Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

17 AWS reviews

External reviews

219 reviews
from

External reviews are not included in the AWS star rating for the product.


    Georges FONGANG

Product offers good stability and easy initial setup

  • June 19, 2023
  • Review provided by PeerSpot

What needs improvement?

In order to make it even better in the future, improved integration with other vendors' solutions could be beneficial.

FortiGate is compatible enough with other infrastructures, but I encountered difficulties when attempting integration with other infrastructures. So, better compatibility could be an area for improvement.

Another area of improvement could be in terms of changing passwords. For instance, when using FortiGate firewall, you can have the option to set up SSL VPN, allowing users to connect to the network externally. It's like using FortiClient software. But here's the thing, when you have a local account on FortiGate, and you use it to access the network, there is no option to change your password, and that becomes a problem. Especially when you are not using Active Directory and instead relying on the local FortiGate database to create accounts. 

The admin creates the account for you with credentials and a password. But when you try to access using the VPN client software, you have the ability to change your password, and that's not ideal. It's quite challenging. So, if you need to change your password, you have to contact the administrator to change it on the equipment, and that's not convenient, especially in large environments. So, that could be the only solution.

For how long have I used the solution?

In terms of personal experience, I've been using the product for about seven years. In my current company, it has been three years.

I'm using version 7 for the majority of my equipment, and for some products, it's version 6.6 or something similar.

What do I think about the stability of the solution?

The product is stable. It offers good stability.

What do I think about the scalability of the solution?

It is a scalable solution. 

How are customer service and support?

The customer service and support have been satisfactory so far.

How would you rate customer service and support?

Positive

How was the initial setup?

FortiGate Next Generation Firewall (NGFW) is easy to deploy. The deployment process is smooth and straightforward.

What was our ROI?

In my experience, the ROI has been positive.

What's my experience with pricing, setup cost, and licensing?

The price of FortiGate Next Generation Firewall (NGFW) is affordable. I believe it offers reasonable value for the features it provides.

If you're using the IPS version, particularly for ATP, the price is higher due to the IP functionality. However, for other features like web filtering, the price is reasonable. For a year, the license cost for ATP is around $8000. 

So far, I haven't had to pay separately for maintenance or support. It's usually included in the support package, including software support.

What other advice do I have?

Overall, I am satisfied with the product. I would rate it a nine out of ten. 

If you are using it in a small environment, you can go for the FortiGate product. However, if you are implementing it in a very large environment or have specific needs, it's recommended to couple FortiGate with another vendor's solution, like Cisco or Palo Alto. 


    Eswara Rao Pitaka

Highly scalable, user-friendly interface and ease of operation

  • June 14, 2023
  • Review provided by PeerSpot

What is our primary use case?

It is a firewall solution, so we utilize it regarding policies and security.

What is most valuable?

The solution is user-friendly and easy to operate.

What needs improvement?

The solution should have more security features and come with VPN authentication and multi-virus authentication.

For how long have I used the solution?

We used the previous model, FortiGate 600D. So, I worked with that. I have been using the solution for three years.  We just procured the new solution, but we need to install it right away.

What do I think about the stability of the solution?

The solution is stable. I would rate the stability of the solution an eight out of ten because there are some issues with security features and aspects like logs not being up to the mark, as well as some challenges with VPN and multiple functionalities.

What do I think about the scalability of the solution?

It's a scalable solution. I would rate the scalability a nine out of ten. There are around 600 users in our organization using this solution. We have plans to increase the usage up to 2000 users. 

How are customer service and support?

The customer service and support team is good. Their response time was great.

How was the initial setup?

The initial setup is straightforward. It has been in use for three years. It may take around four days to make it functional.

Typically, it can be up and running in just one day. However, due to a lack of expertise, it took a bit longer.

What about the implementation team?

I got a consultant to help with the deployment process. One person is enough for the solution; it can be an admin. 

What was our ROI?

I have definitely seen an ROI. 

What's my experience with pricing, setup cost, and licensing?

I don't want to get the full license as the technology is changing day by day. So, I have I prefer to procure a five-year license, and that's it.

Which other solutions did I evaluate?

We have used Microsoft Office and Cisco Switches. We have been using the FortiGate firewall.

What other advice do I have?

I advise the users to compare the solution with existing versions before using it.

Overall I would rate the solution an eight out of ten. I would like add more security features to the solution.

Which deployment model are you using for this solution?

