Fortinet FortiWeb Cloud WAF

Fortinet FortiWeb Cloud WAF for Cloud-Delivered Application Protection

Fortinet FortiWeb Cloud WAF is the cloud-delivered web application firewall service historically used to protect public-facing web applications and APIs without deploying a dedicated WAF appliance. Fortinet’s current ordering material places this Cloud WAF capability within FortiAppSec Cloud, so new buyers and existing FortiWeb Cloud customers should confirm the current plan, migration position, bandwidth requirement and application count before ordering.

The service may suit organisations running ecommerce sites, customer portals, SaaS applications, mobile back-end APIs, partner services or other internet-facing workloads where application-layer attacks, malicious bots, API abuse and availability risks need dedicated controls. Selection is not based on a single fixed appliance size: current plans are structured around Standard, Advanced or Enterprise capabilities, protected application seats and bandwidth seats, with some functions dependent on the chosen tier.

FourTeck can help UAE buyers review application scope, traffic levels, licensing, deployment dependencies and quotation details. Contact FourTeck to confirm current Dubai and UAE availability, the correct Fortinet commercial SKU combination and any configuration or onboarding support required for your environment.

SKU: FORTINET-FORTIWEB-CLOUD-WAF-DUBAI Category:
Cloud-delivered web and API protection

Fortinet FortiWeb Cloud WAF in Dubai, UAE

Fortinet FortiWeb Cloud WAF is the familiar name for Fortinet’s cloud-delivered web application firewall service. Current Fortinet ordering material identifies the SaaS Cloud WAF offer under FortiAppSec Cloud WAF, which brings web application and API security into a cloud-native, multi-tenant service with globally distributed WAF infrastructure. This matters to buyers because a new quotation should be prepared against the current plan and licensing structure rather than an older FortiWeb Cloud part description.

FourTeck can help you translate an existing FortiWeb Cloud requirement, renewal request or new WAF project into the correct current commercial scope, including application seats, bandwidth seats, plan level and optional services.

Before requesting a quote

Confirm four inputs first

Applications: how many web applications or API-facing services need protection?

Bandwidth: what sustained and peak traffic should be considered?

Plan: Standard, Advanced or Enterprise?

Current status: new deployment, migration or legacy FortiWeb Cloud renewal?

Request QuoteConfirm Model and License

SaaS delivery
No WAF appliance is required for the Cloud WAF service.
Current naming
FortiWeb Cloud is now represented in current ordering as FortiAppSec Cloud WAF.
Seat-based licensing
Application and bandwidth requirements are purchased together.
Plan dependent
Advanced protections and services vary by Standard, Advanced and Enterprise tiers.

Direct answer for buyers

Fortinet FortiWeb Cloud WAF is a cloud-hosted WAF service used to inspect and control HTTP and HTTPS traffic before it reaches protected web applications and APIs. It is designed for organisations that want application-layer protection without operating a dedicated physical WAF appliance. Current Fortinet materials place this service under the FortiAppSec Cloud name and offer Standard, Advanced and Enterprise plans. Before proceeding, a buyer should confirm the number of protected applications, required bandwidth, required security functions, cloud or data-centre origin design, logging and integration needs, and whether the request is for a new FortiAppSec Cloud subscription or an existing FortiWeb Cloud contract that needs migration or renewal handling.

What the service does

A web application firewall is positioned between internet users and an application origin so that requests can be inspected against application security rules before they are forwarded. Fortinet’s cloud-delivered implementation provides this function as a service rather than requiring the customer to install a WAF appliance in a rack or deploy and maintain a dedicated WAF virtual machine. The current FortiAppSec Cloud WAF service combines application security with API-focused controls, DDoS protection, delivery features and analytics according to the selected plan.

For a business buyer, the operational value is not simply that traffic is filtered. The service creates a control point for public-facing application traffic, policy enforcement, attack visibility, bot decisions, API controls and selected availability functions. Because it is cloud delivered, procurement focuses more heavily on protected application count, bandwidth, plan tier and service dependencies than on physical interfaces, rack space or appliance power.

Who should consider it

The service may fit organisations exposing customer portals, online stores, reservation engines, digital payment workflows, partner portals, web-based ERP access, mobile application APIs, SaaS platforms, public information services or other internet-facing applications. It is also relevant when the application estate spans public cloud and other hosting environments and the business prefers cloud-delivered protection rather than maintaining a WAF appliance for every environment.

It may not be the right procurement route when a project specifically requires a customer-controlled FortiWeb hardware appliance, a FortiWeb VM inside a private network, unusual inline architecture, or a fixed deployment model that cannot redirect application traffic through a cloud service. Those requirements should be evaluated against the broader FourTeck security product portfolio and current Fortinet deployment options before a bill of materials is prepared.

