Direct answer for buyers
FortiWeb Virtual Series is the virtual-machine edition of Fortinet’s web application firewall platform. It is mainly used to inspect and control application-layer traffic to websites and APIs, helping organisations address common web attacks, malicious automation, API risks and other threats while running the protection layer on virtual or cloud infrastructure. It should be considered by businesses that prefer a software-based WAF close to their workloads rather than a dedicated hardware appliance. Before proceeding, buyers should confirm the exact VM tier, expected HTTP and HTTPS traffic, available vCPU and memory, host or cloud platform, subscription bundle, high-availability requirement and deployment topology. These variables influence both technical suitability and the bill of materials.
What the virtual series does
FortiWeb is positioned in front of protected web applications or APIs so application requests can be evaluated before they reach the server. Its protection model combines conventional WAF controls such as signatures, reputation, protocol checks and policy rules with machine-learning-based analysis. Depending on the selected subscription and configuration, the platform can also provide API discovery and protection, bot-related controls, credential-stuffing defenses, cloud sandbox integration, threat analytics, client-side security and data-loss-prevention functions.
The virtual edition is especially relevant when application infrastructure already runs on hypervisors or in cloud platforms. It allows security teams to deploy FortiWeb as software rather than introducing another physical appliance into the data path.
Who should consider it
The family can fit organisations that publish business portals, e-commerce applications, customer self-service systems, partner applications, mobile back-end APIs or internal web services that need application-aware protection. It may also suit service providers and multi-application environments where a virtual WAF needs to follow workload placement and infrastructure changes.
It is not automatically the right choice for every project. A physical FortiWeb appliance may be more appropriate where dedicated hardware, particular interface requirements or appliance-specific performance are preferred. A SaaS WAF can be attractive where the organisation does not want to operate a virtual appliance. FourTeck can help compare these approaches before a model is selected.
Business problems the virtual WAF can help address
Public application exposure
Internet-facing sites and APIs create a distinct application attack surface. FortiWeb adds inspection and policy enforcement at the application layer rather than relying only on a network firewall.
API growth and visibility
Organisations often expose more APIs as applications become mobile, integrated and automated. FortiWeb includes API discovery and protection capabilities, with exact functionality dependent on the selected service level and configuration.
Automated abuse
Credential stuffing, scraping and unwanted bot traffic can consume resources or target user accounts. Higher subscription levels add more advanced bot and credential-related controls.
Hybrid application hosting
A virtual WAF can be deployed alongside workloads across supported private-cloud and public-cloud platforms, helping security teams keep a similar control model as applications move.
Verified virtual-machine information
| Brand | Fortinet |
|---|---|
| Product family | FortiWeb Virtual Series / FortiWeb-VM |
| Product type | Virtual web application firewall and API protection platform |
| Current VM sizes | FortiWeb-VM01, VM02, VM04, VM08 and VM16 |
| vCPU licensing | Up to 1, 2, 4, 8 or 16 vCPUs according to model; VM04, VM08 and VM16 support a minimum allocation of 2 vCPUs in the published specification. |
| Network interfaces | 1 minimum / 10 maximum across the published VM models |
| Storage support | 40 GB minimum / 2 TB maximum |
| Administrative domains | 4 to 64 based on allocated memory |
| Application licenses | Unlimited in the published VM specification |
| High availability | Supported; design and licensing should be confirmed for the intended topology |
| Supported environments | Published support includes VMware, Microsoft Hyper-V, Citrix XenServer, Open Source Xen, VirtualBox, KVM, AWS, Microsoft Azure, Google Cloud and Oracle Cloud. Confirm supported versions in the current installation guide. |
| Subscription structure | S-series annual subscription options include Standard, Advanced and Enterprise bundles. |
| Availability | Contact FourTeck for current UAE availability, applicable subscription term and lead time. |
Licensing and feature dependencies matter as much as VM size
The FortiWeb-VM S-series is sold as an annual subscription, and the bundle controls which security services are included. In Fortinet’s current ordering guidance, the Standard level covers core web-security services, IP reputation and antimalware. The Advanced level adds services such as FortiWeb Cloud Sandbox, Credential Stuffing Defense and Threat Analytics. The Enterprise level adds capabilities including Advanced Bot Protection, Client-Side Security and data-loss-prevention functions. Additional services such as FortiAI-related functionality and SOC services can have separate subscription requirements.
