Fortinet FortiWeb Cloud WAF in Dubai, UAE
Fortinet FortiWeb Cloud WAF is the familiar name for Fortinet’s cloud-delivered web application firewall service. Current Fortinet ordering material identifies the SaaS Cloud WAF offer under FortiAppSec Cloud WAF, which brings web application and API security into a cloud-native, multi-tenant service with globally distributed WAF infrastructure. This matters to buyers because a new quotation should be prepared against the current plan and licensing structure rather than an older FortiWeb Cloud part description.
FourTeck can help you translate an existing FortiWeb Cloud requirement, renewal request or new WAF project into the correct current commercial scope, including application seats, bandwidth seats, plan level and optional services.
Confirm four inputs first
Applications: how many web applications or API-facing services need protection?
Bandwidth: what sustained and peak traffic should be considered?
Plan: Standard, Advanced or Enterprise?
Current status: new deployment, migration or legacy FortiWeb Cloud renewal?
No WAF appliance is required for the Cloud WAF service.
FortiWeb Cloud is now represented in current ordering as FortiAppSec Cloud WAF.
Application and bandwidth requirements are purchased together.
Advanced protections and services vary by Standard, Advanced and Enterprise tiers.
Direct answer for buyers
Fortinet FortiWeb Cloud WAF is a cloud-hosted WAF service used to inspect and control HTTP and HTTPS traffic before it reaches protected web applications and APIs. It is designed for organisations that want application-layer protection without operating a dedicated physical WAF appliance. Current Fortinet materials place this service under the FortiAppSec Cloud name and offer Standard, Advanced and Enterprise plans. Before proceeding, a buyer should confirm the number of protected applications, required bandwidth, required security functions, cloud or data-centre origin design, logging and integration needs, and whether the request is for a new FortiAppSec Cloud subscription or an existing FortiWeb Cloud contract that needs migration or renewal handling.
What the service does
A web application firewall is positioned between internet users and an application origin so that requests can be inspected against application security rules before they are forwarded. Fortinet’s cloud-delivered implementation provides this function as a service rather than requiring the customer to install a WAF appliance in a rack or deploy and maintain a dedicated WAF virtual machine. The current FortiAppSec Cloud WAF service combines application security with API-focused controls, DDoS protection, delivery features and analytics according to the selected plan.
For a business buyer, the operational value is not simply that traffic is filtered. The service creates a control point for public-facing application traffic, policy enforcement, attack visibility, bot decisions, API controls and selected availability functions. Because it is cloud delivered, procurement focuses more heavily on protected application count, bandwidth, plan tier and service dependencies than on physical interfaces, rack space or appliance power.
Who should consider it
The service may fit organisations exposing customer portals, online stores, reservation engines, digital payment workflows, partner portals, web-based ERP access, mobile application APIs, SaaS platforms, public information services or other internet-facing applications. It is also relevant when the application estate spans public cloud and other hosting environments and the business prefers cloud-delivered protection rather than maintaining a WAF appliance for every environment.
It may not be the right procurement route when a project specifically requires a customer-controlled FortiWeb hardware appliance, a FortiWeb VM inside a private network, unusual inline architecture, or a fixed deployment model that cannot redirect application traffic through a cloud service. Those requirements should be evaluated against the broader FourTeck security product portfolio and current Fortinet deployment options before a bill of materials is prepared.
Business challenges the Cloud WAF approach helps address
The buying decision is usually triggered by a business problem rather than by a product name. The following challenge map explains where a cloud-delivered WAF can be relevant and what still has to be validated during design.
Application-layer attacks
Public web applications can be targeted through malformed requests, exploit attempts and other application-layer techniques that ordinary port-based filtering does not fully address. The WAF provides dedicated inspection and policy controls for HTTP and HTTPS traffic.
Rapidly changing APIs
Modern applications often expose APIs to mobile applications, partners and automation platforms. FortiAppSec Cloud plans include API protection functions, with more advanced discovery and protection capabilities depending on tier.
Automated abuse and bots
Login pages, product catalogues, forms and APIs can attract scraping, credential attacks and automated misuse. Bot protection is available across the platform, while advanced machine-learning and dedicated bot capabilities depend on plan.
