Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

8 AWS reviews

External reviews

63 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    reviewer1729623

Helps users to secure their web-based applications

  • May 14, 2024
  • Review provided by PeerSpot

What is most valuable?

The most valuable feature of FortiWeb Web Application Firewall (WAF) that has proven to be the most effective in protecting web applications stems from the fact that the product recently launched a SaaS model, making it a cost-effective solution, which is a major reason why we selected it in our company.

What needs improvement?

I don't see any issues with the tool apart from the pricing aspect of the product. The price of the product is an area where improvements are required.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for a year. My company is a reseller of the solution.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution since it offers a SaaS model, which is why we can increase the bandwidth and number of applications in our company.

There are around 1,000 people in a company where our organization has provided FortiWeb Web Application Firewall (WAF).

Considering the IT side of the company, there are no plans to increase the usage of the product in the future.

How are customer service and support?

The solution's technical support is good. Compared to the previous year, Fortinet has taken a lot of steps to improve its support services. The response time of the support services offered by Fortinet is good, especially since the solution launched elite support for users. I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have not used the products offered by Fortinet's competitors, but I know that most of the time, such tools can be available at a cheap price.

How was the initial setup?

My company has a team that is ready to help our customers implement the product.

There is a person in my company who knows about the technical team that takes care of the implementation part. I am a part of the marketing team, so the tool's implementation phase is something I don't know about.

What was our ROI?

In terms of ROI, the product helps secure applications and due to the security, there is less downtime when it comes to applications. From a security point, the tool uses cross-site scripting.

What's my experience with pricing, setup cost, and licensing?

The licensing cost of the product is pretty high compared to other OEMs in the market.

What other advice do I have?

As a marketing executive, I don't get to see any machine learning capabilities in the product.

My company only deals with solutions from Fortinet.

I recommend the product for pharma companies.

For administration and management of the product, there are two or three people in my company working in the core IT team.

From a marketing perspective, the product has been promoted enough in my region. My company has been promoting the product for the past 12 years.

The product offers information on the internet, and it can provide sufficient knowledge to employees who support the tool.

In terms of interface, the product is easy to use and is mostly connected to its own protocols,like FortiLink.

I rate the solution an eight out of ten.


    Hend Barbary

Offers good integration capabilities with other security tools

  • April 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution in my company, as we mostly load some web applications at our data center and use it to ensure that the web pages are properly secured.

What is most valuable?

Actually, most of the features of the tool are really good, but I would like to emphasize the importance of its machine learning features, as it can be implemented smoothly in Fortinet FortiWeb, and it is very helpful for our company.

What needs improvement?

Though the reporting is a nice aspect associated with the tool, I feel that it has certain shortcomings and can be made better. The reporting part can provide more information and be more specific.

Fortinet FortiWeb's admin guide could offer more, like, examples or features on how to implement the tool. It can provide information on how a user can make use of it in different usages, and that can help a lot. The admin guide is satisfactory, and it meets our company's needs.

Actually, my company would like it if the product could implement scanning attachments for exchange for assets or exchange needs. The aforementioned area consists of the feature that my company wants to apply, but it is not supported in Fortinet yet. My company needs the product to support us in the aforementioned area, and it can help us a lot by providing a layer of security that can check files and attachments in emails and other stuff, which would be great.

For how long have I used the solution?

I have been using Fortinet FortiWeb for three years. I am an end user of the solution.

What do I think about the stability of the solution?

Stability-wise, I rate the solution an eight out of ten.

In terms of stability, it is a good solution that is easy to use and has many features and resources. The support offered by the product is good, especially since the support team responds on time, keeps you informed, and even follows up. Generally, it is a good solution to have and use.

My company has not experienced any downtime while using the product.

What do I think about the scalability of the solution?

In our company, we have not implemented the product on a large scale.

Around 2,000 people per month use the product in our company.

Every single day, the tool is used to host web applications.

If our company needs to implement more hosted web servers, we will use Fortinet FortiWeb, but if not, then it will remain at the current number. Increasing the use of the tool is not my decision, and I just accommodate the needs of the organization.

How are customer service and support?

The solution's technical support is good. When my company faced some problems with the product, I found the solution's support team to be very supportive and helpful. I rate the technical support a nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

On a scale of one to ten, where one is difficult and ten is easy, I rate the product's initial setup phase as eight or nine.

The product's initial setup phase was straightforward, and since our company didn't have any problems with it, we didn't encounter many problems with the tool. Maybe our company encountered some problems with the product's setup because we used to use it to set up the servers or stuff, which took time, but now Fortinet FortiWeb handles everything smoothly and easily.

The solution is deployed on an on-premises version.

The solution can be deployed in a week.

What was our ROI?