Business challenges the Cloud WAF approach helps address

The buying decision is usually triggered by a business problem rather than by a product name. The following challenge map explains where a cloud-delivered WAF can be relevant and what still has to be validated during design.

Application-layer attacks

Public web applications can be targeted through malformed requests, exploit attempts and other application-layer techniques that ordinary port-based filtering does not fully address. The WAF provides dedicated inspection and policy controls for HTTP and HTTPS traffic.

Rapidly changing APIs

Modern applications often expose APIs to mobile applications, partners and automation platforms. FortiAppSec Cloud plans include API protection functions, with more advanced discovery and protection capabilities depending on tier.

Automated abuse and bots

Login pages, product catalogues, forms and APIs can attract scraping, credential attacks and automated misuse. Bot protection is available across the platform, while advanced machine-learning and dedicated bot capabilities depend on plan.

Operational overhead

Some teams want WAF controls without provisioning, patching and scaling another customer-managed appliance or VM. A SaaS model moves the WAF infrastructure layer to the service while leaving policy, application onboarding and integration decisions with the customer.

Multi-environment protection

Applications may live in different cloud regions or hosting environments. A globally distributed cloud service can provide a common protection approach, although routing, regional requirements and application behaviour must still be checked.

Security alert overload

Security teams need useful context rather than isolated events. Advanced plans include additional analytics functions designed to help teams review traffic, incidents and patterns, but logging destinations, retention and SOC workflow should be confirmed during planning.

Core capabilities buyers should understand

Web application protection

Signature controls, threat intelligence, HTTP compliance, URL and parameter controls, cookie protection and related WAF functions are included in the current plan framework.

API security

Schema enforcement is part of the Cloud WAF platform, while advanced API gateway, mobile API and machine-learning discovery functions depend on plan.

DDoS protection

Current FortiAppSec Cloud plans list both network-layer and application-layer DDoS mitigation capabilities.

Bot defence

Baseline bot controls are available across plans, with machine-learning bot defence and Advanced Bot Protection available at higher tiers.

Application delivery

SSL certificate handling, CDN functions, load balancing and server health monitoring are part of the current service matrix, with additional delivery capabilities depending on tier.

Visibility and management

Attack logs, alerts, dashboards, SIEM integration, role-based access control, single sign-on and API support are listed in the current service capabilities.

Product-fit matrix

RequirementSuitable whenConfirm before ordering
Cloud-delivered WAFYou prefer SaaS protection rather than a customer-managed WAF appliance.Origin architecture, traffic routing, regional requirements and onboarding method.
Multiple public applicationsSeveral sites or APIs need a common cloud security control plane.Exact number of protected applications because application seats are part of licensing.
API protectionMobile, partner or machine-to-machine APIs are internet exposed.API formats, authentication design, discovery needs and the plan required for advanced capabilities.
Advanced bot controlsAutomated abuse, scraping or credential attacks are an important risk.Whether standard bot controls are sufficient or Advanced/Enterprise capabilities are needed.
Threat analyticsSecurity operations need richer investigation and attack context.Current plan entitlement, export requirements and SIEM workflow.
Dedicated WAF environmentThe project requires a separately provisioned WAF environment within the cloud service.Commercial availability and the separately ordered dedicated-environment subscription.

Verified product and licensing information

Fortinet’s current ordering guides are the most useful basis for a new quotation because they distinguish the cloud SaaS offer from FortiWeb VM and hardware options. The table below intentionally avoids fixed hardware specifications because Fortinet FortiWeb Cloud WAF is a service rather than a physical appliance.

BrandFortinet
Product name used by buyerFortinet FortiWeb Cloud WAF
Current Fortinet Cloud WAF nameFortiAppSec Cloud WAF; current materials describe Cloud WAF SKUs as previously FortiWeb Cloud.
Product typeCloud-native, multi-tenant SaaS web application and API protection service.
DeploymentCloud-delivered WAF with globally distributed WAF clusters; no customer WAF appliance is required for the SaaS option.
Plan optionsStandard, Advanced and Enterprise.
Bandwidth licensingCurrent ordering uses bandwidth seats; the FortiWeb ordering guide describes 25 Mbps per bandwidth seat.
Application licensingOne web application per application seat in the current seat-based model.
Plan matching ruleBandwidth and application SKUs must use the same plan; current ordering guidance does not allow mixing Standard, Advanced and Enterprise within an account.
Core WAF and API functionsSignature protection, IP and geographic intelligence, custom rules, HTTP compliance, URL/parameter/CORS controls, cookie protection, file-upload antivirus, API schema enforcement and other functions as listed by plan.
Advanced capabilitiesMachine-learning anomaly detection, advanced API functions, DAST, Threat Analytics, advanced bot functions and other features depend on plan.
DDoSLayer 3–4 and Layer 7 DDoS mitigation are listed across current plans.
Application deliverySSL certificate support, CDN, load balancing and health monitoring are listed, with additional delivery functions dependent on tier.
Management and reportingAttack logs, notifications, SIEM integration, dashboards, role-based access control, single sign-on and API support are part of the current matrix; some analytics/export functions are plan dependent.
SupportCurrent plan matrix lists 24×7 support; ordering SKUs reference FortiCare Premium Support. Confirm the exact entitlement on the quotation.
Purchase routesSubscription through FortiCloud and cloud marketplace options are documented; exact commercial route may depend on the account and project.
AvailabilityContact FourTeck for current UAE plan, licensing and commercial availability.
FourTeck page SKUFORTINET-FORTIWEB-CLOUD-WAF-DUBAI. This is a page identifier, not a Fortinet orderable part number.