Operational overhead
Some teams want WAF controls without provisioning, patching and scaling another customer-managed appliance or VM. A SaaS model moves the WAF infrastructure layer to the service while leaving policy, application onboarding and integration decisions with the customer.
Multi-environment protection
Applications may live in different cloud regions or hosting environments. A globally distributed cloud service can provide a common protection approach, although routing, regional requirements and application behaviour must still be checked.
Security alert overload
Security teams need useful context rather than isolated events. Advanced plans include additional analytics functions designed to help teams review traffic, incidents and patterns, but logging destinations, retention and SOC workflow should be confirmed during planning.
Core capabilities buyers should understand
Signature controls, threat intelligence, HTTP compliance, URL and parameter controls, cookie protection and related WAF functions are included in the current plan framework.
Schema enforcement is part of the Cloud WAF platform, while advanced API gateway, mobile API and machine-learning discovery functions depend on plan.
Current FortiAppSec Cloud plans list both network-layer and application-layer DDoS mitigation capabilities.
Baseline bot controls are available across plans, with machine-learning bot defence and Advanced Bot Protection available at higher tiers.
SSL certificate handling, CDN functions, load balancing and server health monitoring are part of the current service matrix, with additional delivery capabilities depending on tier.
Attack logs, alerts, dashboards, SIEM integration, role-based access control, single sign-on and API support are listed in the current service capabilities.
Product-fit matrix
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Cloud-delivered WAF | You prefer SaaS protection rather than a customer-managed WAF appliance. | Origin architecture, traffic routing, regional requirements and onboarding method. |
| Multiple public applications | Several sites or APIs need a common cloud security control plane. | Exact number of protected applications because application seats are part of licensing. |
| API protection | Mobile, partner or machine-to-machine APIs are internet exposed. | API formats, authentication design, discovery needs and the plan required for advanced capabilities. |
| Advanced bot controls | Automated abuse, scraping or credential attacks are an important risk. | Whether standard bot controls are sufficient or Advanced/Enterprise capabilities are needed. |
| Threat analytics | Security operations need richer investigation and attack context. | Current plan entitlement, export requirements and SIEM workflow. |
| Dedicated WAF environment | The project requires a separately provisioned WAF environment within the cloud service. | Commercial availability and the separately ordered dedicated-environment subscription. |
Verified product and licensing information
Fortinet’s current ordering guides are the most useful basis for a new quotation because they distinguish the cloud SaaS offer from FortiWeb VM and hardware options. The table below intentionally avoids fixed hardware specifications because Fortinet FortiWeb Cloud WAF is a service rather than a physical appliance.
Important naming and contract dependency
A buyer searching for “FortiWeb Cloud WAF” may be using a legacy product name, a previous quotation, an older contract description or an internal procurement label. Current Fortinet documentation states that FortiAppSec Cloud combines services from the former FortiWeb Cloud and that current Cloud WAF SKUs were previously FortiWeb Cloud. New pricing and ordering should therefore be checked against the present FortiAppSec Cloud structure rather than assuming an old FortiWeb Cloud SKU is still the correct item.
This also affects existing customers. Current FortiAppSec contracts are seat based, and legacy FortiWeb Cloud arrangements may need migration handling. Do not purchase a replacement subscription solely by matching an old description. Share the existing contract or marketplace subscription, application count, bandwidth requirement, required plan features and renewal date with FourTeck so the current commercial path can be reviewed.
A practical purchase and deployment journey
Inventory the protected services
List every production website, portal and API that should be protected. Separate independent applications from subdomains that belong to the same application architecture, and note staging or disaster-recovery services if they also require protection. Licensing and onboarding decisions depend on an accurate application inventory.
Measure traffic requirements
Use monitoring data rather than a guess. Capture average traffic, expected peaks, seasonal growth and any large file-transfer behaviour. Current Fortinet Cloud WAF licensing uses bandwidth seats, so a clean traffic estimate improves both sizing and commercial accuracy.
