--- title: Fortinet Managed Rules for AWS WAF Reviews meta\_title: 'Fortinet Managed Rules for AWS WAF Reviews 2026: Details, Pricing, & Features | G2' meta\_description: Filter 23 reviews by the users' company size, role or industry to find out how Fortinet Managed Rules for AWS WAF works for a business like yours. aggregate\_rating: rating\_value: 4.2 review\_count: 23 scale: '5' date\_modified: '2026-09-01' parent\_category: name: Marketplace Apps url: https://www.g2.com/categories/marketplace-apps ---

# Fortinet Managed Rules for AWS WAF Reviews & Product Details

Visit Website

Fortinet’s WAF rulesets are additional security signatures that can be used to enhance the protections included in the base AWS WAF product. They are updated on a regular basis to include the latest threat intelligence from the award-winning FortiGuard Labs. The Complete OWASP Top 10 Ruleset provides a comprehensive package for web application protection offered by Fortinet to help address the OWASP Top 10 web application threats. Includes protection for various Injection attacks such as SQL and command Injection , Cross Site Scripting, General and Known Exploits, Malicious Bots and Common Vulnerabilities and Exposures (CVE).

* * *

Product Website
 Fortinet Managed Rules for AWS WAF
Seller
 [Fortinet](https://www.g2.com/sellers/fortinet)
Discussions
 [Fortinet Managed Rules for AWS WAF Community](https://www.g2.com/products/fortinet-managed-rules-for-aws-waf/discuss)
Overview by
 Elysse Miller

 ![FPT Software](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "FPT Software")
Used by FPT Software and 2 others

##### Featured Companies

[
 ![FPT Software](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "FPT Software")
 FPT Software](https://www.g2.com/products/fpt-software/reviews)[
 ![Huawei Cloud Fabric](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Huawei Cloud Fabric")
 Huawei Cloud Fabric](https://www.g2.com/products/huawei-cloud-fabric/reviews)[
 ![Huawei Firewall](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Huawei Firewall")
 Huawei Firewall](https://www.g2.com/products/huawei-firewall/reviews)

Beta

Show More

## Pricing

Pricing provided by Fortinet Managed Rules for....

### Pay-as-you-go (Consumption-Based)

Pay As You Go

Per Month

[
View More Pricing Information
](https://www.g2.com/products/fortinet-managed-rules-for-aws-waf/pricing)

## Fortinet Managed Rules for AWS WAF Integrations
(5)

What do users say about integrations?

Verified by Fortinet Managed Rules for AWS WAF

  

 ![Milan D.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Milan D.")
MD

Milan D.

Consultant

Small-Business (50 or fewer emp.)

8/30/2026

"Strong, Low-Maintenance Protection for AWS Workloads"

3.5/5

What do you like best about Fortinet Managed Rules for AWS WAF?

The biggest advantage is the combination of strong security coverage and ease of management. The preconfigured rules make it much easier to protect AWS workloads against common threats such as SQL injection, XSS, and known exploits without having to build and maintain everything from scratch. The integration with AWS WAF is straightforward, and the managed updates help keep protection aligned with new threats. Overall, it saves time while providing an additional layer of security for web applications and APIs. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

The main downside is that the rules can sometimes require tuning to avoid false positives, especially for applications with custom traffic patterns. It would also be helpful to have more detailed documentation and clearer guidance for fine-tuning rules for specific workloads. Pricing can also become a consideration as the number of protected resources grows. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

Fortinet Managed Rules for AWS WAF helps us protect our web applications and APIs from common attacks without having to create and maintain WAF rules ourselves. It provides consistent security coverage against threats like SQL injection, XSS, and other known exploits while reducing the time we spend on security rule management. This lets our team focus more on application and infrastructure work while still maintaining a strong security posture. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through a business email account added to their profile)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

SG

Subigya G.

Security Researcher | Tech Writer

Small-Business (50 or fewer emp.)

8/30/2026

"OP: AWS WAF | Know the real power"

4/5

What do you like best about Fortinet Managed Rules for AWS WAF?

The main reason we use Fortinet's managed rules is how easily they plug into our existing AWS setup to cover core security risks like SQL injection and cross-site scripting. Building and updating custom WAF rules by hand takes way too much time, so having Fortinet's team handle the threat intelligence and signature updates behind the scenes saves a massive headache. It gives our public-facing APIs a solid baseline defense right out of the box without forcing us to spend hours tweaking custom logic every time a new vulnerability drops. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

The biggest issue is dealing with false positives when you first turn the rules on. If you jump straight to blocking mode, legitimate traffic or unusual API payloads will definitely get caught and blocked. You end up having to run everything in Count mode for a while, dig through CloudWatch logs, and set up override rules to fix the false alarms before you can actually enforce blocks.