On-premises


    Paul Duxfield

An easy-to-configure product with a reasonably good graphical user interface

  • June 14, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use the solution to provide firewall, cybersecurity, VPN access, and SD-WAN connectivity worldwide.

What is most valuable?

The GUI is reasonably good. The product is easy to configure.

What needs improvement?

The product runs out of memory. The web process often has a memory leak. The support cost could be improved.

For how long have I used the solution?

I have been using the solution for ten years.

What do I think about the stability of the solution?

The solution’s stability is good. I rate stability a nine out of ten.

What do I think about the scalability of the solution?

The scalability is good. I rate the scalability a ten out of ten. Some customers have 20 users, while others have about 5000 users.

How are customer service and support?

Support is good. It's a bit scripted. It takes a while to get to somebody who knows what they're talking about. It'd be nice to talk to someone technical upfront. Sometimes we have to go through a service desk and go through a whole lot of quick repetitive questions before we get to talk to someone knowledgeable.

How was the initial setup?

I've been working with the product for ten years. I find the initial setup quite simple.

What about the implementation team?

I'm currently deploying 50 units around the country. It'll take me about ten minutes each to configure the solution. Once the product is set up, we need about one or two people to maintain it.

What's my experience with pricing, setup cost, and licensing?

The solution’s price has gone up recently, but it's still good value for money compared to the other firewalls we use. Especially for smaller ones, it is good value for money. Our customers pay for licenses annually or once every two to five years. If we have an older version, the support costs get quite high. I rate the support cost a six out of ten.

What other advice do I have?

I work with lots of firewalls. I deploy the product on FortiManager. It'll take me about a day to configure FortiManager. We have lots of customers. I would recommend the solution to others. Overall, I rate the product a nine out of ten.

Which deployment model are you using for this solution?

On-premises


    Abdallah Rukab

Helps secure the internal network and perform unified threat management, forward filtering, and application control

  • June 13, 2023
  • Review provided by PeerSpot

What is our primary use case?

I use Fortinet FortiGate to secure the internal network and perform unified threat management, forward filtering, and application control. This is crucial for the organizations and products I collaborate with on projects. The solution effectively addresses high availability through SD-WAN load balancing. Additionally, we rely on Fortinet FortiGate to resolve remote access issues for our clients.

How has it helped my organization?

Fortinet FortiGate has helped improve our reporting analysis, ease of management, and enhance the security of our environment.

What is most valuable?

Fortinet FortiGate's ease of management is the most valuable feature.

FortiGate offers numerous features that are designed to assist end users in gaining a clear understanding of the activities occurring within their network.

What needs improvement?

The non-error conserve mode has room for improvement.

For how long have I used the solution?

I have been using Fortinet FortiGate for eight years.

What do I think about the stability of the solution?

I rate the stability of FortiGate an eight out of ten.

What do I think about the scalability of the solution?

I rate the scalability of FortiGate a ten out of ten.

How are customer service and support?

The technical support has improved compared to the last few times I used it.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I had previously used a different solution but switched to Fortinet FortiGate due to its better price and ease of use.

How was the initial setup?

The initial setup is straightforward. Depending on the customer's requirements and environment, the deployment can take anywhere from one day to a couple of weeks and can be completed by a single person.

What about the implementation team?

We implement the solution in-house.

What was our ROI?

I achieve approximately a 30 percent return on investment with FortiGate.

What's my experience with pricing, setup cost, and licensing?

Fortinet FortiGate is reasonably priced. 

What other advice do I have?

I rate Fortinet FortiGate a nine out of ten.

Fortinet FortiGate is primarily utilized by medium to large organizations, although it can also be employed by small ones.

In terms of maintaining the solution, updates are typically performed to address bugs.

I highly recommend Fortinet FortiGate to others.

Which deployment model are you using for this solution?

On-premises


    reviewer1959201

Promptly addresses security threats and vulnerabilities commonly found in the modern technology world

  • June 13, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use Fortinet FortiGate for end-to-end advanced firewall protection.

Fortinet FortiGate is deployed both on-premises and in the AWS and Azure clouds.

How has it helped my organization?

Fortinet FortiGate makes it extremely easy to manage the entire security system independently of our enterprise. In our company, we operate multiple networks, each with its own distinct layers of networking. Whether it is a small or large company, each network will consist of various layers, including the first, second, and third layers, as well as Wi-Fi access points. Additionally, we have different access switches, distribution switches, and core switches. FortiGate allows for direct management of all these options, which is one of its core advantages.