Choose the feature tier
Map security requirements to Standard, Advanced or Enterprise. Do not select a higher tier only because it sounds more complete; identify whether machine-learning anomaly detection, advanced API functions, DAST, advanced bot protection, automated client-side protection, GSLB or SOC services are actually required.
Validate the traffic path
Confirm DNS control, origin addresses, TLS certificate handling, allowed source ranges, health checks and change windows. A SaaS WAF still requires deliberate routing and origin hardening so that traffic intended to be inspected does not simply bypass the service.
Plan logging and operations
Decide who will receive alerts, where security events should be reviewed, whether SIEM integration is needed, and how application owners will approve policy changes. WAF value depends on policy tuning and operational ownership after initial onboarding.
Request the commercial combination
The quotation should reflect application seats, bandwidth seats, the same plan level across both, any SOCaaS or dedicated-environment requirement, and the intended purchase route. FourTeck can help turn these inputs into a clearer procurement request.
Capability focus: protecting web applications without owning the WAF infrastructure
The first major decision is whether the organisation wants the WAF function as a cloud service at all. FortiWeb is available in several deployment forms, including SaaS, virtual and physical options. The cloud service is different from a FortiWeb VM or appliance because the customer is not sizing CPU cores, network interfaces, rack space or redundant power supplies. Instead, the service is consumed through application and bandwidth entitlements while Fortinet operates the cloud WAF infrastructure.
For businesses with applications spread across public cloud and hosted environments, this can reduce infrastructure management responsibilities. The security team can focus on onboarding applications, defining policies, reviewing events and coordinating with application owners. However, SaaS delivery does not remove architectural responsibility. DNS changes, TLS certificate handling, origin accessibility, health checks, backend routing and bypass prevention still need to be designed. A business should also identify whether data location, regulatory policy or latency requirements impose conditions on how application traffic may be routed.
The WAF layer provides controls designed around web traffic rather than generic IP filtering. Current FortiAppSec Cloud plan information includes signature-based protection, IP and geographic intelligence, custom security rules, HTTP compliance checks, URL and parameter protection, CORS controls, cookie protection, information-leakage controls and antivirus scanning of file uploads. API schema enforcement is also listed across plans. These capabilities help establish a more application-aware boundary, but policy defaults should not be treated as a complete deployment design. Applications behave differently, and controls that are appropriate for a static public website may require different tuning for a transactional portal or complex API ecosystem.
FourTeck can help buyers distinguish the product selection question from the configuration question. Purchasing the correct plan is necessary, but a successful project also needs an accurate inventory of protected services, DNS ownership, certificate responsibility, origin details, maintenance windows, testing approach and a named team that will handle false positives or required exceptions.
Capability focus: API, bot and advanced threat controls by plan
The second major buying decision is the plan tier. Fortinet’s current Cloud WAF structure has Standard, Advanced and Enterprise levels, and the plan choice applies across the account rather than allowing a buyer to mix one application on Standard with another on Advanced. That makes requirement gathering important before purchase. If only one application needs a higher-tier capability, the effect on the wider account should be understood before a commercial decision is made.
Standard provides the core WAF and API-security baseline. Current plan documentation lists API schema enforcement, baseline bot defence and the main web protection controls. Advanced adds capabilities such as machine-learning-based anomaly detection for zero-day attack protection, advanced API functions, DAST scanning and Threat Analytics. It also includes machine-learning-based bot defence and account-takeover related features in the current feature matrix. Enterprise adds further controls including automated client-side security and Advanced Bot Protection, while also including services such as GSLB and SOCaaS that are otherwise separate or add-on items in other tiers.
The difference between “bot defence” and “Advanced Bot Protection” is commercially important. A buyer should not assume that every bot-related function is available in every tier simply because bot protection appears in general product descriptions. The same caution applies to API discovery, client-side protection, threat analytics and application-delivery functions. The correct approach is to identify the required outcome first—such as reducing automated login abuse, discovering undocumented APIs, scanning runtime applications for vulnerabilities or monitoring client-side script risk—and then match that requirement to the current plan matrix.
