Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FortiWeb (FWB-100F through 4000F / VM / Cloud)

FortiWeb Web Application Firewall

Protect the applications and APIs a network firewall cannot see into

Compare all 7 models

Figures are Fortinet’s own — sortable, cited on every product page
FortiWeb Web Application Firewall model comparison
ModelHTTPActions
FortiWeb 100FFWB-100F100 Mbps4x GE RJ45Details
FortiWeb 400FFWB-400F500 Mbps4x GE RJ45, 4x GE SFPDetails
FortiWeb 600FFWB-600F1 Gbps2 (+2 bypass) x GE RJ45, 4x GE SFPDetails
FortiWeb 1000FFWB-1000F2.5 Gbps2x 10GE SFP+, 4x GE RJ45 bypass, 4x GE SFPDetails
FortiWeb 2000FFWB-2000F5 Gbps4x 10GE SFP+, 4x GE RJ45 bypass, 4x GE SFPDetails
FortiWeb 3000FFWB-3000F10 Gbps10x 10GE SFP+ (incl. 2 bypass), 8x GE RJ45 bypassDetails
FortiWeb 4000FFWB-4000F70 Gbps2x 40GE QSFP bypass, 10x 10GE SFP+ (incl. 2 bypass), 8x GE RJ45 bypassDetails

How to read these numbers

A network firewall inspects traffic; a web application firewall understands the application. FortiWeb defends against the OWASP Top 10, API abuse, bot traffic and credential stuffing — attacks that arrive as perfectly legitimate HTTPS requests and therefore pass a FortiGate untouched.

More on choosing within this range

It uses machine learning to build a model of normal application behaviour rather than relying only on signatures, which matters for custom applications no signature vendor has ever seen.

Throughput runs from 100 Mbps on the FWB-100F to 70 Gbps on the FWB-4000F, with virtual and cloud WAF-as-a-service options alongside the appliances.

Before you order

What is your actual HTTP throughput?

Size on real application traffic, not internet circuit capacity. WAF inspection is expensive and the gap between the two numbers is usually large.

Are you protecting APIs as well as web pages?

API traffic now dominates in most estates and needs schema validation and rate limiting rather than page-oriented rules. Say so — it changes the configuration substantially.

Appliance, VM or cloud WAF?

Cloud WAF-as-a-service is fastest to deploy and needs no hardware. Appliances suit applications that must stay on-premises. Do not put a WAF appliance in a data centre the application has already left.

Is PCI DSS driving this?

PCI DSS effectively requires a WAF or equivalent in front of cardholder-data applications. If that is the driver, the compliance report matters as much as the throughput.

All FortiWeb Web Application Firewall