A buyer therefore should not select a VM only by throughput. Two organisations with similar traffic can need different subscriptions because their risk profile, API exposure, authentication flow, bot problem, compliance requirements and incident-response process are different. FourTeck can help map those requirements to the appropriate subscription before a quotation is prepared.
How to choose the right FortiWeb-VM size
1. Measure protected traffic
Separate normal traffic from peak traffic and identify the proportion that is HTTPS. Encrypted throughput is usually the more important planning figure for modern applications because decryption and inspection add processing work.
2. Count applications and domains
Consider how many distinct application domains will use machine-learning functions. The published maximum rises from four on VM01 to 32 on VM08 and VM16, so application consolidation can influence model selection even when bandwidth is modest.
3. Confirm compute resources
A virtual appliance depends on the host. Confirm vCPU availability, recommended memory, storage and virtual interfaces in the target platform. Avoid assuming that a license alone guarantees the published maximum performance.
4. Plan resilience
If application availability is critical, define the desired HA architecture before purchasing. HA affects topology, resource allocation, licensing, certificates, routing and operational procedures.
Application-layer visibility and policy control
A network firewall and a WAF answer different questions. A network firewall is primarily concerned with network sessions, addresses, ports and broader security controls, while a WAF evaluates the structure and behavior of web requests. FortiWeb can apply signatures, reputation, HTTP protocol validation, application profiling, machine-learning analysis and other controls that are specific to web applications.
For buyers, the operational value is the ability to create policies around an application rather than treating all encrypted web traffic as equivalent. The deployment still requires tuning and ownership. Application changes, APIs, authentication flows and new content can alter what normal behavior looks like, so policy review should be part of application lifecycle management.
API discovery and protection
Modern applications may expose dozens or hundreds of API paths used by mobile apps, partners and automated systems. FortiWeb includes capabilities for discovering APIs from observed traffic and applying schema-oriented protection for supported formats. This can help a security team understand which application interfaces are actually being used and where policy may need to be tightened.
The useful question is not simply whether an organisation “has APIs.” Buyers should identify which APIs are public, which carry sensitive data, which use tokens or user credentials, whether OpenAPI or other schemas are maintained, and how frequently application teams release changes. These details affect both design and policy maintenance.
Bot, credential and client-side considerations
Automated traffic ranges from useful search and monitoring bots to scrapers, account-abuse tools and credential-stuffing activity. FortiWeb offers multiple bot-related controls, but advanced capabilities are tied to higher subscription levels. Client-side security and data-loss-prevention functions are also bundle dependent.
A buyer should describe the actual abuse pattern before selecting the subscription. An e-commerce login portal under credential attacks has a different requirement from a public information site that mainly needs protection against common application exploits. Matching the bundle to the risk avoids paying for unnecessary functions or discovering after purchase that a desired control is not included.
Deployment approaches to discuss before implementation
FortiWeb supports multiple deployment methods, including reverse proxy, inline transparent, true transparent proxy, offline sniffing and WCCP-related designs. The correct choice depends on how the application is published, what network changes are acceptable, how client IP information is preserved, where TLS is terminated and whether FortiWeb will also perform application-delivery functions. In many projects, reverse proxy is attractive because it provides direct control over application connections and TLS termination, but it can require DNS, routing, certificate and server-pool planning. Transparent designs can reduce some addressing changes but still require careful placement and failure-path design.
Cloud deployments introduce their own questions. The team should confirm virtual-network topology, subnets, security groups or equivalent controls, route tables, public and private addressing, load-balancer relationships, autoscaling expectations, image availability, licensing method and the way logs will reach the organisation’s monitoring platform. For private hypervisors, confirm the supported platform version, virtual NIC type, resource reservation, datastore performance and backup policy. FourTeck can help define the configuration scope before implementation so the quotation reflects the intended topology rather than only the license.
A practical purchase and deployment journey
Discover
List protected applications, domains, APIs, traffic levels, hosting locations and current security controls.
