiWeb has some types of licenses, and the main licenses refer to updating a signature and a pattern.
Which other solutions did I evaluate?
We evaluated machine learning and the main signatures about known attack signatures.
What other advice do I have?
I rate the solution a ten out of ten, and I recommend it for every organization with web services.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Engineer at Trans Business Machines Ltd
Easy to scale in terms of learning and utilization with a user-friendly GUI
Pros and Cons
- "The GUI makes it easy to scale in terms of learning and utilization."
- "I like that the GUI makes it easy to scale in terms of learning and utilization."
- "Lacks functionalities that are available in other solutions."
- "There are specific functionalities that I'd like to see improve and that would basically bring it into line with what is being offered by solutions such as F5 and Imperva."
What is our primary use case?
We use this product for load balancing and for their firewall. We are partners with Fortinet.
What is most valuable?
I like that the GUI makes it easy to scale in terms of learning and utilization.
We chose this solution based on the online training and materials they offered. It's easily available on the web.
What needs improvement?
There are specific functionalities that I'd like to see improve and that would basically bring it into line with what is being offered by solutions such as F5 and Imperva.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
This is a stable solution.
How was the initial setup?
The initial setup is straightforward, the deployment took us about two hours. We currently have 16 users.
What other advice do I have?
I rate this solution seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Sales Manager For State-Ownership Enterprise at PT EDI INDONESIA
Useful sandboxing, effective threat protection, and simple configuration
Pros and Cons
- "The most valuable features in Fortinet FortiWeb are sandboxing and threat prevention."
- "In my experience, Fortinet FortiWeb could improve the intelligent features to acknowledge whether any threat or incident that's running happened. Then give us the ability to escalate it to layer 2 or layer 3 in the network operations."
What is most valuable?
The most valuable features in Fortinet FortiWeb are sandboxing and threat prevention.
What needs improvement?
In my experience, Fortinet FortiWeb could improve the intelligent features to acknowledge whether any threat or incident that's running happened. Then give us the ability to escalate it to layer 2 or layer 3 in the network operations.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately two years.
What do I think about the stability of the solution?
I have found Fortinet FortiWeb to be stable.
What do I think about the scalability of the solution?
The solution is scalable, but it can only scale at a medium level.
How are customer service and support?
We use the technical support from the system integration, not directly with Fortinet FortiWeb. It takes them a lot of time to solve an issue when we submit a complaint.
in Indonesia, we need more knowledgeable local support.
How was the initial setup?
The initial implementation is simple and the configuration is straightforward.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb is reasonable. This is one of the key factors of why we use this solution.
What other advice do I have?
I rate Fortinet FortiWeb an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Director at a tech services company with 51-200 employees
Good for compliance, load balancing, and high availability
Pros and Cons
- "Banks have to be compliant with PCI and other things, and FortiWeb is absolutely amazing in terms of providing these reports. Otherwise, they will have to spend a lot of time on them."
- "The automation piece can be improved. Although they say it can be automated very well, there is still manual work. Its usability should be improved in terms of automation because we want to build an infrastructure with code, but you can't do that easily with this solution. If they can give us APIs in the firewalls that we can tap into, it would be perfect."
What is our primary use case?
We mainly use it for protection. OS scanning and load balancing are two of its main use cases.
My team is most probably working with its latest version. In terms of the deployment, lately, it has been on the cloud because the end-user-facing web applications are usually live on the cloud.
How has it helped my organization?
Banks have to be compliant with PCI and other things, and FortiWeb is absolutely amazing in terms of providing these reports. Otherwise, they will have to spend a lot of time on them.
What is most valuable?
The compliance piece is the best feature. Load balancing is also valuable, which is something that all web application firewalls do. Another valuable feature is high availability. You can scale it very well. Load balancing and high availability are the two reasons why we picked it for a couple of banks.
What needs improvement?
From the feature perspective, it is pretty rich. The automation piece can be improved. Although they say it can be automated very well, there is still manual work. Its usability should be improved in terms of automation because we want to build an infrastructure with code, but you can't do that easily with this solution. If they can give us APIs in the firewalls that we can tap into, it would be perfect.
I would also like it to scale automatically based on the traffic.
For how long have I used the solution?
I have been using this solution for about six years.
What do I think about the stability of the solution?
I've never seen any issues, but when you turn on all the features or every single scanning, that's when it slows down a bit.
What do I think about the scalability of the solution?
