We use Fortinet FortiGate to help protect and secure mission-critical data. There are policies and rules that we apply, and there is an intrusion prevention system that notifies if there are critical vulnerabilities on some clients.
Fortinet FortiGate (BYOL) Next-Generation Firewall
Fortinet Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Integrates seamlessly with the team for quick threat remediation and cost benefits
What is our primary use case?
What is most valuable?
I assess the security services provided by Fortinet FortiGate, such as URL filtering and DNS filtering, as quite good; they are quite effective. Fortinet FortiGate is rather sustainable; it's a good, stable product that gets faster and uses less power with new versions.
It helps us remediate threats more quickly because we have specialists who can work with it rather effectively. When there is an alert on the Fortinet FortiGate, they work together with our FortiAnalyzer and can quickly remediate the incidents.
What needs improvement?
They should do a better job in testing when they put out a new release because when a new software version is released, it is not always stable or does not always have all the previous features working correctly. They should do more testing or launch a new version later when they have tested it more thoroughly.
They already did a good job in their GUI, but they can make more features available in the GUI that are still only accessible through the command line.
For how long have I used the solution?
My proper experience is only two or three years, but in the company, they have been using it for over 10 years.
What do I think about the stability of the solution?
In terms of network and security convergence, they are there, but we are not currently using them because in the office itself, we have other brands of switches and access points. It's now not quite stable in the demo lab environment; we are now on the latest version, but in the production environment, we are not. Production is always on a lower version.
What do I think about the scalability of the solution?
It is scalable.
How are customer service and support?
I would give Fortinet's technical support an eight out of 10; they are responsive and helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Sophos before Fortinet FortiGate.
How was the initial setup?
If you first implement Fortinet FortiGate to get it up and running, it takes just a couple of minutes, but to get all the policies configured correctly, it takes a couple of days.
What about the implementation team?
For my company, Exclusive Networks, the whole company had three or four engineers involved.
What was our ROI?
We have seen a return on investment from using Fortinet FortiGate for integration with the SOC team. The automation part is giving us a cost benefit and speed; we can react faster.
What's my experience with pricing, setup cost, and licensing?
The price-to-performance ratio from using Fortinet FortiGate is very good; I would give it a nine out of 10. It has helped save on costs due to reduced power consumption.
Which other solutions did I evaluate?
Performance is the reason I switched from Sophos to Fortinet FortiGate. It has good value for money, ease of use, and a higher security level, with better security solutions. It's more expensive, but it offers a really good total cost of ownership and is still considerably cheaper than Palo Alto.
What other advice do I have?
I would suggest to anyone considering purchasing Fortinet FortiGate's data center firewall to get training to understand very thoroughly how FortiOS works, and if you have several Fortinet FortiGates, to go for a FortiManager with the necessary training.
The users who work with Fortinet FortiGate are only the IT people, around three or four. Locally, we have around 60 end-users for Fortinet FortiGate. The biggest lesson would be that Fortinet FortiGate provides a high level of security at a good total cost of ownership.
I would give Fortinet FortiGate an overall rating of nine.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
VPN connections get streamlined as connectivity requirements are met
What is our primary use case?
For FortiGate Next Generation Firewall (NGFW), I use it primarily to connect with other companies through IPsec VPN. Any other security measures are on AWS itself, not on FortiGate. I'm someone who's familiar with FortiGate from previous jobs, so I use that, but it's how we're using it right now.
The IPsec feature of FortiGate Next Generation Firewall (NGFW) is valuable to our company because we need to connect quickly VPN connections with other companies in our networks, and there are many connections in some cases. We need to keep it as secure as possible, maybe one-way connections or particular ports. FortiGate is the best option, at least that I'm familiar with, that can answer all of that in one product that is mostly easy to use.
In our case, the deployment options of FortiGate Next Generation Firewall (NGFW) are not scalable, but in terms of connectivity to other companies, that's exactly what we needed, and that's exactly what it does perfectly, what is needed.
What is most valuable?
