Fortinet FortiGate (BYOL) Next-Generation Firewall logo

    Fortinet FortiGate (BYOL) Next-Generation Firewall

    Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate firewall includes all of the security and networking services common to FortiGate physical appliances.

    Ratings and reviews

    4.3
    80 ratings
    3 star
    2 star
    1 star
    56%
    44%
    0%
    0%
    0%
    16 AWS reviews
    |
    64 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (80)
    Rameshprabhu Selvaraj

    Centralized gateways have simplified secure global access but still have needed automation features

    Reviewed on Jul 21, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Fortinet FortiGate-VM is to use it as a firewall for protecting the global gateway, and we also use it as a proxy connection for internet access outside our organizations.

    A specific example of how we use Fortinet FortiGate-VM as a firewall or proxy in my organization is that we have multiple airports across the globe and provide internet access through this firewall. We configure a proxy IP address in Fortinet FortiGate-VM, and that IP is given to the customer. Basically, they configure the proxy IP on all the PAC files of the workstations, which send the traffic to these proxy IPs. Once the traffic reaches Fortinet FortiGate-VM, it verifies the policies, and only the permitted ones will be allowed. We also do complete inspection of the traffic and then permit that to the internet.

    What is most valuable?

    Fortinet FortiGate-VM offers a completely useful dashboard where we monitor the complete health checks in one single pane of glass. Fortinet FortiGate-VM's user interface is much friendlier than other firewalls, and the certificates are quite easily configured.

    The dashboard of Fortinet FortiGate-VM gives the complete health status of the firewall, measuring CPU utilization, the firewall primary and secondary status, and traffic utilization. Any problematic issues are immediately flagged in the dashboards. Furthermore, certificates are quite automated, as we have all certificates on Fortinet FortiGate-VM which are automated with another Python script, making modifications and updates easier than on other firewalls.

    Fortinet FortiGate-VM has positively impacted our organization as it is quite user-friendly to access and easy to deploy. Configurations are pretty straightforward to analyze, study, and configure as well, and the deployment is much easier than with other firewalls.

    What needs improvement?

    I would like to see an SD-WAN connection for Fortinet FortiGate-VM, which would provide much more automation.

    For improvement in Fortinet FortiGate-VM, I would suggest adding many more features such as SD-WAN. It would also be beneficial if traffic monitoring could be simpler to use, allowing for detailed insights into what is happening within the packets at a packet level.

    I would appreciate features such as Python integration inside Fortinet FortiGate-VM so that the APIs are easier to script with external scripting languages.

    For how long have I used the solution?

    I have been using Fortinet FortiGate-VM for the past three and a half years.

    What do I think about the stability of the solution?

    Fortinet FortiGate-VM is quite stable. I have not had any problems, and it is easy to do OS upgrades and other user-friendly upgrade processes.

    What do I think about the scalability of the solution?

    Fortinet FortiGate-VM's scalability is quite user-friendly, requiring only access.

    How are customer service and support?

    Fortinet FortiGate-VM's customer support is good. We have raised multiple TAC cases for support with VM issues impacting Fortinet FortiGate-VM performance, and in many instances, they helped us rebuild or understand issues with interfaces not coming up in virtual environments.

    Which solution did I use previously and why did I switch?

    We previously used third-party solutions such as Zscaler, but switching to our own product saves money and is easier to manage as well.

    What was our ROI?

    I have seen a return on investment with Fortinet FortiGate-VM. It acts as a proxy for many customers, which saves time and resources by facilitating internet access. It is completely user-friendly to manage, and the resource utilization on Fortinet FortiGate-VM is well-suited for all the customers.

    What's my experience with pricing, setup cost, and licensing?

    I am not involved in the pricing and costs associated with Fortinet FortiGate-VM, as those are handled by the CFO. We are in operations, and we just access the product as it is and take care of the service level agreements.

    Which other solutions did I evaluate?

    Before choosing Fortinet FortiGate-VM, we analyzed multiple partners such as Palo Alto and Zscaler to use as proxies and to secure the firewall, but since our requirements do not call for immense utilization, we chose Fortinet FortiGate-VM, which meets our needs effectively.

    What other advice do I have?

    Fortinet FortiGate-VM is deployed in our organization in a private cloud across the globe, where we have our servers deployed. Our servers are running on ESXi hosts, and Fortinet FortiGate-VM instances are mostly kept on virtual machines on those servers across the globe, acting as gateways across different geographical locations such as continents.

    We use Equinix data centers in Germany and the US for our private cloud setup.

    Regarding Fortinet FortiGate-VM's AI capabilities, we have not used them so far, but we look forward to having some features shared with us so that we can benefit from them. Concerning the accuracy and reliability of the output from Fortinet FortiGate-VM's AI capabilities, we have not used them yet, but we would appreciate understanding the product more through information or knowledge shared with our company to increase our awareness.

    My advice to others looking into using Fortinet FortiGate-VM is that it is much user-friendly to access the UI and offers additional stability. Fortinet FortiGate-VM's policies are quite easy to configure and operate. However, we would benefit from some additional features, such as SD-WAN and APIs, that can help automate processes with scripts externally to manage multiple devices simultaneously.

    Fortinet FortiGate-VM still lacks some more features and has room for improvement in user-friendly traffic inspection. Additionally, it would be beneficial to manage multiple instances of Fortinet FortiGate-VM from a single pane of glass. I appreciate the support they offer and look forward to improved features such as single pane of glass management for device access and enhanced scripting capabilities. I give Fortinet FortiGate-VM a rating of seven out of ten.

    Naresh Chintala

    Centralized policies have improved secure VPN access and restricted unapproved web applications

    Reviewed on Jul 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our main use case for Fortinet FortiGate-VM is for SSL VPN connections, web filtering, and application controls. We are using EPS and Fortinet FortiGate-VM, and we segregate the policies in this organization by not allowing unacceptable web applications such as WhatsApp and Facebook.