What is most valuable?

FortiGate is highly user-friendly and promptly addresses security threats and vulnerabilities commonly found in the modern technology world. Additionally, Fortinet offers the latest versions to cater to the needs of enterprises. They provide a range of firewalls, suitable for both small-scale businesses and larger enterprises. Overall, we are quite satisfied with their performance, and it has been working well for us so far.

What needs improvement?

Fortinet should focus on enhancing the capabilities of FortiGate by consolidating its various products, such as FortiGate Cloud, FortiManager, and FortiAnalyzer. Currently, these multiple products often confuse users and clients. It would be beneficial if Fortinet could offer a comprehensive integrated solution instead of separate products that cause user confusion. By providing an integrated solution, users would have access to all features and functionalities within a single window, eliminating the need to navigate through multiple windows. This approach would greatly improve the user experience.

For how long have I used the solution?

I have been using Fortinet FortiGate for three years.

What do I think about the stability of the solution?

Fortinet FortiGate is extremely stable.

What do I think about the scalability of the solution?

Fortinet FortiGate can easily scale using the cloud firewall option.

How are customer service and support?

The technical support team is exceptional. They are consistently available and prompt in their responses, regardless of the region from which we open the ticket.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I used Cisco at my previous company and my new company uses FortiGate. FortiGate is better than Cisco. Where Cisco requires a person with great networking or programming knowledge, FortiGate does not. We can manage everything from its user interface. It provides comprehensive security fabric management, including Forti switches and access points. Additionally, FortiGate serves as a gate for our home, allowing us to monitor who enters and exits. Therefore, if we compare it to Cisco, monitoring the entire traffic becomes much easier.

How was the initial setup?

The initial setup is straightforward. Fortinet provides step-by-step instructions in its documentation. The Fortinet engineers and support team are always available to assist, but even for a non-technical person, the deployment is easy.

What's my experience with pricing, setup cost, and licensing?

The pricing depends on the FortiGate model we are using, ranging from $3,000 to $20,000 US dollars. We are using the FortiGate 600E, and its price falls within the midrange. The most expensive part is the renewal of the license subscription.

What other advice do I have?

I give Fortinet FortiGate an eight out of ten.

Fortinet FortiGate offers a cloud trial that organizations can use in a test environment to evaluate the solution before making a purchase.

Which deployment model are you using for this solution?

On-premises


    Philimon Kaitano

Offers a unified view, and is user-friendly, but the support has room for improvement

  • June 12, 2023
  • Review provided by PeerSpot

What is our primary use case?

We implemented Fortinet FortiGate SD-WAN for a small company that had two internet service providers. The goal was to configure the two links to operate independently, ensuring that they don't share the load. This way, when one link reaches a certain threshold, we can seamlessly switch to the other without any issues. 

How has it helped my organization?

We have FortiManager, which enables us to have a unified view for monitoring and managing our devices centrally, as well as dispatching policies.

The solution enables us to consolidate tools and applications and manage them all through FortiManager. You can configure your SD-WAN from Forti Manager, which gives you management functionality. 

The interoperability of the solutions is good because it allows for compatibility with brands other than Fortinet, and we don't encounter issues with it.

FortiGate SD-WAN facilitated a smooth transition for our customers between their two internet service providers, ensuring uninterrupted connectivity without any downtime.

The solution has helped us remediate threats more quickly by enabling real-time monitoring of both links, providing complete visibility into our end links. You can monitor both links on one platform. It's just one single pane of glass where you watch in real-time what is happening. It's easy to manage that way. It helps you to easily remediate issues. 

As long as our policies are granular we are able to use the solution to reduce our MTTD. 

The solution has helped to reduce our MTTR from what used to be five minutes down to 45 seconds.

The solution has helped to reduce the number of help desk tickets because it is now extremely rare for both links to be down simultaneously.

SD-WAN, regardless of the OEM being used, is a beneficial technology that is increasingly adopted by businesses due to its positive impact on business security. It allows us to maintain uninterrupted operations without concerns about past issues.

What is most valuable?

Fortinet FortiGate is user-friendly.

What needs improvement?

The support we receive when we need to upgrade is not satisfactory and has room for improvement.

For how long have I used the solution?

I have been using Fortinet FortiGate for two years.

What do I think about the stability of the solution?

