Listing Thumbnail

    Fortinet Managed Rules for AWS WAF - SQLi/XSS

     Info
    Deployed on AWS
    The SQLi/XSS Rule Group provides the latest protection from the two primary web application attack types: SQL injection and Cross-site scripting.
    4.2

    Overview

    Play video

    Fortinet's WAF rulesets are based on the FortiWeb web application firewall security service signatures, and are updated on a regular basis to include the latest threat information from FortiGuard Labs. The SQLi/XSS Ruleset provides protection from the two primary web application attack types identified in the OWASP Top 10, SQL Injection and Cross-Site Scripting. Please see our other rulesets for additional protections.

    Highlights

    • Detects SQL Injection and Cross-Site Scripting Attacks
    • Can be configured to log, alert and/or block
    • Regular updates from FortiGuard Labs

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet Managed Rules for AWS WAF - SQLi/XSS

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $15.00
    Charge per million requests in each available region
    $1.00

    Vendor refund policy

    Non-Refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support offered by Fortinet. Contact Fortinet directly by email - awswaf@fortinet.com . Please see FAQ for more info.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Threat Intelligence Updates
    Receives regular updates from FortiGuard Labs with latest threat information and security signatures
    Configurable Response Actions
    Supports configuration of multiple response actions including logging, alerting, and blocking of detected threats
    OWASP Top 10 Protection
    Provides protection against primary web application attack types identified in OWASP Top 10 standards
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Comprehensive protection against all OWASP Top 10 Web Application Threats
    Code Injection Prevention
    Managed rules targeting code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Protection
    Dedicated rules for known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Malicious Bots rulesets included for bot-based threat mitigation
    OWASP Top 10 Attack Protection
    Provides protection against web attacks including SQL injection, cross-site scripting (XSS), command injection, NoSQL injection, path traversal, and predictable resource exploitation.
    Managed Rule Updates
    Rules are written, managed and regularly updated by F5's security specialists to ensure protection against evolving threats without requiring manual intervention.
    AWS WAF Integration
    Rules can be attached to AWS WAF instances for immediate deployment and protection enhancement.
    Automated Threat Detection
    Utilizes security expertise to identify and mitigate vulnerabilities that are part of the OWASP Top 10 attack vectors.
    Pay-as-You-Go Licensing Model
    Rules are licensed on a consumption-based pricing structure where usage determines costs.

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    22 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    32%
    64%
    5%
    0%
    0%
    9 AWS reviews
    |
    13 external reviews
    External reviews are from G2  and PeerSpot .
    Rohit Racharla

    Security rules have protected parcel lockers from attacks and now need smarter AI-driven threat detection

    Reviewed on May 19, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We are using Fortinet Managed Rules for AWS WAF  for one of our front-end applications called the lockers application, where it will be interacted with our postmen in Belgium. For that application to protect against hackers and bots, we are using these WAF  rules.

    Currently, I have used Fortinet Managed Rules for AWS WAF  in the AWS  service provider for cloud. We have integrated this in the WAF  for the locker application, which is an end customer application, and we receive around thousands to hundreds of thousands of requests coming to our application. Since this is publicly exposed, we are using it to make our application more secure and robust without any downtime or security attacks.

    What is most valuable?

    Fortinet Managed Rules for AWS WAF is mainly used for controlling the use of bots and hackers, and tracking geolocation rules and source IP behaviors, which is very helpful in our application and organization from a security perspective.

    The main features include integration with AWS , Azure , and Google Cloud . Additionally, it helps protect against OWASP Top 10 vulnerabilities, helps prevent data breaching, and ensures regulatory compliance.

    Fortinet Managed Rules for AWS WAF has positively impacted us. We were not having financial losses because our application, the lockers, is where citizens place their parcels. Someone could potentially try to manipulate those devices. To protect against such security risks and penalties, this solution helped notify us about what is coming to our application from a hacker's perspective and how they are trying to exploit the application. To mitigate these things, it has been helpful for us.

    Since using Fortinet Managed Rules for AWS WAF, financial losses have gradually decreased. Because this is a customer-facing environment where citizens of Belgium use the lockers to place their parcels, we were able to mitigate this risk. Additionally, whenever a hacker was trying to exploit the system and asking for a bounty, that threat was completely eliminated. These two things are very valuable for our application to mitigate.

    What needs improvement?