    A specific example of how we use web filtering and manage the VPN features day-to-day is that we maintain it according to email requests from end-users. They send mail to their team managers, and we approve it for particular end users. We maintain day-to-day activity in these firewalls and have generated logs including local logs, forward logs, and screenshots. When any IPS or IDS triggers in our firewall, we resolve that with the particular end user and maintain communication through email notifications.

    Fortinet FortiGate-VM is deployed in our organization on-premises only. We do not have any private or public cloud deployments. We maintain this firewall for our security purposes.

    What is most valuable?

    Our main valuable features are SSL VPN connections, web filtering, and application controls. We segregate policies in this organization by not allowing unacceptable web applications such as WhatsApp and Facebook.

    Fortinet FortiGate-VM has positively impacted our organization by improving both security and productivity. We are currently using the FortiGate firewall 100F model.

    What needs improvement?

    Fortinet FortiGate-VM's AI capabilities are good, but they could be improved a bit for security purposes. It is easy to manage, but it will be difficult to maintain compared to Palo Alto.

    For how long have I used the solution?

    We have maintained Fortinet FortiGate-VM for the last three years.

    What do I think about the stability of the solution?

    Fortinet FortiGate-VM is stable.

    What do I think about the scalability of the solution?

    Fortinet FortiGate-VM's scalability is very good. The online support is also very good. Previously, we had many tickets, and they resolved our problems in a timely manner.

    How are customer service and support?

    The customer support for Fortinet FortiGate-VM is very good.

    Which solution did I use previously and why did I switch?

    Previously, I have worked with Sophos and Palo Alto firewalls.

    What was our ROI?

    I have seen a return on investment with this firewall. Money was purely saved with this firewall because compared to other vendors, it is very reasonably priced with reasonable licensing costs. We maintain Fortinet FortiGate-VM easily, which is why I recommended this firewall.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Fortinet FortiGate-VM is that licensing is very reasonable. We recently upgraded our licenses with a three-year extension license that we purchased for approximately four lakh.

    Which other solutions did I evaluate?

    Before choosing Fortinet FortiGate-VM, we evaluated other options including Check Point and Palo Alto.

    What other advice do I have?

    The advice I would give to others looking into using Fortinet FortiGate-VM is that there is better pricing and better support for this firewall. We recommended it to other organizations and to some of our colleagues.

    For security purposes, we have triggered it when malware emails come to our end users, and at that time, we trigger to the peer-to-peer security. For email spam, we segregate that URL, copy-paste it into this firewall, and there is no trigger for any malware. It is not a difficult task for our end because Fortinet FortiGate-VM is easy to manage.

    Regarding firmware upgrades every few months, there is a significant difference compared to Sophos or Palo Alto. You can easily trigger web policies, application policies, and user-based policies. It is very easy compared to previous firewalls. Fortinet FortiGate-VM is the best for practice purposes and for live use. You have to maintain firewall notifications and related tasks.

    We maintain ISO guidelines and step-by-step documentation. We are implementing additional applications in our organization, such as Office 365, which is completely online. We maintain that particular URL so we can allow end users access. For these triggers and web applications, we are using Fortinet FortiGate-VM. I would rate this product an 8 out of 10.

    AkshayPawar

    Secure remote access has protected our hybrid cloud and simplifies firewall policy management

    Reviewed on Jul 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Fortinet FortiGate-VM for firewall purposes including traffic allow and deny functions, along with all related firewall policies, VPN, IPsec VPN, SSL VPN, and security purposes.

    Fortinet FortiGate-VM firewall is deployed in the environment for security purposes to protect the outside domain from the internet network to the inside network. Additionally, Fortinet FortiGate-VM VPN client is used for VPN purposes including SSL VPN. Connections to branches are established via IPsec.

    Use cases include IPsec tunneling and VPN for connecting all users as clients. Fortinet FortiGate-VM is also used to protect the outside network. Multiple firewall policies have been created for blocking outside internet traffic to the inside LAN network.

    What is most valuable?

    Fortinet FortiGate-VM offers valuable features including SSL VPN, FortiWAF, and FortiManager.

    FortiWAF is most valuable in the environment to protect web-related traffic. VPN and SSL VPN are also valuable because there are over a thousand users connecting remotely to the data center.

    Fortinet FortiGate-VM protects the environment from the outside and will protect the data center from external threats. It automatically detects signatures that are malfunctioning. When intrusion protections are used, outside domains from countries such as China and Russia are blocked to protect the inside network.

    What needs improvement?

    Regarding Fortinet FortiGate-VM improvements, there is no current specific suggestion. However, there are multiple upgrades available, and recommendations are received every month. This creates a very difficult situation regarding getting downtime for upgrades. The suggestion is to create a more stable software product so that upgrades are not required every month or within months. If a more refined product is created, downtime or continuous upgrades would not be necessary.

    Overall experience is very good, but continuous CVEs require upgrading the firewall to overcome vulnerabilities. The suggestion is to work toward overcoming vulnerabilities to reduce the frequency of upgrades. Due to continuous upgrades required for security patches, the rating given is nine instead of a higher number.

    For how long have I used the solution?

    I have used Fortinet FortiGate-VM for the last five years.

    Which solution did I use previously and why did I switch?

    Different options were available before. Previously, Sophos was used, but Sophos had some limitations, which is why the transition was made to Fortinet FortiGate-VM.

    Which other solutions did I evaluate?

    Palo Alto is used in parallel as an alternative solution. However, Fortinet FortiGate-VM is preferred as it is user-friendly.

    What other advice do I have?

    The interface is excellent and very useful for troubleshooting. Configuration is very user-friendly and is appreciated when compared with other firewalls. The dashboard of Fortinet FortiGate-VM is valuable for troubleshooting, monitoring, and all functions can be performed on the same device.

    FortiGate-VM AI is a new feature that has not had time to be fully explored, but there is anticipation that it will be helpful.

    Fortinet FortiGate-VM is user-friendly and can be handled by anyone. The user interface and dashboard are valuable for troubleshooting and monitoring. Fortinet FortiGate-VM is recommended for use.