Important naming and contract dependency

A buyer searching for “FortiWeb Cloud WAF” may be using a legacy product name, a previous quotation, an older contract description or an internal procurement label. Current Fortinet documentation states that FortiAppSec Cloud combines services from the former FortiWeb Cloud and that current Cloud WAF SKUs were previously FortiWeb Cloud. New pricing and ordering should therefore be checked against the present FortiAppSec Cloud structure rather than assuming an old FortiWeb Cloud SKU is still the correct item.

This also affects existing customers. Current FortiAppSec contracts are seat based, and legacy FortiWeb Cloud arrangements may need migration handling. Do not purchase a replacement subscription solely by matching an old description. Share the existing contract or marketplace subscription, application count, bandwidth requirement, required plan features and renewal date with FourTeck so the current commercial path can be reviewed.

A practical purchase and deployment journey

01

Inventory the protected services

List every production website, portal and API that should be protected. Separate independent applications from subdomains that belong to the same application architecture, and note staging or disaster-recovery services if they also require protection. Licensing and onboarding decisions depend on an accurate application inventory.

02

Measure traffic requirements

Use monitoring data rather than a guess. Capture average traffic, expected peaks, seasonal growth and any large file-transfer behaviour. Current Fortinet Cloud WAF licensing uses bandwidth seats, so a clean traffic estimate improves both sizing and commercial accuracy.

03

Choose the feature tier

Map security requirements to Standard, Advanced or Enterprise. Do not select a higher tier only because it sounds more complete; identify whether machine-learning anomaly detection, advanced API functions, DAST, advanced bot protection, automated client-side protection, GSLB or SOC services are actually required.

04

Validate the traffic path

Confirm DNS control, origin addresses, TLS certificate handling, allowed source ranges, health checks and change windows. A SaaS WAF still requires deliberate routing and origin hardening so that traffic intended to be inspected does not simply bypass the service.

05

Plan logging and operations

Decide who will receive alerts, where security events should be reviewed, whether SIEM integration is needed, and how application owners will approve policy changes. WAF value depends on policy tuning and operational ownership after initial onboarding.

06

Request the commercial combination

The quotation should reflect application seats, bandwidth seats, the same plan level across both, any SOCaaS or dedicated-environment requirement, and the intended purchase route. FourTeck can help turn these inputs into a clearer procurement request.

Capability focus: protecting web applications without owning the WAF infrastructure

The first major decision is whether the organisation wants the WAF function as a cloud service at all. FortiWeb is available in several deployment forms, including SaaS, virtual and physical options. The cloud service is different from a FortiWeb VM or appliance because the customer is not sizing CPU cores, network interfaces, rack space or redundant power supplies. Instead, the service is consumed through application and bandwidth entitlements while Fortinet operates the cloud WAF infrastructure.

For businesses with applications spread across public cloud and hosted environments, this can reduce infrastructure management responsibilities. The security team can focus on onboarding applications, defining policies, reviewing events and coordinating with application owners. However, SaaS delivery does not remove architectural responsibility. DNS changes, TLS certificate handling, origin accessibility, health checks, backend routing and bypass prevention still need to be designed. A business should also identify whether data location, regulatory policy or latency requirements impose conditions on how application traffic may be routed.

The WAF layer provides controls designed around web traffic rather than generic IP filtering. Current FortiAppSec Cloud plan information includes signature-based protection, IP and geographic intelligence, custom security rules, HTTP compliance checks, URL and parameter protection, CORS controls, cookie protection, information-leakage controls and antivirus scanning of file uploads. API schema enforcement is also listed across plans. These capabilities help establish a more application-aware boundary, but policy defaults should not be treated as a complete deployment design. Applications behave differently, and controls that are appropriate for a static public website may require different tuning for a transactional portal or complex API ecosystem.

FourTeck can help buyers distinguish the product selection question from the configuration question. Purchasing the correct plan is necessary, but a successful project also needs an accurate inventory of protected services, DNS ownership, certificate responsibility, origin details, maintenance windows, testing approach and a named team that will handle false positives or required exceptions.

