Logo

Fortinet FortiWeb

Fortinet FortiWeb is a web application firewall and API security platform designed to protect internet-facing and internal applications from application-layer attacks, malicious bots, API abuse, zero-day exploits, credential attacks, and vulnerabilities covered by the OWASP Top 10.

Unlike a conventional network firewall that primarily evaluates network sessions, ports, protocols, and broader security policy, FortiWeb analyzes how users and applications communicate over HTTP and HTTPS. It can learn normal application behavior, inspect requests and responses, discover APIs, evaluate bot activity, and apply security policies before malicious traffic reaches the web or application server. Fortinet currently combines traditional WAF capabilities with machine learning, API discovery, client-side protection, bot mitigation, and threat analytics.

Quick Benefits

Review Fortinet FortiWeb Price List and request a quote tailored to your licensing needs.

View Fortinet FortiWeb Part Numbers

fortiweb benefits

Fortinet FortiWeb At a Glance

What it is: Web Application Firewall and API protection platform

Parent category: Fortinet License

Primary role: Protect web applications and APIs from Layer 7 threats

Current hardware range: FortiWeb 100F, 400F, 600F, 1000F, 2000F, 3000F and 4000F

Current appliance throughput: Approximately 100 Mbps to 70 Gbps depending on model

Virtual editions: VM01, VM02, VM04, VM08 and 16-vCPU editions

Cloud options: AWS, Microsoft Azure, Google Cloud and Oracle Cloud

SaaS option: FortiAppSec Cloud

Fortinet price quote banner

Need FortiWeb Pricing?

Tell us your requirements and receive a tailored quote for your Fortinet licensing, FortiGate devices, security services, deployment model, and support needs.

Get Price Quote →

License Overview

A Fortinet FortiWeb license is selected differently depending on whether the organization wants physical infrastructure, a VM, a public-cloud instance, or WAF-as-a-Service. For traditional data-center environments, Fortinet offers hardware appliances. Current ordering information lists the 100F, 400F, 600F, 1000F, 2000F, 3000F and 4000F, with protected HTTP/HTTPS throughput ranging from approximately 100 Mbps on the 100F to 70 Gbps on the 4000F.

FortiWeb VM can be purchased through subscription-based S-series licensing, while perpetual VM licensing remains available. Public-cloud deployments can also use BYOL or PAYG depending on cloud provider and marketplace availability. Fortinet currently supports AWS and Azure for both BYOL and on-demand models, with additional FortiWeb availability in Google Cloud and OCI.

FortiWeb licensing also includes security-service decisions. A Standard Bundle provides the core FortiWeb functions together with threat-intelligence updates such as signatures and IP reputation. Higher-level security entitlements add services such as cloud sandboxing, credential-stuffing defense, advanced analytics, DLP, Advanced Bot Protection and additional security operations capabilities depending on the selected bundle and SKU.

The correct license should therefore be chosen from the expected application traffic and security requirements—not simply from the number of websites.

Product Overview

Web Application and API Protection

FortiWeb sits close to the application layer, where it can understand the structure of HTTP requests, application URLs, parameters, sessions, cookies and API calls. This allows it to identify attacks that may otherwise look like normal HTTPS traffic to a traditional firewall. Examples include SQL injection, cross-site scripting, malicious file uploads, protocol manipulation, API abuse, attempts to bypass authentication and attacks targeting unknown application behavior.

Fortinet uses a dual-layer machine-learning approach to build models around legitimate application activity and detect abnormal requests. The goal is to improve zero-day detection while reducing the false positives that often make traditional WAF deployments difficult to maintain.

API Discovery and Security

Modern applications increasingly depend on APIs, and in many environments the security team does not have a complete inventory of every exposed endpoint. FortiWeb can continuously evaluate application traffic to discover APIs and create application-specific security controls. Fortinet supports positive security models around formats such as OpenAPI, JSON and XML, allowing API calls to be checked against the expected schema rather than relying only on attack signatures. This is especially useful for customer portals, mobile applications, B2B APIs and microservice architectures where a large portion of application traffic may never involve a traditional browser page.

Bot and Automated Attack Protection

Not every automated client should be blocked. Search engines, monitoring tools and legitimate automation may need access, while credential-stuffing bots, scrapers and account-takeover tools should not. FortiWeb includes bot controls and can integrate with FortiGuard Advanced Bot Protection, a cloud-based service that applies machine learning and behavioral analysis to distinguish human users, legitimate bots and malicious automation. Fortinet specifically identifies use cases such as credential stuffing, account takeover, scraping, fraud and application-layer DDoS.

How Fortinet FortiWeb Works

The most common FortiWeb design is Reverse Proxy Mode. In this architecture, client traffic reaches FortiWeb before the backend application servers. FortiWeb terminates or proxies the connection, applies web and API security policies, and forwards allowed traffic toward the application.

Because FortiWeb is directly involved in the HTTP/HTTPS session in this mode, it can perform the broadest set of application-security functions. DNS is normally configured so that the application hostname resolves toward the FortiWeb virtual server rather than directly to the backend server.

FortiWeb also supports transparent deployment when changing the existing network addressing or DNS design is undesirable. In True Transparent Proxy Mode, FortiWeb bridges traffic while still applying application security policies. Transparent Inspection Mode provides a less intrusive approach but has a more limited feature set because FortiWeb does not fully proxy or modify traffic.