The most valuable feature for our company using FortiGate Next Generation Firewall (NGFW) is the IPsec feature, but actually FortiGate is known for good UTM products such as application filter and web filtering. We don't use it here, but in previous companies I used it on a daily basis.
One of the benefits I've realized from using FortiGate Next Generation Firewall (NGFW) is that it's secure and allows functions such as VPN. You can control Wi-Fi and other things from within, if you have FortiNet devices. It's an easy to use product, yet it allows you all that is needed, or at least all that you can do. Whenever there is a security breach, FortiGate is known to patch it very quickly from what I've seen.
Since FortiGate Next Generation Firewall (NGFW) was implemented, there was a thought in the company about using the VPN that AWS itself provides, but it's far from being as good as FortiGate.
The process can be improved in terms of explaining exactly how the installation should be done step-by-step on AWS, because there are network considerations such as security groups. From what I could find, I didn't do extensive research, but it didn't seem obvious enough in that case.
What needs improvement?
I do not utilize the intrusion prevention and web filtering features of FortiGate Next Generation Firewall (NGFW).
The ability of FortiGate Next Generation Firewall (NGFW) to inspect SSL encrypted traffic is not applicable in the current position, but in previous companies, it was really seamless whenever we used it. It just worked seamlessly.
I don't recall if we use a centralized management console for FortiGate Next Generation Firewall (NGFW) in maintaining oversight across distributed networks.
In my opinion, FortiGate Next Generation Firewall (NGFW) could be better by having specific models for home usage. I'd wish to have a FortiGate in my home, but the licensing isn't something that I want to purchase for home usage.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall (NGFW) almost since day one at this company, which I have been with for three years and something.
What do I think about the stability of the solution?
I experienced the stability and availability of FortiGate Next Generation Firewall (NGFW) more in the previous company. In terms of stability, mostly it is okay; however, in some cases, there are features, especially the UI, that tend to have issues. In some cases, you need to restart it, but mostly, it's working flawlessly, especially if you have an HA environment, high availability.
What do I think about the scalability of the solution?
In our case, the deployment options of FortiGate Next Generation Firewall (NGFW) are not scalable, but in terms of connectivity to other companies, that's exactly what we needed, and that's exactly what it does perfectly, what is needed.
I'm certain that what it allows us in terms of connections to other companies is a straightforward solution that you don't have to use something else. It's easy to configure a new connection, and it works in a few minutes if everything works fine.
How are customer service and support?
In this company, I may have worked with FortiGate Next Generation Firewall (NGFW) support one time, but in my previous company, I actually worked with them extensively. We had multiple FortiGate devices across multiple offices around the world, and we needed to switch them from one account to another sometimes. So I encountered FortiGate support quite frequently.
I would evaluate the level of support for FortiGate Next Generation Firewall (NGFW) somewhere between seven and eight. My experience might be outdated because lately, I haven't had much experience with that. In some cases, you need to come prepared because the people there work by the book and ask for particular things. If you don't have them, you cannot proceed, but if you know what they need, after some time, it's pretty easy to get support or whatever you need.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I don't have enough information on other products that I can tell the pros and cons of FortiGate Next Generation Firewall (NGFW) versus its competitors.
How was the initial setup?
The setup was already done, but from what I read, we considered putting it in another environment that we have, yet we didn't because we didn't actually need the environment at all.
What was our ROI?
I don't know if my company has seen return on the investment from FortiGate Next Generation Firewall (NGFW), but I'm certain that what it allows us in terms of connections to other companies is a straightforward solution that you don't have to use something else. It's easy to configure a new connection, and it works in a few minutes if everything works fine.
What's my experience with pricing, setup cost, and licensing?
Pricing isn't something applicable for me regarding FortiGate Next Generation Firewall (NGFW) because it was already set up once I came to this company.
Which other solutions did I evaluate?
Since FortiGate Next Generation Firewall (NGFW) was implemented, there was a thought that crossed in the company about using the VPN that AWS itself provides, but it's far from being as good as FortiGate.
What other advice do I have?
