FortiWeb Container Series

Container-based Web Application & API Protection

FortiWeb Container Series in Dubai, UAE

FortiWeb Container Series is Fortinet’s container-appliance option for organisations that need web application firewall protection around containerised applications and APIs. The current family spans FortiWeb-VMC01, VMC02, VMC04 and VMC08, with permitted throughput tiers from 25 Mbps to 3 Gbps. Selection should be based on real protected traffic, application architecture, software release, licensing and the operational features required by the security team.

What to confirm first

Protected HTTP/HTTPS throughput and growth headroom

Container platform, FortiWeb release and deployment topology

Required security services, support and subscription term

Certificate, logging, automation and ingress requirements

Family
VMC01 / VMC02 / VMC04 / VMC08
Permitted throughput
25 Mbps to 3 Gbps
Primary role
Web application and API protection
Buying method
Model, license and support dependent

Direct answer for buyers

FortiWeb Container Series is a set of Fortinet web application firewall container appliances designed to protect containerised workloads and data. It is mainly considered when applications or APIs are delivered from container infrastructure and the security team wants a FortiWeb deployment model that can sit within that operational approach. Buyers should consider the family when they need a VMC throughput tier rather than a physical appliance, but they should not choose only by the headline Mbps figure. Confirm the current FortiWeb software release, supported container environment, license and support bundle, feature availability, traffic profile, TLS processing needs, ingress design, logging requirements and the exact VMC model before placing an order.

What the FortiWeb Container Series does

The series places FortiWeb application-security functions into a container-oriented deployment model. Its job is not to replace network firewalls, endpoint controls or secure coding practices. Instead, it focuses on HTTP and HTTPS application traffic, where threats can exploit web forms, APIs, application logic, sessions, credentials and exposed services. FortiWeb as a platform provides web application and API security capabilities such as attack-signature inspection, protocol validation, reputation services, bot controls, API protection and other protection layers. Exactly which capabilities apply to a container deployment can depend on the FortiWeb version, selected services and platform support, so the implementation should be validated against the release documentation used for the project.

For a buyer, this means the container form factor is useful when application infrastructure is being operated with container tooling and the WAF needs to follow that architecture. It can be positioned close to application services, included in infrastructure planning with DevOps teams, and sized by the FortiWeb-VMC capacity tier. The business value comes from applying a dedicated application-security control without forcing every containerised service to be redesigned around a physical appliance.

Who should consider it

The FortiWeb Container Series is most relevant to organisations that already use or are moving toward containerised application infrastructure and have public-facing websites, portals, APIs, business-to-business services, mobile back ends or internal web applications that require stronger application-layer inspection. Typical stakeholders include application-security teams, platform engineers, cloud and infrastructure teams, DevOps leaders, security architects and procurement teams responsible for Fortinet licensing.

It can also be useful for service providers and larger enterprises that want more than one protected application environment and need a consistent FortiWeb policy approach. Smaller organisations can still use the lower VMC tiers when their traffic and architecture justify it. Conversely, a business that simply needs a conventional WAF in front of a small number of applications may find a FortiWeb hardware, VM or cloud-delivered option easier to operate. FourTeck can help compare the deployment choices rather than assuming the container form factor is automatically the best fit.

Business challenges the container family can address

Application attack exposure

Internet-facing applications and APIs receive traffic that a network firewall may allow because it uses permitted web ports. A WAF examines the application layer and can apply controls intended for common web attack patterns, malformed requests and suspicious behaviour.

Container architecture mismatch

Security teams may prefer not to force a traditional hardware topology into a rapidly changing container environment. A FortiWeb container appliance offers another deployment route, but network paths, persistent configuration, orchestration and version support still need careful design.

API growth

Modern applications expose more APIs to mobile apps, partners and internal services. API security therefore becomes part of the WAF discussion. Buyers should identify which endpoints are externally reachable and what schema, authentication and traffic patterns must be protected.

Operational consistency

A known FortiWeb policy and management approach can help teams that already operate Fortinet security technologies. Integration value depends on the selected release and surrounding tools, so logging, monitoring, automation and Security Fabric requirements should be specified during design.