The solution is stable and we have not had any issues.

What do I think about the scalability of the solution?

The solution is highly scalable.

How are customer service and support?

The technical support is good, but they take a long time to respond and resolve the issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have also used Cisco, whose systems are robust and rarely experience downtime. However, with Fortinet, their licensing is highly competitive in terms of pricing. Cisco is primarily geared towards enterprise-level companies, but the learning curve for Cisco is higher compared to Fortinet.

Fortinet's price is very competitive compared to when you look at other brands of equal functionality. The hardware and licensing are compared to the others. It's also simple to use. 

How was the initial setup?

The initial setup is straightforward. I did the deployment and didn't have any issues with it. It took one day to complete. 

What was our ROI?

The solution provides value and, therefore, offers a return on investment.

What's my experience with pricing, setup cost, and licensing?

The price is highly competitive when compared to other brands that offer similar functionality. Fortinet FortiGate is more affordable both in terms of hardware and licensing, in comparison to its competitors.

What other advice do I have?

I give Fortinet FortiGate a seven out of ten.

I recommend FortiGate SD-WAN because it is easy to implement and simple to use.

Which deployment model are you using for this solution?

On-premises


    Aref Molaei

A solution with good performance that is also price-wise reasonable

  • June 12, 2023
  • Review provided by PeerSpot

What is our primary use case?

First, we use the solution as a native firewall. After a native firewall, we use IPS. We also use NGFW features like antivirus, IPS, and shaping, which are very important features for companies. We also manage all of my products with FortiManager or FortiAnalyzer and collect online data. For another feature, we try to use SD-WAN products. The SD-WAN feature on FortiGate was implemented for a company with thirty or fifty branches. We had a good experience with the conversion between Cisco and FortiGate for secure access points because Now I'm a consultant for network administration, and we have a challenge with choosing one of these, and so for example, someone, if I actually choose a Fortinet product, SD-WAN based on Fortinet, sometimes someone chooses SD-WAN based on Cisco, but because my special is Cisco, I prefer SD-WAN based on Cisco.

What needs improvement?

One of the weaknesses of the solution is something we noticed, especially after comparing the tool with SD-WAN features, since, unfortunately, in a massive scale size environment, the solution is not good. It cannot be recommended for massive scaling in terms of size, especially for businesses with more than 1,000 branches.

Cisco is very stable, especially on the larger scale side, and it's very important for SD-WAN features. If you try Next Generation Firewall for a big company, then it is good to purchase a Cisco product. However, Cisco's price is a little high and more than Fortinet's prices. But for small companies, it is better to choose Fortinet and FortiGate products, which is important.

A company needs a tool for accounting. Unfortunately, now we don't have any accounting, especially for the quarter and control side. We don't have any solution in FortiGate. However, Sophos Firewall has it, so it is good for Fortinet's next version.


For how long have I used the solution?

I have been using FortiGate Next Generation Firewall (NGFW) for more than eight years. I am just a technical person, so I'm a solution designer, a network architect involved in network security.

What do I think about the stability of the solution?

In FortiGate, after FortiOS Version 5.6, it is stable, and there is no problem. However, we had many problems with FortiOS Version 5.0.5 in FortiGate. Now, when we use FortiGate's FortiOS Version 7, we don't have any problems. The solution has improved, and it is a good product now. For a larger scale, my recommendation is to choose a Cisco product like Firepower Services because, in a massive-scale business, stability is very important.

What do I think about the scalability of the solution?

When I survey FortiGate and FortiGate products, I see that they have a good performance, especially in terms of next generation firewalls. In the future, improving such features and performance is absolutely better. Juniper has a better performance compared to FortiGate.

How are customer service and support?

Speaking about technical support, I have a good experience with design, especially in terms of security design and security architecture.

In level one support, they connect to customers directly, which is a part of our work, and we should solve customer problems. But I prefer staying in level two, where we develop, implement, and solve huge and complex problems, because I have had a good experience with this for more than ten years. Also, I think I have good behavior when under heavy pressure.

What's my experience with pricing, setup cost, and licensing?

I think price-wise, the solution is totally reasonable since it has many products to serve, starting from small homes to massive scale sites. A company can choose from one of the offerings by the solution company. Also, it's very important to choose a contract support level. Some companies may choose RMA with support twenty-four hours and seven days a week. So, it depends on the contract support, I think. The Fortinet appliance is a reasonable purchase for companies.