I would rate FortiGate Next Generation Firewall (NGFW) as a solution a 10 out of 10. I do love FortiGate.
I give it a 10 because, in my experience, FortiGate Next Generation Firewall (NGFW) is a product that allows you to do many things very easily. If you don't appreciate something about the way it works, you have enough playground to change it to suit your needs.
For someone considering FortiGate Next Generation Firewall (NGFW) for their company, there was a demo online version that they have on their website that is easy to access. You can play with it and see almost all the features in action. That's an easy thing to actually test. Obviously, you cannot connect it to your network and see things live in your case, but it is still a good example of how things work.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Ease of deployment and cost-effective but has occasional support challenges
What is our primary use case?
I use Fortinet FortiGate for security as a firewall.
How has it helped my organization?
Fortinet FortiGate helps improve my organization since it's quick and easy to install, and we don't have to call support frequently.
What is most valuable?
It's very similar to a Cisco firewall, yet they are less expensive. It has all the features the competitors have, including VPN.
Fortinet FortiGate is easy to install and deploy quickly. There's a user-friendly GUI or if you like, CLI, for those who prefer it over CLI you can use that.
What needs improvement?
From a support perspective, I had more issues that I didn't think the person on my case handled the way I was expecting. We called them for a geolocation issue and we didn't get any proper assistance.
For how long have I used the solution?
I've used the solution for about seven years.
What do I think about the stability of the solution?
It is pretty stable. We once had an issue and we had a workaround from Fortinet FortiGate before they deployed a patch.
What do I think about the scalability of the solution?
Fortinet FortiGate is scalable. On a scale of one to ten for scalability, I would rate it as seven out of ten.
How are customer service and support?
I don't call them frequently, which is a good sign. However, we called them for a geolocation issue and we didn't get any proper assistance. If I had to rate them on a scale, I would rate them eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used Checkpoint and used to love them. However, they are expensive and can be complex. I love Palo Alto. That said, they are not that flexible for me. I also used Cisco.
How was the initial setup?
It was easy to set it up, for the most part. The deployment of Fortinet FortiGate is straightforward. On a scale from one to ten, I'd rate ease of deployment at an eight.
We did switch from a competitor and were able to set it up very quickly.
It takes only two people to deploy.
What was our ROI?
The price is very interesting and it ends up being a very cost-effective solution.
What's my experience with pricing, setup cost, and licensing?
The price is the first main difference compared to others. Its prices are very interesting. At the company I work for, people tend to go with Fortinet FortiGate, and it's used especially in my country, as it's a cost-effective solution.
Which other solutions did I evaluate?
I evaluated and compared Palo Alto and Cisco with Fortinet FortiGate after Checkpoint.
What other advice do I have?
I will recommend Fortinet FortiGate to others, depending on the organization's requirements, needs, and budget.
I would rate Fortinet FortiGate as a seven out of ten simply due to the fact that I'm more of a Cisco person. I prefer Cisco since I've been working with it for a long time.
Which deployment model are you using for this solution?
Integrated tools enhance network control and security management
What is our primary use case?
We are using Fortinet FortiGate to block or deny malware and to administrate the network to control the traffic inside and outside.
How has it helped my organization?
It has significantly contributed to the effective control and monitoring of the network infrastructure. We could see its benefits immediately after the implementation.
What is most valuable?
It is complemented by other equipment, such as the Fortinet switch, and it is integrated with other tools that help to prevent cyberattacks, including a web filter, IPS, and application control.
What needs improvement?
The user interface of the Fortinet FortiGate management console could be more intuitive and user-friendly, and the log analysis and reporting features could be enhanced to provide more flexibility and customizable insights.
For how long have I used the solution?
I have had experience with Fortinet FortiGate for one year so far.
What do I think about the stability of the solution?
Fortinet FortiGate is very stable. I would rate its stability a ten out of ten.
What do I think about the scalability of the solution?
It is scalable. I would rate the scalability of Fortinet FortiGate a ten out of ten.
We are a medium-sized organization.