    This review has been rated nine out of ten.

    Alexander Jakober

    Reliable virtual firewalls have simplified troubleshooting and improved 24/7 client protection

    Reviewed on Jul 06, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Fortinet FortiGate-VM is using them as standard firewalls for our clients or as a virtual firewall. For one of our clients, we have an Azure environment, and for the firewall, we just have Fortinet FortiGate-VM installed virtually, and we have a site-to-site tunnel to their main campus. Fortinet FortiGate-VM is deployed in our organization both in the public cloud and on-premises.

    What is most valuable?

    The best features Fortinet FortiGate-VM offers are how easily manageable it is and overall, it just provides a better firewall experience than what I have used in the past. It offers threat protection, web filtering, and all the standard security features that you would expect a firewall to have, but it puts them into the web GUI, making it much better than I have seen in other circumstances. Additionally, troubleshooting is much easier than with Cisco Meraki, which I dislike a lot; Fortinet FortiGate-VM just seems to be much easier to troubleshoot complex issues.

    Compared to Meraki, Fortinet FortiGate-VM lets me get into logs a bit easier; whereas Meraki does not provide the whole picture, and sometimes I actually have to create a troubleshooting ticket with Meraki for them to be able to see into the back end of my system, whereas Fortinet FortiGate-VM shows me everything, absolutely everything.

    Fortinet FortiGate-VM has impacted my organization positively by providing us with the reliability that we need in firewalls. Basically, clients are relying on these firewalls for their internet 24/7, and Fortinet FortiGate-VM has supplied that to us, giving us a sense of relief knowing that Fortinet FortiGate-VM is just going to work.

    A specific example where Fortinet FortiGate-VM's reliability made a difference for our team or clients is that we are constantly having power issues at these clients because their infrastructure is not really set up super reliably, but Fortinet FortiGate-VM has failed over quite well. Whether it is high availability or failing over to the secondary WAN, it just works.

    I can definitely attest to time saved; engineers have spent significantly less time on setting up and troubleshooting and dealing with issues on Fortinet FortiGate-VM compared to other firewalls.

    What needs improvement?

    I think Fortinet FortiGate-VM can be improved. There is not anything about the interface, updates, documentation, or support that I wish was different; support has been good, and documentation has been good. I cannot really think of anything off the top of my head.

    One small thing I wish would improve is when I am going through event logs, it defaults to my cloud environment, and I have to switch it over to look at the local disk. That is a small thing, but every time I am looking at event logs, I have to switch it over, so it becomes annoying sometimes.

    For how long have I used the solution?

    I have been using Fortinet FortiGate-VM for about four years now.

    What do I think about the stability of the solution?

    Fortinet FortiGate-VM is indeed stable.

    What do I think about the scalability of the solution?

    I have tested the scalability of Fortinet FortiGate-VM, and it seems to work fairly well. We have not necessarily used it in practice yet because we do not have to, since a lot of our clients are smaller and only have one office. However, we use the management portal to get a good overview of all the clients, so in that respect, it works fairly well.

    How are customer service and support?

    The customer support for Fortinet FortiGate-VM is good; it has been pretty standard, and they are fairly quick to address tickets and respond. I have not really had a bad experience yet.

    Which solution did I use previously and why did I switch?

    We have switched from Meraki to Fortinet FortiGate-VM just because, as I mentioned earlier, we prefer Fortinet FortiGate-VM much better for troubleshooting logs and setting up firewall policies. It is just a much better experience and provides much more granular detail that is significantly better than Meraki.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is fairly typical. We go through a third-party vendor that gives us a quote and prices it out for us, along with a little bit of a discount, but it seems to be fairly standard.

    Which other solutions did I evaluate?

    Before choosing Fortinet FortiGate-VM, we did evaluate other options, including some Palo Altos, but we just did not prefer the GUI layout, and Fortinet FortiGate-VM just looked a lot simpler and easier to manage.

    What other advice do I have?

    Compared to Meraki, Fortinet FortiGate-VM lets me get into logs a bit easier; whereas Meraki does not provide the whole picture, and sometimes I actually have to create a troubleshooting ticket with Meraki for them to be able to see into the back end of my system, whereas Fortinet FortiGate-VM shows me everything, absolutely everything. I do not have anything else to add about the features; that is about it.

    I would rate Fortinet FortiGate-VM a 10 on a scale of 1 to 10. I give it a 10 because it is just a perfect combination of web GUI, troubleshooting capabilities, and reliability. It just makes it that perfect 10 compared to other firewalls that I have used.

    My advice to others looking into using Fortinet FortiGate-VM is to ensure they understand how to troubleshoot, set up their policies, and configure the firewall correctly. There is a small learning curve on the individual specific details of Fortinet FortiGate-VM, but once you figure that out, it is fairly simple. Fortinet offers extended knowledge training sessions, so people can watch their trainings on Fortinet FortiGate-VM, which are fairly good. My overall rating for this product is 10 out of 10.

    V. Rahul

    Branch connectivity has improved and centralized security management protects distributed sites

    Reviewed on Jul 06, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Fortinet FortiGate-VM involves several customers in our IBM Cloud, where we have more than 300 premium accounts. They will use it for their infrastructure and enterprise management, placing these FortiGates at their branch locations and a few at the perimeter edge. Essentially, the use case is for connecting one branch to another branch, where they build IPsec tunnels between two Fortinet FortiGate-VM instances. Security policies and UTM features play a crucial role here, mainly for connectivity between different branches and securing the enterprise environments.

    When managing those branch-to-branch connections with Fortinet FortiGate-VM, I find it good and easy to use, similar to Palo Alto. I haven't faced any difficulties because Fortinet FortiGate-VM has a clean UI and CLI. For every firewall, the CLI is good, but if you compare UIs in the market, Fortinet FortiGate-VM and Palo Alto have better UIs compared to Check Point or Juniper. Overall, I find it easy to use.

    What is most valuable?