​Another downside is the lack of visibility into the actual underlying rule logic. Because the signatures are proprietary black boxes, troubleshooting why a specific request got flagged takes more time than it should. On top of that, cost can accumulate quickly if you are running these rules across high-traffic Application Load Balancers, since AWS charges for rule evaluations alongside the subscription cost. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

It solves the hassle of keeping web endpoints and open APIs safe from bad traffic, web scrapers, and common attack vectors without forcing us to build or patch security rules by hand. Because Fortinet handles threat signatures automatically, new vulnerabilities are covered right away, saving us from constantly checking security advisories just to tweak firewall settings.

​The biggest win for us is cut-down workload. We get solid, hands-off security built right into our cloud setup, which lets us put our time toward building features instead of sifting through network logs to craft custom filter rules. It simply gives us a dependable safety net for our web apps without adding extra day-to-day maintenance. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through a business email account)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![敏熙 .](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "敏熙 .")
敏

敏熙 .

Independent Software Engineer

Mid-Market (51-1000 emp.)

8/29/2026

"FortiGuard-Powered Managed Rules That Stop SQLi and XSS with Zero Added Latency"

4/5

What do you like best about Fortinet Managed Rules for AWS WAF?

The automated threat intelligence powered by FortiGuard Labs is the biggest win for our team. We use the Fortinet OWASP Top 10 and Known Bad Inputs/Bots Rulesets on our public-facing ALBs. Instead of constantly monitoring new CVEs and manually writing complex regex rules in-house, the rule sets are updated automatically in the background. It effectively neutralizes SQLi, XSS, and automated vulnerability scanner probes without adding latency to our applications. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

While the protection is robust, diagnosing occasional false positives can be challenging due to the 'black-box' nature of managed rules. When a legitimate multi-step API request containing complex JSON payloads gets blocked, AWS WAF logs show the rule group and rule ID, but not the exact string or parameter that triggered the match. We have to spend extra time cross-referencing logs and writing custom label-based exception rules. It would be a huge improvement if Fortinet/AWS could provide more granular trigger explanations or context directly in the logs to speed up root-cause analysis. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

Before implementing Fortinet Managed Rules, our security team struggled with manually tracking new CVEs and writing custom regex rules for our AWS WAF, which consumed 6–8 engineering hours each week and left a window of vulnerability during zero-day events.

By switching to Fortinet Managed Rules, we now have automated, continuously updated threat intelligence applied directly to our CloudFront and ALB distributions. This has eliminated the operational overhead of rule maintenance, cut our vulnerability triage time by roughly 70%, and ensured our public-facing APIs are consistently shielded against OWASP Top 10 threats and automated exploit probes. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Prateek M.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Prateek M.")
PM

Prateek M.

Software Developer

Mid-Market (51-1000 emp.)

8/24/2026

"Easy, Reliable AWS WAF Protection with Fortinet Managed Rules"

4/5

What do you like best about Fortinet Managed Rules for AWS WAF?

What I like best about Fortinet Managed Rules for AWS WAF is how easy it is to strengthen application security without having to build and maintain every rule manually. The managed rules provide broad coverage against common web application threats, are regularly updated to address emerging vulnerabilities, and integrate smoothly with AWS WAF. This saves time for security teams while providing reliable protection and reducing the effort required for ongoing rule management. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

One area that could be improved is the cost, especially for larger environments with multiple applications and AWS accounts. Some rules may also require tuning to reduce false positives and fit specific application requirements. More detailed documentation, clearer rule explanations, and easier troubleshooting would make it simpler to fine-tune the rules and understand why specific requests are being blocked. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

Fortinet Managed Rules for AWS WAF helps us protect our web applications from common threats such as SQL injection, cross-site scripting, bots, and other malicious traffic without having to create and maintain all the security rules ourselves. The managed rules reduce the operational effort required for WAF management, improve our overall security posture, and help us respond to emerging threats more quickly. This allows our security team to focus more on higher-value security initiatives while maintaining consistent protection across AWS-hosted applications. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![Mohamed J.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Mohamed J.")
MJ

Mohamed J.

Software Engineer

Small-Business (50 or fewer emp.)

8/11/2026

"Managed Rules Feel Too Broad—False Positives and Limited Rule-Trigger Visibility"

2.5/5

What do you like best about Fortinet Managed Rules for AWS WAF?

