Fortinet Managed Rules for AWS WAF - API Gateway logo

    Fortinet Managed Rules for AWS WAF - API Gateway

    The Fortinet Managed Rules for AWS API Gateway is a comprehensive package for the best web application protection to help protect against the OWASP Top 10 web application threats, including SQLi/XSS attacks, General and Known Exploits, and Malicious Bots.

    Ratings and reviews

    4.2
    47 ratings
    2 star
    1 star
    43%
    53%
    4%
    0%
    0%
    10 AWS reviews
    |
    37 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (47)
    Mohammed R.

    Strong, Ready-to-Deploy Protection with Fortinet Managed Rules for AWS WAF

    Reviewed on Sep 20, 2026
    Review provided by G2
    What do you like best about the product?
    Fortinet Managed Rules for AWS WAF provides strong, ready-to-deploy protection against common web threats, helping us secure applications without the complexity of creating and managing custom WAF rules.
    What do you dislike about the product?
    One drawback of Fortinet Managed Rules for AWS WAF is that customization options can be somewhat limited for highly specific application requirements. In addition, troubleshooting false positives can occasionally require extra tuning and monitoring to ensure legitimate traffic is not blocked.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect web applications from common threats such as SQL injection, cross-site scripting (XSS), bots, and other malicious attacks without having to build and maintain complex security rules ourselves.
    Amrit P.

    Strong Web Attack Protection with Easy Deployment

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules offer strong protection against common web attacks without requiring me to build everything from scratch. They’re straightforward to deploy, and I can tune them based on real traffic to cut down on false positives while keeping the protection effective.
    What do you dislike about the product?
    Some rules can be overly aggressive and may need tuning to reduce false positives. The default rule set doesn’t always align with application-specific traffic, so customization is sometimes necessary. When an application has unusual or complex request patterns, managing exceptions can quickly become time-consuming.
    What problems is the product solving and how is that benefiting you?
    It reduces the effort required to manually create and maintain WAF rules for common web attacks. As a result, we get a more consistent security baseline, save time, and still protect our applications from common threats.
    Banking

    Managed Rules with Centralized Security

    Reviewed on Sep 18, 2026
    Review provided by G2
    What do you like best about the product?
    Managed rules provide pre-configured, regularly updated security rules which make it easier to protect web applications from common threats without having to build and maintain everything from scratch. The centralized management and Fortinet’s threat intelligence also help simplify ongoing security operations.
    What do you dislike about the product?
    Need fine-tuning for false positives, especially for applications with custom or complex traffic patterns. It would be helpful to have more granular customization and clearer rule-level visibility when troubleshooting blocked requests.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps us protect web applications from common threats such as SQL injection, cross-site scripting, and malicious requests without having to create and maintain all the rules ourselves.
    Anonymous

    Effortless Protection with Fortinet Managed Rules

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    I use Fortinet Managed Rules for AWS WAF because it saves a lot of time with everything being managed end-to-end. It's easy to use and offers great coverage and security practices. I appreciate that it covers each web application with rules that include the OS top 10 and some custom detections, along with threat IDs. It's better than others in terms of cost and detection. The initial setup is straightforward and requires just one click. Overall, it's a reliable service that provides good results.
    What do you dislike about the product?
    The only area where I think Fortinet Managed Rules for AWS WAF could improve is in the threat intelligence aspect. It would be better if they could fine-tune the system to update more rapidly in nearly real-time when it comes to identifying malicious traffic from URLs. This would enhance its effectiveness against threats.
    What problems is the product solving and how is that benefiting you?
    It saves me time by managing and configuring rules end-to-end, offering strong security practices and easy use.
    Suprim C.

    Easy Integration and Strong Protection

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    The ready-to-use managed rules and easy AWS WAF integration are the most valuable features for me. They save time in rule management and provide reliable protection against common web threats. The interface is simple to manage, and Fortinet support is helpful when needed. Overall, it improves security while reducing the effort required for daily administration.
    What do you dislike about the product?
    The rules sometimes need fine-tuning for specific applications, especially when handling false positives. More detailed rule explanations and easier customization would make troubleshooting and policy tuning simpler.
    What problems is the product solving and how is that benefiting you?
    It reduces the effort of creating and maintaining WAF security rules manually. The managed rules provide ready-to-use protection against common web attacks, helping improve security while saving time on daily WAF management.
    Rojina A.

