Listing Thumbnail

    Fortinet FortiGate Next-Generation Firewall

     Info
    Deployed on AWS
    Free Trial
    Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
    4.2

    Overview

    Play video

    FortiGate-VM on AWS delivers next-generation firewall and VPN/SD-WAN capabilities for organizations of all sizes. It enables broad network protection and automated security management for consistent enforcement and visibility across your AWS VPCs and hybrid cloud infrastructure. FortiGate natively integrates with AWS Gateway Load Balancer, AWS Transit Gateway and other AWS security services to simplify and deliver enterprise-class security for applications and workloads running on AWS.

    FortiGate-VM reduces complexity by combining secure connectivity with advanced threat protection capabilities such as powerful intrusion prevention (IPS), malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services. It offers a management console that provides comprehensive network automation and unified visibility across multi-cloud environments.

    FortiGate-VM, in concert with other elements of the Fortinet Security Fabric, enables common deployment scenarios such as cloud security services hub, secure remote access, container security, web application security, and critical workload protection.

    Visit the FortiGate-VM on AWS Community Resource Hub to find onboarding, deployment, and technical information and join in discussions: https://community.fortinet.com/t5/FortiGate-VM-on-AWS/gh-p/fortigate-vm-on-aws 

    Please contact awssales@fortinet.com  with any questions.

    Highlights

    • FortiGate offers protection from a broad array of threats, with support for all of the security and networking services offered by the FortiOS operating system.
    • Delivers complete content and network protection by combining stateful inspection with a comprehensive suite of powerful security features to meet PCI DSS compliance.
    • IPS technology protects against current and emerging network-level threats. In addition to signature-based threat detection, IPS performs anomaly-based detection which alerts users to any traffic that matches attack behavior profiles.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 7.0.19

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Fortinet FortiGate Next-Generation Firewall

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (64)

     Info
    Dimension
    Cost/hour
    c5n.xlarge
    Recommended
    $1.02
    c7i.xlarge
    $1.02
    c7i.2xlarge
    $1.60
    c5n.18xlarge
    $5.16
    c6i.2xlarge
    $1.60
    c6i.24xlarge
    $6.19
    c7i.4xlarge
    $3.29
    c4.8xlarge
    $4.10
    c4.large
    $0.88
    c6in.16xlarge
    $5.16

    Vendor refund policy

    You may terminate the instance at anytime to stop incurring charges.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443 ) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.

    After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiGate-VM. Connect to the secured Web UI via the public DNS address: https:// <public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiGate-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortigate-public-cloud/7.0.0/aws-administration-guide/ 

    Support

    Vendor support

    This product is intended for On-Demand subscription. Please contact Customer Support with the following information instead of trying to register in FortiGate management GUI:

    1. The serial number of your FortiGate instance
    2. The email ID of your Fortinet account. If you do not have an account yet, please sign using the link below

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure, Security
    Top
    10
    In Log Analysis, Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Intrusion Prevention System
    IPS technology with signature-based and anomaly-based detection to protect against current and emerging network-level threats and attack behavior profiles
    Threat Protection Capabilities
    Advanced threat protection including intrusion prevention, malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services
    AWS Native Integration
    Native integration with AWS Gateway Load Balancer, AWS Transit Gateway, and other AWS security services for VPC and hybrid cloud infrastructure protection
    Stateful Inspection and Content Filtering
    Stateful inspection combined with comprehensive security features including content and network protection to meet PCI DSS compliance requirements
    Unified Management and Visibility
    Management console providing comprehensive network automation and unified visibility across multi-cloud environments
    Advanced Threat Prevention Capabilities
    Firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-Bot protection against known and unknown threats.
    Network Traffic Inspection and Control
    Inspects and secures encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
    Unified Security Management
    Centralized management via Check Point CloudGuard Security Management Server enabling consistent policy, log, and report management across AWS, hybrid, and on-premises environments.
    Infrastructure-as-Code Integration
    Integrates with Terraform and Ansible for policy automation and cloud-native scaling with dynamic adaptation of security policies based on real-time cloud metadata.
    AWS Service Integration
    Supports Gateway Load Balancer, AWS Security Hub, VPC Ingress Routing, AWS Traffic Mirroring, AWS Transit Gateway, AWS Outposts, and Amazon Macie with deployment options including auto-scaling groups and multi-AZ redundancy.
    Traffic Identification and Classification
    Powerful traffic identification technology for complete visibility and control over network traffic
    Malware Prevention
    Malware prevention capabilities to protect applications and data from known and unknown attacks
    Dynamic Policy Management
    Dynamically updated whitelisting and segmentation policies based on AWS tags for reduced attack surface
    High-Performance Processing
    DPDK support on C5, C5n, M5, and M5n instances running on AWS Nitro System for efficient traffic processing
    Cloud-Native Integration
    AWS Auto Scaling, ELB integration, Transit VPC with AWS Transit Gateway, and Gateway Load Balancer support for large-scale deployments