    Fortinet FortiGate-VM offers several standout features, with one being its next-generation firewall capabilities that include UTM features. The security processing unit is good in Fortinet FortiGate-VM, and its IPS and VPN SSL inspection help a lot. When comparing price with performance, it has an edge because other vendors such as Palo Alto charge somewhat higher.

    Fortinet FortiGate-VM also has a built-in SD-WAN feature, while other devices often require a separate license for this feature. High availability and threat intelligence are common across firewalls, but I find it convenient that you can open a console session directly from Fortinet FortiGate-VM UI, allowing simultaneous access to the CLI. The console feature saves time because you don't need to log in to PuTTY and create another session; you can access the console directly from the GUI. This is particularly valuable in busy environments.

    The SD-WAN feature is also crucial as it automatically selects the best performance link out of multiple ISPs based on latency and packet loss, eliminating the need for manual BGP failover. Many customers, including those at NTT and MicroLand, use Fortinet FortiGate-VM SD-WAN, which I have observed. In terms of features, one great aspect is that in security policies, you can also add NAT.

    While many elements are common across firewalls, the ease of use of Fortinet FortiGate-VM is significant. A vendor's ability to create an easy-to-navigate device can set them apart. Among the vendors I've seen, only Fortinet and Palo Alto maintain a clean UI, making navigation and creation straightforward. Fortinet FortiGate-VM has positively impacted my organization because the number of bugs reported is less compared to other vendors. For instance, in other vendors such as Palo Alto or Juniper, numerous bugs require fixing in upcoming releases.

    However, Fortinet FortiGate-VM releases are stable, so I don't need to frequently upgrade unless a critical vulnerability is identified. I usually upgrade once or twice a year, and the minimal number of bugs is positive, as this reduces work pressure involving critical integrations with other devices.

    What needs improvement?

    The UI of Fortinet FortiGate-VM could improve further. While I find the UI good, it has potential for enhancement. The CLI is very effective, along with VDOM configurations and root access. On the feature front, I don't see a need for new features in the VM because every device has different rules and limitations. However, they can definitely focus on improving the UI.

    While none of the customers I've interacted with have provided feedback on the UI, I believe Fortinet should take such feedback directly from their customers. From my perspective, having worked with Palo Alto, Juniper, and Fortinet FortiGate-VM, I find Palo Alto's UI cleaner, thus suggesting Fortinet could benefit from UI improvements.

    For how long have I used the solution?

    I have been using Fortinet FortiGate-VM for the past two years, starting from June 2024.

    What do I think about the stability of the solution?

    Fortinet FortiGate-VM has positively impacted my organization because the number of bugs reported is less compared to other vendors. For instance, in other vendors such as Palo Alto or Juniper, numerous bugs require fixing in upcoming releases. However, Fortinet FortiGate-VM releases are stable, so I don't need to frequently upgrade unless a critical vulnerability is identified. I usually upgrade once or twice a year, and the minimal number of bugs is positive, as this reduces work pressure involving critical integrations with other devices.

    With fewer bugs and more stable releases in Fortinet FortiGate-VM, I observe that many people are transitioning from different devices such as Palo Alto and Check Point to Fortinet FortiGate-VM. I've seen many recent migrations among my customers, resulting in a lower number of cases reported. For the Fortinet FortiGate-VM environment specifically, the stability is notable, with few issues unless they involve configuration or external connectivity problems, leading to generally stable usage.

    What do I think about the scalability of the solution?

    The scalability of Fortinet FortiGate-VM is good; it handles over a hundred policies and can manage a large amount of traffic effectively.

    How are customer service and support?

    Customer support for Fortinet FortiGate-VM is overall good, but there is room for improvement, particularly since you can't directly raise a Severity 1 ticket. Usually, you must initiate a chat to request raising it to Severity 1, which they could improve, along with prioritization during case handling. Nevertheless, case management is generally effective.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for Fortinet FortiGate-VM is good overall.

    What other advice do I have?

    My advice for others looking to use Fortinet FortiGate-VM is to migrate slowly. They can start with a small branch location that has an existing firewall and test Fortinet FortiGate-VM for a month. Monitoring how the device handles traffic will help them make an informed decision regarding migrating other locations.

    I don't have any additional thoughts about Fortinet FortiGate-VM before we wrap up, as it offers a wide range of products and performs well, although competition is high and requires ongoing focus on every aspect to maintain its position as a leader. My overall review rating for Fortinet FortiGate-VM is 8.5 out of 10.

    Mehulkumar Prajapati

    Unified security policies have simplified VPN access and optimized multi-tenant cloud management

    Reviewed on Jun 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Fortinet FortiGate-VM is allowing particular VMware subnets in our organization and performing IP NAT translation for cloud environments and virtual machines. We also provide VPN access for two clients to access their internal VMs. Additionally, we created a service based on what customers are looking for, including TCP, IP, HTTP, and other protocols. When customers request access to particular social media applications, we accordingly configure the system according to their requirements.

    Sometimes we also use Fortinet FortiGate-VM as an SD-WAN solution to create templates regarding incoming and outgoing traffic for managing our applications for better performance and scalability.

    How has it helped my organization?

    Fortinet FortiGate-VM has positively impacted our organization by maintaining security with multiple policies for both incoming and outgoing traffic, covering both inside LAN and outside WAN environments. We allow particular subnets we are using in our organization to operate exclusively, while we automatically block and deny other subnets, which helps prevent unauthorized access through Fortinet FortiGate-VM firewalls. This approach also enables us to create specific subnet addresses and services defined for users.

    What is most valuable?

    The best features Fortinet FortiGate-VM offers are the user interface, which is user-friendly and easy to navigate. The GUI allows us to segregate issues efficiently since all features are consolidated into one tab for network, interface, policy, security, policy object, user authentications, addresses, and services, making it very smooth and easy to understand. Another valuable feature is that when Fortinet features such as IDS and IPS are about to expire, the system continuously gives pop-ups reminding us to renew licenses to access these features. This helps us identify and stop potential outages related to sudden license issues. Troubleshooting with Fortinet FortiGate-VM is much easier than with Palo Alto, where troubleshooting is quite difficult.

