For FortiGate Next Generation Firewall (NGFW), I use it primarily to connect with other companies through IPsec VPN. Any other security measures are on AWS itself, not on FortiGate. I'm someone who's familiar with FortiGate from previous jobs, so I use that, but it's how we're using it right now.
The IPsec feature of FortiGate Next Generation Firewall (NGFW) is valuable to our company because we need to connect quickly VPN connections with other companies in our networks, and there are many connections in some cases. We need to keep it as secure as possible, maybe one-way connections or particular ports. FortiGate is the best option, at least that I'm familiar with, that can answer all of that in one product that is mostly easy to use.
In our case, the deployment options of FortiGate Next Generation Firewall (NGFW) are not scalable, but in terms of connectivity to other companies, that's exactly what we needed, and that's exactly what it does perfectly, what is needed.