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    276 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    50%
    46%
    3%
    0%
    2%
    44 AWS reviews
    |
    232 external reviews
    External reviews are from G2  and PeerSpot .
    Hassan Wali Khan

    Comprehensive security has simplified multi-site deployments and protected remote users

    Reviewed on Feb 04, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have worked on multiple products including Fortinet FortiGate  VM, Fortinet FortiGate  firewalls of different models, FortiSwitch, FortiAP , FortiADC , FortiWeb, FortiAuthenticator , and some other products as well.

    I have been working on Fortinet FortiGate and Fortinet FortiGate VM for around five or six years. I have deployed it as a perimeter firewall, as a data center firewall, and as a campus firewall in many banking sectors, commercial sectors, and oil and gas sectors. Most of my clients have deployed Fortinet FortiGate firewall on-premises to protect their services.

    What is most valuable?

    The ease of use and the user-friendly interface are the beauty of this firewall. The UI itself and the documentation are completely available on the internet. The UI is very easy, and you can easily understand the implementation. The product itself has very strong deep features and security features including IPS and malware protection to prevent and save against cyber attacks.

    I have very good hands-on experience and very good deployment experience with Fortinet FortiGate SD-WAN. Fortinet FortiGate SD-WAN allows you to use multiple internets and multiple interfaces separately to load balance your internet and to load balance your services between multiple service providers. This is a very good feature in this firewall that you cannot get as a free default feature in other brands.

    The network performance after enabling SD-WAN is very smooth and very efficient. I recently deployed this in forty commercial sector sites with stores that previously had MPLS circuits. With the MPLS circuit, they had a very high cost for private connectivity between sites and branches. After deploying SD-WAN, the operational cost was cut down around fifty to sixty percent because of this implementation. All MPLS costing was wiped out from their IT budget and is now dependent on internet circuits, which are normally standard internet connections.

    SASE  is a very good feature. For example, I recently deployed this for a customer with users in remote locations. The issue was that they wanted users to remain connected and keep monitoring systems after office hours with no malware installed on the laptop while staying protected. The use case of SASE  involved implementing the POP itself on the cloud. The users, whether remotely at home or anywhere in the world, are connected to and keep connected with POP. They access the internet securely with secure company policies as defined by IT. They are not allowed to go directly to the internet without IT policies as defined on SASE POP. There is very good integration from SASE to Fortinet FortiGate firewall to access private access.

    What needs improvement?

    For improving sectors, they need to focus on technical support and work on the technical part. Although it is good, they need to onboard these things and improve the technical part of the support factor. Although it is good, it needs much more improvement to get more business and a bigger footprint in the market. Second, AI in the market and malware detection exist. Fortinet FortiGate already has these features in the Fortinet FortiGate sandbox features with built-in AI features. I prefer that they work on more features that they can provide in Fortinet FortiGate firewall.

    I would rate this product ten out of ten. For example, when comparing it with Palo Alto and Fortinet FortiGate, I can provide a very good point. In Palo Alto, some features must be purchased separately. In Fortinet FortiGate, it comes with the Wi-Fi controller built-in. Features that you need to buy a separate license for in Palo Alto do not require additional licenses in Fortinet FortiGate as they are built as complimentary features in this firewall.