    For day-to-day logging, the system log feature is where I identify issues regarding particular policies related to the subnet and services. On the dashboard, I can identify problems through system logs. Similarly, we can easily identify CPU graphs showing how much CPU utilization is occurring on our physical or VM firewalls, as well as which processes and users are consuming the most bandwidth, allowing us to manage data transfer effectively.

    What needs improvement?

    Fortinet FortiGate-VM makes troubleshooting easy through its user interface. We can check previous policies and monitor hit counts, allowing us to quickly identify root causes, which is unlike Palo Alto where troubleshooting is complicated. Fortinet FortiGate-VM presents everything in a more user-friendly manner. I recommend that Fortinet provide updates and pop-ups for critical licensing matters.

    For how long have I used the solution?

    I have been using Fortinet FortiGate-VM for six to seven months, and in the past nine months, I have also used it for more than one and a half years.

    What do I think about the stability of the solution?

    Having worked with Fortinet FortiGate-VM for the last three years, I have not encountered any major issues, except for occasional hardware problems such as auto rebooting and CPU utilization spikes that sometimes occur when multiple users log in at the same time, which can create packet latency.

    What do I think about the scalability of the solution?

    Fortinet FortiGate-VM allows us to provide multiple user access to inside applications, enabling users to access the internal network through VPNs. This feature makes Fortinet FortiGate-VM very effective, as we can create virtual machines to manage all clients and environments through its policies.

    How are customer service and support?

    The customer support for Fortinet FortiGate-VM is excellent. During incidents, we can create tech calls with their support team, allowing us quick access and assistance. I would rate the customer support a nine out of ten.

    Which solution did I use previously and why did I switch?

    I am currently using Fortinet FortiGate-VM, but previously in my organization, we used Palo Alto. Based on user interface access, I find Fortinet FortiGate-VM far better than Palo Alto.

    How was the initial setup?

    Before choosing Fortinet FortiGate-VM, we did not evaluate other options and simply opted for it. We were satisfied with the decision, as we already had two to three models existing in our data centers.

    What was our ROI?

    In terms of return on investment, we save time through troubleshooting since Fortinet FortiGate-VM functions as one device, allowing us to eliminate multiple routers. We can manage all routing, switching, and NAT policies within one firewall, which helps us significantly in managing data center operations with fewer employees.

    What's my experience with pricing, setup cost, and licensing?

    Regarding pricing, setup cost, and licensing, the main client I deal with is a reputed company in the market, making it easy for them to afford Fortinet FortiGate-VM compared to Palo Alto, which is much more costly.

    What other advice do I have?

    My selection for a rating of nine out of ten is not based on a specific reason, but there are many factors contributing to it. The features of Fortinet FortiGate-VM are easier to navigate and compatible with other firewalls. Additionally, the continuous introduction of new solutions including SASE, SD-WAN, FortiManager, and FortiLog Analyzer makes Fortinet FortiGate-VM stand out among others.

    I advise others considering Fortinet FortiGate-VM to choose it if they are currently using Cisco ASA or Check Point. If they are using Palo Alto, I suggest switching to Fortinet FortiGate-VM, as it includes everything from SD-WAN and SASE all in one analyzer. With Palo Alto, you need to acquire different products and licenses for comparable features. I would rate Fortinet FortiGate-VM a nine overall.

    AyushShukla

    Centralized egress control has improved cloud security and streamlined Terraform-based operations

    Reviewed on Jun 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I implemented Fortinet FortiGate-VM as the internet egress firewall solution for the Google Cloud landing zone for a major client. We deployed and automated using Terraform and integrated it into a hub and spoke model network architecture. We used Fortinet FortiGate-VM for centralized outbound traffic inspection and worked alongside GCP native components like Cloud NAT, router, and shared VPCs.

    We integrated the high availability structure of Fortinet FortiGate-VM where one appliance was active and one was passive. We integrated it with the internal load balancer, deployed using Terraform. We integrated with Cloud Router, NAT, and Shared VPC and set up custom routes to ensure traffic did not go directly to the internet but through Fortinet FortiGate-VM appliance instead.

    We implemented centralized firewall policy management using Fortinet FortiGate-VM to allow egress traffic for VMs inside GCP to only access patches or certain APIs while blocking all other traffic. We faced initial issues with NIC setups but resolved them through Fortinet documentation and support.

    What is most valuable?

    Logging and monitoring were the best features, followed by traffic inspection and high availability. Fortinet FortiGate-VM allowed us to inspect, control, and log egress traffic while fitting into a hub-spoke landing zone architecture. It provided consistent security policy across environments and allowed granularity for security policies that was not possible with native FQDN control in GCP. High availability features provided resilience and minimized downtime.

    The solution's high availability structure, integration with Terraform, NAT, and GCP, and its ease of managing security policies for outbound traffic significantly enhanced operational efficiency. The reduction in manual deployment effort contributed substantially to our improved operations. Features also include internet egress firewalling, security policies, logging, and monitoring.

    The unexpected integration ease with Terraform allowed for easy deployment of policies. The pay-as-you-go model proved cost-effective. Fortinet FortiGate-VM provided excellent scalability coupled with strong security reinforcement.

    What needs improvement?

    Initial deployment and networking configuration can be complex, especially with GCP. Guided deployment templates for multiple use cases or a compilation of known issues would help reduce implementation time. Better CLI documentation and infrastructure as code support, including comprehensive Terraform examples, would streamline execution.

    Pricing could be more tier-based to accommodate smaller organizations by offering cost-effective options that align with their specific needs. Introducing serverless deployment for cost reduction or simplifying structural upgrades would also enhance customer benefits. Diagnostic tools and well-guided documentation could further aid in troubleshooting and enhance user experience.

    Support should shift away from a blame culture toward a streamlined issue-tracking approach. Enhanced support could further mitigate the complexities experienced during implementation and usage.

    For how long have I used the solution?

    I have been using this solution for five years.