Size
Compare HTTP and HTTPS demand with VM01 through VM16 and allow capacity for peaks, security features and future growth.
Select bundle
Choose Standard, Advanced or Enterprise according to required security services and operational objectives.
Design
Confirm topology, HA, certificates, networking, logging, administration and integration dependencies.
Deploy and tune
Implement policy, observe traffic, validate legitimate application behavior and refine controls before moving to stricter enforcement.
Where FortiWeb Virtual Series can fit well
Hybrid enterprise applications
Enterprises running a combination of virtualized data-center workloads and public-cloud applications can use the virtual form factor to place a WAF close to each workload. The suitability depends on where traffic enters the environment and whether a consistent operating model can be maintained across platforms.
Customer and partner portals
Authenticated portals expose login flows, business transactions and user data. A WAF can add controls around application attacks and automated abuse, while higher service bundles may be relevant where credential-stuffing or advanced bot activity is a concern.
API-centric services
Organisations delivering mobile back ends, B2B integrations or machine-to-machine services can benefit from API discovery and policy features. The application team should maintain API documentation and coordinate changes with the security team.
Service-provider environments
Administrative domains and a range of virtual machine sizes can be useful where several applications or customers need logical separation. The exact multi-tenant design, memory sizing and operational responsibilities must be confirmed before purchase.
Integration and operational considerations
A WAF is most effective when it is integrated into the way applications are designed, released and monitored. Security teams should decide who owns FortiWeb policy, who approves exceptions, how developers notify the security team of application changes, and where logs are reviewed. If vulnerability scanners are used, FortiWeb can integrate with supported third-party scanners for virtual-patching workflows. Fortinet Security Fabric integrations can also be relevant where FortiGate or FortiSandbox products are part of the environment. Compatibility and license requirements should be checked for the specific versions involved.
Certificate management is another practical issue. Decide whether FortiWeb will terminate TLS, re-encrypt traffic to the origin server, use certificates supplied by the organisation, or integrate with an existing certificate process. For API protection, define where schemas are stored and how they are updated as development teams release new versions. For logging, determine whether local FortiView visibility is enough or whether events must also be sent to a SIEM, syslog platform or wider security-operations workflow. These operational decisions are often more important to long-term success than the initial virtual machine deployment itself.
Questions buyers should resolve before asking for a quotation
Provide average and peak figures where possible, not only internet circuit speed.
This can affect the VM tier independently of raw throughput.
Include hypervisor or cloud provider and the relevant version or service details.
Clarify whether advanced bot, credential, sandbox, threat analytics, client-side or DLP capabilities are required.
Define the desired failover behavior and whether the project requires active/active or active/passive operation.
Include configuration, migration, testing, handover and ongoing support expectations in the scope.
Procurement checklist for FortiWeb Virtual Series
✓ Confirm the exact FortiWeb-VM tier: VM01, VM02, VM04, VM08 or VM16.
✓ Record required quantity and whether HA requires more than one instance.
✓ Provide measured average and peak HTTP/HTTPS throughput.
✓ Confirm the number of application domains and APIs in scope.
✓ Verify vCPU, RAM, storage and virtual-interface resources on the target platform.
✓ Confirm hypervisor or cloud platform and supported version.
✓ Select Standard, Advanced or Enterprise subscription according to needed services.
✓ Identify certificates, DNS, routing and load-balancer dependencies.
✓ Define high-availability and disaster-recovery expectations.
✓ Confirm logging, SIEM and monitoring integrations.
✓ State whether installation, configuration, migration or policy tuning is required.
✓ Confirm support expectations and subscription term.
✓ Share deployment country, target timeline and any regional licensing constraints.
How FourTeck can assist with planning and procurement
FourTeck can help convert a broad requirement such as “we need FortiWeb in the cloud” into a more useful bill of materials. The process can begin with application inventory, traffic estimates, environment details and security objectives. From there, the suitable VM tier can be compared against published performance limits and resource requirements, while the subscription bundle is reviewed against the security services actually required. This is useful for organisations that want a commercial quotation without accidentally selecting an undersized VM, an unnecessary high-end tier or a bundle that does not contain a required control.