    What do I think about the stability of the solution?

    The network performance after enabling SD-WAN is very smooth and very efficient.

    What do I think about the scalability of the solution?

    Scalability is the same, and I would rate it ten out of ten.

    How are customer service and support?

    Technical support can be marked as ten out of eight. There is some lag, but you can find documentation and all things over the internet. They can provide support, and I would rate it eight point five to nine.

    How would you rate customer service and support?

    Positive

    What about the implementation team?

    My technical team are all technically expert in deployment of Fortinet FortiGate firewall.

    My team has around five or six people who are all technically sound in Fortinet FortiGate firewalls.

    Which other solutions did I evaluate?

    If we are talking about Check Point, Cisco, and Palo Alto, these are the top-tier firewalls and top-tier vendors for providing firewalls. Following the Gartner report, Palo Alto and Fortinet are at the top in the Gartner report. Because of that, Fortinet FortiGate firewall itself does not require management centers as required in Cisco and Check Point. Fortinet FortiGate firewall cannot be managed by a management center. In Fortinet FortiGate case, there is no requirement for these prerequisites to configure or implement Fortinet FortiGate firewall without a management center. We can deploy Fortinet FortiGate firewall without any management center. It is a very web-based firewall and you can access the firewall GUI from the website, and we can easily deploy it without any management center. In Check Point or Cisco cases, a management center is required. In Cisco case, the Firepower Management Center is required to get the advanced features. But in Fortinet case, it does not require these things. This is a very beauty of this firewall.

    I suggest buying Fortinet instead of buying Palo Alto, Cisco, or Check Point. I will definitely recommend Fortinet.

    What other advice do I have?

    Fortinet FortiGate has different models of firewalls which are high capacity and high variant firewalls that you can deploy as data center firewalls to protect your data centers, your server farms, and your services which are hosted inside a data center.

    Fortinet FortiGate has embedded services, these FortiGuard services which have machine learning-based and artificial intelligence-based malware analysis. These services analyze malwares and next-generation malwares that are not easily identified by signature-based detection. They have the capability to analyze malware by AI-based methods and can identify zero-day attacks. Before they exploit as a zero-day, they prevent this signature and stop this attack to prevent that this is an attack. Those services are hosted in my data centers, web applications, storage, and SaaS. All are protected by those cyber attacks.

    Regarding pricing, we cannot compare it right now because pricing matters based on business size and the business deal. We cannot say whether it is high or low. Sometimes we can easily compete with any brand, and in some cases we cannot compete. For example, if we have a big deal, we can get good discounts from Fortinet team. In some cases, the deal is not big, so we cannot get enough good discount. Deployment from FortiSASE  to your Fortinet FortiGate firewall over SD-WAN is very easy. Fortinet gives you multiple connections from SASE POP to your Fortinet FortiGate firewall. They have fully redundant connections on SASE POP if you have the same redundant connections with ISP connection on your Fortinet FortiGate firewalls. They have the secure SPX tunnel from FortiSASE  to Fortinet FortiGate firewall. You can easily access from Fortinet FortiGate firewall to SASE applications and SASE users who are connected on SASE POP can access local services from SASE POP to Fortinet FortiGate and access the local services.

    My overall rating for this product is nine out of ten.

    Mattia De Lillo

    Unified security fabric has enabled centralized control and has simplified multi-site protection

    Reviewed on Dec 09, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I mainly use Fortinet FortiGate  to implement it as a perimetral firewall solution because Fortinet FortiGate  are next-generation firewalls. I use it to protect internal network customers and configure remote access, firewall policies, internal access websites, web filtering solutions, IPS, and IDS configurations.

    I implemented it approximately one year ago in an Italian manufacturer producer. My perspective on the effectiveness of the unified SASE  in providing consistent security policies across multiple locations is that it is very similar to Fortinet FortiGate, so if you know how to manage Fortinet FortiGate firewalls, it is easier and very easy to implement and configure FortiSASE .