Core capability band

Application-layer inspection

Apply FortiWeb policies to web traffic rather than relying only on network-layer controls.

API protection planning

Include exposed APIs, schema handling and CI/CD-related requirements in the security design.

Container deployment

Use the VMC form factor for container-based environments where supported by the selected release.

Capacity tiers

Choose among 25 Mbps, 100 Mbps, 500 Mbps and 3 Gbps permitted throughput tiers.

FortiWeb Container Series model-selection matrix

RequirementSuitable whenConfirm before ordering
Lower-volume application setProtected throughput stays within the VMC01 tier with reasonable operational headroom.Peak traffic, HTTPS profile, future growth, release support and required services.
Growing web/API workloadThe project requires a middle tier such as VMC02 or VMC04 rather than the smallest container appliance.Sustained and peak traffic, number of protected applications and operational policy complexity.
Higher-throughput container WAFThe design requires the VMC08 permitted throughput tier and the platform can allocate the required resources.Real traffic mix, TLS demand, infrastructure resources, scaling design and HA approach.
Kubernetes-managed ingress workflowKubernetes resources need to interact with FortiWeb through a supported FortiWeb Ingress Controller architecture.FortiWeb release, controller version, cluster design, secrets, services, ingress resources and change-management ownership.

FortiWeb Container Series verified family information

Model values are family-level permitted maximums published by Fortinet. Actual performance can vary with traffic and configuration.

BrandFortinet
Product familyFortiWeb Container Series
Product typeContainer web application firewall appliances
FortiWeb-VMC0125 Mbps permitted throughput
FortiWeb-VMC02100 Mbps permitted throughput
FortiWeb-VMC04500 Mbps permitted throughput
FortiWeb-VMC083 Gbps permitted throughput
Primary protection scopeWeb applications and APIs; exact supported features depend on release, license and deployment.
Container platform supportVersion dependent. Fortinet documentation includes Docker deployment guidance; validate the exact current supported environment for the chosen FortiWeb release.
Kubernetes integrationFortiWeb Ingress Controller is available for supported Kubernetes workflows; controller and FortiWeb compatibility should be confirmed.
LicensingModel, security service, support and subscription dependent. Request an exact bill of materials.
AvailabilityContact FourTeck for current UAE model and license availability.
Important noteDo not combine VM, hardware and container specifications as if they were identical. Confirm container-specific release notes and deployment documentation.

Configuration, licensing and compatibility dependencies

The most important purchasing rule for the FortiWeb Container Series is to avoid assuming complete feature parity with every other FortiWeb form factor. FortiWeb is offered in hardware, virtual machine, public-cloud, SaaS and container approaches, but specific functionality can vary by software release and deployment target. A feature described on the general FortiWeb product page may require a certain subscription, may apply only to particular form factors, or may have limitations in a container build. For this reason, the implementation team should identify the exact FortiWeb version and confirm its container documentation before the commercial order is finalised.

Licensing also deserves careful review. A product-family request such as “FortiWeb Container Series” is not enough for a clean purchase order. The buyer should define VMC01, VMC02, VMC04 or VMC08, then identify the required FortiCare and FortiGuard services or bundle, term length and any additional subscriptions. If the project uses Kubernetes, include the planned ingress architecture and controller version. If the application terminates TLS at FortiWeb, include certificate and key-management requirements. If logs must be sent to a SIEM, FortiAnalyzer or another monitoring platform, define the expected logging flow and retention responsibilities.

These dependencies are not reasons to avoid the container family; they are simply the details that determine whether a deployment works cleanly. FourTeck can help buyers convert the architecture into a bill of materials and quote request, while the technical team should validate the final configuration against Fortinet’s current documentation.

A practical purchase and deployment journey

01

Map the applications

List websites, portals and APIs to be protected, where they run, how users reach them and which traffic paths must pass through the WAF.

02

Measure real traffic

Collect normal and peak HTTP/HTTPS throughput, growth expectations, TLS mix and seasonal demand before choosing a VMC tier.

03

Confirm platform support

Check the selected FortiWeb release, container runtime, orchestration design, deployment guide and any current platform limitations.