Capability focus: API, bot and advanced threat controls by plan

The second major buying decision is the plan tier. Fortinet’s current Cloud WAF structure has Standard, Advanced and Enterprise levels, and the plan choice applies across the account rather than allowing a buyer to mix one application on Standard with another on Advanced. That makes requirement gathering important before purchase. If only one application needs a higher-tier capability, the effect on the wider account should be understood before a commercial decision is made.

Standard provides the core WAF and API-security baseline. Current plan documentation lists API schema enforcement, baseline bot defence and the main web protection controls. Advanced adds capabilities such as machine-learning-based anomaly detection for zero-day attack protection, advanced API functions, DAST scanning and Threat Analytics. It also includes machine-learning-based bot defence and account-takeover related features in the current feature matrix. Enterprise adds further controls including automated client-side security and Advanced Bot Protection, while also including services such as GSLB and SOCaaS that are otherwise separate or add-on items in other tiers.

The difference between “bot defence” and “Advanced Bot Protection” is commercially important. A buyer should not assume that every bot-related function is available in every tier simply because bot protection appears in general product descriptions. The same caution applies to API discovery, client-side protection, threat analytics and application-delivery functions. The correct approach is to identify the required outcome first—such as reducing automated login abuse, discovering undocumented APIs, scanning runtime applications for vulnerabilities or monitoring client-side script risk—and then match that requirement to the current plan matrix.

This is particularly relevant for ecommerce, banking, SaaS and consumer-facing portals where automated abuse may have several forms: scraping, account takeover attempts, credential stuffing, fake account creation, inventory abuse or excessive API calls. No WAF plan guarantees that every malicious action will be stopped. The platform provides security controls, but effectiveness depends on correct onboarding, policy design, traffic visibility and continued tuning as the application changes.

When preparing a FourTeck quotation request, describe the business problem rather than listing feature names alone. For example, “we need to protect three login-heavy applications from credential abuse and discover unmanaged APIs” gives more useful context than simply requesting an “advanced WAF.” That context helps determine whether Advanced or Enterprise should be evaluated and which optional services need to be included.

Capability focus: availability, traffic management and security operations

The third major area is operational resilience. A public application is not useful if legitimate users cannot reach it, so application-security projects frequently overlap with DDoS protection, health monitoring, content delivery and load distribution. Current FortiAppSec Cloud plan information lists Layer 3–4 and Layer 7 DDoS mitigation across plans, together with CDN capability, load balancing and server health monitoring. Advanced and Enterprise add further application-delivery functions, and Enterprise includes GSLB in the current plan framework.

These functions should be evaluated as part of the architecture rather than treated as automatic replacements for every existing CDN, DNS, load balancer or cloud-native service. A business may already use a cloud provider’s load balancer, a global DNS service or a separate CDN. The team should decide which component owns TLS termination, routing, health checks and failover, and whether overlapping features are desirable or unnecessarily complex. If GSLB is required, confirm whether it will be consumed within Enterprise or as the separately orderable service available for other plans.

Security operations are equally important. Current plan matrices include attack logs, alert notifications, SIEM integration, dashboards and role-based access control. Advanced plans add richer analytics capabilities. Decide in advance who will review alerts, what events should be sent to the SIEM, how long logs must be retained in external systems, how incident response will escalate to application owners, and whether the customer wants SOCaaS. In Standard and Advanced, SOCaaS is listed as an add-on; Enterprise includes it in the current plan structure.

Availability and security controls are only useful when ownership is clear. FourTeck can help include the right commercial services in the quotation, while the customer should define internal operational roles, maintenance procedures, testing approvals and incident-response contacts. Where deployment assistance is required, FourTeck service options can be discussed as a separate project scope.

Ideal business environments and use cases

Ecommerce and digital retail

Online storefronts, customer accounts, checkout workflows and product APIs are common WAF candidates. Buyers should identify bot risks, payment-related application paths, third-party scripts, peak traffic periods and API dependencies before choosing a tier.

SaaS and software platforms

SaaS providers may need to protect login pages, tenant-facing applications, API endpoints and administrative interfaces. Application count, traffic growth, automation requirements and separation between production and non-production services should be defined carefully.

Financial and customer portals

Portals handling account access, document exchange or sensitive workflows often require strict change control and strong visibility. Buyers should review authentication behaviour, bot and account-takeover risks, SIEM integration and incident handling.

Hospitality and booking services

Reservation platforms and customer-facing booking engines can experience seasonal peaks and automated traffic. Traffic sizing, global user distribution and dependency on third-party booking or payment APIs are useful inputs for WAF planning.

Education and healthcare portals

Student, learning, appointment and patient-facing services often combine authenticated users, file uploads and integrations. Security policy needs to be balanced with application functionality, privacy requirements and operational support.

