MR
Technical Engineer
Information Technology and Services
Mid-Market (51-1000 emp.)
"Good baseline WAF protection for teams without a security engineer"
5/5
What do you like best about Fortinet Managed Rules for AWS WAF?

1.Fast to deploy — subscribe on Marketplace, attach to the existing web ACL, running same day

2.No rule writing or tuning required to get OWASP Top 10 coverage FortiGuard Labs handles signature updates, so we're not chasing new CVEs

3.Stays native to AWS — same console, CloudWatch metrics, sampled logs, Terraform workflow

4.Rule groups are separable (OWASP, SQLi/XSS, bots, API), so we only pay for what we use

5.COUNT mode let us validate against real traffic before blocking Strong coverage-to-effort ratio for a small team with no dedicated WAF engineer Review collected by and hosted on G2.com.

What do you dislike about Fortinet Managed Rules for AWS WAF?

1.False positives on legitimate traffic (file uploads, rich-text fields, complex query strings) take trial and error to isolate

2.Documentation is lighter than Fortinet's on-prem WAF products; limited guidance on which rule group to pick for a given workload Review collected by and hosted on G2.com.

See what 30 reviewers think of Fortinet Managed Rules for AWS WAF

4.3 out of 5 · Verified reviews from real users

Read all reviews