I have experience in deployment for banking processes and at the perimeter of a financial institution. I have experience in configuration for PCI DSS compliance.
Fortinet FortiGate (BYOL) Next-Generation Firewall
Fortinet Inc.External reviews
External reviews are not included in the AWS star rating for the product.
A robust solution with automated threat response and easy setup
What is our primary use case?
What is most valuable?
The best feature of Fortinet FortiGate-VM is the deployment. I applied best practices for deployment with Fortinet FortiGate-VM. By the VPN connection into the site, on-premise and cloud or hybrid for segmentation of level of security, the perimeter and inside zone.
It's very robust. It's a solution that is very complete with accessible support. The feature for deep inspection (DPI) for Fortinet FortiGate-VM is used for generating alerts or to automate threat response.
What needs improvement?
Licensing could be easier to understand.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM for around six years and Cisco for around 10 years.
How are customer service and support?
The support deserves a rating of ten out of ten.
Which solution did I use previously and why did I switch?
I have also worked with Cisco firewalls. The main differences between FortiNet and Cisco include the price, which is very different. The variant of Cisco ASA, Cisco Firepower, is more difficult for configuration. Firepower is more complicated. Fortinet FortiNet is easier to deploy and also less expensive.
How was the initial setup?
I find that the initial setup of Fortinet FortiGate-VM is easy. Of course, I am very experienced in the area of telecom, and this setup and configuration is friendly. I see that other people find Fortinet FortiGate-VM to be user-friendly. The setup and learning curve is short.
What other advice do I have?
I would rate Fortinet FortiGate-VM a 10 out of 10. It is very good.
Expertly manage multiple domains with unique integration capabilities for efficient cybersecurity solutions
What is our primary use case?
I was called regarding a review on Fortinet FortiGate, FortiSOAR, and I mentioned working with it, so it is acceptable for me to answer some questions. I have just initiated one requirement with FortiSOAR. The impact of SD-WAN on the network performance is significant, and SD-WAN is the basic feature today offered by every firewall OEM. Previously, we worked with Fortinet FortiGate for IPsec VPN tunneling, and today we have implemented SD-WAN as well. We are implementers with many customers for whom we have been working. Some customers are big, some are small, but we have been working with many companies. My customers work in varied industries, including banking, finance, manufacturing, and IT, because cybersecurity is the need of the hour. Every company requires it, and firewalls are basic; companies choose either Fortinet FortiGate, Check Point, Palo Alto, or SonicWall. We have integrated SD-WAN capabilities with Fortinet FortiGate for our customers' networks. We have not partnered with any company for that matter. We implement and do the servicing. People purchase, and we do the servicing and integration to their network.
What is most valuable?
One feature of Fortinet FortiGate that I find very unique is the virtual domain, VDOM. The VDOM feature allows you to integrate multiple domains; if you have multiple domains, you can create multiple VDOMs. VDOMs are a feature that is very unique and not available with other competitors. Fortinet FortiGate has that feature, which I really appreciate. Regarding Fortinet Unified SASE, the effectiveness of security policies across multiple locations is managing efficiently with FortiManager. The stability of Fortinet FortiGate is excellent.
For how long have I used the solution?
For Fortinet FortiGate firewall, I have been working for the last 15 years.
What do I think about the stability of the solution?
The stability of Fortinet FortiGate is excellent. It is a very stable product.
What do I think about the scalability of the solution?
It is easy to scale Fortinet FortiGate. There are no problems with scalability.
How are customer service and support?
I had a chance to work with Fortinet support. My impression of the support is really good. It rates 9 out of 10 for support. If you consider it, 10 out of 10 is acceptable. I don't see any challenge with the support center. The support needs to be maintained at a high standard.
How was the initial setup?
Setting up Fortinet FortiGate is really very easy.
What about the implementation team?
People purchase, and we do the servicing and integration to their network.
What was our ROI?
My customers' return on investment after implementing Fortinet FortiGate depends on how they analyze it. Quantifying it is complicated, and Fortinet FortiGate is definitely a proven product with strong threat handling and management. The value of Fortinet FortiGate is significant, with a huge database of signatures that effectively blocks attacks. However, quantifying the return on investment in percentage terms is very subjective.
What's my experience with pricing, setup cost, and licensing?
As an implementer, I don't sell devices, so I may not know about pricing. However, I interact with pre-sales and support teams, and I find their adaptability and support to be very good.
Which other solutions did I evaluate?
My customers work in varied industries, including banking, finance, manufacturing, and IT, because cybersecurity is the need of the hour. Every company requires it, and firewalls are basic; companies choose either Fortinet FortiGate, Check Point, Palo Alto, or SonicWall.
