FortiWeb Web Application Firewall
Protect the applications and APIs a network firewall cannot see into
Compare all 7 models
Figures are Fortinet’s own — sortable, cited on every product page| Model | HTTP | Actions | |
|---|---|---|---|
| FortiWeb 100FFWB-100F | 100 Mbps | 4x GE RJ45 | Details |
| FortiWeb 400FFWB-400F | 500 Mbps | 4x GE RJ45, 4x GE SFP | Details |
| FortiWeb 600FFWB-600F | 1 Gbps | 2 (+2 bypass) x GE RJ45, 4x GE SFP | Details |
| FortiWeb 1000FFWB-1000F | 2.5 Gbps | 2x 10GE SFP+, 4x GE RJ45 bypass, 4x GE SFP | Details |
| FortiWeb 2000FFWB-2000F | 5 Gbps | 4x 10GE SFP+, 4x GE RJ45 bypass, 4x GE SFP | Details |
| FortiWeb 3000FFWB-3000F | 10 Gbps | 10x 10GE SFP+ (incl. 2 bypass), 8x GE RJ45 bypass | Details |
| FortiWeb 4000FFWB-4000F | 70 Gbps | 2x 40GE QSFP bypass, 10x 10GE SFP+ (incl. 2 bypass), 8x GE RJ45 bypass | Details |
How to read these numbers
A network firewall inspects traffic; a web application firewall understands the application. FortiWeb defends against the OWASP Top 10, API abuse, bot traffic and credential stuffing — attacks that arrive as perfectly legitimate HTTPS requests and therefore pass a FortiGate untouched.
More on choosing within this range
It uses machine learning to build a model of normal application behaviour rather than relying only on signatures, which matters for custom applications no signature vendor has ever seen.
Throughput runs from 100 Mbps on the FWB-100F to 70 Gbps on the FWB-4000F, with virtual and cloud WAF-as-a-service options alongside the appliances.
Before you order
What is your actual HTTP throughput?
Size on real application traffic, not internet circuit capacity. WAF inspection is expensive and the gap between the two numbers is usually large.
Are you protecting APIs as well as web pages?
API traffic now dominates in most estates and needs schema validation and rate limiting rather than page-oriented rules. Say so — it changes the configuration substantially.
Appliance, VM or cloud WAF?
Cloud WAF-as-a-service is fastest to deploy and needs no hardware. Appliances suit applications that must stay on-premises. Do not put a WAF appliance in a data centre the application has already left.
Is PCI DSS driving this?
PCI DSS effectively requires a WAF or equivalent in front of cardholder-data applications. If that is the driver, the compliance report matters as much as the throughput.
All FortiWeb Web Application Firewall
FortiWeb 100F
100 Mbps of HTTP throughput with full WAF inspection
FortiWeb 400F
500 Mbps of HTTP throughput with full WAF inspection
FortiWeb 600F
1 Gbps of HTTP throughput with full WAF inspection
FortiWeb 1000F
2.5 Gbps of HTTP throughput with full WAF inspection
FortiWeb 2000F
5 Gbps of HTTP throughput with full WAF inspection
FortiWeb 3000F
10 Gbps of HTTP throughput with full WAF inspection
FortiWeb 4000F
70 Gbps of HTTP throughput with full WAF inspection