Where deployment assistance is required, configuration scope can be discussed separately. Typical planning may cover topology, interfaces, server objects, certificates, protected hostnames, policy mode, logging, HA, administrative access and integration points. Buyers can also explore broader FourTeck technology services or review other security and infrastructure products when FortiWeb forms part of a larger application-security project. For Fortinet-focused environments, the Fortinet solutions page can provide related context.
UAE availability and support guidance
Contact FourTeck to confirm current UAE availability for the required FortiWeb-VM subscription, license tier and quantity. Virtual products avoid many of the logistics associated with a physical appliance, but entitlement, subscription region, vendor processing, cloud image availability and project scheduling can still affect the purchase timeline. Buyers should share the exact destination, deployment platform, requested model, bundle and term so that the quotation is based on the right item rather than a generic FortiWeb description.
If the project includes configuration, policy migration, certificate work, HA setup or testing, include that scope in the request rather than assuming it is bundled with the license. FourTeck can coordinate requirement review and quotation planning for Dubai and wider UAE projects. Delivery and implementation dates should be agreed only after the exact bill of materials and service scope are confirmed.
Dubai, Abu Dhabi, Sharjah and Ajman coverage
Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for FortiWeb Virtual Series requirement review, model sizing, license selection and quotation coordination. Because this is a virtual security platform, the core discussion normally centres on the application environment rather than the physical office location: the protected workloads may sit in a UAE data centre, a private virtual environment, a regional cloud tenant or a global public-cloud service. The location still matters for subscription, project access, support coordination and internal security requirements. Share the hosting architecture and operational expectations so FourTeck can align the commercial and technical discussion with the actual deployment.
GCC Availability
For GCC projects, FourTeck can assist organisations that need to evaluate FortiWeb Virtual Series for applications hosted in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman. The useful starting point is a complete requirement rather than a country name alone: identify the FortiWeb-VM tier under consideration, subscription bundle, quantity, hosting platform, expected traffic, deployment location and any installation or configuration assistance required. This allows licensing and technical dependencies to be reviewed together. Product availability, subscription processing, cloud-marketplace options, service visits, project schedules and vendor lead times can differ by market, model and quantity, so these items should be confirmed before commitments are made. FourTeck can coordinate requirement review, quotation planning, license selection, implementation scope and renewal guidance where applicable. For Kuwait-related enquiries, buyers can also review FourTeck Kuwait resources. Share the destination country and expected timeline so the correct regional path can be discussed.
Africa Availability
Organisations planning FortiWeb Virtual Series deployments in Africa can contact FourTeck for guidance on model sizing, subscription options, cloud or hypervisor deployment requirements and procurement planning. A virtual WAF can be relevant for applications hosted locally, in regional data centres or in public-cloud environments, but availability and fulfilment may depend on the destination country, license region, selected model, quantity, deployment platform, support requirement and vendor processing time. Buyers should provide the exact requirement, target country, protected application profile, expected traffic, desired subscription bundle and preferred deployment schedule. If configuration, HA design, migration or support is needed, that should also be included in the request. FourTeck maintains regional information for markets including Kenya, Uganda and broader Africa technology enquiries. Local inventory, customs outcomes and fixed delivery times should always be confirmed for the specific project rather than assumed.
Related options worth comparing
FortiWeb physical appliances
Consider dedicated appliances when hardware form factor, dedicated interfaces or appliance-specific performance are preferred over a virtual deployment.
FortiAppSec Cloud WAF
A SaaS approach can suit teams that want application protection without operating a FortiWeb virtual appliance. Compare management model, coverage, integration and commercial structure.
FortiWeb container appliances
Container-based FortiWeb variants are available for container-oriented environments. Do not assume the VM and container performance or HA characteristics are identical.
FortiGate integration
Where FortiGate is already deployed, Security Fabric integration may support a broader security architecture. Confirm versions, topology and desired information sharing.