What other advice do I have?
We feel that Fortinet FortiGate is a very proven product that has undergone many changes in the market and has added many products. I recommend Fortinet FortiGate as a proven product that needs to be sized properly for proper implementation. It is easily integrable, especially for us. I strongly suggest Fortinet FortiGate. On a scale of 1-10, I rate this solution a 10.
An easy to configure and manage solution with fabric features
What is our primary use case?
We use Fortinet FortiGate-VM as an edge firewall for Internet traffic control and as the main firewall for cloud environments. Whether they're on AWS, Alibaba Cloud, or another platform, FortiGate-VM serves as the primary firewall.
What is most valuable?
One notable feature is the SD-WAN, which is a strong component of the FortiGate-VM. The fabric feature is also good, but not all customers use FortiGate's networking components, such as the switches. We enable various protection features on FortiGate, such as IPS and web application security. Most customers utilize these protection features to enhance their security.
What needs improvement?
Integrating multi-factor authentication with FortiGate-VM can be challenging. While multi-factor authentication is important, not all customers have it enabled. Integration with third-party solutions like ManageEngine or Duo can be complex and sometimes problematic during testing. However, high availability works smoothly with FortiGate-VM. We use high availability, and SD-WAN features effectively; overall, the performance is good.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM as a reseller for eight years.
What do I think about the stability of the solution?
The stability is good.
I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
We implemented it for more than one thousand users.
I rate the solution’s scalability a ten out of ten.
How are customer service and support?
Support from the engineering team has some weaknesses. Sometimes, they focus on closing tickets quickly or asking for logs without thoroughly addressing the issue. However, the support team includes knowledgeable and responsive individuals, especially those from non-Arabic backgrounds.
How was the initial setup?
Setting up FortiGate-VM is straightforward, but there is a step that can be a bit tricky. After installing the VM, you need to log into the CLI for the first time to set a static IP address if you have multiple interfaces. By default, interfaces will receive IP addresses via DHCP from the cloud service provider. You must disable DHCP on the additional interfaces and set static IPs to ensure proper access and configuration. You may have trouble accessing the firewall if you don't do this.
Issues with certificates and licenses often arise from the distributor, not Fortinet.
The setup process is generally easy. FortiGate is becoming popular in Saudi Arabia due to its user-friendly interface and ease of configuration compared to other vendors like Palo Alto. High availability setup is also simple and not overly complicated.
What's my experience with pricing, setup cost, and licensing?
When comparing Fortinet to other vendors in Saudi Arabia, like Palo Alto, Fortinet stands out positively. In comparison to Sophos, many customers are currently switching to Fortinet. Fortinet's pricing is competitive, making it an attractive option.
What other advice do I have?
To block HTTPS management traffic from the WAN, you must carefully manage the HTTPS settings. If HTTPS is not enabled on the WAN interface, you won't be able to block management traffic effectively. Some customers require HTTPS because of NAT services and use public IPs. Disabling HTTPS can disrupt management access. Better controls for managing the interface from the WAN side would be helpful.
Fortinet FortiGate is easier to configure and manage compared to Palo Alto. Setting up policies, routing, and VPN tunnels on FortiGate is more straightforward and faster. Palo Alto can be complex, requiring multiple steps to create a policy and manage interfaces.
FortiGate also excels in troubleshooting and logging. The logs are easier to read and provide better classification, making it simpler to troubleshoot issues. In contrast, Sophos is less effective for larger-scale operations and doesn’t match Fortinet’s capabilities.
In cloud environments, we recommend FortiGate-VM because it integrates well with cloud service providers. On-premises, many customers prefer physical FortiGate hardware, particularly with VMware setups. However, FortiGate-VM is more commonly used for service providers like SCC, Alibaba, and AWS.
Overall, I rate the solution a ten out of ten.
Has the option to choose either a default or create a self-description
What is our primary use case?
We use Fortinet FortiGate-VM for a constrained firewall and comprehensible security solution. Currently, I'm involved in implementing FortiGate and FortiManager for a customer project over the past month, and Fortinet has proven to be quite effective in this regard.
What is most valuable?
Regarding specific features, I appreciate the option for external selection, where you can choose either to use a default or create a self-description. This simplifies the process compared to other vendors that require creating a test extension profile and then applying it to the installation. With FortiGate, there is a streamlined approach. From the benefits perspective, clients mainly see cost reduction, especially with FortiGate VM Firewall, as it eliminates the need for additional hardware.
What needs improvement?
The product is satisfactory. I haven't identified any features to improve, and based on the number of deployments I've handled with FortiGate-VM, there haven't been any complaints from the customer's side.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM for the past five years.