04

Build the BOM

Specify the exact VMC model, bundle, support term, security subscriptions and any related management or deployment services.

05

Test and tune

Plan staging, policy validation, certificate handling, logging, application-owner testing and rollback before enforcing production traffic.

Capability focus: protecting applications without treating every request the same

A web application firewall is valuable because allowed web traffic can still contain harmful inputs. An attacker does not need to scan a blocked TCP port if a vulnerable application is already reachable over HTTPS. FortiWeb evaluates application requests using several security approaches within the broader platform, including signatures, protocol checks, reputation information and other inspection methods. The objective is to let valid customer and business traffic reach the application while detecting requests that match malicious behaviour or violate expected application rules.

For container environments, the operational point is placement. The WAF must see the traffic that needs protection. If traffic bypasses FortiWeb through another ingress path, direct service exposure or an alternate load balancer, the security policy cannot inspect that flow. Application teams therefore need to work with networking and platform teams so DNS, load balancing, service exposure, certificates and health checking all follow the intended design. This is especially important in environments where services are frequently redeployed or where multiple ingress controllers exist.

Buyers should also plan for policy tuning. A WAF is not a “deploy once and forget” control. New application functions, API paths, authentication changes, file-upload features and third-party integrations can alter normal request patterns. Operational ownership should be defined: who receives alerts, who can approve policy changes, who coordinates with developers, and how a false positive is investigated. Container deployment may make infrastructure more agile, but security governance still needs clear human responsibility.

Capability focus: sizing by protected traffic and architecture

Fortinet currently lists four container appliance tiers: VMC01 at 25 Mbps, VMC02 at 100 Mbps, VMC04 at 500 Mbps and VMC08 at 3 Gbps permitted throughput. These figures are useful for the first sizing conversation, but they should not be interpreted as guaranteed application performance in every environment. Fortinet notes that actual performance can vary depending on network traffic and system configuration. A buyer therefore needs to understand what “throughput” means in the context of the application estate rather than selecting the smallest model that appears to exceed an average traffic figure.

Peak traffic is more important than a quiet monthly average. Ecommerce campaigns, online registration deadlines, public-sector service windows, ticket releases, batch API activity or mobile-app updates can create bursts. HTTPS processing, request sizes, file uploads and security-policy depth can also change resource demand. Sizing should include headroom for these effects and for expected growth over the chosen commercial term.

The architecture may also spread traffic across multiple FortiWeb instances rather than pushing everything through one container appliance. That can support separate environments, application groups, regions or lifecycle stages, but it changes the licensing and management discussion. High availability, failover and persistence must be designed deliberately rather than assumed. FourTeck can help the procurement team compare model options while the technical team validates the target topology with Fortinet deployment guidance.

Capability focus: API and DevOps alignment

Containerised application projects often expose APIs at least as heavily as traditional web pages. Mobile applications call back-end endpoints, partner integrations exchange structured data, internal services communicate through APIs, and automated workflows rely on predictable interfaces. This makes API inventory and protection an important part of the FortiWeb conversation. The broader FortiWeb platform includes API discovery and protection functions, schema-related controls and CI/CD integration capabilities. The exact container support for these functions must be confirmed against the chosen FortiWeb release and license.

The DevOps value is not simply that FortiWeb can be “put in a container”. The bigger question is whether application delivery and security change processes can be coordinated. If a new API version is released, the WAF policy may need to understand new paths, parameters or schemas. If a service is renamed or moved, routing and backend definitions may change. If certificates are rotated automatically, the FortiWeb design must account for how keys and secrets are handled. If Kubernetes ingress resources are used, the FortiWeb Ingress Controller can form part of a supported architecture, but version compatibility and ownership should be documented.

A mature implementation treats application security as part of the delivery lifecycle. Developers do not need to manage every WAF setting, and security teams do not need to own every application decision, but the change process should connect them. This reduces the risk that application changes unexpectedly break protection or that security rules block new legitimate functions after deployment.

