FortiWeb-100F
Predictive, proactive, and adaptive towards an autonomous network

Web Application Firewall — 4x GE RJ45 ports, 4 GB RAM, 1x 64 GB SSD storage.
Web Application Firewall — 4x GE RJ45 ports, 4x GE SFP ports, 480 GB SSD storage.
Web Application Firewall — 4x GE RJ45 (2 bypass), 4x GE SFP ports, 480 GB SSD storage.
Web Application Firewall — 2x 10 GE SFP+ ports, 8x GE RJ45 bypass ports, 4x GE SFP ports, 2x GE management ports, dual AC power supplies, 2x 480 GB SSD storage.
Web Application Firewall — 4x 10 GE SFP+ ports, 4x GE RJ45 bypass ports, 4x GE SFP ports, 2x GE management ports, dual AC power supplies, 2x 480 GB SSD storage.
Web Application Firewall — 10x 10 GE SFP+ ports (2 bypass), 8x GE RJ45 bypass ports, 2x GE management ports, dual AC power supplies, 2x 960 GB SSD storage.
Web Application Firewall — 2x 40 GE bypass ports, 10x 10 GE SFP+ ports (2 bypass), 8x GE RJ45 bypass ports, 2x GE management ports, dual AC power supplies, 2x 960 GB SSD storage.
FortiWeb-VM, up to 1 vCPU supported. 64-bit OS.
FortiWeb-VM, up to 2 vCPUs supported. 64-bit OS.
FortiWeb-VM, up to 4 vCPUs supported. 64-bit OS.
FortiWeb-VM, up to 8 vCPUs supported. 64-bit OS.
FortiWeb-VM, up to 16 vCPUs supported. 64-bit OS.
FWB-VMC01 for container-based environments. Up to 25 Mbps throughput.
FWB-VMC02 for container-based environments. Up to 100 Mbps throughput.
FWB-VMC04 for container-based environments. Up to 500 Mbps throughput.
FWB-VMC08 for container-based environments. Up to 2 Gbps throughput.
FortiWeb Central Manager license key, manage up to 10 FortiWeb devices, VMware vSphere.
FortiWeb Central Manager license key, manage unlimited number of FortiWeb devices, VMware vSphere.
AC power supply for FWB-600F and FAD-420F, power cable SP-FGPCOR-XX sold separately.
AC power supply for FWB-3000F and FWB-4000F, power cable SP-FGPCOR-XX sold separately.
AC power supply for FAD-400F, FAZ-300G, FMG-200G, FWB-600E and FPX-400G, module only power cable SP‑FGPCOR‑XX sold separately
Subscription license for FortiWeb-VM (1 CPU) with Standard bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (1 CPU) with Advanced bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (1 CPU) with Enterprise bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (2 CPU) with Standard bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (2 CPU) with Advanced bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (2 CPU) with Enterprise bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (4 CPU) with Standard bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (4 CPU) with Advanced bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (4 CPU) with Enterprise bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (8 CPU) with Standard bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (8 CPU) with Advanced bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (8 CPU) with Enterprise bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (16 CPU) with Standard bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (16 CPU) with Advanced bundle included.
Our Price: Request a Quote
Subscription license for FortiWeb-VM (16 CPU) with Enterprise bundle included.
Our Price: Request a Quote
Click here to jump to more pricing!
Please Note: All Prices are Inclusive of GST
Overview:
Web Application and API Protection
FortiWeb is a web application firewall (WAF) that protects
web applications and APIs from attacks that target known
and unknown exploits and helps maintain compliance with
regulations.
Using machine learning to model each application,
FortiWeb defends applications from known vulnerabilities
and from zero-day threats. High performance physical,
virtual appliances, and containers deploy on-site or in the
public cloud to serve any size of the organization—from
small businesses to service providers, carriers, and large
enterprises.