Buyer insights for planning a FortiWeb-VM project
A common buying mistake is to size a WAF from the internet connection rather than the traffic that will actually pass through the WAF. A company may have a 1 Gbps internet circuit but only 80 Mbps of peak web traffic for the applications being protected. Another company may have a smaller average load but very high short-duration peaks during campaigns, ticket releases or financial events. The meaningful inputs are therefore application-specific average and peak requests, encrypted throughput, concurrent connections, response sizes and the growth expected over the subscription period. Published throughput should be treated as a ceiling measured in vendor test conditions, not as a guaranteed production number.
Why HTTPS matters in sizing
Most business applications now use TLS. The WAF must often decrypt traffic, inspect it and then re-encrypt it toward the origin. That work consumes CPU and can make encrypted throughput a more relevant planning value than headline HTTP throughput. Certificate type, cipher choices, request patterns and enabled security functions can also affect performance. When in doubt, size from real encrypted traffic and preserve headroom rather than selecting the smallest tier that barely matches a peak.
The model name is only one part of the bill
FortiWeb-VM01 through VM16 describe the compute tier, but the annual subscription bundle determines important services. A buyer comparing quotations should make sure every supplier is quoting the same VM size, subscription level and term. A lower quote can simply be a smaller model or a Standard bundle where an Advanced or Enterprise function was expected. Ask for the exact subscription SKU where possible.
Cloud marketplace versus subscription quotation
FortiWeb can be available through public-cloud marketplaces as well as license-based deployment. Marketplace billing can simplify procurement for some cloud teams, while a subscription quotation may fit organisations that centralise security purchasing outside the cloud account. The right route depends on region, commercial policy, cloud architecture and the desired bundle. Compare the total entitlement and operating model, not only the first visible hourly or annual price.
Do you need a virtual WAF or WAF-as-a-Service?
Teams that want direct control over networking, policy and the appliance instance may prefer FortiWeb-VM. Teams that would rather consume application protection as a service may compare FortiAppSec Cloud WAF. The trade-off is not simply “cloud versus on-premises”; FortiWeb-VM itself can run in public cloud. The deeper difference is whether your team operates the WAF instance and surrounding network architecture or consumes a managed SaaS control plane.
Another useful planning question is how often protected applications change. Applications released weekly or daily require stronger coordination between development and security teams than a relatively static corporate portal. New API paths, authentication changes, JavaScript libraries, file upload functions and payment-page code can all affect WAF behavior. Define a change process in which the application team tells the security team what is changing and the security team reviews alerts, exceptions and policies after releases. This reduces the temptation to disable useful controls when a legitimate application change produces unexpected blocks.
For organisations replacing an existing WAF, prepare an inventory of current policies and identify which rules are business-specific rather than default vendor rules. Migration is rarely a direct one-to-one translation. Policies may need to be rebuilt around FortiWeb objects, server pools, protected hostnames, signatures, profiles and exceptions. Run a learning or monitoring phase where appropriate, validate normal user journeys, and move to blocking deliberately. Include application owners in testing because they understand critical workflows such as login, search, checkout, upload, password reset and API transactions.
Finally, keep renewal planning in view from the beginning. The VM S-series uses annual subscription licensing, so security managers should document which bundle was selected, why it was selected, who owns the renewal date and whether the application environment has changed before renewal. Growth in traffic, domains or bot exposure can justify a different tier at the next term. Conversely, application consolidation or retirement may reduce the requirement. FourTeck can help review the current deployment information before a renewal or new quotation so the order reflects current use rather than automatically repeating an old bill of materials.
Questions that help buyers avoid the wrong FortiWeb choice
Should I choose VM01 because my average traffic is below 25 Mbps?
Not automatically. Average traffic can hide short peaks, and HTTPS inspection has a lower published throughput value than HTTP. Also consider the number of machine-learning domains, vCPU allocation, security services and expected growth. A small average may still justify VM02 or a higher tier if peak encrypted traffic or application count is greater.
Can one FortiWeb-VM protect several web applications?
Yes, the published VM specification allows unlimited application licenses, but practical sizing still depends on traffic, memory and the number of machine-learning domains. Administrative domains can also vary with memory allocation. Consolidating many applications on one instance should therefore be an architectural decision, not simply a licensing assumption.
Does the Enterprise subscription make the VM faster?