How are customer service and support?
I would rate Fortinet's customer service as very good. They are good because they provide solutions to problems that we encounter and help us make new changes or meet requirements, and they have the ability to work with us to make the changes that we want.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Sophos for web filtering. We now use Fortinet FortiGate for web filtering as well. We switched from Sophos to Fortinet FortiGate because we chose to adopt a Fortinet ecosystem to achieve better centralized control. We wanted to streamline security management while integrating firewalls, switches, endpoint protections, and wireless.
We used Sophos only for web filtering control applications, but when we switched to Fortinet FortiGate, we achieved better integration with other devices in the security management.
How was the initial setup?
I was involved with the initial setup and deployment of Fortinet FortiGate. It was of medium complexity. It was easy because the tools we were integrating were well-documented, but somewhat difficult due to the learning curve and the need to adapt our legacy system to the new environment.
What about the implementation team?
It took four technical people to deploy Fortinet FortiGate.
Only two people maintain it; for implementation, we used four people, but to maintain it, it is just two.
It doesn't require a lot of maintenance. The job roles of those who maintain it include making changes, adjusting web filter configurations, and switching ports. The people who maintain it are network administrators.
What other advice do I have?
I would advise people considering using Fortinet FortiGate to carefully plan the network structure and train the team; Fortinet is powerful, but its full potential comes with understanding the platform. I would recommend starting small, documenting everything, and using its centralized tools to stay secure and efficient.
Overall, I would rate Fortinet FortiGate a ten out of ten.
Which deployment model are you using for this solution?
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
What is our primary use case?
I use Fortinet FortiGate for SD-WAN, specifically for branches, and for firewall purposes.
Fortinet FortiGate is sold to everyone, including banks, mining companies, and oil companies, as it's one of the most popular SD-WAN products that we sell. These are mainly medium-sized businesses or enterprise businesses because we only sell business-to-business, B2B, and we don't sell to normal clients, only businesses.
How has it helped my organization?
We usually do not have any problems. It's a very easy-to-use product. We also have a SOC or service operations center. They are certified in Fortinet FortiGate.
From the point of view of a reseller, Fortinet FortiGate improves our business because it is one of the products that we sell the most. We also use it on our backend because the devices have many slots and support substantial bandwidth.
What is most valuable?
The most valuable features of Fortinet FortiGate are its SD-WAN capabilities, such as dynamic routing, and other features, including security options such as antivirus, IPS, and IDS—all integrated into one device.
Another beneficial aspect of using Fortinet FortiGate is that if you have a LAN network, you can integrate it with FortiSwitch. You can manage everything from Fortinet FortiGate. It is easy to manage and integrate with other Fortinet devices.
What needs improvement?
Fortinet FortiGate is a very good device overall, though it can be improved in certain areas regarding the licenses, particularly the big one called unified threat management, which has many capabilities. The big license options have web filtering, IDS, and a lot of other things, but it's not like they are all good. That's the only thing I would change because the rest is very good.
For how long have I used the solution?
I have about 4 or 5 years of experience with Fortinet FortiGate.
What do I think about the stability of the solution?
I find Fortinet FortiGate to be quite stable, as I have never heard of any issues where they broke or malfunctioned; they are always working. I would rate the stability of Fortinet FortiGate a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability for Fortinet FortiGate as an eight out of ten
How are customer service and support?
We don't usually use that service. We only engage with Fortinet support when a device is broken and needs RMA, so I am not familiar with their operational teams.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used to use Cisco firewalls and devices, which are also quite good. However, Cisco is more expensive, approximately twice their prices, but they are similar in functionality. With Fortinet, we are partner experts, which is a big advantage, whereas with Cisco, we are premium partners, which is not the biggest status, so if we are going to resell to our clients, we don't have the best discount or prices.
How was the initial setup?
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point.
We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
What about the implementation team?
For deployments at one site, it usually requires only one person, and if we are talking about 1 to 50 sites, it still only takes one person because the same template is used for all sites.