Regarding the license costs, when you choose the 100 series, it is completely different from the 1000 series. It's very important, and so when you choose one-year support or five-year support, or seven-year support, the pricing depends on which one you choose.

In Iran, we have a massive sanction, so we don't use direct support. We don't talk about this. But, concerning my country and direct support from Fortinet, I can't speak about this event. So, in Iran, I don't have an idea about the use of support since we don't use direct support, but we do get indirect support.


What other advice do I have?

When planning to choose FortiGate Next Generation Firewall (NGFW), the scope of the company is very important. Also, it is important for a company to consider if they want one gig, ten gigs, or another concurrent pair concurrent session. Totally, a company's scale and size are very important. After that, for example, we use a prototype with a five gigabit per second, including the performance. However, if we compare Cisco, Fortinet, and other things, Firepower is very good because Cisco's Firepower is a big and active solution which is very strong compared to Fortinet. However, it's very important for a company to have a native firewall, so such companies can't choose from Fortinet series. So, it very much depends on the situation of the company. So, before that, we review a company's requirements and survey network. After that, usually, I recommend the solution. Also, it is very important to have a budget. For example, a company can first tell me about its budget, like, one billion dollars or whatever. After that, we choose a guide and recommend choosing one of the solutions.

I rate the overall solution an eight out of ten.



    Peter Livingi

A user-friendly and easy-to-install product that has a seamless performance

  • June 07, 2023
  • Review provided by PeerSpot

What is our primary use case?

Our clients use the solution to ensure their environment is secured on all the layers. The application layer all the way to the networking. That's one of the main reasons they use the product in their environment.

What is most valuable?

It's a seamless product, and it's not buggy. The updates we receive from FortiGate are one of the most important features. The product is user-friendly and not complex.

What needs improvement?

The solution must improve the support provided for customers around the globe, considering the time differences in different places. The product could add some functionalities and features provided by its competitors to stay ahead in the market.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

The product is stable. We haven't had issues so far. I rate the stability a nine out of ten.

What do I think about the scalability of the solution?

The solution is scalable in most cases. It all depends on the customer's requirements. We haven't yet come across a situation whereby scaling is not possible. Our clients are small, medium, and enterprise businesses. Currently, one of our customers is not able to reach the specific level of scalability that they require so far. I rate the scalability an eight out of ten.

How are customer service and support?

The support is great. However, support needs to improve constantly. Even though they are good, they should try to stay ahead of the competitors.

How would you rate customer service and support?

Positive

How was the initial setup?

The solution is easy to install. The ease of setup depends upon the customer’s requirements. I rate the ease of setup a ten out of ten.

What about the implementation team?

The time to deploy the product depends on the clients’ requirements because we have to work hand in hand with the service provider. If we have to terminate a link on the firewall and everything from the networking perspective is all in place, it might just take a couple of minutes to deploy.

We need just need one to three engineers to deploy the solution. It depends on the magnitude of the client. The solution requires maintenance. More than three people are needed to maintain the product.

What's my experience with pricing, setup cost, and licensing?

The product is a little bit expensive. The certifications cost $400. Other vendors provide it for an average of $200 to $300. The product has an annual licensing fee. Additional costs depend on the user's requirements.

What other advice do I have?

People looking to use the product must ensure they have enough engineers who know how to work with it. Overall, I rate the solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises


    Reviewer:734513

Offers superior control and visibility, is affordable, and scalable

  • June 05, 2023
  • Review provided by PeerSpot

What is our primary use case?

In our current data center, we use eight Fortinet firewalls. These firewalls serve multiple tiers of the network, including internet users, server farms, and DMZ ports. This gives us multiple approaches to our system and network. As a result, we are able to receive all reports before the analyzer.

In 2011, we were using a Cisco ASA 5540 fixed firewall. We moved to Fortinet because their UTM appliance was a next-generation firewall that offered more than one solution in a single box. This meant that we could handle the network, server, and client parts of our infrastructure with a single device. We also chose Fortinet because of the ease of its GUI and its ease of implementation in multiple locations. Currently, I have three data centers. We are using a consolidated console with a broader view of the network traffic. This is why we moved to Fortinet. We had previously used Juniper and Cisco, but we found that Fortinet offered a better solution for our needs.

We deployed the solution on-premises because, while the private sector in Kuwait has begun to move to the cloud, government entities are not permitted to do so.

