Current Analysis
Markets We Cover Solutions & Tools Who Can Benefit What is Competitive Response Custom Solutions
Competitive Intelligence Highlights
Enterprise Security
Client access
Overview
Intelligence Report Summaries
Company Report Summaries
Product Report Summaries
Complimentary Competitive Intelligence
Business Technology
and Software
MARKET SEGMENTS
Application Platforms
Collaboration Platforms
Data Center Technology
Enterprise Mobility Technology
Enterprise Networking
Enterprise Security
Unified Communications
and Contact Center
   




Complimentary
Competitive Intelligence
INTELLIGENCE HIGHLIGHTS
Business Network and IT Services
Business Technology and Software
Consumer Services and Devices
Service Provider Infrastructure
  Most recent >>
MORE COMPLIMENTARY COMPETITIVE INTELLIGENCE
Complimentary Advisory Reports
CurrentCast Podcasts
Webinar Replays
 


Fortinet Fortifies Web Application Firewall with Enhanced Usability, DoS Protection


| Aug 3, 2011 | Enterprise Security
| Analyst: Paula Musich

Event Summary

August 1, 2011 -- Fortinet continued to bolster its fledgling FortiWeb Web application firewall in the latest release of its software, which adds a range of usability enhancements as well as greater protection against automated denial of service attacks, coupled with new compression and server load balancing functions.

Quick Take

Analytical Summary

• Current Perspective: Moderate on the new FortiWeb MR3 release and appliance option, because while they expand the product line’s functionality and deployment options, they represent small steps in making Fortinet’s WAF line more competitive against well-entrenched market leaders.

• Vendor Importance: Moderate to Fortinet, which views Web application firewalls (WAFs) as a growth opportunity for the company, because the enhancements create synergies between its WAF and its FortiGate flagship UTM appliance line that can help it increase its business with existing customers. FortiWeb, however, still has a lot of catching up to do with incumbent players in the market.

• Market Impact: Low on the Web application firewall market segment, because the enhancements and new deployment option represent backfilling of a fairly new product line from a vendor that has not yet made its mark in the long-simmering but not yet full-blown WAF market.


CLIENTS ONLY

Current Perspective

Competitive Strengths and Weaknesses

Response & Recommendations

Buyer Actions

Analytical Perspective

| Client access - Full report in Enterprise Security | More information

Top

Top


Current Analysis Offices
Washington, D.C. +1 703 404 9200, Toll free 877 787 8947
Paris, France +33 (0) 1 41 14 83 15
© 2012 Current Analysis Inc. All rights reserved. | Privacy Policy
Follow Current Analysis


Fortinet Strengthens Web Application Protection with Feature-Rich Updates to its Web Application Firewall Operating System and a New Appliance

FortiWeb 4.0 MR3 First and Only Web Application Firewall to Integrate Web Vulnerability Scanner and Application Delivery Capabilities in Single Appliance

SUNNYVALE, Calif., August 1, 2011 - Fortinet® (NASDAQ: FTNT) - a leading network security provider and the worldwide leader of unified threat management (UTM) solutions - today announced a major new release of its FortiWeb™ Web application firewall (WAF) family for enterprises, application service, software as a service (SaaS) and managed security service providers (MSSPs). Fortinet's Web application firewall appliances are the industry's first and only systems to integrate a Web vulnerability scanner and advanced application load balancing features in a single device to significantly reduce deployment times and resource utilization while improving application performance.

In addition to the software updates, Fortinet is also introducing the FortiWeb-3000CFsx appliance, which now provides large enterprises, application service and cloud-based service providers with enhanced performance through its fiber fail open interface.

As an integrated WAF and Web vulnerability scanner, FortiWeb 4.0 MR3 is ideal for organizations subject to Payment Card Industry Data Security Standards (PCI-DSS) 6.6, data breach notification requirements such as California State Assembly Bill 1386 or HIPAA compliance. For customers in need of assistance in protecting critical Web applications from attacks such as SQL Injection and Cross-Site Scripting, FortiWeb appliances leverage the built-in Web vulnerability scanner to proactively identify and guard against potential data loss from Open Web Application Security Program (OWASP) Top 10 attack profiles. In addition, as part of this release, FortiWeb 4.0 MR3 features advanced data compression capabilities to improve bandwidth utilization and user response times, as well as the overall performance of application delivery.

New FortiWeb 4.0 MR3 Capabilities

FortiWeb 4.0 MR3 features a wide range of new capabilities that span security and configuration, logging and reporting and ease-of-use, including:
• A new denial of service (DoS) protection scheme provides network and application layer DoS policies. This enables FortiWeb appliances to analyze requests originating from individual users to determine whether they are authentic or masquerading as automated attacks
• A new Period Blocking feature enhances organizational protection by enabling administrators to block users for specified periods of time rather than denying access on the basis of a particular connection
• Advanced compression has also been added to allow for more efficient bandwidth utilization and improved user response time by compressing data retrieval from servers
• New load balancing enhancements provide content-based "health checks" and offer additional alerts in the event of a server failure. For added protection when logging into FortiWeb devices, Radius/LDAP authentication is supported. Plus, access to FortiGuard updates - providing up-to-the-minute information on breaking threats, vulnerabilities and security research - are downloadable via proxy.

For improved logging and reporting, FortiWeb is now fully integrated with Fortinet's FortiAnalyzer™ to provide a simplified means of centrally managing all logs and reports from multiple FortiWeb devices. Providing a new analytics interface, FortiWeb appliances now feature tools to help customers understand Web application usage using different vectors such as number of requests, data transferred and attack types all mapped to their geographic location. New alert enhancements are also included, enabling security administrators to receive email and alert notifications for a variety of conditions such as low system resources, server health issues and session limitations.

The FortiWeb family also features an updated and simplified user interface that emulates the FortiGate&™ consolidated security appliances from Fortinet. As a result, system configuration is greatly simplified and key usability features such as error page customization are supported.

"Our worldwide customer base has made it clear that Web application protection is a very high priority," said Michael Xie, founder, CTO and vice president of engineering at Fortinet. "At the same time, given IT and security resource constraints, we are hearing loud and clear the need to consolidate key functionality into a single, multi-purpose appliance that can be managed on a unified basis for deployment simplicity, optimal data protection and maximum resource utilization. The introduction of our new FortiWeb product family underscores our commitment to meeting global customer demands."

Availability

FortiWeb 4.0 MR3 and FortiWeb-3000CFsx appliance are available now.