Ideal business environments and use cases

Digital customer portals

Customer login portals, booking systems, self-service platforms and ecommerce applications can benefit from a WAF layer when the applications run in container infrastructure. The security design should include authentication behaviour, API calls, file uploads and payment-related pages where applicable.

Microservice API platforms

Organisations using microservices may expose many API endpoints. FortiWeb can be considered at ingress points where external or cross-domain traffic enters protected services. Service-to-service traffic that never passes through the WAF requires its own controls.

Hybrid application estates

A business may operate hardware or VM FortiWeb in one environment and container applications in another. The VMC family can be evaluated when the organisation wants a FortiWeb option aligned with the container segment while maintaining clear policy and logging responsibilities.

Service-provider platforms

Hosting providers, managed platforms and larger application teams may need separate WAF capacity for multiple application groups. Tenant separation, logging, support boundaries and management responsibilities should be defined before sizing and licensing.

Integration and operational considerations

A FortiWeb Container Series deployment sits inside a wider application-delivery chain. Before implementation, map the components in front of and behind the WAF: public DNS, CDN, DDoS service, cloud or on-premises load balancers, reverse proxies, ingress controllers, API gateways, service meshes, application services, identity providers, certificate stores, logging platforms and monitoring tools. The order of these components affects which client information FortiWeb can see and which system is responsible for TLS termination, health checking and routing.

Logging should be designed before go-live. Security teams need enough information to investigate blocked requests without collecting unnecessary sensitive data. Decide where attack, event and traffic logs will be reviewed, how long they are retained, and who responds. If FortiAnalyzer, syslog or SIEM integration is required, include network reachability and log volume in planning. Operational teams should also decide whether configuration is managed through the FortiWeb interface, automation, central management or a combination supported by the deployment.

Certificates and secrets deserve the same attention. HTTPS protection may require FortiWeb to terminate or inspect encrypted traffic. The certificate lifecycle, private-key handling, renewal process and emergency replacement procedure should be documented. In Kubernetes environments, secrets may also be part of the ingress workflow. These details can affect both security and uptime, so they should not be left until the final deployment day.

Buyer questions to resolve before ordering

Which VMC tier matches peak protected traffic?

Measure the traffic that will actually pass through FortiWeb and include growth and TLS demand, not only average internet bandwidth.

Which exact FortiWeb release will be deployed?

Container support and feature behaviour can change by release. Align the commercial order with the technical version plan.

What security services are required?

Define the required bundle, FortiGuard services, FortiCare support and any optional capabilities before requesting a final quote.

How will traffic reach FortiWeb?

Document DNS, load balancers, ingress, routing and backend services so protected traffic cannot accidentally bypass the WAF.

Is Kubernetes part of the design?

If yes, confirm the FortiWeb Ingress Controller architecture, supported versions and ownership of Kubernetes resources.

Who owns ongoing policy tuning?

Application changes continue after purchase. Assign responsibility for alerts, exceptions, false positives and rule changes.

Procurement checklist for a clean FortiWeb VMC quote

✓ Exact FortiWeb-VMC01, VMC02, VMC04 or VMC08 model requirement

✓ Required quantity and whether separate environments need separate instances

✓ Expected normal and peak HTTP/HTTPS throughput

✓ Container platform, orchestration platform and target FortiWeb version

✓ Number and type of protected applications and APIs

✓ Security service bundle and subscription term

✓ FortiCare support requirement and desired term

✓ TLS certificate termination and key-handling plan

✓ Kubernetes ingress or controller requirement, if applicable

✓ Logging, FortiAnalyzer, SIEM or syslog integration requirement

✓ Installation, configuration, migration or policy-tuning scope

✓ Deployment country, target date and procurement deadline

How FourTeck can assist with sizing and quotation

FourTeck can help turn a broad request for “FortiWeb Container Series” into a more accurate commercial requirement. The first step is clarifying the architecture: the applications being protected, expected traffic, container platform, target FortiWeb release, required security services, support term and deployment location. This allows the sales and technical conversation to focus on an exact VMC tier rather than an ambiguous family name.