In Argentina, we service about 100 locations. There are about 200 companies in Colombia and Brazil.
What was our ROI?
We service about 100 locations with Fortinet FortiGate in Argentina, but if we account for all the company's clients, it can be around 2,000 across Colombia and Brazil, since we have clients in all of these countries.
What's my experience with pricing, setup cost, and licensing?
Fortinet prices are around $600 for the small 40F model, and for licenses, the simplest option is about $300 for a year. They sell licenses that can last for 1, 2, 3, or 5 years.
Which other solutions did I evaluate?
Before using Fortinet, we evaluated other options such as Versa and Meraki, but Meraki is also from Cisco. Fortinet is better than Versa. One of the main differences between them is that we don't have many partners or distributors for Versa here in Argentina, making it difficult to sell something that you cannot pay for locally. It has been easier in the past to handle payments, but Versa doesn't have many providers or distributors in Latin America, making it a less viable option. Fortinet offers more products that are easier to integrate into our clients' networks, such as firewalls and access points, so that was one of the main reasons we didn't use Versa.
What other advice do I have?
My advice to other businesses or people considering using Fortinet FortiGate is that it is the starting product from Fortinet, and when you start using Fortinet FortiGate, you can then move on to the next products they offer, which are numerous.
We sell the 40F, 60F, 80F, 100F, and 200F models. There are the ones we sell readily from the bottom to the top. Sometimes, we sell bigger ones such as the 300 model.
Overall, I would rate Fortinet FortiGate around a nine out of ten.
Which deployment model are you using for this solution?
Extensive web controls enhance our security posture
What is our primary use case?
We use Fortinet FortiGate for the firewall as well as for the VPN. Any of the users outside the organization use the VPN. Any staff members working outside the office headquarters or our office location use the VPN.
The main aspect that I deal with is URL blocking and web access. I don't work with other aspects of this firewall.
How has it helped my organization?
It has upscaled our security posture, especially regarding external connectivity, because any access or connection from the company has to go through the Fortinet FortiGate firewall. It's doing a pretty good job. We do not have any complaints there.
Anything that we don't want to allow is not coming in. Anything we want to allow is not being blocked. We always have the granular control where we can block malicious IPs or subnets if needed.
Geofencing allows us to limit the countries from which we allow IP connections. There are many features that I may not even know or haven't explored, but in general, Fortinet FortiGate is doing a pretty good job for us.
What is most valuable?
The web controls are what I appreciate about Fortinet FortiGate. We have extensive controls over areas where we could block external-facing IPs, external URLs. We can do geo-fencing with the firewalls, which is a good feature.
What needs improvement?
There are too many updates coming for VPN, and the VPN keeps disconnecting frequently, which I find problematic. It does what it's supposed to do, but I practically face reconnection issues with the VPN.
Regarding the Fortinet FortiGate firewall, I don't have any input. My scope is limited.
For how long have I used the solution?
I have been using Fortinet FortiGate for around three years.
What do I think about the stability of the solution?
Fortinet FortiGate is stable. We haven't seen any latency issues related to it, though we do experience latency from ISPs.
What do I think about the scalability of the solution?
I would rate the scalability as eight out of ten based purely on my exposure to security controls relating to URL blocking and website access.
How are customer service and support?
I haven't had a chance to work with Fortinet FortiGate technical support, but from my colleagues' experience, they say the Fortinet FortiGate people are easy to reach but hard to schedule time with. It's not as easy as having the Fortinet FortiGate engineer on the call and getting other teams involved; it requires careful arrangements to join in with the Fortinet team. I would give their support a neutral score of maybe five.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I don't know why we switched to Fortinet FortiGate from Juniper; it's a management decision.
How was the initial setup?
I was not involved in the deployment. I think it's not that difficult; there's no complexity involved as long as we are clear on what we want to do.
We have it on both cloud and on-premises.
What was our ROI?
I was not part of the team that implemented it. I don't know how much they invested, but it would be worth the investment.
What other advice do I have?
My overall experience with Fortinet FortiGate rates as eight out of ten.