    Fortinet Managed Rules for AWS WAF should have AI-driven threat detection to reduce false positives, and the UI should be improved. Additionally, improvements should be made to the logging methods and web application protection. It should also be more effective for modern environments, and as the world evolves along with AI, it should evolve with an AI-driven architecture as well.

    We are emerging in the AI space, and Fortinet Managed Rules for AWS WAF should be AI compatible as well. I am not certain whether it is AI compatible, as I have not used that particular service. I suggest enhancing it for more AI-driven applications.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for the last one year.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    Fortinet Managed Rules for AWS WAF was easily scaled without any issues. We did not have to monitor anything, but it scaled directly.

    How are customer service and support?

    The customer support for Fortinet Managed Rules for AWS WAF was very prompt. Whenever assistance was needed, there was always an engineer available to help us. I really appreciate their support.

    Which solution did I use previously and why did I switch?

    I have not used any other services. I am directly using Fortinet Managed Rules for AWS WAF only.

    How was the initial setup?

    I purchased Fortinet Managed Rules for AWS WAF through the AWS Marketplace , which is the only option available.

    Since it is present in AWS, the cost of Fortinet Managed Rules for AWS WAF is not high, and my customer is also happy with the cost and the work it is doing. At the integration level, it is a click and use solution.

    What was our ROI?

    For return on investment, since we are protecting our application from Layer 7 attacks and deadly attacks, Fortinet Managed Rules for AWS WAF helps us prevent data breaches and protects against hackers trying to exploit the lockers or someone trying to steal parcels from the lockers. For that, it has been very helpful.

    Which other solutions did I evaluate?

    I checked F5 and Imperva before choosing Fortinet Managed Rules for AWS WAF. Comparing all those options, I made the decision to use Fortinet.

    What other advice do I have?

    I would rate Fortinet Managed Rules for AWS WAF a seven out of ten. I highly recommend others to try Fortinet Managed Rules for AWS WAF and see how exactly these managed rules are working.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    HARISH JOGADIYA

    Protection against API attacks has improved and security teams save time with managed rules

    Reviewed on May 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Fortinet Managed Rules for AWS WAF  is to manage our rules and utilize its pre-configured security rules as an AWS WAF  forensic provider.

    What is most valuable?

    The best features Fortinet Managed Rules for AWS WAF  offers include regularly updated rules which incorporate the latest threat intelligence, logs, alerts, and the ability to block malicious requests that we have found on this WAF .

    Fortinet Managed Rules for AWS WAF  positively impacts my organization by providing protections against API-based attacks, rule-based security, and threat intelligence from FortiGuard.

    What needs improvement?

    Improvements for Fortinet Managed Rules for AWS WAF could enhance its capabilities as a cloud-based software application by directly identifying application model-wise for monthly usage which resembles billing concerning AWS  billing, deployment, and infrastructure management.

    I find Fortinet Managed Rules for AWS WAF acceptable with no specific recommendations for improvements.

    There are no additional improvements needed for Fortinet Managed Rules for AWS WAF that I have not mentioned.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for one year.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    The scalability of Fortinet Managed Rules for AWS WAF ensures stability while handling large traffic volumes efficiently, making it a suitable enterprise application.

    How are customer service and support?

    Customer support is good, and customers are expressing satisfaction.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    I purchased Fortinet Managed Rules for AWS WAF through the AWS Marketplace .

    What about the implementation team?

    My company has a business relationship with this vendor as a partner.

    What was our ROI?

    I have seen a return on investment with money saved and time saved.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Fortinet Managed Rules for AWS WAF is acceptable as a budgetary matter.

    Which other solutions did I evaluate?

    Before choosing Fortinet Managed Rules for AWS WAF, I did not evaluate other options.

    What other advice do I have?

    I have no additional comments or advice to give to others looking into using Fortinet Managed Rules for AWS WAF. I have no additional thoughts about Fortinet Managed Rules for AWS WAF. I would rate this product a 10.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Kelghazouli Rasuli

    Security rules have protected internal web servers and now control access from distributed tablets

    Reviewed on May 13, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Fortinet Managed Rules for AWS WAF  is to use it as a firewall to protect my internal device which is in the internal network in AWS  and the internet.

    To protect my internal device, I had some servers inside the internal network in AWS , one of which is a published server, a web server, that we would like to publish some of this website's application to users outside in our previous company. We have an application hosted in AWS that has a web interface accessible through multiple tablets connected to around 110 trucks all around Egypt, and we have used Fortinet Managed Rules for AWS WAF  to publish only this website to a specific number of tablets.

