Normally I deal with on-premises installations. The firewalls are always on-prem for government departments. In a recent case, I was looking at a cloud solution because it was what the client preferred. So it was the Fortinet rules applied to an AWS solution. I was looking at the architecture around becoming an IRAP (Information Security Registered Assessors Program) certified program and I was looking at the AWS firewalls around how it would be able to comply with the ISM (International Safety Management) standards.
GRC Security Consultant at a computer software company with 51-200 employees
This flexible suite solves compliance problems but that comes at a cost
Pros and Cons
- "If I need something from tech support, I can get it answered within the hour."
- "Both the internal firewall management and the cloud can be managed by a single console."
- "It costs too much."
- "It is not entirely user-friendly."
What is our primary use case?
What is most valuable?
For me personally, the most valuable thing is that I like the fact that it is standardized so both internal firewall management and the cloud can be managed by the same company. Communication between the two works well and it can be a benefit. We can keep a single console to manage both.
What needs improvement?
User administrative controls could be a little bit better. I guess that would be the main thing. The usability within Fortinet could be a little bit easier on the users. But it is what it is.
The thing that was more difficult was not the tool itself but dealing with the logistics of the compliance issues. I was applying a standard set of rules to an AWS firewall. It served a purpose. The complex part of the solution was more of a compliance issue.
For how long have I used the solution?
We have been using Fortinet FortiWeb probably for over a year-and-a-half. Closer to two years.
Buyer's Guide
Fortinet FortiWeb
January 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
What do I think about the scalability of the solution?
At this point in time, scalability seems to be fine. I mean, we are talking processing requests from all over Australia. It seems to be keeping up quite well. My impression of it at this stage is that it is very scalable. It is quite well suited for data management.
How are customer service and support?
I think judging our experience with technical support is a little bit unfair because I know all the local support people. I do go into the help desk when I have to, but I do know most of the teachers or technical support staff. I would rate them as being very responsive to customers. I have had no issues. If I need something I can get it answered within the hour. It is quite good.
How was the initial setup?
It was quite easy to do the initial setup and apply basic rules. Administratively, keeping an AWS firewall and applying the Fortinet rules made it quite simple for the difficulty level of this particular requirement.
What's my experience with pricing, setup cost, and licensing?
I think that ForiWeb is expensive for what they are offering. At the end of the day, when you sell a suite, compliance within the suite is easy to maintain. That is the good part. It is an expensive suite and it is an expensive solution, but it is a manageable one for an enterprise. It should just be cheaper for what they are offering in comparison to other tools on the market.
What other advice do I have?
My advice to people would be to evaluate the marketplace against your requirements and choose appropriately. Fortinet does operate at the enterprise level. It is listed on the Australian standard and it does carry Australia's approval for common criteria. So it does address the requirements needed for security for the assessments. Not every product can.
On a scale from one to ten (where one is the worst and ten is the best), I would rate this Fortinet solution as a seven-out-of-ten because of user administrative controls, usability, and price.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Specialist at a financial services firm with 201-500 employees
Efficient, stable, and has good IP reputation features, but there are many false positive with the layer 7 attacks
Pros and Cons
- "It's stable and works efficiently against OWASP Top 10 attacks."
- "The Layer 7 DDoS attacks need improvement, it could be better."
What is our primary use case?
Fortinet FortiWeb is known for its web application firewalls. We are using it for preventing and detecting layer 7 attacks such as SQL injection.
We have several web applications in our organization and we use this solution to protect them against attacks.
What is most valuable?
It's stable and works efficiently against OWASP Top 10 attacks.
It's good at checking IP reputation and it's capable of detecting Layer 7 DDoS attacks.
Overall, it has many features.
What needs improvement?
The Layer 7 DDoS attacks need improvement, it could be better. When you compare it with the F5 solution, FortiWeb is weak in detecting the Layer 7 DDoS attacks. At times, it generates several false positives and there should be fewer.
In the next release, I would like to see better DDoS protection. It's an essential feature that should be included.
For how long have I used the solution?
I have been using Fortinet FortiWeb for more than five years.
We are using the 4000D model.
What do I think about the stability of the solution?