    What do I think about the stability of the solution?

    After initial deployment and routing configuration, Fortinet FortiGate-VM performed reliably with no significant issues. The high availability design ensures resilience, though no enterprise networking solution is completely maintenance-free.

    What do I think about the scalability of the solution?

    Fortinet FortiGate-VM was very scalable, supporting the onboarding of new projects and routing their outbound traffic through the centralized environment. New environments followed the same deployment pattern, allowing easy additions without requiring redesign of the security architecture.

    How are customer service and support?

    The limited interaction I had with customer support was positive. They provided specific guidance pointing to documentation lines. However, I believe there is room for improvement in their approach. Overall, I would rate the support seven to eight out of ten.

    Which solution did I use previously and why did I switch?

    This was a new Google Cloud landing zone deployment. Previously, we relied on native Google Cloud networking components and firewall rules for basic traffic control. As the environment grew, Fortinet FortiGate-VM was introduced to centralize security beyond what native solutions provided.

    How was the initial setup?

    The initial deployment phase and networking configuration can be complex, especially in GCP. Setting up the solution involved designing custom routes and high availability structures with integrations into Google's networking components. We conducted numerous proofs of concept and experiments to understand quirks in the system, such as NIC configuration. Using Terraform for deployment streamlined these efforts.

    What about the implementation team?

    Many higher management leaders were involved in the purchasing or licensing processes. From an engineering perspective, setup cost was mainly implementation rather than the product itself. The organization's focus was on efficient design and automation using Terraform.

    What was our ROI?

    There were substantial operational benefits. Automating Fortinet FortiGate-VM deployment reduced manual effort, making provisioning much more consistent. Deployment time reduced considerably, with reduced configuration errors and a return on investment achieved by enhancing consistency and lowering operational overhead.

    What's my experience with pricing, setup cost, and licensing?

    The primary investment was in designing and implementing the solution. Licensing seemed appropriate for the scale and security requirements, though it was not the lowest cost option for enterprise deployment. Savings stemmed largely from automating the process using Terraform.

    Which other solutions did I evaluate?

    Options including Palo Alto and Cisco were considered, but Fortinet FortiGate-VM offered easier deployment and integration with our existing network structures. Its competitive licensing and automation with Terraform catered well to our architecture and needs.

    What other advice do I have?

    Spend sufficient time on network architecture design before deployment. Automate deployments wherever possible to reduce manual errors and improve consistency. The success of Fortinet FortiGate-VM depends significantly on network planning and security policy validation.

    Ensure that deployments are efficiently automated and that adequate time is spent on planning and designing configurations and routing strategies. This is a crucial step to ensure Fortinet FortiGate-VM's effectiveness and operational value. I would rate this review an eight out of ten.

    Ehab Ali

    Unified security fabric has simplified multi-country deployments and strengthened threat response

    Reviewed on Mar 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I work as a cybersecurity pre-sales consultant and regularly engage with multiple leading vendors, including Cisco, Palo Alto Networks, Fortinet, and F5. My role requires me to quickly evaluate new solutions, understand their technical and commercial value, and position them effectively in RFP responses and customer presentations.

    I have more than 10 years of hands-on experience with Fortinet technologies, particularly FortiGate and FortiGate-VM, extending beyond firewalls to the broader Fortinet Security Fabric. My exposure to Fortinet spans several roles throughout my career—including customer, technical project manager, and pre-sales consultant—which has provided me with both operational and strategic perspectives on the platform.

    Over the past six years, I have worked with three different system integrators across Kuwait, Egypt, and Saudi Arabia, all of which maintained the highest partnership tier with Fortinet. This has allowed me to consistently work on enterprise-grade deployments, vendor engagement, and high-value opportunities across multiple markets.

    How has it helped my organization?

    Having worked with them both as a customer and later as a reseller, the experience has consistently been smooth and positive from both business and technical perspectives.

    What is most valuable?

    FortiGate VM delivers exceptional performance and security with no degradation of service or protection (same features as the HW option).

    As part of the Fortinet Security Fabric, it extends across clouds and distributed locations, mitigating blind spots in virtual infrastructures. FortiGate VM can be rapidly deployed, managed through a centralized platform, and offers a range of purchasing options to suit every need.

    Also, FortiGate VM offers versatile deployment options across both public and private clouds, supporting all major public clouds including AWS, Azure, and Google as well as most hypervisors such as VMware, Hyper-V, and KVM. These deployments enable organizations to create scalable, high-performance firewalls that can be tailored to different virtualized environments and hyper-scale public cloud infrastructures. FortiGate VM integrates seamlessly with various infrastructure as code (IaC) tools such as Jenkins and GitLab, supporting security as code practices.

    What needs improvement?

    Fortinet FortiGate-VM has a suggested room for improvement, like enabling the partners and pushing this as an enablement for partners, along with the sizing tools for the proper selection.

    For how long have I used the solution?

    I have been working with Fortinet FortiGate for more than 10 years.

    What do I think about the stability of the solution?

    In one of my previous deployments, I experienced a delay in Fortinet Security Fabric’s real-time threat response. During an attack, the malicious file was not immediately detected by FortiGuard and was able to pass through both the firewall and FortiMail. Fortunately, a second layer of protection—Symantec endpoint security—successfully blocked it on the workstation.

    This happened a few years ago, so the platform may have improved since then. In general, forming a solid judgment on real-time threat intelligence requires extensive testing across different scenarios. However, at the time, the delayed FortiGuard update was a notable gap, and without endpoint protection in place, the potential impact could have been significant.

    How are customer service and support?

    I would rate Fortinet’s technical support as good overall, particularly due to their strong local presence. Unlike many vendors that assign only one sales and one technical resource per country or region, Fortinet typically maintains a large in-country team of technical sales engineers, SEs, and subject matter experts. This extensive on-ground coverage is a significant advantage, as it often allows customers and partners to obtain guidance quickly through direct contact without the need to open formal support tickets.