For procurement teams, FourTeck can help prepare a bill-of-material discussion that separates the base container appliance model from support and subscription items. For security teams, the same process helps highlight version compatibility, ingress design, certificate handling, logging and implementation scope that may need to be included in the project. Buyers who require broader Fortinet planning can review FourTeck cybersecurity products and technology services when the WAF is one part of a larger infrastructure requirement.

FourTeck does not need to assume stock, final price or lead time before the exact requirement is known. Once the model, license, term, quantity and destination are confirmed, the team can coordinate a current quotation and discuss deployment assistance where required.

UAE availability and support guidance

UAE buyers should contact FourTeck to confirm current FortiWeb Container Series availability because the commercial path can depend on the exact VMC model, subscription bundle, support term, quantity and vendor lead time. Software and license fulfilment can also be affected by regional entitlement rules and the product lifecycle. A useful quotation request should therefore include the target model, company location, required quantity, support term, security-service requirement and expected project date.

Delivery and project coordination can be discussed after the requirement is confirmed. Where installation or configuration assistance is needed, include that scope in the quotation rather than assuming it is part of the license. FourTeck can also help buyers compare a container deployment with other FortiWeb options when architecture or licensing makes another form factor more appropriate. For a direct requirement review, use the FourTeck UAE contact page.

Dubai, Abu Dhabi, Sharjah and Ajman coverage

Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for FortiWeb Container Series requirement review, model selection, license clarification and quotation coordination. The same buyer questions apply regardless of the UAE office location: which applications are being protected, where the container environment runs, which VMC tier is required, what subscriptions are needed and whether implementation services should be quoted. Project coordination can support head offices, data centres, hosted environments, development teams and organisations operating applications for customers across the Emirates. Current availability and project timing should be confirmed against the exact bill of materials rather than assumed from the product-family name.

GCC Availability

FourTeck can support GCC organisations that are evaluating FortiWeb Container Series for application and API security projects, including businesses with requirements in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain and Oman. The useful starting point is not simply the destination country; it is the complete technical and commercial requirement. Buyers should share the intended FortiWeb-VMC model or traffic profile, quantity, target container environment, required license or security-service bundle, support term, deployment location and expected timeline. FourTeck can then assist with requirement review, model-selection discussion, quotation coordination, configuration scope and regional project planning. Availability, licensing, delivery schedules, service visits and vendor lead times can vary by country, model, quantity and project conditions. No local inventory, customs result or fixed installation date should be assumed until the destination and bill of materials are confirmed. GCC buyers can also review FourTeck Kuwait regional technology support where relevant.

Africa Availability

Organisations planning containerised application security in Africa can contact FourTeck for FortiWeb model and licensing guidance, especially where the project involves web portals, APIs, cloud-hosted services or regional digital platforms. Procurement conditions differ widely by destination, so buyers should provide the country, exact VMC requirement or expected protected traffic, quantity, subscription term, container platform, preferred deployment schedule and any installation or support expectations. FourTeck can help evaluate the bill of materials, related subscriptions, configuration scope and renewal planning before a quotation is finalised. Availability and fulfilment may depend on the destination, model, quantity, license region, shipping arrangement, vendor lead time and local project conditions. FourTeck does not assume local inventory or country-wide onsite coverage without confirmation. Buyers in East Africa can use FourTeck Kenya, while wider regional inquiries can be directed through FourTeck Africa.

Related FourTeck options to evaluate

FortiWeb hardware or VM

Consider when the application environment is better served by a conventional appliance or virtual-machine topology rather than a container deployment.

Explore product options

Fortinet firewall architecture

A WAF protects application traffic; a FortiGate requirement may still exist for network segmentation, secure access and broader threat protection.

Review Fortinet firewall guidance

Installation and configuration

Plan traffic routing, certificates, policies, logging, integration, testing and handover as a defined project scope instead of treating deployment as a license-only task.

Discuss service scope

FortiWeb renewals

Existing VMC deployments may require support or security-service renewal rather than a new container appliance entitlement.