A solid firewall with straightforward management and robust capabilities
What is our primary use case?
We primarily use Fortinet FortiGate as endpoint firewalls for our campuses. Nothing too extravagant, just providing access out and limiting access to certain applications and restricting unauthorized access from external sources. I have recently been using it also as the controller for the wireless access points.
What is most valuable?
It is pretty straightforward to manage and has robust capabilities. I appreciate that Fortinet FortiGate can be a central controller for other Fortinet products, such as switches and access points. I have used its VPN abilities a little bit, but not a great deal. I appreciate that it has some SD-WAN capabilities, though I've only used that to a limited degree. It is a solid, usable, reliable solution.
What needs improvement?
It's one of the more expensive brands.
FortiManager has not been my favorite. I don't use it and cannot say I really care for FortiManager for managing the firewalls. I primarily just access and manage the firewalls individually. Nothing else particularly comes to mind, as it has been a pretty good experience.
For how long have I used the solution?
I have about four and a half years of experience with Fortinet FortiGate.
What do I think about the stability of the solution?
The stability has been very good. I have had very few issues. I had one unit that required some reboots and eventually needed a factory reset. But outside of one issue, I've never had stability issues or problems with them going down or disconnecting or having other issues. They have been very stable and reliable.
What do I think about the scalability of the solution?
I have experienced no scalability problems thus far. We expand out with other campuses as needed. If there are any scalability problems, I think that would probably be with making FortiManager a little bit better. Otherwise, scalability is fine.
We are a medium-sized business with 17 campuses. We plan to increase its usage. We'll probably continue with FortiGate for any other campuses that we extend out to, as well as keeping them when we do our hardware refresh.
How are customer service and support?
Fortinet FortiGate has very good support. I've been able to contact them on a couple of things for FortiGate and other products, and I've never had an issue. They've always been polite and helpful and worked to get me to solutions. I've had a good experience with Fortinet support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've always had Fortinet FortiGate in place, so I don't have a previous firewall here to compare it to, but it has basically done its job. It's manageable, and it has not created a lot of problems. Only once, I had to call their support to apply a patch update across a couple of them. One of the best features is that it does not require a lot of extra attention for me to fix problems. It's not a problem generator, so that's probably the best quality.
How was the initial setup?
I've set up several Fortinet FortiGate firewalls, and it's a pretty straightforward setup. I haven't ever really had any particular issue with getting them in place.
It's deployed physically at the locations for our campuses. To deploy one, it takes approximately an hour to program and then another hour or so to install. It can get deployed within three hours.
Just one person can manage Fortinet FortiGate; I'm able to manage everything by myself.
What about the implementation team?
The implementation was done by me, one person. Sometimes I need to walk through someone else to physically install it because it might be at a site remote from me. If I'm not physically there, it requires a second person. However, if that was not the case, I could do it as a single person.
What's my experience with pricing, setup cost, and licensing?
It's one of the more expensive brands.
The 100 series costs around $4,000. They are similar in pricing to what you might get from Cisco solutions and probably other similar ones. They're not more expensive than other similar solutions, but they're certainly not cheaper either.
What other advice do I have?
The advice is to go ahead and try it out and see how it works. The product speaks for itself.
I would rate Fortinet FortiGate a nine out of ten, as I always prefer to leave a little bit of room for improvement.
Which deployment model are you using for this solution?
Ease of setup and cost-effectiveness but support needs improvement
What is our primary use case?
Fortinet FortiGate is used on three separate sites: one in Tehachapi, one in Simi Valley, California, and one in Memphis, Tennessee. I work in distribution with Fortinet FortiGate.
What is most valuable?
The primary feature I appreciate about Fortinet FortiGate is the ease of setup. It's more affordable than Cisco and very configurable. When discussing configurability regarding Fortinet FortiGate, I don't have to download modules to have features such as IPSec VPN or SSL VPN - it's already there. Most of the popular features are pre-installed and I only need to configure them, unlike with MikroTik where I have to download components that may not work, and with Netgate, I can't install everything I want without uninstalling other packages.