Multi-cloud application estates

Organisations running applications across more than one hosting environment may prefer a common SaaS control plane. Regional traffic paths, latency, origin access and existing cloud-native security services should still be reviewed before deployment.

Integration and operational considerations

DNS and traffic steering

A cloud WAF becomes effective only when intended application traffic is directed through it. Confirm who controls public DNS, how quickly changes can be made, whether low-TTL cutover is appropriate, and what rollback method is available. The origin should also be reviewed so that direct access does not create an obvious bypass path around the WAF.

TLS certificates and HTTPS behaviour

Certificate ownership, automatic certificate options, custom certificates, TLS termination and backend encryption should be understood before onboarding. Applications that use mutual TLS, client authentication or unusual certificate chains may require higher-tier capabilities or additional configuration decisions.

Application testing and false-positive handling

WAF policies can affect legitimate requests when applications use uncommon parameters, large payloads, custom headers or complex APIs. Use a controlled rollout and a defined testing plan. Involve application owners in validation because they understand normal business transactions better than a security team reviewing traffic in isolation.

SIEM, alerting and incident ownership

Decide whether events will be reviewed only in the cloud portal or forwarded into an existing SIEM. Define escalation paths for suspicious activity, application failures and policy exceptions. If the organisation wants managed monitoring, evaluate the current SOCaaS option and its plan dependency rather than assuming monitoring is included automatically in every subscription.

Automation and infrastructure workflows

Fortinet documents Terraform integration for FortiAppSec Cloud, which can help organisations that manage application infrastructure through code. Automation should be governed carefully: credentials, role permissions, change approval and test environments are still needed. The value of automation is consistency, not the removal of review.

Legacy FortiWeb Cloud migration

Existing FortiWeb Cloud customers should identify the current marketplace or contract arrangement before changing subscriptions. Current FortiAppSec Cloud APIs and contracts differ from legacy services, and contract structures have moved to seat-based licensing. Migration planning should therefore include entitlement review, configuration dependencies, automation scripts and timing, not just a new purchase order.

Buyer questions to resolve before ordering

How many applications really need protection?

Count production web applications and APIs accurately. Do not assume one company domain means one billable application.

What traffic level should be licensed?

Use observed traffic and growth assumptions. Current licensing uses bandwidth seats and marketplace billing may also meter bandwidth.

Which plan features are mandatory?

Separate required functions from desirable ones. API discovery, advanced bot protection, DAST, Threat Analytics and client-side controls do not have identical availability across tiers.

Where are the origin servers?

Record hosting providers, regions, origin IPs or hostnames, firewall rules and any existing load balancers or CDNs.

Who controls DNS and certificates?

The deployment can stall if the security team cannot coordinate with the teams responsible for DNS, TLS certificates and application maintenance.

Is this a new service or a legacy renewal?

An old FortiWeb Cloud quotation may not map directly to the current FortiAppSec Cloud seat structure. Share contract details before requesting renewal pricing.

Procurement checklist

A useful quotation request gives the supplier enough detail to identify the correct plan and seat counts without repeated commercial revisions. Confirm the following before a purchase order is raised.

✓ Exact requirement: new FortiAppSec Cloud WAF, legacy FortiWeb Cloud migration or renewal

✓ Number of protected web applications and API services

✓ Measured average bandwidth and expected peak/growth pattern

✓ Required plan: Standard, Advanced or Enterprise

✓ Need for Threat Analytics, advanced bot controls, DAST or advanced API features

✓ Need for GSLB, SOCaaS or a dedicated WAF environment

✓ Hosting locations and origin architecture

✓ DNS ownership and planned cutover method

✓ TLS certificate and mutual-TLS requirements

✓ SIEM, log export and alerting expectations

✓ Required subscription or commercial route and billing preference

✓ Deployment, configuration, migration or knowledge-transfer scope

✓ UAE delivery/billing entity details and required quotation timeline

How FourTeck can assist with sizing and quotation

FourTeck can help buyers turn an application-security requirement into a procurement-ready request. That may include clarifying whether the buyer is asking for the current FortiAppSec Cloud WAF service or referencing the older FortiWeb Cloud name, reviewing how many applications need protection, checking the bandwidth information supplied by the customer, mapping required capabilities to a plan and identifying optional services that should appear in the quotation.

This assistance is useful when IT, procurement and application teams use different terminology. The application team may describe domains and APIs, the security team may describe WAF controls and bot risks, while procurement may hold an old SKU or previous subscription reference. Bringing these details together reduces the chance of ordering an outdated or incomplete item.

FourTeck can also discuss implementation scope where required, including onboarding coordination, DNS and certificate planning, policy configuration, testing, migration or operational handover. Service scope should be quoted separately and depends on the number of applications, application complexity, existing environment and customer responsibilities. Use the FourTeck contact page to share the technical and commercial inputs for review.