Visit FourTeck UAE

Why businesses contact FourTeck for FortiWeb VMC projects

The most practical reason to involve FourTeck is requirement clarity. FortiWeb Container Series is a family rather than a single one-size-fits-all item. The buyer needs to choose a VMC tier, define support and security-service terms, check software compatibility and decide whether configuration services belong in the purchase. A sales quote is easier to approve when those items are separated clearly.

FourTeck can help procurement teams understand which information the security or platform team must provide, and can help technical teams express their architecture in a form that purchasing can use. This includes model selection, license-term discussion, bill-of-material review, compatibility questions, quotation coordination and planning for installation or migration work. The goal is to reduce wrong-model orders and ambiguous subscription requests rather than to make unsupported claims about availability or performance.

What buyers are trying to understand before choosing a FortiWeb container appliance

The first question many buyers ask is whether a container WAF is simply the FortiWeb virtual appliance placed inside Docker. The practical answer is that Fortinet provides container appliance models in the FortiWeb portfolio and also documents FortiWeb deployment on Docker, but purchasing and implementation still need to follow the exact container model and release documentation. The VMC01, VMC02, VMC04 and VMC08 names identify different permitted throughput tiers. This is important because a search for “FortiWeb VM” can return virtual-machine licensing that is not the same commercial item as a VMC container model. When requesting a quote, state “VMC” explicitly and include the capacity tier.

Another common question is whether the smallest model is enough for a low-traffic website. Raw website visitor counts do not size a WAF accurately. What matters is protected traffic volume, request behaviour, TLS usage, file sizes, API calls, peaks and the security processing being applied. A public portal may be quiet for most of the month and then surge during registration or payment periods. An API may move relatively little data but handle a very high request rate. Buyers should therefore gather monitoring data from the current environment or estimate realistic peak behaviour with the application owner. The Fortinet-published VMC throughput tier is a ceiling for the selected version, not a promise that every workload will perform identically.

Buyers also search for “FortiWeb Docker vs Kubernetes” and often mix two different questions. Docker describes a container runtime approach, while Kubernetes orchestrates workloads and exposes services using resources such as Ingress and Service. Fortinet provides FortiWeb Docker deployment documentation and a FortiWeb Ingress Controller for supported Kubernetes environments. A Kubernetes project should therefore be designed around the exact controller and FortiWeb compatibility matrix rather than assuming that any FortiWeb container can be dropped into any cluster unchanged. The platform team should specify how ingress resources, services, secrets and external access are managed.

Licensing is another high-value search topic. Buyers may see VMC support SKUs, Standard bundles, Advanced services and other subscriptions on global reseller sites and assume the cheapest visible item is the complete product. It may not be. A support SKU can be different from the base entitlement; a one-year security-service bundle can be different from a multi-year contract; and add-on services may require a specific base bundle. The safest procurement method is to request an exact bill of materials containing the VMC model, selected bundle, term and any optional services. This also makes renewal planning easier because each entitlement can be tracked against its purpose.

A further question is how FortiWeb fits beside an API gateway, load balancer or cloud ingress service. These components can coexist, but their order matters. An API gateway may handle authentication, transformation or developer-facing API functions, while FortiWeb focuses on application-layer protection. A load balancer distributes traffic, while a WAF inspects requests according to security policy. If a CDN or DDoS service sits in front, FortiWeb may receive traffic from that service rather than directly from users. The design must preserve the client information needed for policy and logging while preventing a bypass path to the backend.

Security teams also ask whether container deployment means FortiWeb configuration becomes fully ephemeral. It should not. A production design needs persistent configuration, controlled secrets, repeatable deployment and a backup or recovery process. Container tooling can improve repeatability, but the WAF still holds operational state such as policies, certificates, backend definitions and security settings. The implementation team should understand what is stored persistently and how a failed instance is replaced without losing the intended security posture.

Finally, UAE buyers often search for price and availability before they have selected a model. Public web prices can help establish a rough budget, but FortiWeb VMC pricing varies significantly by capacity, bundle, term and region. A visible overseas price may also be tied to a region-specific entitlement. FourTeck can help prepare a UAE quotation after the model, subscription term, quantity and deployment requirement are confirmed. That approach is more useful than treating an overseas list price as a final Dubai selling price.