    Regarding my main use case, we choose the right rule which is only publishing this web interface with a specific port, and we changed this port to a non-standard port to be able to be secured, and changing the port also decreases the threats usually aimed at the default ports for HTTP and HTTPS.

    What is most valuable?

    Fortinet Managed Rules for AWS WAF  offers the best features by protecting my servers and blocking unauthorized access while also giving me the flexibility to only enable allowed access.

    The flexibility it offers for enabling allowed access works for me as I have multiple websites on this server using multiple ports, so using port address translation allows us to publish only a specific website.

    Fortinet Managed Rules for AWS WAF  has positively impacted my organization by decreasing the risk and vulnerability and the threats to attack my internal server.

    What needs improvement?

    I do not have anything else to add about the needed improvements. I chose eight out of ten for my rating because there are some competitor software or applications that offer more advanced rules and policies.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for two years.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    I cannot comment on its scalability because I have only a couple of servers in AWS and was using it with only two servers.

    How are customer service and support?

    I did not use customer support because I did the configuration by myself.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution, as this was the first time solution to do that, and after that, I have also used the WAF for Huawei Cloud.

    How was the initial setup?

    I purchased Fortinet Managed Rules for AWS WAF through the AWS Marketplace .

    My experience with pricing, setup costs, and licensing is that I did not take a large amount or large package, so it is acceptable for me.

    What about the implementation team?

    My company does not have a business relationship with this vendor other than being a customer.

    What was our ROI?

    A general sense is that Fortinet Managed Rules for AWS WAF is decreasing our risk.

    I do not have an exact number or figures or metrics to share, but based on what we are checking on the logs, we find that multiple unauthenticated access attempts have already been blocked.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup costs, and licensing is that I did not take a large amount or large package, so it is acceptable for me.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Fortinet Managed Rules for AWS WAF.

    What other advice do I have?

    My advice to others looking into using Fortinet Managed Rules for AWS WAF is that it is reasonable, flexible, and cost-sufficient.

    In my point of view, Fortinet Managed Rules for AWS WAF is acceptable, as I did not face any issue or any complicated configuration. I gave this product a rating of eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    AravindR

    Strengthened API security has reduced web attacks and simplifies incident response workflows

    Reviewed on Apr 06, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Fortinet Managed Rules for AWS WAF  mainly for protection against common web attacks like SQL injection, cross-site scripting, and remote code execution, securing AWS  workloads, including virtual patching, API and application protection, and continuous threat intelligence updates.

    In virtual patching with Fortinet Managed Rules for AWS WAF , it blocks an exploit at the WAF  layer before the code fix, which is illustrated by a typical scenario where I have a web app running on Amazon EC2  with a discovered vulnerability, such as an SQL injection in the login API, where an urgent fix is required but takes days, allowing attackers to exploit it. By enabling Fortinet Managed Rules for AWS WAF  group in WAF, SQLi detection and payload pattern blocking are provided, so malicious requests are blocked before reaching the app.

    A fintech app had a login endpoint vulnerable to SQLi, and with a three-day patch ETA, Fortinet Managed Rules for AWS WAF rules immediately blocked the SQLi patterns with no downtime, avoiding the need for a hotfix.

    What is most valuable?

    Fortinet Managed Rules for AWS WAF offers many features, starting with the API security rule set, which covers SQL injection, XSS, command injection, file inclusion, deserialization, and is particularly essential for API apps protecting against JSON payload manipulation, API abuse patterns, and injection via API parameters.

    Fortinet Managed Rules for AWS WAF API rules help with API security compared to other tools I have used. With Fortinet Managed Rules for AWS WAF API, there is no need to write complex custom rules, which contrasts with other setups where I must write JSON inspection rules and regex for payload validation, saving significant time in rule creation and testing, since Fortinet Managed Rules for AWS WAF understands API behavior patterns and automatically detects abnormal parameter changes and JSON injections, including bot detection, credential stuffing detection, and requires minimal maintenance due to continuous updates.

    Staging Mode with count-to-block feature of Fortinet Managed Rules for AWS WAF helps avoid breaking production traffic, as it allows for rule tuning before switching to block mode, and its visibility and logging offer detailed insights into triggered rules and malicious payloads, aiding incident investigation.