How has it helped my organization?

I started with the firewall module, and we were using multiple boxes for multiple functions. I was using a Juniper SSL VPN. They came to us with a single-box solution that included SSL VPN, so we moved to that. Then they came up with client endpoint security, and we moved to that as well. They also introduced web filtering in Fortinet, so we moved to that as well. All of the technology that we were using previously on separate consoles is now consolidated into a single console. I can see the beauty of this product in that it has a single console that manages all of the facilities on one web page.

What is most valuable?

The firewall is top-notch. We are using SSL VPN.

What needs improvement?

When we first started, Fortinet was using a single appliance with a firewall module in the region. They later came up with many different solutions. I have also used FortiDB, but it has been discontinued. We have since removed it. We are looking forward to Fortinet considering a sandboxing solution. This would allow us to secure our database at that layer. I see the database area as being weaker. I would suggest that Fortinet add sandboxing to their solution.

For how long have I used the solution?

I have been using Fortinet FortiGate for 12 years.

What do I think about the stability of the solution?

Fortinet FortiGate is stable which is why we have stuck with it for almost 12 years.

What do I think about the scalability of the solution?

The scalability is good. In 2016, we scaled our system to ensure that we would have enough capacity for the next five to seven years. We are currently only utilizing 25 percent of the hardware processing.

We have around 900 users on our networks per second with a total active directory of 7,000.

How are customer service and support?

The technical support in our region is excellent. There are three levels of support. I remember one time when my problem was not resolved by level one or level two, so it was escalated to level three which was awesome. The level three technician was able to understand the issue quickly by reviewing the chain of email logs and the available information.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Juniper and Cisco firewalls before switching to Fortinet FortiGate. We were drawn to Fortinet because of its superior control and visibility, as well as its high availability, throughput, and durability. Fortinet's FortiGate firewalls are ASIC-based, which makes them more reliable and efficient than other solutions. As a result, we were able to handle more traffic with Fortinet than with any other vendor.

How was the initial setup?

The initial deployment was complex. We started with a low-level design, discussing with the vendor that we had a certain number of firewalls and concurrent sessions available on the network, and that we had remote sites. We began by implementing the boxes in the data center, then the main data center headquarters, and then the campus network, which has its own data center with a firewall module. We later installed it in one of our accessory branches in their data center. The installation was done in phases.

When the high-level design was in place, we began migrating the configuration. We used a migration tool from Cisco and Juniper, which was very smooth because it was intelligent enough to take all the network IDs, policies, and source destinations, forward based. This meant that we had fewer challenges when we started the migration.

However, we did encounter some challenges during the migration. These were not due to Fortinet, but rather to the configuration that had been migrated from the other vendor. We resolved these challenges by manually checking each policy one by one, and the issue was rectified within a couple of days.

A total of four people were involved in the deployment. Two people from our organization, one from the vendor, and one from the partner. We have to go through our partner to access the vendor.

What about the implementation team?

The implementation was completed by the vendor.

What was our ROI?

Fortinet FortiGate's features and price have provided a return on investment for our organization.

What's my experience with pricing, setup cost, and licensing?

The pricing is a bit more expensive than the others but Fortinet is the best in the region. They have a good hold on the market because they are everywhere.

We pay for support and licensing fees.

I give the pricing a nine out of ten.

Which other solutions did I evaluate?

We evaluated Palo Alto Networks, but they did not have a presence in our region, so we did not move forward with them. We also evaluated Check Point, but it is not a government-approved solution in our region.

What other advice do I have?

I give Fortinet FortiGate a nine out of ten. 

Fortinet FortiGate has good regional support. One of the best things about this solution is that Fortinet doesn't disappear after the sale. They keep engaging us with new technologies. For example, they recently engaged us with a SIEM and SOAR solution that allows me to have a single console for all of my security needs. I have a plan to move to this solution and consolidate all of my firewalls into a single FortiManager. This will allow me to have a more secure and efficient network.

Fortinet is not as focused on cybersecurity as some other companies, but they are very strong in network security. They are constantly coming up with new and innovative solutions that help us to protect our networks. I am very happy with Fortinet FortiGate and I would recommend it to anyone looking for a reliable and secure network solution.

We have deployed the solution in multiple locations.