What do I think about the stability of the solution?
Fortinet is a stable and user-friendly solution. The configuration is straightforward, and it provides a secure environment. I recall a challenge where a customer was using VDOM to segment their networks, but faced issues with communication between firewalls. Through online research, I discovered a tool to replace Fortinet, and it resolved the issue. During a critical migration for a large customer with six hardware firewalls, Fortinet proved reliable and prevented the possibility of mistakes. The GUI interface is well-organized, especially the security tab, making it easy to navigate. Fortinet simplifies network and security tasks, making it accessible for those with a basic understanding of networking and security concepts. Overall, as a vendor, Fortinet stands out for its streamlined approach, avoiding the need to navigate between multiple locations for configuration.
How are customer service and support?
I haven't personally tried Fortinet's technical support, but according to my colleague who has used it, the experience was not positive. He mentioned that the support process is not as direct and efficient as Cisco's. In Cisco, when there's an issue, you can call, initiate a case, and the support engineer can join you directly for troubleshooting. However, with Fortinet, it seems the process involves working on the case independently, and the support requests are assigned to different engineers.
How was the initial setup?
What other advice do I have?
When advising the team for cost reduction, I suggest going with the VM if there's no budget. However, if there is a budget, I recommend purchasing the hardware. For all vendors, technically speaking, hardware is considered better than VM. However, for Fortinet, the difference between VM and hardware is mainly budget-related. If the customer has a budget, it's advisable to purchase the hardware. When recommending from the sales team's perspective, if the customer has a budget, they will suggest going with hardware. If there's no budget, the recommendation is to opt for VM, especially if the customer is working with Azure or AWS. The difference between VM and hardware lies primarily in patches, and overall, everything is satisfactory. One aspect worth noting is that during VM deployment, checking connectivity between the hypervisor, distribution switch, and network firewall is required. In contrast, for hardware, once the configuration is complete, connectivity is straightforward.
As for my overall rating of the FortiGate VM solution on a scale from one to ten, with one being the worst and ten being the best, I would rate it as a ten.
A private cloud solution with a hardware firewall and easy deployment
What is our primary use case?
We use the solution for the private cloud.
What is most valuable?
Fortinet FortiGate-VM has a standard hardware firewall and easy deployment. You download a pre-configured virtual machine and run it on your hypervisor, Hyper-V, or ESXi by VMware. It is an excellent solution for private cloud setups, allowing seamless management using Fortinet without additional hardware purchases. Moreover, it offers flexibility—you can integrate it with physical hardware for redundancy or establish branch office VPNs effortlessly. Fortinet's automation capabilities facilitate smooth connectivity between public and private clouds.
What needs improvement?
The solution is highly scalable, depending on the type of hardware it runs on. You need knowledge of hypervisors to learn about the virtualized environment.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM as an integrator for one year.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
We cater the solution to SMBs.
Which solution did I use previously and why did I switch?
I have used SonicWall. Fortinet has fewer hardware requirements than SonicWall. The basic requirement is the same.
How was the initial setup?
The initial setup is easy and doesn't take more than one hour.
What was our ROI?
ROI is pretty good because it's simply software as a service. You subscribe to a service, and VM is available from FortiGate to download, install, and run. You get all the features. The scalability depends upon the hardware or VM. It could be serving 1000s or 100s users, depending on the configuration.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive.
It could have some versions limited by several users to reduce the price. Else, they could limit the product features, and create some version for a smaller organization with basic requirements.
Support is additional and comes apart from the subscription.
What other advice do I have?
There's not much maintenance required. One to two people is required. Patches and upgrades are required and happen automatically if you've configured it that way. It is easy to deploy over the cloud. There are ready appliances to run in a public cloud like Amazon, Microsoft, or Google Cloud.
I recommend the solution. It is fantastic, easy to deploy, and very scalable. It saves a lot of time. Some particular hardware is not available in stock. FortiGate-VM is a good alternative. You could download, configure, and apply it. You could buy it online or from a Fortinet partner. It's quick and easy to set up.
Overall, I rate the solution a ten out of ten.
Great Product but shame its only BYOL?
This is a great product and Ive used many of their hardware boxes. Its does very good all-round protection and application control.
Its a shame that its BYOL only, I have had to use a competitor product in AWS more often as a result of this as it doesn't fit in with the Elastic Computing Model.
Broad protection for IaaS installations
This firewall offers broad protection against a variety of threats to include controls like Application Control, Intrusion Prevention and Data Leak Prevention among others. Meets Common Criteria EAL4+ and FIPS140 certifications and supports multi-tenancy.
Awesome product, love it.