    For Fortinet FortiGate, it is very easy because it is very near to zero-touch provisioning. You need to install the box and if we speak about hardware appliances, you just need to install the boxes on the infrastructure and connect the cables to connect Fortinet FortiGate firewalls to the internet routers or MPLS routers, and configure basically the main IP address to have the connectivity. Next, you configure policy firewalls and it is very easy and very fast.

    You can implement Fortinet FortiGate for small, medium, and large enterprise because it is very suitable for small and medium enterprise. For one to five or six firewalls on different branches or different sites, you can manage it manually and independently. But if you need to scale or have a large enterprise deployment, you can manage all Fortinet FortiGates directly in one panel with the FortiManager solution. There is a dedicated orchestrator delivered by Fortinet in hardware or VM solution, and with FortiManager you can manage all Fortinet FortiGates in one platform. For example, two years ago, I used to manage around 500 Fortinet FortiGates with FortiManager. It is very scalable with the correct solution and the other things you need to manage large deployments.

    What is most valuable?

    What I appreciate the most about Fortinet FortiGate is that it has a very large integration using Fabric , which they call Fabric  Connectors. With Fortinet FortiGate firewalls, you can manage not only the perimetral firewalls but also all the internal infrastructure. For example, you can connect access points of Fortinet for wireless and Wi-Fi and manage them directly on Fortinet FortiGate. The same applies for switches and other Fortinet appliances that can be managed directly from one single dashboard.

    What needs improvement?

    Fortinet has developed the firmware for Fortinet FortiGate extensively. They change the operating system continuously and very often. Sometimes they introduce many features or new features or change the commands or the method you need to use to implement something or some configuration. The fact is if you develop always or very often the firmware, you need to study every release to see if there is a new feature or something changed. Sometimes it is difficult to remain aligned with the new firmware and the features.

    You need to maintain alignment with Fortinet FortiGate. For example, in Europe, we have many policies and regulations, so you need to check, tune, and configure your firewall in the correct manner and maintain alignment with the policy of the European Union. You need to always check, improve, and maintain the firmware of Fortinet FortiGate up to date.

    For how long have I used the solution?

    I have been using Fortinet FortiGate for seven to eight years.

    What do I think about the stability of the solution?

    Sometimes I experience stability issues, but sometimes they are related to hardware not functioning properly or related to a software bug. Sometimes I have encountered this type of situation using Fortinet FortiGate. But in those specific cases, I opened a ticket and worked directly with Fortinet to resolve the issue for the customer.

    How are customer service and support?

    I have worked with the technical assistance of Fortinet for my seven to eight years of career with Fortinet, and I have opened tickets with different departments of the TAC. For example, the FortiSASE  team is very effective. If you open a ticket, you have very good engineers to interact with, and they help in a correct manner. The flow is very clear to understand and resolve the issue. The only problem I have encountered in the last years with Fortinet is that if you open a support ticket for the main solution of Fortinet, for example, Fortinet FortiGate, FortiManager, or FortiAnalyzer, the support is not delivered directly from Fortinet but from partners of Fortinet. If you need to speak directly with the main core solution of Fortinet and you open a ticket, initially you are followed by a partner of Fortinet. But if you escalate to a more specific support, next you can go through a real Fortinet engineer. But sometimes this step extends the duration of the ticket and the analysis. I would give a score of 7.5 to 8 for the support of Fortinet FortiGate.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The first time that I deployed Fortinet FortiGate depends on the size of the customer. For a small to medium customer, I think three days for the initial setup and to configure some firewall rules is appropriate.

    What about the implementation team?

    If you are a junior network engineer, you need to be followed by a middle or senior engineer in the backend that helps the junior to implement and test the solution. But for a middle or senior engineer, one person is adequate for deploying Fortinet FortiGate.

    What's my experience with pricing, setup cost, and licensing?

    I do not follow the finance perspective directly, but what I know about Fortinet FortiGate pricing is that it is very affordable compared to, for example, Palo Alto Networks. I have observed that some people see and speak about the price of the Fortinet solution as very convenient.

    What other advice do I have?