Questions that shape the right container WAF decision

Do I size by internet connection speed or WAF traffic?

Size by the traffic that FortiWeb will actually protect, not by the full WAN circuit. If only selected applications pass through the WAF, their combined peak traffic is the relevant starting point. Add growth headroom and consider HTTPS processing, request patterns and security policies. The VMC tier should be selected after this traffic path is mapped.

Can I use FortiWeb VMC for Kubernetes?

Fortinet provides a FortiWeb Ingress Controller that works with Kubernetes resources in supported deployments. The exact FortiWeb release, controller version and cluster design must be checked before implementation. Do not treat Kubernetes compatibility as a generic yes/no feature independent of software versions and architecture.

Is machine learning included in every container deployment?

Do not assume that every general FortiWeb feature is available identically in every container release. Fortinet’s broader FortiWeb platform uses machine-learning capabilities, but container-specific feature support should be verified in the documentation for the exact version and license you plan to deploy.

What should be included in a quotation request?

Include the VMC model or required throughput, quantity, FortiWeb version plan, container platform, support term, required security bundle, deployment country, expected start date and whether configuration assistance is needed. If the model is not yet known, share measured traffic and application details so sizing can be discussed first.

Should FortiWeb terminate TLS?

That depends on the architecture. If FortiWeb needs to inspect encrypted application traffic, the design must determine where TLS is terminated or re-encrypted and how certificates and keys are managed. Coordinate this with load balancers, ingress services, application owners and certificate-management processes.

When should I choose another FortiWeb form factor?

Choose another form factor when the application environment, operational skills, support model or cloud architecture makes hardware, VM or SaaS easier to run. The container family is valuable when it fits the application platform; it is not automatically better simply because the organisation uses containers elsewhere.

Frequently asked questions

What models are in the FortiWeb Container Series?

Fortinet currently lists FortiWeb-VMC01, FortiWeb-VMC02, FortiWeb-VMC04 and FortiWeb-VMC08 as container appliances. Their permitted throughput tiers are 25 Mbps, 100 Mbps, 500 Mbps and 3 Gbps respectively.

What is FortiWeb Container Series used for?

It is used to protect web applications and APIs in containerised environments with FortiWeb application-security controls. The exact protection features available depend on the selected FortiWeb release, license and deployment architecture.

How do I choose between VMC01, VMC02, VMC04 and VMC08?

Start with measured protected traffic and peak demand, then consider growth, TLS usage, security-policy depth and architecture. Do not choose only from average bandwidth. FourTeck can help map requirements to the appropriate VMC tier before quotation.

Does FortiWeb Container Series work with Docker?

Fortinet publishes FortiWeb deployment documentation for Docker. The exact Docker and operating-system versions supported depend on the FortiWeb release, so check the current deployment guide before implementation.

Can FortiWeb integrate with Kubernetes ingress?

Fortinet provides a FortiWeb Ingress Controller that can manage FortiWeb objects from Kubernetes in supported environments. Controller version, FortiWeb version and cluster architecture should be confirmed as part of the project design.

Are security services and support included automatically?

Do not assume every service is included. FortiWeb VMC commercial options can include different support and security-service bundles and terms. Request an exact bill of materials showing the model, subscription and support items.

Is FortiWeb VMC the same as FortiWeb VM?

They are related FortiWeb form factors but should not be treated as the same product for ordering. VMC identifies the container-appliance family, while VM identifies virtual-machine models. Use the exact model and SKU family in procurement documents.

Is FortiWeb Container Series available in Dubai?

FourTeck can assist Dubai and UAE buyers with current availability checks, model selection and quotation. Final availability depends on the required VMC model, license, term, quantity and vendor lead time.

What information does FourTeck need for a quote?

Share the intended VMC model or protected traffic, quantity, container platform, target FortiWeb version, security-service requirement, support term, deployment location and whether installation or configuration support is required.

Need help selecting the right FortiWeb VMC tier?

Share your protected traffic estimate, container platform, application count, required services and deployment location. FourTeck can help prepare a model and licensing discussion before a UAE quotation is issued.

Scroll to Top
Powered by Joinchat