This is particularly relevant for ecommerce, banking, SaaS and consumer-facing portals where automated abuse may have several forms: scraping, account takeover attempts, credential stuffing, fake account creation, inventory abuse or excessive API calls. No WAF plan guarantees that every malicious action will be stopped. The platform provides security controls, but effectiveness depends on correct onboarding, policy design, traffic visibility and continued tuning as the application changes.
When preparing a FourTeck quotation request, describe the business problem rather than listing feature names alone. For example, “we need to protect three login-heavy applications from credential abuse and discover unmanaged APIs” gives more useful context than simply requesting an “advanced WAF.” That context helps determine whether Advanced or Enterprise should be evaluated and which optional services need to be included.
Capability focus: availability, traffic management and security operations
The third major area is operational resilience. A public application is not useful if legitimate users cannot reach it, so application-security projects frequently overlap with DDoS protection, health monitoring, content delivery and load distribution. Current FortiAppSec Cloud plan information lists Layer 3–4 and Layer 7 DDoS mitigation across plans, together with CDN capability, load balancing and server health monitoring. Advanced and Enterprise add further application-delivery functions, and Enterprise includes GSLB in the current plan framework.
These functions should be evaluated as part of the architecture rather than treated as automatic replacements for every existing CDN, DNS, load balancer or cloud-native service. A business may already use a cloud provider’s load balancer, a global DNS service or a separate CDN. The team should decide which component owns TLS termination, routing, health checks and failover, and whether overlapping features are desirable or unnecessarily complex. If GSLB is required, confirm whether it will be consumed within Enterprise or as the separately orderable service available for other plans.
Security operations are equally important. Current plan matrices include attack logs, alert notifications, SIEM integration, dashboards and role-based access control. Advanced plans add richer analytics capabilities. Decide in advance who will review alerts, what events should be sent to the SIEM, how long logs must be retained in external systems, how incident response will escalate to application owners, and whether the customer wants SOCaaS. In Standard and Advanced, SOCaaS is listed as an add-on; Enterprise includes it in the current plan structure.
Availability and security controls are only useful when ownership is clear. FourTeck can help include the right commercial services in the quotation, while the customer should define internal operational roles, maintenance procedures, testing approvals and incident-response contacts. Where deployment assistance is required, FourTeck service options can be discussed as a separate project scope.
Ideal business environments and use cases
Ecommerce and digital retail
Online storefronts, customer accounts, checkout workflows and product APIs are common WAF candidates. Buyers should identify bot risks, payment-related application paths, third-party scripts, peak traffic periods and API dependencies before choosing a tier.
SaaS and software platforms
SaaS providers may need to protect login pages, tenant-facing applications, API endpoints and administrative interfaces. Application count, traffic growth, automation requirements and separation between production and non-production services should be defined carefully.
Financial and customer portals
Portals handling account access, document exchange or sensitive workflows often require strict change control and strong visibility. Buyers should review authentication behaviour, bot and account-takeover risks, SIEM integration and incident handling.
Hospitality and booking services
Reservation platforms and customer-facing booking engines can experience seasonal peaks and automated traffic. Traffic sizing, global user distribution and dependency on third-party booking or payment APIs are useful inputs for WAF planning.
Education and healthcare portals
Student, learning, appointment and patient-facing services often combine authenticated users, file uploads and integrations. Security policy needs to be balanced with application functionality, privacy requirements and operational support.
Multi-cloud application estates
Organisations running applications across more than one hosting environment may prefer a common SaaS control plane. Regional traffic paths, latency, origin access and existing cloud-native security services should still be reviewed before deployment.
Buyer questions to resolve before ordering
Count production web applications and APIs accurately. Do not assume one company domain means one billable application.
Use observed traffic and growth assumptions. Current licensing uses bandwidth seats and marketplace billing may also meter bandwidth.
Separate required functions from desirable ones. API discovery, advanced bot protection, DAST, Threat Analytics and client-side controls do not have identical availability across tiers.
Record hosting providers, regions, origin IPs or hostnames, firewall rules and any existing load balancers or CDNs.
The deployment can stall if the security team cannot coordinate with the teams responsible for DNS, TLS certificates and application maintenance.