    Fortinet Managed Rules for AWS WAF has had a clear positive impact on my organization, with a significant reduction in attack traffic. I had frequently seen SQL injection attempts previously, and after enabling Fortinet Managed Rules for AWS WAF, a large portion was automatically blocked at the edge, resulting in fewer security incidents and reduced operational efforts.

    After implementing Fortinet Managed Rules for AWS WAF, I observed measurable improvements, with around 70 to 90% of common web attack traffic blocked, a 60% reduction in application-level security alerts and incidents, and a substantial decrease in the time spent on WAF management from hours per week to near zero.

    What needs improvement?

    Fortinet Managed Rules for AWS WAF are very effective, but areas for improvement include better visibility into rule logic, deeper API schema validation, and advanced bot management features.

    For example, legitimate API payloads can be blocked due to generic pattern matching without clear logs indicating the trigger, and there is a need for more advanced capabilities in bot detection, such as device fingerprinting.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for almost eight or more years.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF is stable.

    What do I think about the scalability of the solution?

    Fortinet Managed Rules for AWS WAF scales very well because of its cloud-native architecture, scaling automatically with traffic without requiring infrastructure changes.

    How are customer service and support?

    Overall, the customer support for Fortinet Managed Rules for AWS WAF has been good, although there can be some variability based on region and SLAs.

    Which solution did I use previously and why did I switch?

    I previously relied on the native managed rule set of AWS WAF  along with custom rules, switching to Fortinet Managed Rules for AWS WAF for advanced protection and reduced operational overhead.

    How was the initial setup?

    I purchased Fortinet Managed Rules for AWS WAF through the AWS Marketplace .

    What was our ROI?

    I see a clear return on investment after seeing significant time savings, reduced risk, and lower infrastructure load, leading to cost efficiency without needing to scale the security team.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing and licensing for Fortinet Managed Rules for AWS WAF through AWS Marketplace  was straightforward with minimal setup costs, aligning well with the AWS  pay-as-you-go model.

    Which other solutions did I evaluate?

    Before selecting Fortinet Managed Rules for AWS WAF, I evaluated AWS native rules, Cloudflare , F5, and Imperva, but Fortinet Managed Rules for AWS WAF offered the best balance of security and operational efficiency.

    What other advice do I have?

    Fortinet Managed Rules for AWS WAF have helped me in many scenarios.

    If someone is planning to use Fortinet Managed Rules for AWS WAF, I recommend starting in count mode, understanding the application and traffic, tuning for sensitive endpoints, and testing in lower environments.

    Fortinet Managed Rules for AWS WAF have been foundational for my security stack, providing a good balance between strong out-of-the-box protection and reduced operational overhead. I would rate my overall experience with Fortinet Managed Rules for AWS WAF as an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Vivek Patoliya

    Automation has strengthened bot control and web traffic security across our cloud workloads

    Reviewed on Apr 01, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Our primary use case is protecting public‑facing web applications hosted on AWS  against common web threats while reducing the effort required to manage custom WAF  rules. We use Fortinet Managed Rules to enhance baseline AWS WAF  protection, particularly for OWASP Top 10 vulnerabilities, malicious bots, and abnormal web traffic.

    The managed rule sets help standardize application security across workloads fronted by AWS  services such as Application Load Balancers  and CloudFront, while allowing us to focus on operations rather than constant rule tuning.

    How has it helped my organization?

    Fortinet Managed Rules for AWS WAF  have helped strengthen our overall web application security posture while significantly reducing operational effort. By using managed rule sets, we improved protection against common OWASP Top 10 threats and malicious bot traffic without continuously maintaining custom rules.

    Automatic updates from Fortinet reduced manual intervention, improved consistency across applications, and allowed the team to focus more on operations and monitoring rather than rule maintenance.

    What is most valuable?

    One of the best features of Fortinet Managed Rules for AWS WAF  is the automation of rule updates, which significantly reduces the need for manual intervention. The managed rule sets provide effective coverage for common OWASP Top 10 threats, SQL injection attempts, and malicious bot activity, helping strengthen baseline application security.

    Bot control and traffic filtering capabilities have been particularly useful in ensuring that incoming traffic is legitimate, improving visibility into request behavior and reducing unwanted or suspicious activity. The ability to quickly apply policies such as geo‑blocking and IP reputation checks through AWS WAF  integration also saves time and simplifies daily operations. Overall, these features help balance strong security with lower operational overhead.

    What needs improvement?