Fortinet FortiGate is very competitive compared to Palo Alto Networks and Cisco; they are better priced than both competitors. On average, Cisco would be 10% to 20% higher than Fortinet FortiGate, and the same applies to Palo Alto.
What needs improvement?
The AI with Fortinet FortiGate is not very well integrated on their devices, and their cloud infrastructure is not as good as Cisco's.
The support is inadequate. The support staff I have dealt with lately are very rude. Some support staff are not up-to-speed with the technology. They basically read a script. If they don't know how to fix an issue, they send me to another engineer.
For how long have I used the solution?
I have used Fortinet FortiGate since 2012.
How are customer service and support?
The support is inadequate. The Fortinet FortiGate support staff I have dealt with lately are very rude and some of them are not up-to-speed with the technology; they basically read a script. If they don't know how to fix an issue, they send me to another engineer. The last representative I had to deal with was very rude to me.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I wasn't involved in the decision of picking Fortinet FortiGate, however, before we switched over, we were using SonicWall firewall appliance.
How was the initial setup?
I was part of the initial setup of Fortinet FortiGate. When it was originally set up, on a scale between one to ten, with ten being really easy to set up, I would rate it about an eight or nine.
When we first deployed Fortinet FortiGate, it was just me, and one person could actually deploy it in three sites, so it's relatively easy.
Once we deployed the last time, we actually moved our whole management of it to a third party. They manage our Fortinet for us now. It's supposed to be easy, however, during the last deployment, when they upgraded us, there was some project management snafu. That said, that's not a Fortinet issue. When I was deploying it, it was relatively easy.
What's my experience with pricing, setup cost, and licensing?
Currently, we are paying about $1,500 a month for three sites. We have a company that leases the equipment from Fortinet FortiGate, configures it, and I tell them what features I want on and off and how to secure it. We paid about $1,500 on the last contract, and it's probably going to go up this year.
Which other solutions did I evaluate?
I've also evaluated other options. Other than price, Cisco has a better cloud management infrastructure, while Palo Alto has better security features such as deep packet inspection algorithms and AI integration on their devices.
What other advice do I have?
I would recommend Fortinet FortiGate if you have a small to medium business, which we have. For a large business with multiple campuses, Fortinet FortiGate is probably not going to work for you.
On a scale of one to ten, I give this solution a rating of seven.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Ensures business continuity with reliable internet connectivity and robust security features
What is our primary use case?
We are using it for perimeter security. By implementing Fortinet FortiGate, we wanted to have secure internet access to our network and prevent cyber risks.
How has it helped my organization?
The content filtering and URL filtering capabilities, along with packet content filtering, are very good. It helps us restrict internet traffic during working hours to legitimate work-related traffic. Workers are only able to access social media, YouTube, and similar sites after work hours.
It helps in protecting the edge significantly because we are able to determine what must be accepted and what must not be accepted. We also have FortiAnalyzer, which is the log analyzer for Fortinet FortiGate. Being AI-driven, it helps us see what is happening and new emerging threats quickly. We are able to make the necessary interventions to protect the network.
We are using QRadar as a SIEM, and Fortinet FortiGate integrates with it seamlessly. FortiAnalyzer picks all logs from Fortinet FortiGate, integrates with QRadar, and allows us to see everything. It also integrates beautifully with our EDR from WithSecure.
It also helps reduce power consumption. Fortinet FortiGate is a greener listing in terms of power consumption.
What is most valuable?
Stateful packet inspection is valuable. It also does SSL packet inspection. It is able to provide a VPN for remote users with secure connectivity. Being a next-generation firewall, it helps.
It has been able to host internet feeds from two different ISPs, with one as a backup. We've two internet services on Fortinet FortiGate. We have been able to deploy it in a high-availability mode. We have redundancy. When there is a problem with one, the other picks up quickly, ensuring business continuity.
What needs improvement?
I wish that they could integrate zero-trust technology into Fortinet FortiGate. I am not sure whether it has been done already, but if they could implement that, it would help significantly.