An old FortiWeb Cloud quotation may not map directly to the current FortiAppSec Cloud seat structure. Share contract details before requesting renewal pricing.
Procurement checklist
A useful quotation request gives the supplier enough detail to identify the correct plan and seat counts without repeated commercial revisions. Confirm the following before a purchase order is raised.
✓ Exact requirement: new FortiAppSec Cloud WAF, legacy FortiWeb Cloud migration or renewal
✓ Number of protected web applications and API services
✓ Measured average bandwidth and expected peak/growth pattern
✓ Required plan: Standard, Advanced or Enterprise
✓ Need for Threat Analytics, advanced bot controls, DAST or advanced API features
✓ Need for GSLB, SOCaaS or a dedicated WAF environment
✓ Hosting locations and origin architecture
✓ DNS ownership and planned cutover method
✓ TLS certificate and mutual-TLS requirements
✓ SIEM, log export and alerting expectations
✓ Required subscription or commercial route and billing preference
✓ Deployment, configuration, migration or knowledge-transfer scope
✓ UAE delivery/billing entity details and required quotation timeline
How FourTeck can assist with sizing and quotation
FourTeck can help buyers turn an application-security requirement into a procurement-ready request. That may include clarifying whether the buyer is asking for the current FortiAppSec Cloud WAF service or referencing the older FortiWeb Cloud name, reviewing how many applications need protection, checking the bandwidth information supplied by the customer, mapping required capabilities to a plan and identifying optional services that should appear in the quotation.
This assistance is useful when IT, procurement and application teams use different terminology. The application team may describe domains and APIs, the security team may describe WAF controls and bot risks, while procurement may hold an old SKU or previous subscription reference. Bringing these details together reduces the chance of ordering an outdated or incomplete item.
FourTeck can also discuss implementation scope where required, including onboarding coordination, DNS and certificate planning, policy configuration, testing, migration or operational handover. Service scope should be quoted separately and depends on the number of applications, application complexity, existing environment and customer responsibilities. Use the FourTeck contact page to share the technical and commercial inputs for review.
Useful information to send
• Current contract or old FortiWeb Cloud SKU, if applicable
• Application and API count
• Bandwidth estimate
• Required plan capabilities
• Hosting and DNS details
• Expected subscription start or renewal date
• Whether configuration or migration assistance is required
UAE availability and support guidance
Contact FourTeck to confirm current UAE availability for the required FortiAppSec Cloud WAF plan, application seats, bandwidth seats and any add-on or standalone services. Availability and commercial terms may depend on the chosen plan, quantity of seats, purchase route, vendor lead time, marketplace account structure and whether the request is a new subscription or migration from a legacy FortiWeb Cloud arrangement. A cloud service does not require physical appliance delivery, but the quotation, activation route and project schedule still need to be coordinated.
If installation or configuration assistance is required, include it in the request rather than assuming it is part of the subscription. Application onboarding can require DNS changes, origin configuration, certificate coordination, policy tuning, test windows and communication with application owners. FourTeck can discuss these dependencies and help prepare a scope appropriate to the UAE project.
Dubai, Abu Dhabi, Sharjah and Ajman coverage
Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for Fortinet application-security quotation assistance, current Cloud WAF licensing guidance and project coordination. The requirement may come from an enterprise IT team, an ecommerce operator, a systems integrator, a software company, a hospitality group, a financial-services organisation or another business running public web applications and APIs. FourTeck can help review the commercial inputs needed for a suitable quotation and can discuss related network-security requirements through the wider Fortinet firewall solutions portfolio when application protection is part of a broader security project.
GCC Availability
FourTeck can assist organisations planning Fortinet Cloud WAF requirements across GCC markets with requirement review, current product naming, plan selection, application and bandwidth sizing, quotation coordination and deployment-scope discussion. Buyers in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain and Oman should provide the destination country, billing entity, number of applications, expected traffic, required plan, subscription timing and any configuration or migration requirement. Cloud-service availability, marketplace options, commercial terms, licensing, regional service conditions and project schedules can vary by country and account structure. For existing FortiWeb Cloud customers, migration or renewal handling may also depend on the current contract type and marketplace. FourTeck can help organise the request and, for Kuwait-related enquiries, buyers may also use the FourTeck Kuwait channel. Confirm the exact requirement before assuming that a UAE quotation or legacy SKU applies unchanged elsewhere in the GCC.