Useful information to send

• Current contract or old FortiWeb Cloud SKU, if applicable

• Application and API count

• Bandwidth estimate

• Required plan capabilities

• Hosting and DNS details

• Expected subscription start or renewal date

• Whether configuration or migration assistance is required

UAE availability and support guidance

Contact FourTeck to confirm current UAE availability for the required FortiAppSec Cloud WAF plan, application seats, bandwidth seats and any add-on or standalone services. Availability and commercial terms may depend on the chosen plan, quantity of seats, purchase route, vendor lead time, marketplace account structure and whether the request is a new subscription or migration from a legacy FortiWeb Cloud arrangement. A cloud service does not require physical appliance delivery, but the quotation, activation route and project schedule still need to be coordinated.

If installation or configuration assistance is required, include it in the request rather than assuming it is part of the subscription. Application onboarding can require DNS changes, origin configuration, certificate coordination, policy tuning, test windows and communication with application owners. FourTeck can discuss these dependencies and help prepare a scope appropriate to the UAE project.

Dubai, Abu Dhabi, Sharjah and Ajman coverage

Businesses in Dubai, Abu Dhabi, Sharjah and Ajman can contact FourTeck for Fortinet application-security quotation assistance, current Cloud WAF licensing guidance and project coordination. The requirement may come from an enterprise IT team, an ecommerce operator, a systems integrator, a software company, a hospitality group, a financial-services organisation or another business running public web applications and APIs. FourTeck can help review the commercial inputs needed for a suitable quotation and can discuss related network-security requirements through the wider Fortinet firewall solutions portfolio when application protection is part of a broader security project.

GCC Availability

FourTeck can assist organisations planning Fortinet Cloud WAF requirements across GCC markets with requirement review, current product naming, plan selection, application and bandwidth sizing, quotation coordination and deployment-scope discussion. Buyers in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain and Oman should provide the destination country, billing entity, number of applications, expected traffic, required plan, subscription timing and any configuration or migration requirement. Cloud-service availability, marketplace options, commercial terms, licensing, regional service conditions and project schedules can vary by country and account structure. For existing FortiWeb Cloud customers, migration or renewal handling may also depend on the current contract type and marketplace. FourTeck can help organise the request and, for Kuwait-related enquiries, buyers may also use the FourTeck Kuwait channel. Confirm the exact requirement before assuming that a UAE quotation or legacy SKU applies unchanged elsewhere in the GCC.

Africa Availability

FourTeck can also assist organisations evaluating cloud-delivered web application and API protection for projects in Africa. The planning discussion can cover the number of web applications and APIs, expected bandwidth, required FortiAppSec Cloud tier, optional services, migration from older FortiWeb Cloud contracts, configuration scope and operational support expectations. Availability and fulfilment can depend on the destination country, billing arrangement, license region, cloud marketplace route, application origin locations, local project conditions and vendor commercial policy. Buyers should share the destination, exact application-security requirement, preferred deployment schedule and whether remote configuration, migration guidance or other support is expected. For East Africa and wider regional enquiries, the FourTeck Africa platform can provide a regional contact path. No assumption should be made about local inventory or immediate activation until the subscription route and account requirements are confirmed.

Related FourTeck options to consider

FortiWeb hardware or VM

Consider customer-managed FortiWeb when the architecture requires an appliance or virtual WAF rather than SaaS delivery. Sizing and licensing are different from the Cloud WAF model.

FortiGate network security

A WAF protects application-layer traffic; it does not replace the wider network-security role of a next-generation firewall. Review both layers where the project covers internet edge and application security.

Application onboarding services

Configuration assistance can include planning, DNS coordination, certificate handling, policy setup, validation and handover depending on scope.

Security logging integration

If WAF events must feed a wider security-operations process, include SIEM and logging requirements during design instead of treating them as an afterthought.

Migration and renewal review

Legacy FortiWeb Cloud customers can request help checking the current contract position before moving to a current FortiAppSec Cloud subscription structure.

Why businesses contact FourTeck for this requirement

The difficult part of a Cloud WAF purchase is often not identifying the brand; it is defining the current orderable requirement. FourTeck can help clarify whether the request should be quoted as current FortiAppSec Cloud WAF, identify the plan level, assemble the application and bandwidth requirement, check whether GSLB or SOCaaS is needed, and flag migration questions for customers holding older FortiWeb Cloud subscriptions.

This approach helps procurement teams avoid buying only from an outdated SKU description and helps technical teams make sure the quotation reflects actual protected applications and traffic. FourTeck can also coordinate a separate implementation or migration discussion where the project needs assistance beyond licensing. For wider information about the company and service approach, visit About FourTeck.