    I am a system integrator in Italy. Previously, until three months ago, I worked for one of the main partners in Italy called Maticmind SPA. Now I work for another system integrator, and we are a lower partnership, but we manage and install Fortinet FortiGate appliances for our customers. My overall review rating for this product is 8 out of 10.

    Dhiren

    Centralized policies have simplified branch security while low-cost deployment protects SMEs

    Reviewed on Dec 08, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Fortinet FortiGate  is commonly used by many customers in my region requiring a low-cost and better solution. Fortinet offers antivirus, next-generation antivirus feeds, DLP , application control, URL filtering, and IPsec VPN. These are the common use cases that many customers use, including IPsec, SSL VPN , URL filtering, DNS filtering, video filtering, and application filtering.

    What is most valuable?

    A useful feature of Fortinet FortiGate  is its firewall capability because when I create and implement a rule, it is simple to execute. I just need to select the incoming interface, outgoing interface, and apply the source and destination, and that is all. This is the simplest way to implement the policy, and I can easily create a simple rule in this manner, which I consider one of the best features in Fortinet FortiGate.

    When considering the effectiveness of Fortinet Unified SASE  in providing consistent security policies across multiple locations, I find there is a very good positive response from many customers and from my side as well, as it provides centralized, verified policy creation. For many locations, I can create a simple policy from a centralized location without any difficulty, simply by putting one Fortinet FortiGate in the branch and creating a central policy from my head office.

    What needs improvement?

    I would like to improve the application filter aspect of Fortinet FortiGate, similar to other solutions that offer a simple click to select categories. If I do not want to block an entire category, there should be a provision to just enter the website or application, which I believe would be a beneficial improvement.

    Regarding how stable and reliable Fortinet FortiGate is, I find it reliable as far as the rule implementation is concerned, and I can rely on the simple way of creating the rule. However, one feature that I cannot rely on is the application filter, which requires tedious steps compared to other solutions like Check Point and Palo Alto, where creating the application filter rule is simpler. In Fortinet FortiGate, I need to create and edit the profile and add websites according to my list, making it a bit cumbersome.

    For how long have I used the solution?

    For around two years I have been working with Fortinet FortiGate as a partner, and I have deployed the Fortinet FortiGate firewall at more than twelve to thirteen customer locations.

    What do I think about the stability of the solution?

    In general, I think that Fortinet FortiGate is mostly used by small to medium enterprises, as it offers a low-budget option for security. Fortinet is the best choice for small enterprises because it provides security as per their requirement and comes under their budget, making the pricing very acceptable for medium-level and small-level enterprise customers.

    What do I think about the scalability of the solution?

    My experience with the initial setup and deployment of Fortinet FortiGate is that it is very easy, as I just need to open the box and power on the appliance. I can register the appliance on a portal from the firmware, and within half a day, I can make Fortinet FortiGate live in any office setup with a simple policy.

    How are customer service and support?

    When rating the technical support from Fortinet, I can say that I am personally not happy with it, so I would rate it at a six out of ten.

    My frustrations with the technical support come from the need to log a ticket for issues with Fortinet firewalls and FortiSwitches, as I have to create separate tickets for each, which increases my workload and delays issue resolution since I must manage multiple tickets for the same problem.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I have integrated SD-WAN capabilities with Fortinet FortiGate when multiple customers have two ISPs, as it provides ISP redundancy failover with simple configuration. I have integrated with SD-WAN as well.

    Which other solutions did I evaluate?

    Comparing Fortinet FortiGate with similar tools in the firewall area, I find that Fortinet FortiGate does better in pricing for small to medium businesses, as they offer a good deal compared to other OEMs.

    What other advice do I have?

    The last time I worked with Fortinet FortiGate was two to three days ago when I assisted a customer in migrating from Check Point to Fortinet.

    I have not worked on a Fortinet FortiGate data center solution currently, as I have mostly deployed for medium branches and small offices.

    These are all the improvements that I would like to suggest for Fortinet FortiGate.

    My customers usually prefer deployment on-premises for Fortinet FortiGate.

    My experience with integrating Fortinet FortiGate with third-party tools involves LDAP, which integrates very easily by entering the LDAP ID, username, password, and port number, making the experience fairly good.