    The technical capability and maturity of Fortinet’s local teams are generally very strong, which contributes positively to customer experience and issue resolution speed. However, within the formal ticketing system, meaningful progress on complex or deep technical issues often requires escalation to Level 3 support. Initial Tier 1 responses tend to focus on standard troubleshooting steps or knowledge base articles, which experienced engineers have typically already reviewed. As a result, resolution of advanced issues can depend on successful escalation to more senior technical resources.

    Which solution did I use previously and why did I switch?

    Fortinet would benefit from adopting a more structured customer-enablement program focused not only on driving product sales, but on ensuring customers fully utilize the capabilities of the solutions they have already deployed. At present, this type of proactive, value-realization engagement is not consistently visible in the market.

    Competitors such as Palo Alto Networks offer formalized assessment programs that analyze firewall logs and generate both executive-level and technical reports, highlighting configuration gaps, policy inefficiencies, and unused security features. These reports provide clear, actionable guidance—often down to the individual policy level—allowing organizations to quickly optimize large and complex rule bases.

    While Fortinet offers similar diagnostic and support capabilities, they are not packaged as a structured, partner-driven program, nor are there clear incentives for distributors and system integrators to promote them. Establishing such a program would help customers maximize the value of their investments while improving long-term adoption, customer satisfaction, and platform stickiness.

    How was the initial setup?

    usually, it's complex due to the nature of the implementation, especially if the site is up and operational.

    What about the implementation team?

    What was our ROI?

    The total cost of hardware goes beyond the initial purchase price. It also includes ongoing considerations such as power consumption, maintenance, RMA handling, high-availability design, and the associated cabling and infrastructure.

    These factors can significantly impact the overall cost and operational complexity of the solution.

    What's my experience with pricing, setup cost, and licensing?

    Fortinet FortiGate-VM's pricing is very good. As long as there is competition, they go with 50% + discounts. Their prices are very competitive. However, if there is no competition, they usually go with the standard discount or standard price, which their price list is already available online. This is equal to any other vendor. Unless there is competition, you will not have a decent price.

    Which other solutions did I evaluate?

    Palo alto,

    What other advice do I have?

    Fortinet FortiGate-VM can manage multiple devices using CM for central management. Fortinet Security Fabric automation features are used to generate alerts or automate threat response. Once the firewall detects something, it will send it to the EDR or to the endpoint to FortiClient, and it will block it. If there is a malicious IP or domain, it communicates with the mail gateway or FortiMail and the domain is blocked.

    If the customer is mature enough or the company that is offering the solution implements the integration properly, the Security Fabric works well. The whole idea of selling or implementing the Security Fabric is that it creates added value through integration. Without the integration, without achieving one plus one equals three, there is no added value from this integration. It requires an engineer or someone who wants to enable the feature. Once you read the features and read the data sheet, everything is fancy and beautiful. Once it is implemented and on site, usually people take it very slowly or are afraid of changes or they worry about interruptions, especially if it is a complex environment like banking or similar environments. They get afraid that something might happen in the background that impacts the services. They usually enable the basic features.

    My overall rating for this product is 8 out of 10.

    Hassan Wali Khan

    Virtual firewall deployment has protected data center apps and simplified threat management

    Reviewed on Feb 04, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Fortinet FortiGate-VM is used for virtual machine deployment within data centers to protect applications. Some customers do not want to deploy hardware firewalls due to budget constraints. With a good hypervisor, they can deploy Fortinet FortiGate-VM firewall in their data center as a virtual firewall.

    For example, if you have applications hosted in a data center and do not want to deploy Fortinet FortiGate hardware firewalls due to budget constraints and have a good hypervisor, you can secure your application by deploying Fortinet FortiGate-VM on your hypervisor in the data center to protect the application directly. Traffic comes first to Fortinet FortiGate-VM, and then clean or secure traffic reaches the data center server.

    What is most valuable?

    Fortinet FortiGate-VM is similar to a Fortinet FortiGate hardware firewall, and we can get all the same features. It is a good solution with Fortinet FortiGate-VM firewall.

    Deployment is easy within any hypervisor cloud, whether Citrix Xen, VMware, or Nutanix.

    The threat detection capabilities are excellent. I would rate this as ten out of ten because of the good features that come with the services and FortiGuard connection. You can get signatures every hour, including IPS signatures, anti-malware signatures, web filters, and application filters. These signatures come directly from the firewalls. An additional feature is the ability to create custom signatures in Fortinet FortiGate-VM, such as application signatures and IPS signatures.

    What needs improvement?

    Regarding the solutions, more features need to be introduced. Fortinet FortiGate-VM has FortiWAF features, but they are limited. These features need to be enhanced in Fortinet FortiGate-VM itself. Although Fortinet FortiGate has FortiWAF feature as a standalone feature, more features need to be onboarded into this firewall. Additionally, some features should be offered for free. For example, the minimum comes with two CPU, but at least four CPU license-based or still two CPU should be free.

    For how long have I used the solution?

    I have been using Fortinet FortiGate-VM for the last six to seven years.

    What do I think about the stability of the solution?

    Stability is ten out of ten. Stability and scalability are both ten out of ten.

    What do I think about the scalability of the solution?

    Stability and scalability are both ten out of ten.

    How are customer service and support?

    The technical support of Fortinet FortiGate-VM and Fortinet FortiGate is eight or nine out of ten.

    Which solution did I use previously and why did I switch?

    Regarding Fortinet FortiGate-VM, I do not see any virtual machine of Cisco firewall to deploy in any hypervisor. This is the only time I have seen Fortinet FortiGate-VM with the feature to deploy on any hypervisor. Usually, these features are not available in other vendors.

    How was the initial setup?

    Setup can be completed within ten to fifteen minutes. Operational tasks and maintenance are very easy.

    What about the implementation team?

    Five people, all technical staff, are capable of deploying Fortinet FortiGate-VM.

    What was our ROI?

    Integration capabilities are very good. I deployed and integrated Fortinet FortiGate-VM with Microsoft AD server. Integration is very easy and can be completed within two to three minutes with Microsoft AD or any other third-party servers.