What I like best is the combination of \*\*strong, continuously updated threat protection and ease of management\*\*. Fortinet’s managed rules add protection against common web and API attacks, including OWASP Top 10 threats, SQL injection, XSS, known exploits, CVEs, and malicious bots, while the rules are regularly updated through FortiGuard Labs. This reduces the amount of time and effort required to maintain WAF rules manually. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

The main drawback is that managed rules can sometimes be \*\*too broad or generate false positives\*\*, requiring additional tuning and exclusions for specific applications. It would also be helpful to have more granular visibility into why a particular rule triggered and simpler customization options without increasing the management overhead. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

Fortinet Managed Rules for AWS WAF help reduce the effort required to protect our web applications and APIs from common threats such as SQL injection, XSS, and known exploits. The continuously updated rules reduce manual rule maintenance, improve our security coverage, and help our team respond to emerging threats more quickly while saving time on WAF management. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Youcef E.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Youcef E.")
YE

Youcef E.

Offensive Security Researcher

Mid-Market (51-1000 emp.)

8/11/2026

"Set-and-Forget Security with Auto-Updating Rules"

4/5

What do you like best about Fortinet Managed Rules for AWS WAF?

I like that Fortinet Managed Rules for AWS WAF protects our web apps against OWASP Top 10 attacks, including SQL injection, XSS, and bot attacks. The managed rulesets save us from writing custom rules manually, and layering them with rate limiting and geo-blocking enhances security. I appreciate that it blocks attacks at the edge without the need for manual rule upkeep, and we no longer have to write and update signatures ourselves. The automatic handling of new CVEs allows our developers to stay focused on features while security remains current. I love the 'set and forget' threat protection with rules updating automatically, requiring zero manual patching. The initial setup was smooth, taking under 30 minutes and attaching to the ALB in the AWS console without needing any config files, and it worked out of the box. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

I occasionally experience false positives, where some legitimate traffic gets flagged, especially with multi-step web apps. Additionally, I feel the logging could be more granular. Another concern is the pricing, which jumps at certain request volume tiers. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

I use Fortinet Managed Rules for AWS WAF to protect web apps from attacks like SQL injection without manual rule upkeep. It saves time by auto-updating rules, allowing my team to focus on development while maintaining current security. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![shubham t.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "shubham t.")
ST

shubham t.

Full Stack Engineer (Contractor)

Small-Business (50 or fewer emp.)

8/22/2026

"Robust Security with Easy Integration"

4.5/5

What do you like best about Fortinet Managed Rules for AWS WAF?

I like that Fortinet Managed Rules for AWS WAF enhances firewall protection, blocking threats before they reach the application and defending against common web attacks and known CVEs. I find the integration with AWS SNS really useful because it provides real-time updates to admins, letting them quickly respond to updates. Integrating Fortinet with AWS WAF is super easy, and the documentation is helpful. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

I think they have everything that is needed. I dont have any dislike points to be mentioned Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

I use Fortinet Managed Rules for AWS WAF to enhance firewall protection, blocking threats and common web attacks before they reach my application. It provides robust safety against AI-driven threats, offers seamless AWS integration, and sends real-time updates for immediate action. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Verified User](/assets/icons/anonymous-avatar-purple-4ae1032bdb50ee5682003170c8184aee790d25958bd397abbd384ba52c596a7b.svg "Verified User")
G

Verified User
 (This reviewer's identity has been verified by our review moderation team. They have asked not to show their name, job title, or picture.)

Small-Business (50 or fewer emp.)

8/25/2026

"Saves Time with Effective Web Attack Coverage"

4.5/5

What do you like best about Fortinet Managed Rules for AWS WAF?

I appreciate the simplicity of usage for Fortinet Managed Rules for AWS WAF. It doesn't need much maintenance and does its job simply, which is really crucial as we are a small team of developers. It saves us time because we don't have to deal with keeping up with signature updates, and it helps manage the noise from the internet that isn't always a direct threat but can use up unnecessary capacity. I like that we can apply the group rule only where it makes sense, rather than globally, which saved a lot of time and pain. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

I find the rules confusing as I don't always know why something was blocked. I get an ID and label but have to infer the intent. Also, I think the documentation is pretty thin, which could definitely be improved. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

I save time with Fortinet Managed Rules for AWS WAF, avoiding signature management. It simplifies usage with minimal maintenance and allows rule application only where needed, reducing unnecessary resource use. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Eddy Omar L.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Eddy Omar L.")
EL

Eddy Omar L.

Software Implementation Specialist

Small-Business (50 or fewer emp.)

8/11/2026

"Ready-to-Use Security Rules That Simplify API Protection"

4.5/5

What do you like best about Fortinet Managed Rules for AWS WAF?