    I would rate this review an eight out of ten.

    Erik Cheng

    Unified security has improved border protection, boosted SD-WAN performance, and simplified VPNs

    Reviewed on Dec 04, 2025
    Review provided by PeerSpot

    What is our primary use case?

    My clients use Fortinet FortiGate  in the boundary and border gateway as a border firewall, positioned between the internet and the company. We also use it for VPN and IPsec VPN to connect remote office sites. Additionally, I have a use case for MES in high technology where it blocks malware in machines such as those used for producing semiconductors.

    I have used Fortinet FortiGate 's data center solution, specifically the FortiGuard service, which is included in every Fortinet FortiGate deployment. In the data center, we use Fortinet FortiGate to block server farms from the internal LAN due to its performance, which is higher than other products. We consistently use it in server farm environments.

    What is most valuable?

    The best feature of Fortinet FortiGate is its SD-WAN capability, which is included and differs from other products that require an additional license.

    With SD-WAN capabilities, I notice a significant impact on network performance. The E series offers good performance, double that of the D series. If a new series is released, it always performs well. For example, if my customer uses the 200D model, the new 100E model can serve as an upgrade.

    My experience in integrating SD-WAN capabilities with Fortinet FortiGate indicates that the integration is not difficult. We simply incorporate user ID and user account, and we have not encountered other challenges.

    The main benefits that my customers see from Fortinet FortiGate include low cost and the integration of switches, APs, and Fortinet FortiGate, which reduces management overhead.

    What needs improvement?

    I have not used the Unified SASE  capabilities in Fortinet FortiGate.

    I do not have the AI or ML enhanced FortiGuard with machine learning or AI.

    My impression of the dynamic segmentation feature in Fortinet FortiGate is that while some customers use it, I believe it is not granular enough. It can separate VLANs, but it cannot separate individual users. We use it with FortiSwitch or AP to expand Fortinet FortiGate ports to every switch port.

    Regarding stability, I have experienced performance issues with Fortinet FortiGate. Sometimes it does not work correctly in certain situations, such as DNS or URL categories, where it might block incorrectly.

    When it comes to scalability, I find Fortinet FortiGate somewhat scalable, but not highly scalable because we usually replace it. We always buy a larger model to replace the old one. For better scalability, Check Point performs best as it offers products that allow for adding more firewalls to expand performance or bandwidth.

    In assessing the performance of the hardware-assisted DDoS protection in Fortinet FortiGate, I think it does not work effectively in critical events, as DDoS protection is challenging due to the number of attackers.

    In the future, I would like to see improvements with Fortinet FortiGate, especially as all firewalls emphasize AI or machine learning. I do not see significant use of AI in Fortinet FortiGate, whereas I can see how AI improves functionality in Palo Alto.

    For how long have I used the solution?

    I have been working with Fortinet FortiGate for approximately twenty years.

    What do I think about the stability of the solution?

    Regarding stability, I have experienced performance issues with Fortinet FortiGate. Sometimes it does not work correctly in certain situations, such as DNS or URL categories, where it might block incorrectly.

    What do I think about the scalability of the solution?

    When it comes to scalability, I find Fortinet FortiGate somewhat scalable, but not highly scalable because we usually replace it. We always buy a larger model to replace the old one. For better scalability, Check Point performs best as it offers products that allow for adding more firewalls to expand performance or bandwidth.

    How are customer service and support?

    I would evaluate Fortinet's customer service and technical support teams with a rating of nine.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I mainly work with firewalls from Palo Alto Networks.

    Apart from Palo Alto, I have worked with Check Point, but I used it very minimally.

    How was the initial setup?

    The initial setup of Fortinet FortiGate is not difficult for me.

    What about the implementation team?

    I have a business relationship with Fortinet as a reseller and system integrator.

    What was our ROI?

    I am aware of investment regarding ROI, but I need clarification on what type of investment you mean. The cost is the main concern of my customers, and Fortinet FortiGate offers the future we need.

    What other advice do I have?