What buyers are really trying to determine before choosing FortiWeb Cloud WAF

A buyer who searches for Fortinet FortiWeb Cloud WAF is often trying to answer several different questions at once: Is the old product still available? Is it the same as FortiAppSec Cloud? How is it licensed now? Can it protect APIs and bots as well as websites? How does it differ from a FortiWeb appliance or VM? What information is needed to get a reliable price? These questions are closely connected, and resolving them in the right order is more useful than simply comparing a list of features.

FortiWeb Cloud versus FortiAppSec Cloud

The most important naming point is that Fortinet’s current materials treat Cloud WAF as part of FortiAppSec Cloud and explicitly identify current Cloud WAF SKUs as previously FortiWeb Cloud. An organisation holding an older FortiWeb Cloud contract should therefore not assume the legacy SKU remains the correct renewal path. New buyers should ask for the current FortiAppSec Cloud WAF plan that matches their needs. Existing customers should share their contract or marketplace subscription so migration and renewal details can be checked before commercial action.

Cloud WAF versus FortiWeb VM or appliance

The SaaS service is chosen when the organisation wants Fortinet to operate the WAF infrastructure in the cloud. A FortiWeb VM or appliance is customer deployed and has a different sizing model based on virtual capacity or hardware performance. The cloud service instead focuses commercial sizing on application count and bandwidth. The correct option depends on architecture, operational preference, regulatory constraints and where the organisation wants the enforcement point to be managed. A request for “FortiWeb” alone is therefore too broad for a final quote.

Why application count matters

Current seat-based licensing uses application seats, with the FortiWeb ordering guide describing one web application per application seat. This makes application inventory a commercial input, not just a technical document. A company may own one public domain while operating several separate applications, APIs or services beneath it. Before asking for a quote, map the application estate in a way that the security and procurement teams both understand. If uncertain, share the architecture with FourTeck rather than choosing a seat count by assumption.

How bandwidth affects cost and sizing

Cloud WAF licensing also depends on bandwidth. Current ordering uses 25 Mbps bandwidth seats, while public cloud marketplace consumption models can meter traffic in smaller units and calculate charges from usage. Buyers should use observed monitoring data and account for seasonal peaks, planned growth and large transaction patterns. An estimate based only on the internet circuit size can be misleading because the relevant figure is the application traffic being protected. A short traffic report is often more useful for quotation preparation than a generic request for “100 Mbps WAF.”

Which plan should a business shortlist?

Start with the security outcome. Standard is the core WAF and API-security tier. Advanced is relevant when the requirement includes machine-learning anomaly detection, richer API functions, vulnerability scanning and Threat Analytics. Enterprise is the tier to examine when advanced bot protection, automated client-side security, included GSLB and included SOCaaS are important. Because the account uses one plan type for both application and bandwidth SKUs, organisations should confirm the highest-value required features before selecting the account tier.

How to prepare for onboarding

Cloud delivery removes the need to install a WAF appliance, but the application still has to be onboarded. The team should prepare origin server details, DNS control, certificate requirements, health-check expectations, backend firewall rules and a test plan. Application owners should identify sensitive workflows such as login, file upload, payment, API calls and administrative actions. This makes policy validation more efficient and helps the team distinguish legitimate unusual traffic from attack activity.

What determines the final UAE quotation?

There is no single universal price for a FortiWeb Cloud WAF requirement. The quote depends on the current FortiAppSec Cloud plan, application seats, bandwidth seats, subscription route, optional SOCaaS, GSLB or dedicated-environment requirements, and whether migration or deployment services are included. Cloud marketplaces can use consumption-based point models, while private offers and traditional subscriptions may be structured differently. For a business quotation, provide the exact workload and commercial route rather than relying on a public example price.

When a cloud WAF may not be the preferred choice

A SaaS WAF is not automatically the right answer for every application. Some organisations require traffic enforcement entirely inside a private environment, have architectures that cannot use external traffic steering, or want a WAF appliance with customer-controlled network interfaces and local placement. Others may already have a mature cloud-native WAF design they do not want to replace. In those cases, compare FortiWeb VM, hardware and existing platform controls. The goal is to select the deployment model that fits the architecture, not to force every application into the same pattern.

Questions buyers ask while building a shortlist

These decision questions are separate from the general product FAQ because they focus on choices that can change the bill of materials, migration approach or deployment plan.

Can I keep using an old FortiWeb Cloud SKU for renewal?

Do not assume so. Current Fortinet materials use FortiAppSec Cloud WAF SKUs and describe them as replacing the previous FortiWeb Cloud model. Legacy contracts may have different structures, marketplace arrangements or migration requirements. The safest approach is to provide the old SKU, contract identifier, renewal date and current protected applications so the present renewal path can be checked.

Can different applications use different FortiAppSec Cloud plans in one account?

Current ordering guidance says the plan cannot be mixed within the account: applications and bandwidth must use the same Standard, Advanced or Enterprise level. This means a higher-tier requirement on one important application can influence the account-wide plan decision. Before ordering, review which advanced capabilities are genuinely needed and whether account separation has any practical relevance to your design.

