1.Fast to deploy — subscribe on Marketplace, attach to the existing web ACL, running same day
2.No rule writing or tuning required to get OWASP Top 10 coverage FortiGuard Labs handles signature updates, so we're not chasing new CVEs
3.Stays native to AWS — same console, CloudWatch metrics, sampled logs, Terraform workflow
4.Rule groups are separable (OWASP, SQLi/XSS, bots, API), so we only pay for what we use
5.COUNT mode let us validate against real traffic before blocking Strong coverage-to-effort ratio for a small team with no dedicated WAF engineer Review collected by and hosted on G2.com.
1.False positives on legitimate traffic (file uploads, rich-text fields, complex query strings) take trial and error to isolate
2.Documentation is lighter than Fortinet's on-prem WAF products; limited guidance on which rule group to pick for a given workload Review collected by and hosted on G2.com.