Our partner is involved in maintenance, especially when a new FortiOS is released. We engage the vendor to understand the maintenance requirements, such as stability and any potential risks. We follow the vendor's recommendations and perform maintenance accordingly. We also use FortiAnalyzer to manage our logs. We delete old logs in accordance with government policy, which requires six months of data to be kept. We take care to ensure that maintenance does not affect these logs.

Fortinet FortiGate is one of the best and most affordable solutions with top-notch technology on the market. We get something that is both cheaper and of good quality with Fortinet FortiGate. Fortinet submitted the lowest-priced bid and met all of our technical requirements.

Which deployment model are you using for this solution?

On-premises


    Irshad Ali

Good licensing, saves costs, and provides good security and visibility

  • June 05, 2023
  • Review provided by PeerSpot

What is our primary use case?

I used this solution while working with my last organization. I handled plain firewall deployment as well as SD-WAN deployment. 

How has it helped my organization?

I was providing consulting services to various Telco customers. It helped customers save on the cost of highly expensive MPLS links. With the help of Secure SD-WAN, they were able to utilize broadband or even LTE connectivity, which saves costs. That's the flexibility that Secure SD-WAN gives to various customers. In addition to saving costs, they are also able to utilize active-active load balancing, where you can have two parallel links: primary and secondary. The secondary one used to sit idle in traditional scenarios, whereas now, the solution gives you the flexibility to configure both links as active-active, so you can prioritize critical traffic from link one and other traffic from link two. At the same time, you also have the option to maintain redundancy.

Secure SD-WAN is a great way to manage your entire organization network, especially the WAN network. Customers don't have to hop to multiple places. Fortinet has a solution called FortiManager. With the help of that, you can monitor, configure, and maintain your entire organization's network. It's a very convenient option. It's a single pane of glass from a customer's point of view. They don't have to log in to individual devices, and they can see the real traffic. They can see what's coming into the network, what sort of alerts or logs are there, and what sort of applications are being consumed.

Secure SD-WAN doesn't help with tool consolidation, but it's a secure way or mechanism they provide so that if branch users are accessing the internet, they can directly break out from the branch location rather than coming back to the data center. In that way, it improves the user experience while also giving security at the highest level.

I have not interacted much with Secure SD-WAN in terms of API integration or third-party integrations. However, they have pretty good integration with the RADIUS, LDAP, and AD servers. In that way, they have everything in-built. You can make the firewall a DNS server or some sort of DHCP server. Such features are included there. From a security standpoint, they have open API integration with their own SIEM or SOAR solutions. Third-party API integration is also possible, but the API details that are exposed are very limited.

The integrated application protection provided by Secure SD-WAN is a cool feature. They have real-time scanning of the application with the help of SSL inspection. You get to see the real-time traffic of applications, and you can protect your network from harmful websites. They have a signature database for that. This data also gets refreshed. It's a direct feed that the device takes from the central intelligence.

When you have Secure SD-WAN in place, you are more secure from the outside internet. They have a flavor of SASE, but I have not worked on it.

When you have a granular view of your entire network including users and security features being enabled, you get more visibility into your network. You get to know what's coming in and going out. If an administrator sees that some traffic is being hit repetitively from a particular location, functionality is available to block a region, country, or even an IP or domain.

In terms of Secure SD-WAN reducing our mean time to resolve, in the case of issues specific to SD-WAN, I've seen instances where customers can look into the dashboard and inform the support team that this is the issue they are facing. This helps them to have some visibility into these firewalls and isolate the entire issue from the technology perspective; for example, when a wireless client is facing some sort of challenge accessing the internet, whereas some of the wired users are able to access the internet. The testing tools given in the FortiGate GUI dashboard come in handy during troubleshooting. With the very user-friendly interface, it becomes very obvious and easy for any IT guy to simply follow the workflow to resolve any day-to-day operational issues.

What is most valuable?

The security features that they have are quite good. On top of that, their licensing model is quite nice where they don't charge you anything for the SD-WAN functionality for the firewall. The routing and firewall features are also good.

The unified view that they have built into this firewall is good. Within the same dashboard, you get to see the security profiles, the type of traffic that's passing through, the top applications that are being consumed, etc.

It's also very easy to use.

What needs improvement?