Africa Availability
FourTeck can also assist organisations evaluating cloud-delivered web application and API protection for projects in Africa. The planning discussion can cover the number of web applications and APIs, expected bandwidth, required FortiAppSec Cloud tier, optional services, migration from older FortiWeb Cloud contracts, configuration scope and operational support expectations. Availability and fulfilment can depend on the destination country, billing arrangement, license region, cloud marketplace route, application origin locations, local project conditions and vendor commercial policy. Buyers should share the destination, exact application-security requirement, preferred deployment schedule and whether remote configuration, migration guidance or other support is expected. For East Africa and wider regional enquiries, the FourTeck Africa platform can provide a regional contact path. No assumption should be made about local inventory or immediate activation until the subscription route and account requirements are confirmed.
Related FourTeck options to consider
FortiWeb hardware or VM
Consider customer-managed FortiWeb when the architecture requires an appliance or virtual WAF rather than SaaS delivery. Sizing and licensing are different from the Cloud WAF model.
FortiGate network security
A WAF protects application-layer traffic; it does not replace the wider network-security role of a next-generation firewall. Review both layers where the project covers internet edge and application security.
Application onboarding services
Configuration assistance can include planning, DNS coordination, certificate handling, policy setup, validation and handover depending on scope.
Security logging integration
If WAF events must feed a wider security-operations process, include SIEM and logging requirements during design instead of treating them as an afterthought.
Migration and renewal review
Legacy FortiWeb Cloud customers can request help checking the current contract position before moving to a current FortiAppSec Cloud subscription structure.
Why businesses contact FourTeck for this requirement
The difficult part of a Cloud WAF purchase is often not identifying the brand; it is defining the current orderable requirement. FourTeck can help clarify whether the request should be quoted as current FortiAppSec Cloud WAF, identify the plan level, assemble the application and bandwidth requirement, check whether GSLB or SOCaaS is needed, and flag migration questions for customers holding older FortiWeb Cloud subscriptions.
This approach helps procurement teams avoid buying only from an outdated SKU description and helps technical teams make sure the quotation reflects actual protected applications and traffic. FourTeck can also coordinate a separate implementation or migration discussion where the project needs assistance beyond licensing. For wider information about the company and service approach, visit About FourTeck.
What buyers are really trying to determine before choosing FortiWeb Cloud WAF
A buyer who searches for Fortinet FortiWeb Cloud WAF is often trying to answer several different questions at once: Is the old product still available? Is it the same as FortiAppSec Cloud? How is it licensed now? Can it protect APIs and bots as well as websites? How does it differ from a FortiWeb appliance or VM? What information is needed to get a reliable price? These questions are closely connected, and resolving them in the right order is more useful than simply comparing a list of features.
FortiWeb Cloud versus FortiAppSec Cloud
The most important naming point is that Fortinet’s current materials treat Cloud WAF as part of FortiAppSec Cloud and explicitly identify current Cloud WAF SKUs as previously FortiWeb Cloud. An organisation holding an older FortiWeb Cloud contract should therefore not assume the legacy SKU remains the correct renewal path. New buyers should ask for the current FortiAppSec Cloud WAF plan that matches their needs. Existing customers should share their contract or marketplace subscription so migration and renewal details can be checked before commercial action.
Cloud WAF versus FortiWeb VM or appliance
The SaaS service is chosen when the organisation wants Fortinet to operate the WAF infrastructure in the cloud. A FortiWeb VM or appliance is customer deployed and has a different sizing model based on virtual capacity or hardware performance. The cloud service instead focuses commercial sizing on application count and bandwidth. The correct option depends on architecture, operational preference, regulatory constraints and where the organisation wants the enforcement point to be managed. A request for “FortiWeb” alone is therefore too broad for a final quote.