It's a stable solution and we run it 24/7. In the past five years, we have had four cases where there were some inconsistencies with the firmware. There are times where we experience crashes because of issues with the firmware.
What do I think about the scalability of the solution?
It's not easy to scale this solution. It has a determined throughput and if your throughput is more than it should be then you have to use another solution or purchase another FortiWeb model.
We have less than 10 people using this solution on a daily basis.
How are customer service and technical support?
We are not able to use international support because of US sanctions. We use a consultant to help us troubleshoot.
Which solution did I use previously and why did I switch?
Previously with another company, we used ModSecurity, which is an open-source solution. FortiWeb is better.
If I compare with F5 solutions, I would suggest F5.
How was the initial setup?
The initial setup was not easy but not exactly complex.
We maintain the system ourselves.
What about the implementation team?
We completed the initial setup ourselves and we had a consultant help us with some of the features. It was a hybrid implementation.
What's my experience with pricing, setup cost, and licensing?
It's an expensive solution, although there are no additional costs.
What other advice do I have?
In my opinion, F5 is the best solution in the world, whereas Fortinet FortiWeb would be second.
I have heard that Barracuda is a good solution, but I have not worked with it. In my experience, F5 is the better solution.
I would rate Fortinet FortiWeb a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiWeb
January 2026
Learn what your peers think about Fortinet FortiWeb. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
Data Center Network Expert at a financial services firm with 501-1,000 employees
User-friendly and makes it easy to find vulnerabilities
Pros and Cons
- "This product is very user-friendly."
- "FortiWeb needs to have support for the newest technology being used in web applications."
What is our primary use case?
We are using FortiWeb for publishing web services and some web applications.
What is most valuable?
The interface makes it easy to identify vulnerabilities.
The best features for us are the signature services. The devices uses signatures for identifying vulnerabilities in web applications.
This product is very user-friendly.
The security is very good.
What needs improvement?
FortiWeb needs to have support for the newest technology being used in web applications. For example, some companies have developed new features using the latest technology, but we are still waiting for Fortinet to support them.
For how long have I used the solution?
I have been using FortiWeb for between four and five years.
What do I think about the stability of the solution?
The stability is very good and we're fortunate that we haven't had any issues.
What do I think about the scalability of the solution?
We have had no issues with scalability.
How are customer service and technical support?
We are in Iran and working under sanctions, which means that we cannot buy new American products and cannot get support. Companies usually buy devices that are second hand, or from a third-party, neither of which have support.
That said, my impression is that the support is good for companies who are eligible to use it.
How was the initial setup?
The initial setup was not complex. Like all Fortinet devices, it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
Due to the situation in Iran with the sanctions, the price of this solution is very expensive.
Which other solutions did I evaluate?
The only other two web application firewall products that are available in my country are F5 and Imperva.
What other advice do I have?
This is a good product and I strongly recommend it, especially for companies in the banking industry.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Network Security Engineer at a computer software company with 5,001-10,000 employees
User-friendly, stable and efficiently secure VMs and applications
Pros and Cons
- "We use it to secure VMs and applications. It protects against DDoS attacks. It's very user-friendly."
- "There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support."
What is our primary use case?
I initially deployed it for my company, but now I administrate it for a client.
What is most valuable?
We use it to secure VMs and applications in Azure. It protects against DDoS attacks.
It's very user-friendly.
What needs improvement?
There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support.
In future releases, I would like to see added antivirus features that provide user-based activity indicators. For example, if a user downloads a large number of files or connects frequently, the WAF could flag this activity for investigation.
For how long have I used the solution?
I have been using it for three months now.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable product.
How are customer service and support?
For some initial issues. It's good, but not during the first year. FortiWeb could improve response time and first-level support clarity.
How would you rate customer service and support?
Positive
What about the implementation team?
The first implementation with an expert took two hours. My solo attempt took three weeks.
What other advice do I have?
Take time to test it thoroughly. Consider buying an existing solution if needed.
Overall, I would rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber Security Engineer at a manufacturing company with 11-50 employees
Has a user-friendly dashboard, but its technical support services need improvement
Pros and Cons
- "The product has a very user-friendly dashboard."
- "The product's scalability could be better."
What is our primary use case?