The bundle primarily changes included services, not the licensed vCPU tier. Enabling additional inspection can influence actual resource consumption, so the sizing conversation should account for the services that will be active. Choose the bundle for security requirements and the VM tier for resource and performance requirements, then validate both together.
What information makes a quotation more accurate?
Provide the desired model if known, expected throughput, protected domains, platform, region, quantity, HA requirement, subscription level, subscription term and service scope. If the model is not known, provide the application and traffic information so FourTeck can help shortlist a tier instead of guessing from company size.
Do public-cloud deployments remove the need for network design?
No. A cloud VM still needs virtual networks, routes, interfaces, security controls and traffic paths. You also need to decide where TLS terminates, how application servers are reached and how HA or resilience is handled. Cloud changes the implementation tools, not the need for architecture.
When should a buyer compare a physical FortiWeb appliance?
Compare hardware when the project prefers dedicated interfaces, appliance-level performance, a fixed data-centre form factor or an architecture that keeps application security separate from the virtual infrastructure cluster. Compare the same security-service requirements across both options before deciding.
Why businesses contact FourTeck for FortiWeb projects
The useful part of a FortiWeb procurement discussion is requirement clarification. FourTeck can help buyers translate technical and business inputs into a model and subscription shortlist, review whether HA or professional services should be included, and coordinate a quotation with the relevant licensing structure. This is especially helpful when a project spans security, cloud, networking and application teams, because each group may describe the requirement differently.
FourTeck can also help identify questions that need vendor confirmation rather than making assumptions. These can include current regional entitlement, subscription term options, supported software versions, exact cloud-marketplace availability, compatibility with a specific third-party scanner or whether a feature is included in a particular bundle. Buyers can contact FourTeck with the application profile and target environment for a more accurate discussion.
Frequently asked questions
What models are included in the FortiWeb Virtual Series?
The current FortiWeb-VM range includes VM01, VM02, VM04, VM08 and VM16. The model number corresponds to the licensed vCPU tier, with published performance and recommended memory increasing across the range.
What is the difference between Standard, Advanced and Enterprise subscriptions?
Standard covers core web-security services, IP reputation and antimalware. Advanced adds services such as cloud sandboxing, credential-stuffing defense and threat analytics. Enterprise adds advanced bot protection, client-side security and DLP-related capabilities. Exact inclusions should be confirmed on the current ordering guide.
Can FortiWeb-VM run in public cloud?
Yes. Fortinet publishes support for AWS, Microsoft Azure, Google Cloud and Oracle Cloud, alongside several private-cloud hypervisors. Confirm the currently supported image and deployment method for the chosen platform and region.
Does FortiWeb-VM support high availability?
High availability is supported in the published virtual-machine specification. The required instance count, architecture, licensing and network design should be confirmed for the intended active/passive or active/active approach.
How much memory should be allocated?
Fortinet’s published recommended memory is 8 GB for VM01 and VM02, 16 GB for VM04, 32 GB for VM08 and 64 GB for VM16. Actual resource planning should also reflect the host platform and enabled services.
Can FortiWeb protect APIs as well as websites?
Yes. FortiWeb includes API discovery and protection functions, including schema-oriented controls for supported formats. Exact capabilities can depend on software version, policy and subscription, so the API use case should be described during sizing.
Is FortiWeb Virtual Series licensed by application count?
The current published VM specification lists application licenses as unlimited. However, machine-learning domains, performance, memory and administrative-domain requirements still affect practical sizing.
What does FourTeck need to prepare a quotation?
Share the target model if known, traffic level, number of protected domains, hosting platform, region, quantity, HA design, subscription bundle, desired term and whether configuration or migration assistance is required.
Is FortiWeb-VM available in Dubai and the UAE?
FourTeck can assist with UAE quotation and availability checks. Subscription processing, regional licensing, cloud image availability and project scheduling can vary, so current status should be confirmed for the exact VM tier and requirement.
Confirm the FortiWeb-VM tier and subscription before you buy
Send FourTeck your application traffic, hosting platform, domain count, HA requirement and security-service needs. The team can help shortlist the suitable FortiWeb Virtual Series option and prepare a UAE quotation.