    What's my experience with pricing, setup cost, and licensing?

    Pricing cannot be said to be cheap because the pricing is not fixed. Pricing varies based on the size of the deal. If you have a good size deal, you can get more discount from Fortinet FortiGate team. If you buy a single Fortinet FortiGate-VM, you will not get as much discount from the Fortinet team. This can be marked as six, seven, or eight.

    What other advice do I have?

    Many organizations, enterprises, oil and gas companies, public sector, and commercial sector are all using these firewalls. The banking sector is also using them.

    Automation can be configured in Fortinet FortiGate-VM. For example, if someone logs into Fortinet FortiGate-VM from an IP address, I can receive an email with the user login IP address, username, login time, and date.

    I recommend this one hundred percent if you want to deploy a solution, have budget constraints, and do not want to buy hardware Fortinet FortiGate-VM. I will recommend using Fortinet FortiGate-VM deployed on your hypervisor. I would rate this solution ten out of nine. My overall review rating for this product is nine out of ten.

    reviewer2283873

    Security has improved with deep visibility and zero trust, but performance sizing needs work

    Reviewed on Jan 30, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Network and infrastructure security can be used depending on the environment which a customer has, but it is usually more useful in virtual data center protection. Fortinet FortiGate-VM can protect VM infrastructure, virtual infrastructure, or cloud infrastructure in AWS, Azure, or other cloud vendor providers, as well as virtual infrastructure on premises in your own private data center.

    What is most valuable?

    I would say that it is cheaper than other vendors. In comparison of features, it is at the same level as Palo Alto and Check Point. It is a leader in the Gartner quadrant with the same feature set but at a lower price. However, it also has some weak points that require careful sizing of the solution before using it with all security features switched on, because it has a significant downgrade of throughput capacity when switching on more security features. If you need all features switched on with all signatures and SSL inspection, then you need to check for a higher grade model.

    Fortinet FortiGate-VM provides integration across various environments, which is important especially for integration with domain controllers and authentication services. This is very important nowadays. All other integrations depend on the project and company needs.

    With this solution, you can apply the zero trust concept in place with role-based access to the internet. URL filtering works well, and it is flexible. At the same time, with integration with other security solutions, you can quickly respond to incidents if anything happens. In total, fewer security incidents appear and you can respond more quickly.

    After deployment, you have better visibility. You can see who, where, when, and how, and you can make reports.

    What needs improvement?

    I would say that it is cheaper than other vendors. In comparison of features, it is at the same level as Palo Alto and Check Point. It is a leader in the Gartner quadrant with the same feature set but at a lower price. However, it also has some weak points that require careful sizing of the solution before using it with all security features switched on, because it has a significant downgrade of throughput capacity when switching on more security features. If you need all features switched on with all signatures and SSL inspection, then you need to check for a higher grade model.

    Real-time threat response is better in Palo Alto because they have an embedded machine learning engine which can detect viruses. In Check Point, you have to have a sandbox or be connected to the sandbox to check for unknown threats.

    These are not problems per se, but you need to be more careful and more experienced when choosing this solution. You should not look just at a data sheet, but also look at real tests in the field and load tests from companies who are making them. The best way to choose is to test in your environment, see the capacity and throughput which you need, and then choose the model after a proof of concept.

    For how long have I used the solution?

    Fifteen years.

    What do I think about the stability of the solution?

    If it is sized in a proper way, there would be no downtime. If it is sized in an improper way, there would be questions.

    What do I think about the scalability of the solution?

    It is scalable.

    How are customer service and support?

    I was a tech support person, so I did not have a chance to escalate. I faced issues and fixed them myself. I did not escalate to the second level, so I do not closely work with their support team.

    How would you rate customer service and support?

    How was the initial setup?

    It depends on the project. If you need just an internet connection for a few people, you just plug it in and it is done. You write two rules which allow access and apply basic URL filtering. If it is a data center segmentation solution, you need to plan a lot before you deploy it, and deployment would be complicated with any product. For basic setups for small businesses, it is easy and plug and play. However, for big projects like data center protection, it is complicated with any vendor, not just easy.

    What was our ROI?

    It is difficult to count honestly. When you need a cheap solution, you go for Fortinet. If you have more money, it is a matter of choosing between Android phone or iPhone. Both products are good, but one is a little bit better. If you do not have money to overpay, then you go for the cheaper one. If you have budget, then you can go for a more expensive one.

    What other advice do I have?

    I work with the product both as a customer and as a partner integrator, and also as a reseller.

    There is a significant impact because you see full network visibility from layer three to layer seven, all threats, and all vulnerability exploitation attempts. With SIEM integration, it highlights a lot of data which can be used with PI solutions and also for incident response.

    It is scalable. As for technical support, I was a tech support person, so I did not have a chance to escalate. I faced issues and fixed them myself. I did not escalate to the second level, so I do not closely work with their support team.

    Regarding real-time threat response capabilities, I think they are better in Palo Alto because they have an embedded machine learning engine which can detect viruses. In Check Point, you have to have a sandbox or be connected to the sandbox to check for unknown threats.

    The impact of threat detection on IT security operations is significant because you see full network visibility from layer three to layer seven, all threats, and all vulnerability exploitation attempts. With SIEM integration, it highlights a lot of data which can be used with PI solutions and for incident response.

    As a reseller and a user, the biggest benefit that stands out is that it is cheaper than other vendors. In comparison of features, it is at the same level as Palo Alto and Check Point. It is a leader in the Gartner quadrant with the same feature set but at a lower price. However, it also has some weak points that require careful sizing of the solution before using it with all security features switched on, because it has a significant downgrade of throughput capacity when switching on more security features. If you need all features switched on with all signatures and SSL inspection, then you need to check for a higher grade model.

    Fortinet FortiGate-VM has some embedded features for automation such as tagging and dynamic groups. Using the API, you can respond and integrate with SIEM solutions. However, this requires technical background and work effort.

    My overall review rating for this product is seven out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)