Why application count matters
Current seat-based licensing uses application seats, with the FortiWeb ordering guide describing one web application per application seat. This makes application inventory a commercial input, not just a technical document. A company may own one public domain while operating several separate applications, APIs or services beneath it. Before asking for a quote, map the application estate in a way that the security and procurement teams both understand. If uncertain, share the architecture with FourTeck rather than choosing a seat count by assumption.
How bandwidth affects cost and sizing
Cloud WAF licensing also depends on bandwidth. Current ordering uses 25 Mbps bandwidth seats, while public cloud marketplace consumption models can meter traffic in smaller units and calculate charges from usage. Buyers should use observed monitoring data and account for seasonal peaks, planned growth and large transaction patterns. An estimate based only on the internet circuit size can be misleading because the relevant figure is the application traffic being protected. A short traffic report is often more useful for quotation preparation than a generic request for “100 Mbps WAF.”
Which plan should a business shortlist?
Start with the security outcome. Standard is the core WAF and API-security tier. Advanced is relevant when the requirement includes machine-learning anomaly detection, richer API functions, vulnerability scanning and Threat Analytics. Enterprise is the tier to examine when advanced bot protection, automated client-side security, included GSLB and included SOCaaS are important. Because the account uses one plan type for both application and bandwidth SKUs, organisations should confirm the highest-value required features before selecting the account tier.
How to prepare for onboarding
Cloud delivery removes the need to install a WAF appliance, but the application still has to be onboarded. The team should prepare origin server details, DNS control, certificate requirements, health-check expectations, backend firewall rules and a test plan. Application owners should identify sensitive workflows such as login, file upload, payment, API calls and administrative actions. This makes policy validation more efficient and helps the team distinguish legitimate unusual traffic from attack activity.
What determines the final UAE quotation?
There is no single universal price for a FortiWeb Cloud WAF requirement. The quote depends on the current FortiAppSec Cloud plan, application seats, bandwidth seats, subscription route, optional SOCaaS, GSLB or dedicated-environment requirements, and whether migration or deployment services are included. Cloud marketplaces can use consumption-based point models, while private offers and traditional subscriptions may be structured differently. For a business quotation, provide the exact workload and commercial route rather than relying on a public example price.
When a cloud WAF may not be the preferred choice
A SaaS WAF is not automatically the right answer for every application. Some organisations require traffic enforcement entirely inside a private environment, have architectures that cannot use external traffic steering, or want a WAF appliance with customer-controlled network interfaces and local placement. Others may already have a mature cloud-native WAF design they do not want to replace. In those cases, compare FortiWeb VM, hardware and existing platform controls. The goal is to select the deployment model that fits the architecture, not to force every application into the same pattern.
Questions buyers ask while building a shortlist
These decision questions are separate from the general product FAQ because they focus on choices that can change the bill of materials, migration approach or deployment plan.
Can I keep using an old FortiWeb Cloud SKU for renewal?
Do not assume so. Current Fortinet materials use FortiAppSec Cloud WAF SKUs and describe them as replacing the previous FortiWeb Cloud model. Legacy contracts may have different structures, marketplace arrangements or migration requirements. The safest approach is to provide the old SKU, contract identifier, renewal date and current protected applications so the present renewal path can be checked.
Can different applications use different FortiAppSec Cloud plans in one account?
Current ordering guidance says the plan cannot be mixed within the account: applications and bandwidth must use the same Standard, Advanced or Enterprise level. This means a higher-tier requirement on one important application can influence the account-wide plan decision. Before ordering, review which advanced capabilities are genuinely needed and whether account separation has any practical relevance to your design.
Does API protection mean I do not need an API gateway?
Not automatically. FortiAppSec Cloud includes API-security functions, and higher tiers list API gateway capabilities, but architecture roles should still be defined. An existing API gateway may handle developer onboarding, authentication, transformation, quotas or service routing that the business wants to retain. Review overlap and integration instead of removing a component simply because both products mention APIs.
How should I estimate protected bandwidth if traffic varies?