    I use Fortinet FortiGate primarily as a physical appliance; the VM deployment is minimal. My impression of the dynamic segmentation feature in Fortinet FortiGate is that while some customers use it, I believe it is not granular enough. It can separate VLANs, but it cannot separate individual users. We use it with FortiSwitch or AP to expand Fortinet FortiGate ports to every switch port.

    Regarding stability, I have experienced performance issues with Fortinet FortiGate. Sometimes it does not work correctly in certain situations, such as DNS or URL categories, where it might block incorrectly.

    In assessing the performance of the hardware-assisted DDoS protection in Fortinet FortiGate, I think it does not work effectively in critical events, as DDoS protection is challenging due to the number of attackers.

    My clients use Fortinet FortiGate in the boundary and border gateway as a border firewall, positioned between the internet and the company. We also use it for VPN and IPsec VPN to connect remote office sites. Additionally, I have a use case for MES in high technology where it blocks malware in machines such as those used for producing semiconductors.

    In the future, I would like to see improvements with Fortinet FortiGate, especially as all firewalls emphasize AI or machine learning. I do not see significant use of AI in Fortinet FortiGate, whereas I can see how AI improves functionality in Palo Alto.

    I mainly work with firewalls from Palo Alto Networks.

    Apart from Palo Alto, I have worked with Check Point, but I used it very minimally. I would rate this review with an overall score of nine.

    Shane Maxson

    Centralized security has simplified remote site protection and reduced staffing needs

    Reviewed on Dec 02, 2025
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Fortinet FortiGate  is for VPN and its appliances and for securing all of our remote locations.

    A specific example of how I use Fortinet FortiGate  to secure my remote locations is that we set rules on each of our locations about what traffic can and cannot go in, so we can allow certain connections for our partners such as Frontiers.

    What is most valuable?

    The best features Fortinet FortiGate offers are the built-in security functions, which I think are very nice.

    We find the built-in security functions most valuable in Fortinet FortiGate, particularly web filtering, as it is all hands-on. Web filtering is our standout feature, and I don't want to add anything else about the features.

    Fortinet FortiGate has positively impacted my organization by centralizing the way to access all of our network firewalls.

    What needs improvement?

    I wish Fortinet FortiGate's UI updates would be done in a more simplified way to improve it.

    I choose nine for my rating because I think there's always room for improvement, and I think some of the things in the UI need to be adjusted so they're a little bit more simplified and not overcomplicated.

    For how long have I used the solution?

    I have been using Fortinet FortiGate for at least three and a half, maybe four years now.

    What do I think about the stability of the solution?

    In my experience, Fortinet FortiGate is very stable, and it has been quite consistent during times of downtime.

    What do I think about the scalability of the solution?

    Fortinet FortiGate's scalability has been keeping up well with my organization's growth or changes, as each location gets larger and we feel the need to put a Fortinet FortiGate in each one.

    How are customer service and support?

    We have had to reach out multiple times to Fortinet engineers for customer support, and it has been great every time; they always seem to get to the bottom of it within one to two calls.

    How would you rate customer service and support?

    Which solution did I use previously and why did I switch?

    We did use a different solution before Fortinet FortiGate, but it has been so long that I cannot remember who it was; it may have been Palo Alto.

    What was our ROI?

    I believe we have seen a return on investment in terms of fewer employees needed, but otherwise, it is outside of my scope.

    What's my experience with pricing, setup cost, and licensing?

    I was not directly involved in the pricing, setup cost, and licensing for Fortinet FortiGate.

    Which other solutions did I evaluate?

    We did consider other options before choosing Fortinet FortiGate, but it was a straightforward decision, and I am not quite sure what the other options were.

    What other advice do I have?

    I do not have anything that is unique to us about how we use Fortinet FortiGate in our setup.

    We do not utilize Fortinet FortiGate's data center solution, and we do not feel the need to consider AI and ML enhanced FortiGuard services within Fortinet FortiGate.

    I would advise others looking into using Fortinet FortiGate to make sure that they get their configurations right from the start, as that means they have less of a need to get support involved. I would rate this product a nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    View all reviews