For how long have I used the solution?
I have been using it for about ten years now.
How are customer service and support?
Their support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I didn't use any similar solution previously.
How was the initial setup?
I wasn't involved in the recent deployment.
It was quite quick. The last deployment was more of a migration, where we migrated from an old platform to a new platform. It was a matter of hours because the configs had been backed up. In eight hours, we were done completely.
What about the implementation team?
We had two people from my side and two from Fortinet's side.
What was our ROI?
If we look at the average revenue loss due to downtime, even if I conservatively put it at $10,000 an hour, we have paid back the investment within six months.
Compared to a sister company that did not take security seriously and lost significant money through ransomware attacks and outages, we have not experienced a single successful ransomware attack. In one instance, we were able to thwart an attack by detecting the initial steps quickly through EDR and FortiAnalyzer. We saw the footprints and stopped it before it reached the encryption phase of the ransomware attack.
The analysis being AI-based helped us quickly pick up unusual activity. Once alerted, we were able to quickly identify the affected nodes, isolate them, and stop the attack.
It has reduced the total cost of ownership by 10%.
What's my experience with pricing, setup cost, and licensing?
For the performance that we get, the price is reasonable. There are cheaper options, but they may not deliver the same kind of performance that we want. For the performance they provide, the price is acceptable.
What other advice do I have?
Currently, there is a project we are doing to converge OT and IT using Fortinet FortiGate, because of the cluster we have. Fortinet FortiGate is going to broker the convergence between IT and OT. We want to make the convergence one-way, with only read-only data coming from OT into IT.
They keep bringing new versions and firmware updates, making sure that their products are always relevant. They are always providing what the industry needs.
We have implemented FortiAnalyzer. We are also looking seriously at FortiIdentity to help us with enterprise single sign-on and multi-factor authentication. Because we already have Fortinet FortiGate in the system, we are seriously considering other Fortinet solutions.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Integrated security solution is effective but support can be better
What is our primary use case?
We are using it for the data center firewall and perimeter firewall facing the Internet, which are my main use cases for Fortinet FortiGate.
What is most valuable?
The combined license for the network, the next-generation firewall, and the integration with SD-WAN for all branches are what I consider to be the best features. It's effective for multi-branch customers.
SD-WAN has had a positive impact by reducing the operational costs in terms of headcount and management. It has had an impact on the network performance. It reduced the operational, Internet connection, and MPLS costs. With a combined solution, there is no need to put a specific firewall to secure the connection. It's like a single box.
What needs improvement?
Performance on the box and technical support are areas where Fortinet FortiGate can be improved. In their datasheet, they put the throughput as huge, but once you enable all the features of the box, the performance is impacted dramatically. In reality, it will be 20% to 30% of what they have mentioned in the datasheet.
For how long have I used the solution?
I have worked with FortiGate from a design perspective for almost ten years.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
It's scalable. They are providing a good number of ports; there's no need to put a switch to connect to the appliance itself.
How are customer service and support?
I would rate technical support from Fortinet a five out of ten. To escalate the case severity from three to one, you need to have the account manager engaged to accelerate and get the technical people involved. It's not like other competitors who have premium support 24/7.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used to perform the same function by placing a router and a firewall to secure the connection. It required multiple vendors and multiple boxes, which was a huge engagement from the operational perspective and investment-wise. Now, a small firewall with SD-WAN features can handle the entire situation, including connection with the branch, encryption, and security.
How was the initial setup?
It's user-friendly deployment because they have an enhanced dashboard to manage and implement, not requiring the CLI or command line interface, which needs deep study. They have a GUI that is user-friendly and attractive.
What about the implementation team?
We are system integrators, and our delivery team implements the project for deployment.
What was our ROI?
Reducing the operation cost and reducing the internet connection and MPLS cost has been my evaluation of changes in return on investment after implementing Fortinet solutions for SD-WAN and hybrid workforce.
What other advice do I have?
I would rate Fortinet FortiGate a seven out of ten overall.