Use historical monitoring that covers normal periods and known peaks. Note campaigns, seasonal demand, software releases and large file-transfer events. Current marketplace descriptions also use measured bandwidth concepts, so traffic variability matters commercially. If data is incomplete, provide the best available monitoring window and growth expectation rather than selecting a license solely from WAN circuit capacity.
What makes a WAF migration risky?
The main risks are traffic-path changes, incomplete origin restrictions, certificate issues, application behaviour that triggers false positives, and differences between old and new policy or API structures. A migration should include test applications, rollback planning, validation of critical transactions and review of automation scripts or integrations. The commercial migration and the technical migration should be planned together.
What should procurement ask the technical team before requesting pricing?
Ask for the number of applications, expected bandwidth, required plan features, optional services, current contract details if renewing, origin architecture and expected start date. Also ask whether deployment or migration assistance is part of the requirement. These inputs let FourTeck prepare a more relevant quotation and reduce revisions caused by missing technical scope.
Frequently Asked Questions
Is Fortinet FortiWeb Cloud WAF still the current product name?
FortiWeb Cloud is the legacy and still widely recognised name, but Fortinet’s current ordering material places the Cloud WAF service under FortiAppSec Cloud WAF and describes current Cloud WAF SKUs as previously FortiWeb Cloud. New quotations should therefore be checked against current FortiAppSec Cloud plans and SKUs.
What is Fortinet FortiWeb Cloud WAF used for?
It is used to protect internet-facing web applications and APIs by filtering and monitoring HTTP and HTTPS traffic through a cloud-delivered WAF service. Current FortiAppSec Cloud plans include core web application protection, API security, bot defence, DDoS mitigation, logging and application-delivery capabilities, with advanced functions dependent on plan.
How is the current Cloud WAF licensed?
Current Fortinet ordering uses a seat-based model with both bandwidth and application SKUs. The FortiWeb ordering guide describes 25 Mbps per bandwidth seat and one web application per application seat. Buyers must select matching Standard, Advanced or Enterprise plans for both application and bandwidth requirements.
Can Standard, Advanced and Enterprise plans be mixed?
Current ordering guidance says no. An account uses one plan type, and the application and bandwidth SKUs must use the same Standard, Advanced or Enterprise level. Buyers should review required advanced features across all protected applications before selecting the account plan.
Does the service require a FortiWeb appliance?
No. The Cloud WAF option is a SaaS service and does not require the customer to deploy a FortiWeb hardware appliance for the WAF function. However, application onboarding still requires planning for DNS, TLS certificates, origin access, traffic routing, health checks and policy validation.
Which plan includes Threat Analytics and advanced bot protection?
Current Fortinet plan information places Threat Analytics in Advanced and Enterprise, while Advanced Bot Protection is an Enterprise capability. Standard includes core WAF, API and baseline bot controls. Exact feature entitlement should be confirmed against the current ordering guide when the quote is prepared.
Can FourTeck help with migration from legacy FortiWeb Cloud?
FourTeck can help review the commercial requirement and discuss migration scope. Share the existing FortiWeb Cloud contract or marketplace subscription, protected applications, bandwidth, current features and renewal timing so the current FortiAppSec Cloud option and any migration assistance can be evaluated.
What information is needed for a UAE quotation?
Provide the number of applications, expected bandwidth, required plan, optional SOCaaS or GSLB needs, existing contract details if renewing, hosting environment, preferred subscription route and whether configuration or migration support is required. FourTeck can then check current UAE commercial availability and prepare a more relevant quotation.
Is a public marketplace price the same as a FourTeck UAE quote?
No. Public cloud marketplaces may use usage-based point pricing, while private offers and traditional subscription quotations can use different commercial structures. The final UAE price depends on plan, applications, bandwidth, optional services, account route and project scope, so current quotation details should be confirmed before purchase.
Need help translating a FortiWeb Cloud requirement into the current FortiAppSec Cloud WAF plan?
Share your application count, bandwidth, required security capabilities and any existing FortiWeb Cloud contract. FourTeck can help review the current licensing structure, UAE quotation path and any configuration or migration assistance you need.



Reviews
There are no reviews yet.