    Fortinet Managed Rules for AWS WAF  could be improved by providing more granular visibility and tuning capabilities while still keeping the managed nature of the service. Simplifying  rule customization and offering clearer insights into why certain rules trigger would help reduce the effort required to fine‑tune policies for complex applications.

    Additional enhancements around analytics and reporting — such as faster access to traffic insights and clearer threat context — would further improve operational efficiency and help teams respond more quickly to security events.

    For how long have I used the solution?

    I have been using Fortinet Managed Rules for AWS WAF for over three years as part of our AWS web application security operations.

    What do I think about the stability of the solution?

    Fortinet Managed Rules for AWS WAF has been stable and reliable in our environment. Over the past several months of use, we have not experienced service disruptions, unexpected behavior, or rule‑related issues impacting application availability.

    The managed updates have been applied smoothly without requiring manual intervention, which has helped maintain consistent protection while keeping operations stable.

    What do I think about the scalability of the solution?

    Fortinet Managed Rules for AWS WAF scale well because they are built on top of AWS WAF’s cloud‑native architecture. The solution automatically scales with application traffic, allowing protection to remain consistent during traffic spikes without requiring manual intervention or additional infrastructure.

    From an operational perspective, the managed rule updates and native integration with AWS services make it easier to maintain consistent security as environments grow. This scalability is particularly useful for applications hosted behind AWS Application Load Balancers  or CloudFront where traffic patterns can change dynamically.

    How are customer service and support?

    Our experience with customer service and technical support has been positive. When support was needed, responses were timely and knowledgeable, and issues were addressed efficiently. Overall, the support experience has been reliable and adequate for operational needs.

    Which solution did I use previously and why did I switch?

    Previously, we used an open‑source solution based on pfSense, primarily due to budget constraints at the time. While it provided flexibility, it required significant manual configuration and ongoing management. As our environment matured, we moved to a managed solution to reduce operational overhead and improve consistency in application security.

    How was the initial setup?

    The initial setup was straightforward. We purchased Fortinet Managed Rules for AWS WAF through the AWS Marketplace , and enabling the managed rule sets within AWS WAF was simple. Since it integrates natively with AWS WAF, there was no additional infrastructure to deploy, and the configuration process was quick and easy to manage.

    What about the implementation team?

    No, we did not use an integrator, reseller, or external consultant for the deployment. The solution was implemented internally, and the integration with AWS WAF was straightforward enough to manage without third‑party assistance.

    What was our ROI?

    While it is difficult to quantify ROI strictly in terms of direct cost savings, we have seen positive returns through improved security posture and operational efficiency. Fortinet Managed Rules for AWS WAF reduced the time and effort required to manage and update WAF rules manually, allowing the team to focus on monitoring and response rather than constant tuning.

    From a risk‑reduction perspective, preventing web attacks and ensuring consistent application availability provides clear business value, even if the benefits are not always directly measurable in monetary terms.

    What's my experience with pricing, setup cost, and licensing?

    Our experience with pricing and licensing has been reasonable and aligned with the value provided. As a managed solution integrated with AWS WAF, the setup cost was relatively low compared to deploying and maintaining standalone infrastructure.

    Licensing was straightforward and flexible, allowing us to scale protection based on actual security needs. While cost considerations always depend on the level of protection required, the overall pricing felt justified given the reduced operational effort and ongoing rule management handled by the vendor.

    Which other solutions did I evaluate?

    Before selecting Fortinet Managed Rules for AWS WAF, we evaluated other solutions such as Palo Alto and Sophos. These options provided strong security capabilities but typically required more complex deployment models or additional infrastructure and management overhead in a cloud‑native AWS environment.

    Fortinet Managed Rules integrated more seamlessly with AWS WAF and offered a simpler, managed approach to rule updates and ongoing maintenance. This made it easier to standardize web application security while reducing operational effort compared to the alternatives we reviewed.

    What other advice do I have?

    I would rate Fortinet Managed Rules for AWS WAF 8 out of 10.

    My advice to other organizations would be to clearly assess their application security requirements and operational capabilities before selecting a WAF solution. Fortinet Managed Rules work well for teams looking to strengthen baseline web application security on AWS without taking on heavy rule‑management overhead.

    The combination of native AWS WAF scalability with Fortinet’s managed threat intelligence provides a good balance between cloud‑native simplicity and enterprise‑grade security. For organizations that value ease of deployment, automated updates, and consistent protection, this solution is a strong and practical choice.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    View all reviews