Offline Protection provides another option where mirrored traffic is analyzed without FortiWeb sitting inline. This is useful for monitoring and policy tuning, but because traffic is mirrored rather than passing through FortiWeb, the appliance cannot provide the same inline blocking capability.

fortiweb technical flow

Core Technical Flow

Internet / Users / API Clients
→ FortiWeb Virtual Server or Transparent Inspection Point
→ TLS Decryption and HTTP/S Inspection
→ IP Reputation / Signature Analysis
→ Machine Learning and Anomaly Detection
→ API / Bot / Authentication Policy Evaluation
→ Allow / Block / Challenge / Rate Limit
→ Backend Web or Application Server
→ Response Inspection
→ User

The exact flow changes with deployment mode, but the central objective remains the same: inspect application traffic before an attacker can interact directly with the protected workload.

Options and Licensing Models

FortiWeb hardware is generally selected by the amount of protected HTTP/HTTPS traffic. Current Fortinet specifications range from 100 Mbps on FortiWeb 100F, through 500 Mbps on the 400F, 1 Gbps on the 600F, 2.5 Gbps on the 1000F, 5 Gbps on the 2000F and 10 Gbps on the 3000F, up to 70 Gbps on FortiWeb 4000F.

Virtual editions provide a different sizing path:

FortiWeb VM Published throughput vCPU
VM01 25 Mbps 1
VM02 100 Mbps 2
VM04 500 Mbps 4
VM08 3 Gbps 8
VM16 6 Gbps 16

These figures are maximum published values and real performance varies according to security policies, SSL processing, traffic behavior and underlying compute resources. For organizations that do not want to operate WAF infrastructure, FortiAppSec Cloud provides Fortinet’s SaaS-based application-security model. Current Fortinet ordering guidance prices this approach according to factors such as protected bandwidth and number of applications.

Features and Benefits

One of FortiWeb’s strongest advantages is that it can apply application-specific protection rather than treating every HTTPS connection in the same way. A login page, payment API and public product catalog have very different normal behaviors. Machine-learning models can help FortiWeb understand those differences, which reduces the need to build every application rule manually.

FortiWeb can also act as part of a wider Fortinet Security Fabric. Integration with FortiGate and FortiSandbox allows application-security events and suspicious files to participate in broader threat-detection workflows. For payment and browser-facing applications, Fortinet also includes client-side protection capabilities intended to identify unauthorized scripts, DOM manipulation, form hijacking and other attacks that occur in the user’s browser after the original page has been delivered. This is particularly relevant where PCI DSS and payment-page integrity requirements apply.

Compatibility and Requirements

Before selecting FortiWeb, first identify where the applications actually live. An application hosted behind an on-premises load balancer may favor a hardware or VM WAF, while workloads that regularly move between cloud environments may justify FortiWeb VM, containers or a SaaS architecture.

Traffic measurements should include both HTTP and HTTPS throughput, peak request rates, TLS usage and the number of applications requiring protection. HTTPS inspection consumes substantially more resources than plain HTTP because the WAF must decrypt, inspect and often re-encrypt traffic.

The number of application domains also matters. Current Fortinet appliance specifications include limits on machine-learning domains that vary between models, so an environment protecting dozens of unrelated applications should not be sized from throughput alone. Also review DNS design, backend server addresses, TLS certificates, API specifications, authentication methods, load balancers, existing FortiGate placement, required HA design and whether client IP addresses must remain visible to backend servers.

How Activation and Deployment Work

For hardware deployments, the appliance is registered and the selected FortiWeb security subscription is activated before production policies are configured. FortiWeb VM uses an associated license file or subscription entitlement, while BYOL public-cloud instances are registered to the organization’s Fortinet account before the license is applied. Fortinet’s current guidance allows the VM license file to be retrieved through the Fortinet Support/FortiCloud environment after registration.

Deployment should normally begin in monitoring or less aggressive policy settings. Allowing FortiWeb to learn application behavior before enabling strict blocking policies gives administrators time to identify unusual but legitimate application requests.

Reverse Proxy deployments also require careful DNS, certificate and backend-server configuration because the WAF becomes part of the application’s production traffic path. Where downtime is unacceptable, FortiWeb supports HA. Current FortiWeb software includes active-passive, standard active-active and high-volume active-active options. In an active-passive design, the secondary appliance takes over when the active member fails.

Pricing and Quote Process

The price of a Fortinet FortiWeb license depends first on the deployment model and required capacity. For hardware, provide the peak protected HTTP/HTTPS throughput, application count, expected SSL/TLS load and required interface speeds. The quote should also identify whether Standard or more advanced application-security services are required and whether the deployment will use a single appliance or HA pair.

For FortiWeb VM, specify the target hypervisor or cloud platform, vCPU requirement, application traffic and preferred perpetual or subscription licensing model. AWS and Azure customers should also decide whether BYOL or PAYG better fits their procurement model.

For FortiAppSec Cloud, application count and traffic become major pricing inputs. A useful quote should therefore include the number of protected applications and APIs, peak HTTPS traffic, hosting location, deployment preference, application domains, bot-protection requirements, API-security needs, HA design and support term.

Fortinet pricing depends on your product edition, FortiGate model, security services, license term, deployment model, and support requirements.

Request Fortinet Quote →

Frequently Asked Questions