Does API protection mean I do not need an API gateway?

Not automatically. FortiAppSec Cloud includes API-security functions, and higher tiers list API gateway capabilities, but architecture roles should still be defined. An existing API gateway may handle developer onboarding, authentication, transformation, quotas or service routing that the business wants to retain. Review overlap and integration instead of removing a component simply because both products mention APIs.

How should I estimate protected bandwidth if traffic varies?

Use historical monitoring that covers normal periods and known peaks. Note campaigns, seasonal demand, software releases and large file-transfer events. Current marketplace descriptions also use measured bandwidth concepts, so traffic variability matters commercially. If data is incomplete, provide the best available monitoring window and growth expectation rather than selecting a license solely from WAN circuit capacity.

What makes a WAF migration risky?

The main risks are traffic-path changes, incomplete origin restrictions, certificate issues, application behaviour that triggers false positives, and differences between old and new policy or API structures. A migration should include test applications, rollback planning, validation of critical transactions and review of automation scripts or integrations. The commercial migration and the technical migration should be planned together.

What should procurement ask the technical team before requesting pricing?

Ask for the number of applications, expected bandwidth, required plan features, optional services, current contract details if renewing, origin architecture and expected start date. Also ask whether deployment or migration assistance is part of the requirement. These inputs let FourTeck prepare a more relevant quotation and reduce revisions caused by missing technical scope.

Frequently Asked Questions

Is Fortinet FortiWeb Cloud WAF still the current product name?

FortiWeb Cloud is the legacy and still widely recognised name, but Fortinet’s current ordering material places the Cloud WAF service under FortiAppSec Cloud WAF and describes current Cloud WAF SKUs as previously FortiWeb Cloud. New quotations should therefore be checked against current FortiAppSec Cloud plans and SKUs.

What is Fortinet FortiWeb Cloud WAF used for?

It is used to protect internet-facing web applications and APIs by filtering and monitoring HTTP and HTTPS traffic through a cloud-delivered WAF service. Current FortiAppSec Cloud plans include core web application protection, API security, bot defence, DDoS mitigation, logging and application-delivery capabilities, with advanced functions dependent on plan.

How is the current Cloud WAF licensed?

Current Fortinet ordering uses a seat-based model with both bandwidth and application SKUs. The FortiWeb ordering guide describes 25 Mbps per bandwidth seat and one web application per application seat. Buyers must select matching Standard, Advanced or Enterprise plans for both application and bandwidth requirements.

Can Standard, Advanced and Enterprise plans be mixed?

Current ordering guidance says no. An account uses one plan type, and the application and bandwidth SKUs must use the same Standard, Advanced or Enterprise level. Buyers should review required advanced features across all protected applications before selecting the account plan.

Does the service require a FortiWeb appliance?

No. The Cloud WAF option is a SaaS service and does not require the customer to deploy a FortiWeb hardware appliance for the WAF function. However, application onboarding still requires planning for DNS, TLS certificates, origin access, traffic routing, health checks and policy validation.

Which plan includes Threat Analytics and advanced bot protection?

Current Fortinet plan information places Threat Analytics in Advanced and Enterprise, while Advanced Bot Protection is an Enterprise capability. Standard includes core WAF, API and baseline bot controls. Exact feature entitlement should be confirmed against the current ordering guide when the quote is prepared.

Can FourTeck help with migration from legacy FortiWeb Cloud?

FourTeck can help review the commercial requirement and discuss migration scope. Share the existing FortiWeb Cloud contract or marketplace subscription, protected applications, bandwidth, current features and renewal timing so the current FortiAppSec Cloud option and any migration assistance can be evaluated.

What information is needed for a UAE quotation?

Provide the number of applications, expected bandwidth, required plan, optional SOCaaS or GSLB needs, existing contract details if renewing, hosting environment, preferred subscription route and whether configuration or migration support is required. FourTeck can then check current UAE commercial availability and prepare a more relevant quotation.

Is a public marketplace price the same as a FourTeck UAE quote?

No. Public cloud marketplaces may use usage-based point pricing, while private offers and traditional subscription quotations can use different commercial structures. The final UAE price depends on plan, applications, bandwidth, optional services, account route and project scope, so current quotation details should be confirmed before purchase.

Need help translating a FortiWeb Cloud requirement into the current FortiAppSec Cloud WAF plan?

Share your application count, bandwidth, required security capabilities and any existing FortiWeb Cloud contract. FourTeck can help review the current licensing structure, UAE quotation path and any configuration or migration assistance you need.

Request Product ConsultationCheck UAE Availability

Reviews

There are no reviews yet.

Be the first to review “Fortinet FortiWeb Cloud WAF”

Your email address will not be published. Required fields are marked *

Scroll to Top
Powered by Joinchat