It is scalable, but it is a roundabout way of automated scaling. It is not truly automated scaling. In general, when the size is okay, scaling is not a problem. I would like it to scale automatically based on the traffic, but that doesn't happen because automation is not there.
I haven't seen any big issues with performance. We ran 20,000 connections through it, and it was okay. When you deploy it in the cloud, you can increase the size of the VM, and with extra licensing, it is fine performance-wise.
It is suitable for medium and large customers. My team has deployed at least 500 of these in the last few years. In general, it's okay. We don't have any issue with it.
How are customer service and support?
They have been pretty good, honest, and upfront. It all comes down to expectations when you buy these things.
I know the country manager very well. He is my friend for Fortinet. They are very good in terms of support.
When you buy these things from a marketplace like Amazon or AWS, the support is not as good as it can be because the first line of support is the cloud provider, and then there is the vendor. So, our preference usually is to go directly to the vendor because they know more about it.
Which solution did I use previously and why did I switch?
One of the best things about Azure Firewall is the automation. There is a huge difference. The second thing is pricing.
With FortiWeb, when you want to buy HA, you need to start designing high availability across different regions. With Azure, it comes by default.
How was the initial setup?
It depends on the customer and the use case. Usually, it's straightforward, but as you add more applications, it can become more and more complex.
The deployment duration varies. Usually, designing, building, and putting in production take about four weeks, but it also depends on the application type.
It requires maintenance all the time. Everything requires maintenance. Usually, we build it and operationalize it, and we then hand it over to the customer.
What's my experience with pricing, setup cost, and licensing?
It keeps changing, but it's based on the size of the VM you buy and also the traffic throughput you want from it, whereas what we have on Azure is just the traffic throughput. You can also pay on a monthly basis from Azure. During each part of the project, it's okay to get Azure-based licensing or AWS-based licensing for FortiWeb, but over time, you would want to go with the perpetual license. You should go to Fortinet and buy the license from them. So, there is a two-step process there.
What other advice do I have?
I would advise getting the right engineer. You need someone who is a specialist, and that's very important.
I would rate it an eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Engineer at a tech consulting company with 51-200 employees
Regular attack signature updates, responsive support, and blocks unknown attack
Pros and Cons
- "The most valuable feature is the attack signature and machine learning."
- "No solution is 100% secure and the security could always be worked on."
What is our primary use case?
I use Fortinet FortiWeb to protect my web application. It works to protect my applications from attack signatures. It allows me to create a URL profile and HTTP content routing when I have many web servers working on the same virtual server.
How has it helped my organization?
Fortinet FortiWeb has helped our organization by protecting the web application from any attack, known and unknown. The unknown protection is done by effective machine learning that is working on many unknown attacks. It operates on the probability of attacks.
What is most valuable?
The most valuable feature is the attack signature and machine learning.
What needs improvement?
The machine learning feature of the solution could be improved.
No solution is 100% secure and the security could always be worked on.
For how long have I used the solution?
I have been using Fortinet FortiWeb for a year and a half.
What do I think about the stability of the solution?
Fortinet FortiWeb is stable. It is able to detect the latest vulnerability from Log4j that happened on The Verge.
The solution's attack signature receives its update from Fortinet Developer Network, and many of the updates are immediate. The attack signatures are updated regularly due to the connection to Fortinet Developer Network.
What do I think about the scalability of the solution?
The solution is highly scalable.
How are customer service and support?
The technical support was good, they were very fast. They were able to resolve my issues.
I have used the support in many solutions, such as FortiClient, FortiWeb, for Sandbox integration with FortiMail, and other products in Fortinet.
How was the initial setup?
The installation is easy. It takes one day for the implementation, and after 14 days one day for tuning.
Some customer needs to go to production fast, it can take me one day for the installation, and after seven days I can do the tuning quickly.
What about the implementation team?
I do the implementation and support the solution.
What's my experience with pricing, setup cost, and licensing?
There is a subscription to use this solution. There are some additional features that can be added for an extra fee. The use of the features depends on the client's needs, such as full machine learning and signatures.
What other advice do I have?
I would recommend this solution to others. Additionally, I would recommend F5.
I rate Fortinet FortiWeb a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Cloudflare Web Application Firewall
NetScaler
F5 Advanced WAF
Microsoft Azure Application Gateway
AWS WAF
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
Check Point CloudGuard WAF
NGINX App Protect
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?
