Comprehensive Web Application Security
Using an advanced multi-layered and correlated approach, FortiWeb provides complete security for your web-based applications from the OWASP Top 10 and many other threats. FortiWeb’s first layer of defense uses traditional WAF detection engines (e.g. attack signatures, IP address reputation, protocol validation, and more) to identify and block malicious traffic, powered by intelligence from Fortinet’s industry leading security research from FortiGuard Labs. FortiWeb’s machine learning detection engine then examines traffic that passes this first layer, using a continuously updated model of your application to identify malicious anomalies and block them as well.
API Discovery and Protection
Fueling the digital transformation, APIs have become increasingly popular, providing the backbone for mobile applications, automated business-to-business operations, and ease of management across applications. However, with their popularity they also increase the attack surface with additional exposed application surfaces that organizations must secure. Fortinet’s FortiWeb web application firewall provides the right tools to address threats to APIs.
FortiWeb API Discovery and Protection uses machine learning algorithms to automatically discover APIs by continuously evaluating application traffic. Discovery is an integral role for establishing a positive security model and FortiWeb protects your critical APIs based on your profiled API inventory. FortiWeb can also integrate out-of-the-box policies together with an automatically generated positive security model policy that is based on your organization’s schema specification (OpenAPI, XML, and generic JSON are supported schemas) to protect against API exploits. FortiWeb schema validation can be integrated into the CI/CD pipeline, automatically generating an updated positive security model policy once the API is updated.
Bot Mitigation
FortiWeb protects against automated bots, web scrapers, crawlers, data harvesting, credential stuffing, and other automated attacks to protect your web assets, mobile APIs, applications, users, and sensitive data. Combining machine learning with policies such as threshold-based detection, bot deception, and biometrics-based detection with superior good bot identification, FortiWeb is able to block malicious bot attacks while reducing friction on legitimate users.
With advanced tracking techniques, FortiWeb can differentiate between humans, automated requests, and repeat offenders, track behavior over time to better identify humans from bots, and enforce CAPTCHA challenges when required. Together with FortiView, FortiWeb’s graphical analysis dashboard, organizations can quickly identify attacks and differentiate between good bots and legitimate users.
Client-Side Protection (PCI DSS 4.0 Compliance)
FortiWeb Client-Side Protection continuously detects and blocks malicious and unauthorized JavaScript running in users’ browsers, providing real-time visibility and robust security for your websites—without impacting performance. The solution defends against threats like formjacking, Magecart, and online skimming, helping to safeguard sensitive customer data.
Security teams gain detailed monitoring, activity alerts, and control over both first- and third-party scripts, streamlining incident response.
Features:
Deployment Options
- Reverse Proxy
- Inline Transparent
- True Transparent Proxy
- Offline Sniffing
- WCCP
Web Security
- AI-based Machine Learning
- Automatic profiling (white list)
- Web server and application signatures (black list)
- IP address reputation
- IP address geolocation
- HTTP RFC compliance
- Native support for HTTP/2
- WebSocket protection and signature enforcement
- Man in the Browser (MiTB) protection
- Client-Side Protection
Application Attack Protection
- OWASP Top 10
- Cross Site Scripting
- SQL Injection
- Cross Site Request Forgery
- Session Hijacking
- Built-in Vulnerability Scanner
- Third-party scanner integration (virtual patching)
- File upload scanning with AV and sandbox
Specifications:
| Feature | FortiWeb 100F | FortiWeb 400F | FortiWeb 600F |
|---|---|---|---|
| Hardware | |||
| 10/100/1000 Interfaces (RJ-45 ports) | 4 | 4 GE RJ45, 4 SFP GE | 4 GE RJ45 (2 bypass), 4 SFP GE |
| 10G BASE-SR SFP+ Ports | — | — | — |
| SSL/TLS Processing | Software | Software | Hardware |