If my company did not have Fortinet FortiWeb, then I believe that we would have had to host some of the services in an external data center with extra fees and there we would have had to pay for the web services, but we don't need that anymore because now, we have an on-prem web service that can promote us to be able to host as much as we need of web services.

On a scale of one to ten, where one is zero percent and ten is a hundred percent, I rate the ROI as an eight.

What's my experience with pricing, setup cost, and licensing?

If one is very cheap and ten is very expensive, I rate the product price as three or four. The tool is cost-effective and offers value for money. I didn't mean it was very expensive. The price is fixed, but some features need an extra license.

Which other solutions did I evaluate?

My company was considering F5, but you actually went for Fortinet FortiWeb after considering the cost aspect.

What other advice do I have?

My company doesn't specifically host e-commerce platforms since we offer mainly government services.

The security part has been satisfactory till now, and we haven't faced any problems yet.

FortiGate FortiWeb's features that have been most effective in mitigating web-based threats are possible because of the signatures. My company doesn't need to enforce a lot of policies or stuff. Fortinet FortiWeb has a lot of internal databases that can help you, and you can use whatever platform you are hosting your web applications through whichever software you use. it can build up a web protection profile that matches your needs, making it a very helpful tool.

Speaking about how machine learning features enhance our security posture, I would say that some aspects of the website are not normally clear for our company, and machine learning helps in such areas. It just traces the normal usage of the web applications along with the websites or links most users visit while also checking which URLs are mostly used, after which the tool differentiates between the normal usage and any abnormalities, based on which it builds the model that can be used to improve the security. Sometimes, a person cannot do things manually and is not sure about all the aspects of our web applications because many are not developers. Machine learning comes into the picture because one may not know all the stuff associated with the product.

A team of four or five people is enough to deploy the tool. Maintaining the tool is actually not a very big task and not many people are required for it.

The integration capabilities of the product with other security tools have benefited our company's security strategy as it sits smoothly in our network. The tool doesn't cause any problems with the integration part.

I would recommend that users use the tool's high availability. With the tool, one box is not enough, so there is a need to have a cluster of two boxes. Users need to measure their needs regarding the logging process and everything else, including processing. Even before starting to use it, we have to set up everything, or you would be confused about how to use the tool in the future, and it would be difficult to figure out how much retention log retention we would need in our company. It is important to set up everything related to the users' needs so that they don't need to change a lot of settings in the future.

I rate the tool an eight out of ten.


    Som Sharma

Used for web filtering purposes and has a user-friendly interface

  • April 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for web filtering purposes. We use it to allow or block any application.

What is most valuable?

The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS. The solution's console is very user-friendly and very easy to manage. The solution has good stability and a user-friendly interface.

What needs improvement?

It would be good if the solution integrated with other solutions, like SAP.

For how long have I used the solution?

I have been using FortiWeb Web Application Firewall (WAF) for nine to ten years.

What do I think about the stability of the solution?

FortiWeb Web Application Firewall is a very stable solution.

I rate the solution’s stability ten out of ten.

What do I think about the scalability of the solution?

Every location with 200 to 300 people has installed the FortiWeb Web Application Firewall.

I rate the solution a nine out of ten for scalability.

How are customer service and support?

Our experience with the solution's technical support has been good. We promptly get support from the technical support team.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution’s initial setup is easy and can be done in a few hours.

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup a nine or ten out of ten.

What other advice do I have?

I would recommend FortiWeb Web Application Firewall to other users because it is a good product.

Overall, I rate the solution a nine out of ten.


    Kacem CHAMMALI

Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb

  • April 01, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use FortiWeb to protect our web applications, including web servers, websites, and mobile apps – especially mobile payment apps. As an integrator, we also sell FortiWeb to our clients.

It is mainly for banking and NCS sector clients, but we also have others like universities and industrial companies.

How has it helped my organization?

After configuring security profiles and policies in FortiWeb, it does its best to block all web attacks, including SQL injections and other types of attacks. While I don't have the interface in front of me to provide exact details, FortiWeb is highly effective in this regard.

Most of our clients use reverse proxy mode. In this mode, FortiWeb acts as a reverse proxy, preventing attackers from directly connecting to the server or web server. All traffic passes through FortiWeb, allowing us to inspect everything.

What is most valuable?

The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead.

Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb.

Machine learning capabilities in FortiWeb:

I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.

What needs improvement?

Maybe the load balancing options could be enhanced. FortiWeb provides very good protection for web applications, web servers, and mobile apps, but the load-balancing capabilities and mechanisms are not as well-developed as those of other products like F5.

Currently, we need to purchase another solution, like FortiADC, for load balancing. It would be better if the load balancing features were more integrated and advanced within FortiWeb itself so it could handle both load balancing and web application firewall functions.

For how long have I used the solution?

I have been using it for four years.

What do I think about the stability of the solution?

