Subigya G.
SG
Security Researcher | Tech Writer
Computer & Network Security
Small-Business (50 or fewer emp.)
"OP: AWS WAF | Know the real power"
4/5
What do you like best about Fortinet Managed Rules for AWS WAF?

The main reason we use Fortinet's managed rules is how easily they plug into our existing AWS setup to cover core security risks like SQL injection and cross-site scripting. Building and updating custom WAF rules by hand takes way too much time, so having Fortinet's team handle the threat intelligence and signature updates behind the scenes saves a massive headache. It gives our public-facing APIs a solid baseline defense right out of the box without forcing us to spend hours tweaking custom logic every time a new vulnerability drops. Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

The biggest issue is dealing with false positives when you first turn the rules on. If you jump straight to blocking mode, legitimate traffic or unusual API payloads will definitely get caught and blocked. You end up having to run everything in Count mode for a while, dig through CloudWatch logs, and set up override rules to fix the false alarms before you can actually enforce blocks. Another downside is the lack of visibility into the actual underlying rule logic. Because the signatures are proprietary black boxes, troubleshooting why a specific request got flagged takes more time than it should. On top of that, cost can accumulate quickly if you are running these rules across high-traffic Application Load Balancers, since AWS charges for rule evaluations alongside the subscription cost. Review collected by and hosted on G2.com.

See what 30 reviewers think of Fortinet Managed Rules for AWS WAF

4.3 out of 5 · Verified reviews from real users

Read all reviews