| USB Interfaces | 2 | 2 | 2 |
| Storage | 64 GB SSD | 480 GB SSD | 480 GB SSD |
| Form Factor | Desktop | 1U | 1U |
| Trusted Platform Module (TPM) | — | — | — |
| Power Supply | Single | Single | Dual |
| System Performance | |||
| Throughput | 100 Mbps | 500 Mbps | 1 Gbps |
| Latency | <5ms | <5ms | <5ms |
| High Availability | Active/Passive, Active/Active Clustering | Active/Passive, Active/Active Clustering | Active/Passive, Active/Active Clustering |
| Application Licenses | Unlimited | Unlimited | Unlimited |
| Administrative Domains | — | 32 | 32 |
| All performance values are “up to” and vary depending on the system configuration. | |||
| Dimensions | |||
| Height x Width x Length (inches) | 8.5 x 5.98 x 1.59 | 1.73 x 17.24 x 16.53 | 1.73 x 17.24 x 16.54 |
| Height x Width x Length (mm) | 216 x 152 x 40.5 | 44 x 438 x 420 | 44 x 438 x 420 |
| Weight | 3.42 lbs (1.55 kg) | 11.91 lbs (5.4 kg) | 14.99 lbs (6.8 kg) |
| Rack Mountable | N/A | ✔ | ✔ |
| Environment | |||
| Power Required | 100–240V AC, 50–60 Hz | 100–240V AC, 50–60 Hz | 100–240V AC, 50–60 Hz |
| Maximum Current | 110V/1.2A, 220V/1.2A | 100V/1.53A, 240V/0.64A | 100V/1.66A, 240V/0.69A |
| Power Consumption (Average) | 18 W | 127.33 W | 138.74 W |
| Heat Dissipation | 74 BTU/h | 521.38 BTU/h | 568.09 BTU/h |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) | 32°F to 104°F (0°C to 40°C) | 32°F to 104°F (0°C to 40°C) |
| Storage Temperature | 32°F ~ 104°F (0°C ~ 40°C) | -13°F to 158°F (-25°C to 75°C) | -13°F to 158°F (-25°C to 75°C) |
| Forced Airflow | N/A (fanless) | Front to Back | Front to Back |
| Humidity | 10% to 85% non-condensing | 5% to 95% non-condensing | 5% to 95% non-condensing |
| Compliance | |||
| Safety Certifications | FCC Class A Part 15, RCM, VCCI, CE, UL/cUL, CB | FCC Class A Part 15, RCM, VCCI, CE, UL/CB/cUL | FCC Class A Part 15, RCM, VCCI, CE, UL/CB/cUL |
Documentation:
Download the FortiWeb-100F Data Sheet (PDF).
Pricing Notes:
- All Prices are Inclusive of GST
- Hardware plus FortiCare Premium and FortiGuard Enterprise Protection
Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Enterprise Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering, Antispam, Security Rating, Industrial Security and FortiConverter Service) plus term of contract - Hardware plus FortiCare Premium and FortiGuard SMB Protection
Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, SMB Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering , Antispam and FortiGate Cloud subscription service) plus term of contract - Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP)
Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering and Antispam Service) plus term of contract - Enterprise Protection (IPS, Advanced Malware Protection, Application Control, Web & Video Filtering, Antispam, Security Rating, IoT Detection, Industrial Security, FortiConverter Svc, and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Enterprise Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering, Antispam, Security Rating, Industrial Security and FortiConverter Service) - SMB Protection (IPS, Advanced Malware Protection, Application Control, Web & Video Filtering, Antispam, plus FortiGate Cloud subscription and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, SMB Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering, Antispam and FortiGate Cloud subscription service) - Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, Web & Video Filtering, Antispam Service, and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering and Antispam Service) - Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Advanced Threat Protection Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct Service, Application Control) - FortiCare Essential Support
FortiCare Essential Ticket Handling, Hardware Replacement, Firmware and General Upgrades, Application Control - FortiCare Premium Support
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Application Control - FortiCare Elite Support
FortiCare Premium Support with FortiCare Elite Ticket Handling. - Prices are for one year of Premium RMA support. Usual discounts can be applied.
- Annual contracts only. No multi-year SKUs are available for these services.
- Contact Fortinet Renewals team for upgrade quotations for existing FortiCare contracts.
- Pricing and product availability subject to change without notice.