We use FortiWeb for protecting web applications.
What is most valuable?
The product has a very user-friendly dashboard.
What needs improvement?
The software's support services could be better compared to Sophos.
What do I think about the scalability of the solution?
The product's scalability could be better compared to Sophos.
How are customer service and support?
It is challenging to communicate with the FortiWeb's support team.
Which solution did I use previously and why did I switch?
We use Sophos as well.
How was the initial setup?
FortiWeb's configuration process is more difficult than Sophos. I rate the process a one out of ten.
What's my experience with pricing, setup cost, and licensing?
The product is expensive. I rate the pricing a ten out of ten.
What other advice do I have?
I rate FortiWeb a five out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network security engineer at a outsourcing company with self employed
Great machine learning, artificial intelligence and behaviour detection
Pros and Cons
- "It helps us prevent attacks on servers."
- "The initial setup is complex."
What is our primary use case?
It helps us prevent attacks on servers, and we deploy it on-premises.
What is most valuable?
There are many valuable features. It has machine learning, artificial intelligence, behaviour detection, and many other features capable of detecting web attacks.
What needs improvement?
The initial setup could be simplified.
For how long have I used the solution?
We have been using the solution for approximately ten years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
We do not have experience with customer service and support.
How was the initial setup?
The initial setup is complex and takes between three to six months.
What about the implementation team?
We implemented the solution in-house.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiWeb has some types of licenses, and the main licenses refer to updating a signature and a pattern.
Which other solutions did I evaluate?
We evaluated machine learning and the main signatures about known attack signatures.
What other advice do I have?
I rate the solution a ten out of ten, and I recommend it for every organization with web services.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Engineer at a tech services company with 11-50 employees
Easy to scale in terms of learning and utilization with a user-friendly GUI
Pros and Cons
- "The GUI makes it easy to scale in terms of learning and utilization."
- "Lacks functionalities that are available in other solutions."
What is our primary use case?
We use this product for load balancing and for their firewall. We are partners with Fortinet.
What is most valuable?
I like that the GUI makes it easy to scale in terms of learning and utilization.
We chose this solution based on the online training and materials they offered. It's easily available on the web.
What needs improvement?
There are specific functionalities that I'd like to see improve and that would basically bring it into line with what is being offered by solutions such as F5 and Imperva.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
This is a stable solution.
How was the initial setup?
The initial setup is straightforward, the deployment took us about two hours. We currently have 16 users.
What other advice do I have?
I rate this solution seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Sales Manager For State-Ownership Enterprise at a tech services company with 201-500 employees
Useful sandboxing, effective threat protection, and simple configuration
Pros and Cons
- "The most valuable features in Fortinet FortiWeb are sandboxing and threat prevention."
- "In my experience, Fortinet FortiWeb could improve the intelligent features to acknowledge whether any threat or incident that's running happened. Then give us the ability to escalate it to layer 2 or layer 3 in the network operations."
What is most valuable?
The most valuable features in Fortinet FortiWeb are sandboxing and threat prevention.
What needs improvement?
In my experience, Fortinet FortiWeb could improve the intelligent features to acknowledge whether any threat or incident that's running happened. Then give us the ability to escalate it to layer 2 or layer 3 in the network operations.
For how long have I used the solution?
I have been using Fortinet FortiWeb for approximately two years.
What do I think about the stability of the solution?
I have found Fortinet FortiWeb to be stable.
What do I think about the scalability of the solution?
The solution is scalable, but it can only scale at a medium level.
How are customer service and support?
We use the technical support from the system integration, not directly with Fortinet FortiWeb. It takes them a lot of time to solve an issue when we submit a complaint.
in Indonesia, we need more knowledgeable local support.
How was the initial setup?
The initial implementation is simple and the configuration is straightforward.
What's my experience with pricing, setup cost, and licensing?
The price of Fortinet FortiWeb is reasonable. This is one of the key factors of why we use this solution.
What other advice do I have?
I rate Fortinet FortiWeb an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
NetScaler
AWS WAF
Cloudflare Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Check Point CloudGuard WAF
Buyer's Guide
Download our free Fortinet FortiWeb Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?
















