Highlights
- High performance
- Included vulnerability scanner
- Included Layer 7 server load balancing
- Behavioral attack detection
- FortiGuard IP reputation, attack signatures, and antivirus
- Correlated, multi-layer threat scanning
- User scoring and session tracking
- Simplified deployment with FortiGate integration
- Transparent user validation for botnet protection
- Out-of-the-box protection against automated attacks
- Network and application layer DoS protection
- Authentication, site publishing and SSO
Marketing description
Using an advanced multi-layered and correlated approach, FortiWeb provides complete security for your external and internal web-based applications. Using IP reputation services, botnets and other malicious sources are automatically screened out before they can do any damage. DoS detection and prevention keeps your applications safe from being overloaded by Layer 7 DoS attacks.
FortiWeb checks that the request hasn't been manipulated using HTTP RFC validation. Requests are checked against FortiWeb's signatures to compare them against known attack types to make sure they're clean. Any files, attachments or code are scrubbed with FortiWeb's built-in antivirus and antimalware services. FortiWeb's auto-learning behavioral detection engine reviews.
Product Features
- Included vulnerability scanning
Only FortiWeb includes a web application vulnerability scanner in every appliance at no extra cost to help you meet PCI DSS compliance. FortiWeb's vulnerability scanning dives deep into all application elements and provides in-depth results of potential weaknesses in your applications. Vulnerability scanning is always up to date with regular updates from FortiGuard Labs. - Deep integration with FortiGate and FortiSandbox
As the threat landscape evolves, many different threats require a multi-pronged approach for protecting web-based applications. Advanced persistent threats that target users can take many different forms than traditional single vector attack types and can evade protections offered only by a single device. FortiWeb's integration with FortiGate and FortiSandbox extend basic WAF protections through synchronization and sharing of threat information to both deeply scan suspicious files and share infected internal sources. - Blazing-fast SSL offloading
FortiWeb is able to process up to tens of thousands of web transactions by providing hardware accelerated SSL offloading in most models. With near real-time decryption and encryption using ASIC-based chipsets, FortiWeb can easily detect threats that target secure applications. - Application delivery and authentication
FortiWeb provides advanced Layer 7 load balancing and authentication offload services. FortiWeb can easily expand your applications across multiple servers using intelligent, application-aware Layer 7 load balancing and can be combined with SSL offloading for load balancing secure application traffic. Using HTTP compression, FortiWeb can also improve bandwidth utilization and user response times for content-rich applications. Authentication offloading integrates with many authentication services. Using these authentication services, you can easily publish websites and use Single Sign On (SSO) for any web application. Finally, FortiWeb can improve application response times by caching often-used content to serve it to users faster than having to request the same information each time it is needed.