It's stable. We haven't had any issues, except for maybe some hardware problems with the hard disk. But the Fortinet team and their advanced support team were great. We received a new firewall in less than a week. It was just a logistical issue.

That's the best thing about working with Fortinet's support. If there's a hardware issue or failure, we can contact them directly, they open a ticket, and send a new device. Then they check if the issue was due to human error or a hardware problem.

What do I think about the scalability of the solution?

I would rate the scalability a ten out of ten. We passed this test with one of our clients. They initially had the FortiWeb VM01, which is the fifth model of virtual machines. As the number of servers and applications behind FortiWeb grew, they needed to upgrade their license. We were able to easily upgrade the license and adjust the virtual machine specs like CPU and memory.

It's scalable without any issues. This applies to virtual machines but not necessarily to hardware appliances.

It is suitable for all types of businesses, including small, medium, or enterprise. The difference between SMBs and large enterprises is the type of license or model, such as hardware. For example, we have a bank client using FortiWeb-1000B, a cluster of two FortiWeb hardware appliances. Another client, a university in Tunisia, started with the minimum GB1 or GB0 license and upgraded to GB8.

We also have a smaller client with around 30 users and five applications, and they use FortiWeb without any issues. FortiWeb is especially needed for clients working with specific sectors like banks, mobile-payment apps and insurance companies, as they often need to comply with PCI DSS and other standards.

How are customer service and support?

I've been working with the Fortinet team for over five years, so I know how to contact them directly and ask the right questions.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

There's F5, and also Radware. FortiWeb performs the same functions as F5, Cloudflare (which is cloud-based), and other products.

But, some of these other products are more developed, especially in terms of load-balancing services. But they all do the same basic functions. F5 and FortiWeb have similar features. FortiWeb is not as expensive as F5 and other products.

The security features, like SSL offloading, are the same. There's no latency in accessing our web apps with or without the WAF. The difference lies in the security of our web and mobile apps. There's no latency, so it's the same.

How was the initial setup?

The deployment is easy, maybe because I'm familiar with Fortinet products and their deployment, whether it's hardware or virtual machines. Most of our clients are also familiar with Fortinet products and find the FortiWeb interface to be user-friendly, as it's similar to other Fortinet products like FortiGate and FortiAnalyzer.

There might be some technical aspects to the interface, but overall it's easy to use. For example, network settings are under "Network," system settings are under "System," and so on. It's consistent across all Fortinet products.

Integration with other products:

Most of our clients use Fortinet products like FortiGate firewalls, but there's no problem deploying FortiWeb with other products like Cisco or others. On the firewall, we create a virtual IP to pass traffic to FortiWeb, and then configure the virtual server and other settings on FortiWeb. FortiWeb also gives us the option to allow synchronization with SIEMs like QRadar and ArcSight.

So it can integrate with third-party tools. We can use any SIEM solution, like FortiSIEM or LogRhythm. We just need to configure the Syslog option on FortiWeb to forward logs to our SIEM server.

What about the implementation team?

I work as a FortiWeb integrator.

What's my experience with pricing, setup cost, and licensing?

It's not cheap, but it's not expensive either. It depends on the features you need and whether you choose hardware or a virtual machine.

I would rate the pricing a five out of ten, where one is high, and ten is low

What other advice do I have?

As an integrator, I recommend FortiWeb to our clients and all other clients.

Overall, I would rate it an eight out of ten.


    IgnitiusMolepo

Protects internal applications and prevents target attacks

  • February 20, 2024
  • Review provided by PeerSpot

What is our primary use case?

The tool is a valuable web application that protects our internal mobile money application. It enforces policies, ensuring secure access for users connecting to the application. It complies with PCI DSS, safeguarding financial transactions and contributing to our revenue. The solution effectively addresses malware threats.

What is most valuable?

The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises.

You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary.

The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.

What needs improvement?

We have encountered issues with webhooks and management of FortiWeb Web Application Firewall's on-premise version.

For how long have I used the solution?

I have been using the product for three years.

What do I think about the stability of the solution?

You may encounter problems if you don't have FortiAnalyzer.

What do I think about the scalability of the solution?

My company has 11,000 users.

How are customer service and support?

We've encountered several issues before, like the web and firmware's lack of responsiveness for 50 minutes. The Firewall, FortiWeb Manager firmware, and firmware updates must sync properly. We've addressed this, and our partners have helped resolve these issues.

Which solution did I use previously and why did I switch?

I tried to work with Cisco, but it wasn't working well.

How was the initial setup?

FortiWeb Web Application Firewall's deployment is not complex. The setup involves connecting the switch and the firewall. Our main task is to redirect all traffic from the application to the website. The overall process can be completed in two weeks. Maintaining it isn't challenging, but the issue arises when the firmware becomes outdated; you must check and update it.

What about the implementation team?

FortiWeb Web Application Firewall helped us with the deployment.