It’s a library of preconfigured, ready-to-use signatures and rules that makes security protections extremely easy to deploy and maintain. These rules are updated regularly to ensure up-to-date security. To be specific they help to secure API from injection attacks (CSS. CEVs, etc) Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

Rules can become complex to set up, and the UI doesn’t really help, which makes management and enrolling new personnel difficult. Also, these rules can only be applied to WAS apps/services. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

It helped us harden our API by applying a preconfigured OWASP Top 10 ruleset. As a result, we were able to align with security standards and best practices, making our API connections/integrations and management more secure. Also, performance was not impacted. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)

 (Copy Review URL)

  

 ![Emmanuel N.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Emmanuel N.")
EN

Emmanuel N.

Software developer

Small-Business (50 or fewer emp.)

8/21/2026

"Strong AWS Protection for EC2 and S3 with Proactive Security Controls"

4/5

What do you like best about Fortinet Managed Rules for AWS WAF?

I like using it as one of the AWS services to protect what I run on AWS, such as applications deployed on EC2 and assets stored in an S3 bucket. It also helps me set up security measures in advance, before requests reach my apps. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

I’d say there’s something I dislike: if I had to, I would disconnect myself from the service and let requests hit my app through AWS WAF as a proxy for protection. Review collected by and hosted on G2.com.

What problems is Fortinet Managed Rules for AWS WAF solving and how is that benefiting you?

This AWS WAF service helps me improve my cybersecurity measures by reducing suspicious requests to my applications hosted on AWS S3 bucket, where I keep sensitive assets. Review collected by and hosted on G2.com.

Show More

Validated Reviewer (Validated through LinkedIn)Incentivized (This reviewer was offered a nominal incentive as thanks for completing this review.)Source: Organic Review from User Profile (Invitation from G2. This reviewer was offered a nominal incentive as thanks for completing this review.)

 (Copy Review URL)

## Pricing Options

Pricing provided by Fortinet Managed Rules for....

### Pay-as-you-go (Consumption-Based)

Pay As You Go

Per Month

[
View More Pricing Information
](https://www.g2.com/products/fortinet-managed-rules-for-aws-waf/pricing)

## Top-Rated Alternatives

[

 ![HAProxy](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "HAProxy")

HAProxy

4.7/5(912)

](https://www.g2.com/products/haproxy/reviews)

[

 ![Cloudflare Application Security and Performance](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Cloudflare Application Security and Performance")

Cloudflare Application Security and Performance

4.5/5(757)

](https://www.g2.com/products/cloudflare-application-security-and-performance/reviews)

[

 ![Harness Platform](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Harness Platform")

Harness Platform

4.6/5(326)

](https://www.g2.com/products/harness-platform/reviews)

[
View All Alternatives
](https://www.g2.com/products/fortinet-managed-rules-for-aws-waf/competitors/alternatives)

##### Categories on G2

[AWS Marketplace](https://www.g2.com/categories/aws-marketplace)[Web Application Firewall (WAF)](https://www.g2.com/categories/web-application-firewall-waf)

##### Explore More

[What ERM tools connect with existing business intelligence, audit and compliance platforms without requiring a separate middleware layer?](https://www.g2.com/discussions/what-erm-tools-connect-with-existing-business-intelligence-audit-and-compliance-platforms-without-requiring-a-separate-middleware-layer)[Which encryption software integrates transparently with enterprise productivity suites like Microsoft 365 and Google Workspace?](https://www.g2.com/discussions/which-encryption-software-integrates-transparently-with-enterprise-productivity-suites-like-microsoft-365-and-google-workspace)[What are the highest rated E-Signature platforms for distributed teams optimizing document workflows efficiently and securely?](https://www.g2.com/discussions/what-are-the-highest-rated-e-signature-platforms-for-distributed-teams-optimizing-document-workflows-efficiently-and-securely)

[Which audience intelligence platforms are worth using for a brand that wants to understand how their target audience compares to competitors' audiences without a full market research engagement?](https://www.g2.com/discussions/which-audience-intelligence-platforms-are-worth-using-for-a-brand-that-wants-to-understand-how-their-target-audience-compares-to-competitors-audiences-without-a-full-market-research-engagement%20)[Recommended live chat platforms for SaaS businesses](https://www.g2.com/discussions/recommended-live-chat-platforms-for-saas-businesses-what-delivers-the-best-support-experience)[Pros and Cons Details](https://www.g2.com/products/fortinet-managed-rules-for-aws-waf/reviews?qs=pros-and-cons)

[Show MoreShow Less](javascript:void(0);)