    Eases Web Security with Minimal Configuration

    Reviewed on Sep 09, 2026
    Review provided by G2
    What do you like best about the product?
    I like Fortinet Managed Rules for AWS WAF because of its easy setup and the ready-made security rules that provide reliable protection against common web attacks like SQL injection and XSS. The consistent protection and easy rule management are great, as they reduce the need for manual security configuration. I particularly value the OWASP protection because it's easy to manage and reduces manual configuration. Overall, the initial setup was fairly easy and straightforward, requiring just a little configuration.
    What do you dislike about the product?
    The pricing could be more affordable, and the configuration could be simpler for new users. A simpler setup wizard, clearer step-by-step guidance, and recommended default rules would make configuration easier for new users.
    What problems is the product solving and how is that benefiting you?
    I use Fortinet Managed Rules for AWS WAF to protect my web apps from common attacks and reduce manual security configuration time. It offers easy setup with ready-made security rules for reliable protection.
    Łukasz T.

    My impressions on Fortinet Managed Rules for AWS WAF

    Reviewed on Sep 08, 2026
    Review provided by G2
    What do you like best about the product?
    I like how easy it is to deploy and manage the rules without having to build and maintain everything from scratch. It saves me time and makes AWS WAF management much simpler overall.
    What do you dislike about the product?
    The main downside is that some rules need fine-tuning to reduce false positives. It would also be helpful to have clearer, more detailed visibility into why specific requests are being blocked, along with easier customization options for individual rules.
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF help protect our web applications from common attacks, without requiring us to manually create and maintain every security rule ourselves.
    Ekpono A.

    Fortinet WAF Simplifies Rule Management and Signature Testing

    Reviewed on Sep 07, 2026
    Review provided by G2
    What do you like best about the product?
    Thing I like most about Fortinet WAF is that it takes away manual management and maintenance of rules. The entire process of writing and testing WAF signatures
    What do you dislike about the product?
    It takes away the freedom to edit or add to the fine-tuned individual signature parameter, and the recurring subscription cost also puts pressure on our budget.
    What problems is the product solving and how is that benefiting you?
    1. It removes the need for continuous rule management for our team.
    2. We don’t have to manage dedicated infrastructure.
    3. Lastly, it saves time by keeping threat defence up to date.
    Ilario M.

    Intuitive and NIS2 Compliance with Fortinet WAF

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Fortinet Managed Rules for AWS WAF is very intuitive and that we can manage groups and users precisely thanks to its integration with Azure AD. Additionally, we are Fortinet partners and receive dedicated discounts, which is an added advantage.
    What do you dislike about the product?
    nothing in particular
    What problems is the product solving and how is that benefiting you?
    Fortinet Managed Rules for AWS WAF helps me manage user access integrated with Azure AD, keeping us compliant with NIS2 regulations, and it's intuitive, allowing precise group and user management.
    Mohammed R.

    Good baseline WAF protection for teams without a security engineer

    Reviewed on Sep 04, 2026
    Review provided by G2
    What do you like best about the product?
    1.Fast to deploy — subscribe on Marketplace, attach to the existing web ACL, running same day

    2.No rule writing or tuning required to get OWASP Top 10 coverage FortiGuard Labs handles signature updates, so we're not chasing new CVEs

    3.Stays native to AWS — same console, CloudWatch metrics, sampled logs, Terraform workflow

    4.Rule groups are separable (OWASP, SQLi/XSS, bots, API), so we only pay for what we use

    5.COUNT mode let us validate against real traffic before blocking Strong coverage-to-effort ratio for a small team with no dedicated WAF engineer
    What do you dislike about the product?
    1.False positives on legitimate traffic (file uploads, rich-text fields, complex query strings) take trial and error to isolate

    2.Documentation is lighter than Fortinet's on-prem WAF products; limited guidance on which rule group to pick for a given workload
    What problems is the product solving and how is that benefiting you?
    1.Gave us real OWASP Top 10 coverage without anyone writing or maintaining rule logic — we simply didn't have the headcount for that

    2.FortiGuard handles signature updates, so new CVEs get covered faster than we could virtual-patch ourselves

    3.Satisfies the WAF control for compliance and customer security questionnaires with something documented and defensible