What other advice do I have?

I rate the overall solution a nine out of ten.


    CharlesFamisaran

Easy to setup, stable and scalable solution

  • January 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

My main use case is for security and routing.

What is most valuable?

It is good for web tracking applications.

What needs improvement?

There is room for improvement in pricing, and actually, the price is a bit higher because on the same terms I purchased, the support subscription is so high.

For how long have I used the solution?

I've been using it for a long time. It has been more than three years now.

What do I think about the stability of the solution?

Stability is guaranteed stability. I'm okay with stability. I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten.

How are customer service and support?

I am okay with the support. The support's subscription is high.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

pfSense is open-source and free, while FortiWeb is subscription-based. Both are manageable, but FortiWeb's features scale up connections per second, depending on the payment plan.

How was the initial setup?

I would rate my experience with the initial setup a nine out of ten, where one is difficult, and ten is easy.

It took us two days to set up.

What about the implementation team?

I deployed it myself. I just got a reference from the old system, and I configured it.

What's my experience with pricing, setup cost, and licensing?

I would rate the pricing a seven out of ten, where one is cheap and ten is expensive.

What other advice do I have?

Overall, I would rate it a solid eight out of ten.


    reviewer2323683

User-friendly, stable and efficiently secure VMs and applications

  • December 18, 2023
  • Review provided by PeerSpot

What is our primary use case?

I initially deployed it for my company, but now I administrate it for a client.

What is most valuable?

We use it to secure VMs and applications in Azure. It protects against DDoS attacks.

It's very user-friendly.

What needs improvement?

There is room for improvement in the support. The response time could be faster. Plus, they ask for a lot of information. It is not easy to get support.

In future releases, I would like to see added antivirus features that provide user-based activity indicators. For example, if a user downloads a large number of files or connects frequently, the WAF could flag this activity for investigation.

For how long have I used the solution?

I have been using it for three months now.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

It is a scalable product.

How are customer service and support?

For some initial issues. It's good, but not during the first year. FortiWeb could improve response time and first-level support clarity.

How would you rate customer service and support?

Positive

What about the implementation team?

The first implementation with an expert took two hours. My solo attempt took three weeks.

What other advice do I have?

Take time to test it thoroughly. Consider buying an existing solution if needed.

Overall, I would rate the solution an eight out of ten.


    Jishain-Ali

An easy-to-deploy solution with machine learning features that reduce false positives

  • October 18, 2023
  • Review provided by PeerSpot

What is most valuable?

The product has some unique features. The machine learning feature reduces the false positives. The tool detects zero-day attacks. It has an in-built antivirus, which most WAF tools do not have.

What needs improvement?

Advanced configurations require high skill. FortiWeb team should work on making it easier. The documentation is poor. The tool must provide advanced and robust DDoS protection.

For how long have I used the solution?

I have been using the solution for almost six years.

How are customer service and support?

The technical support is fine. The support team gives delayed responses if there is a complex issue.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have worked with F5 Advanced WAF. It is a robust product and is suitable for complex environments. It is flexible. However, it depends on other solutions for inbuilt security and packet inspection.

How was the initial setup?

The initial setup is easy. It requires less intervention.

What's my experience with pricing, setup cost, and licensing?

I recommend the product to others. Overall, I rate the solution an eight out of ten.


    Md. Al Imran Chowdhury

An useer-friendly solution with easy configuration

  • October 12, 2023
  • Review provided by PeerSpot

What is most valuable?

The tool's HTTP traffic, website fixing, and blocking are fantastic. It is user-friendly with easy configuration.

What needs improvement?

FortiWeb Web Application Firewall needs to improve its performance.

What do I think about the scalability of the solution?

FortiWeb Web Application Firewall is scalable.

How are customer service and support?

The tool's tech support is good.

How was the initial setup?

The tool's installation is straightforward.

What's my experience with pricing, setup cost, and licensing?

FortiWeb Web Application Firewall is not expensive.

What other advice do I have?

I rate the solution an eight out of ten.


    Oche Eluma

Helps us to view all of our logs on one platform

  • September 21, 2023
  • Review from a verified AWS customer

What is our primary use case?

I have a multi-cloud environment. I have a production workload in Nigeria, with some data centers in Continental Europe and in the East US in multiple regions.

We have two different public clouds, AWS and Azure. Because of how Fortinet works, we connect to our customers via a remote access VPN.

What is most valuable?

The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature.

Emails can be configured, and text messages can be sent via the mobile app.

It is a cheap solution.

What needs improvement?

The user interface can be improved. Also, there are authentication failures that need improvement in the next release.

For how long have I used the solution?


How are customer service and support?

The technical support team is bad.

How would you rate customer service and support?

Neutral

What other advice do I have?

I would rate the overall solution a eight out of ten due to the support and user interface issues.