I was not looking after the operations part, but sometimes, I did get engaged in some critical activities related to operations. There are some caveats in every product. Tunnel flapping was one of the major things I had seen wherein your internet link remains but your VPN tunnel is down. However, since I got a fix from the TAC team, I have not noticed it, but the customer complained a few times that they couldn't access the internet because of this problem. There were tunnel issues where there was already established connectivity, but at the kernel level, there were some issues. For example, there's a feature for auto-site connectivity wherein whenever it automatically creates a new tunnel, at the kernel level, it also creates an interface. Sometimes, that interface crashes and a new interface could not be created, which results in connectivity loss. 

Fortinet has established itself in the SMB market segment. It's doing pretty well in that space, but when it comes to the enterprise segment, they are lagging a little bit. It all boils down to the performance of the hardware. If I enable all of the security features available on my device, the throughput degrades quite a lot. If I have put 10 GBPS of throughput on a firewall and I enable all of these features available, such as IPS or UTM functionalities, the throughput comes down to 1 GBPS.

For how long have I used the solution?

I used Fortinet FortiGate for seven months. I last used it in February of this year.

What do I think about the stability of the solution?

I'd rate it a seven out of ten in terms of stability.

What do I think about the scalability of the solution?

The solution offers the option of deploying VMs or virtual machines to any public cloud, such as AWS or Azure. It provides such flexibility. If you have any application hosted in the cloud space, you can have a VM spin of the FortiGate over there and have a site-to-site tunnel established, so the scalability is there. Otherwise, at the site level, it's mostly hardware-based work. If you size it properly, then you have the option to expand. You might have chosen a low-end model because of the tight budget. In that case, it's not scalable on a specific site. However, if you have a certain number of sites, for example, if you have 400 of them and you want to expand to 500 or 1,000, there is simply a license that goes at the FortiManager level to support additional devices. FortiManager provides a single pane of management. 

I'd rate it a seven out of ten in terms of scalability.

How are customer service and support?

My experience was not that rewarding. It took me around three hours in total to get a simple issue identified and fixed. I escalated it to their L3 engineer, and after that, I was able to resolve the issue. The entire process took around three hours. First, their initial level person was troubleshooting, then it went to the next level, and then it went to the highest level.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

From the security perspective, I have not used any other solution, but I did have a glance at Cisco's portfolio. Cisco Meraki is one of the solutions that you can compare it with. Others were more specific to the routing and switching domain. I know the concepts and theory of Cisco SD-WAN, but I have not used it in a real environment for any customer.

How was the initial setup?

For one of the clients, it was deployed on the Azure public cloud. Initially, it was not easy. It was complex. Every product and technology requires a certain type of prerequisite, and when you have anything hosted on a public cloud, it becomes a tedious job to get things done quickly because multiple stakeholders are involved in that.

I have deployed Secure SD-WAN specifically for many customers. I find it easy, but you need one person to be at the site for remote connectivity. That person just needs to do the basic configuration. Once the device has IP reachability, you can easily discover it from FortiManager, which is the central controller. So, once you have the device on FortiManager, it takes a few clicks to onboard the device because you already would have a template in place.

The deployment duration depends on the number of sites. For a customer with ten sites, it would take a week's time because there are a lot of dependencies. It also depends on the customer's readiness and availability, but a week's time would be enough for the deployment of ten sites. If there is proper planning in place, you can also deploy 50 sites in a week, but that's something you cannot control from your side because there are a lot of dependencies on the customer and the service provider. If you have to integrate it into a customer's existing network, it becomes quite challenging to make them understand your prerequisites. There are instances where nobody is available from the customer side from the technical standpoint to help you. Those are the roadblocks, but from the solution perspective, it's quite easy to onboard devices.

What about the implementation team?

The deployment can be done by one person if that person is dedicated to a single project, but if more projects are running in parallel, you would require a few more people.

It does require maintenance, which includes upgrading the operating system and installing patches. Two to three people would be enough for around 500 site maintenance but not in the 24/7 case. If it's 24/7, then nine people would be required for that.

What's my experience with pricing, setup cost, and licensing?

By default, they give SD-WAN along with the firewall. They don't have separate licensing for the SD-WAN functionality. However, they have security licenses that are sold separately on a subscription basis. Customers can consume these security features to protect their users from internet traffic.

What other advice do I have?

To those evaluating this solution, I'd advise doing a PoC of different vendors who are meeting their requirements. They can then decide for themselves after seeing the demo.

Overall, I'd rate it an eight out of ten. It's user-friendly. It's also good features-wise, but their support is weak, and on the architecture front, it's not true SD-WAN. It's not decoupling the control chain functionality from the device to the controller. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure