Fortinet FortiGate VM Next-Generation Firewall | Network Security
Unified security platform has simplified daily network protection and accelerated troubleshooting
What is our primary use case?
Fortinet FortiGate is used primarily for network security and secure internet access, with primary applications in firewall policy management, VPN connectivity, SD-WAN, application and URL filtering, NAT, and protecting the internal network and servers from external threats.
A common example involves using Fortinet FortiGate to provide secure internet access for different departments by creating firewall policies based on the user, application, and destination while applying security profiles such as URL filtering, application control, and IPS. Traffic logs are monitored to identify and block suspicious activities. For VPN connectivity, IPsec VPN is used for site-to-site connectivity between offices and SSL VPN is used for remote user access when required. Recently, an IPsec VPN was configured and tested between a branch office and main office to securely access internal applications and servers over the internet.
Beyond secure internet access and VPN connectivity, Fortinet FortiGate is relied upon for day-to-day firewall policy management, NAT, SD-WAN, application control, URL filtering, traffic monitoring, and troubleshooting connectivity issues. It is also used for security monitoring, firmware upgrades, HA management, and checking CPU, memory, and interface utilization. Overall, Fortinet FortiGate is an important part of daily network security and operations.
How has it helped my organization?
Fortinet FortiGate has improved overall network security and made day-to-day network management more efficient. Better visibility into network traffic is available through detailed logs and monitoring, and features such as IPS, application control, URL filtering, and security policies help to control and protect internet access. Reliability has been improved through HA and SD-WAN capabilities, while VPN features make secure connectivity between sites and remote users easier to manage. Overall, faster troubleshooting, better control over network traffic, and more consistent security across the organization have been achieved.
One of the main improvements noticed is faster troubleshooting because Fortinet FortiGate provides detailed traffic logs, session information, and real-time monitoring. This helps to identify whether an issue is related to firewall policies, application or VPN connectivity, or network traffic much more quickly.
What is most valuable?
The features that stand out most are centralized policy management, IPS, application control, web and URL filtering, SSL or IPsec VPN, SD-WAN, and high availability. The traffic log and monitoring tools are very useful for troubleshooting and security analysis. Another strong point is the integration of multiple security capabilities in a single platform, which makes day-to-day network security management easier and more efficient.
Fortinet FortiGate's UI is intuitive and makes day-to-day administration easier, as firewall policies, interfaces, VPN, SD-WAN, security policies, and traffic logs can be quickly navigated without relying heavily on the CLI. The dashboard also gives a quick view of CPU, memory, session, and interface utilization, which helps with monitoring and troubleshooting. For high availability, Fortinet FortiGate HA is very useful because two firewalls can be configured in an active-passive cluster, and if the primary firewall experiences a failure, the secondary firewall takes over, which helps to minimize downtime.
Fortinet FortiGate combines multiple security functions into one platform, including firewall, IPS, application control, web filtering, VPN, and SD-WAN. The detailed logging and reporting are also helpful for troubleshooting and security analysis. Overall, these features provide good visibility and control over network traffic while reducing the need to manage multiple separate security solutions.
What needs improvement?
Fortinet FortiGate is generally easy to manage, but there are a few areas where it could be improved. The interface can become complex when managing a large number of firewall policies, and better policy search organization and reporting would be helpful. Firmware upgrades can also require careful planning and testing, especially in production environments. Troubleshooting some advanced issues may require deeper CLI knowledge or assistance from Fortinet support, and more advanced automation and AI-assisted troubleshooting within the management interface would be beneficial, such as clear recommendations for policy optimization, configuration issues, and security events. These improvements could make day-to-day administration even more efficient.
More AI-driven capabilities for day-to-day administration would be valuable, especially for troubleshooting, policy optimization, and identifying potential configuration issues. More intelligent recommendations based on traffic patterns and security events could help administrators respond faster. More advanced reporting and dashboards that can be easily customized for different teams and management requirements would also be helpful, while better automation for routine tasks, firmware planning, and configuration validation would further reduce manual effort.
For how long have I used the solution?
There is approximately two years of hands-on experience working with Fortinet FortiGate firewall, including configuration, troubleshooting, and managing firewall, SD-WAN policies, security profiles, and firmware upgrades.
What do I think about the stability of the solution?
Fortinet FortiGate is stable and working fine.
What do I think about the scalability of the solution?
Fortinet FortiGate has good scalability and can support different network sizes, from smaller branch offices to large enterprise networks with a range of hardware models and Fortinet FortiGate VM options for virtual and cloud deployment. It also scales well through features such as HA, SD-WAN, centralized management, and segmentation. As the organization grows, firewall capacity can be increased or additional Fortinet FortiGate devices can be deployed without completely redesigning the security architecture. The combination of different hardware options, cloud flexibility, and HA makes Fortinet FortiGate suitable for both current requirements and future network growth.
How are customer service and support?
Fortinet customer support is excellent overall. Fortinet technical support is useful for troubleshooting complex issues, firmware-related problems, and integration questions. The support team can also help with detailed log analysis and provide recommendations when an issue cannot be resolved through normal troubleshooting.
Which solution did I use previously and why did I switch?
Before using Fortinet FortiGate, other firewall platforms were used, including Check Point and Palo Alto, depending on customer requirements. The move to Fortinet FortiGate was mainly driven by the combination of security and networking features, straightforward management, VPN and SD-WAN capabilities, and the ability to manage multiple security functions from a single dashboard or single platform. The graphical user interface and the monitoring capabilities were found helpful for day-to-day administration and troubleshooting. Overall, Fortinet FortiGate provided a good balance of functionality, operational efficiency, and scalability for the environment.
What was our ROI?
A positive return on investment has been seen, mainly due to improved efficiency and reduced troubleshooting effort. Fortinet FortiGate combines firewall, VPN, SD-WAN, IPS, application control, and web filtering capabilities on one platform, so fewer separate security solutions need to be managed. The detailed logs, monitoring, and centralized management also help to identify and resolve network issues faster, which saves engineering time. HA and SD-WAN improve availability and reduce the potential impact of connectivity or firewall failures. An exact percentage for cost saving or reduction has not been formally calculated, but the time saved in daily administration and troubleshooting has been a clear benefit.
What's my experience with pricing, setup cost, and licensing?
The experience with Fortinet FortiGate pricing and licensing has been generally positive. The initial setup cost depends on the firewall model, required performance, and the security feature or subscription selected. The licensing is straightforward, with additional security services such as IPS, antivirus, web filtering, and application control available through subscription packages. The main consideration is the recurring cost of the security subscription and the support renewal, and for an organization using multiple Fortinet FortiGate devices, budgeting for this renewal is important. Overall, the pricing is reasonable considering the number of security and networking capabilities provided in a single platform.
Which other solutions did I evaluate?
Other firewall solutions were evaluated, mainly Check Point and Palo Alto, as well as Fortinet FortiGate. They were compared based on security capabilities, firewall and VPN functionality, SD-WAN, ease of management, monitoring and reporting capabilities, scalability, support, and overall cost. Fortinet FortiGate stood out because it provides a broad set of security and networking features in a single platform while being relatively straightforward to manage for day-to-day operations.
What other advice do I have?
The combination of reliability, security features, and ease of management stands out most. Fortinet FortiGate provides a single platform for firewall, security, SD-WAN, IPsec, IPS, application control, URL filtering, and traffic monitoring. The usability in day-to-day operations is valued, and the visibility provided through logs and dashboards makes troubleshooting much faster. HA capabilities are another important factor because they help to maintain network availability. Overall, the combination of strong security capabilities, reliable performance, and practical day-to-day management makes Fortinet FortiGate stand out.
Fortinet FortiGate's AI capabilities are useful when combined with strong security controls and governance. AI-driven threat detection and security analysis can help identify suspicious activity and provide useful insights, while administrators still have control over policies and security decisions. From the governance perspective, clear visibility into how AI-based recommendations are generated is important, along with strong access control, logging, and auditing. Security is especially important when AI is involved, so having control access and keeping human oversight in the decision-making process is crucial. Overall, AI is seen as a useful enhancement to Fortinet FortiGate's security capabilities, particularly for faster threat detection, analysis, and troubleshooting.
Fortinet FortiGate's AI-assisted capabilities can provide useful and relevant insights, particularly for identifying suspicious activity, analyzing security events, and supporting threat detection. The recommendations are helpful as a starting point and can reduce the time required to investigate issues. However, AI recommendations alone should not be relied upon for critical security decisions, as recommendations should still be validated against traffic logs, existing policies, and the actual network environment before making changes. Overall, the AI capabilities are useful and reliable for assisting security operations, while human validation remains important for production environments.
Fortinet FortiGate is primarily deployed on-premises in the organization, where it is used as a perimeter firewall for securing internet traffic, internal network segments, servers, and VPN connectivity. There is also experience with Fortinet FortiGate VM deployment in cloud environments when required. The on-premises deployment gives direct control over network security, firewall policies, monitoring, and HA, while virtual and cloud deployment provides flexibility for workloads hosted in cloud environments.
Fortinet FortiGate would be recommended to organizations looking for a comprehensive firewall and network security solution. Before purchasing, it is important to clearly define network requirements, expected traffic volume, VPN users, security features, and future scalability so the right Fortinet FortiGate model and licensing can be selected. Testing the required security policies, profiles, VPN, SD-WAN, and HA configuration in a lab or proof-of-concept environment before deploying them in production is also crucial. Proper planning, configuration, monitoring, and regular firmware upgrades are important to get the most value from the platform. A rating of 10 out of 10 would be given for Fortinet FortiGate.
Integrated security and SD-WAN have improved network resilience and simplify daily operations
What is our primary use case?
What is most valuable?
My experience with Fortinet FortiGate has been very positive. In addition to firewall security, VPNs, and SD-WAN, I regularly perform firmware upgrades, troubleshoot network issues, implement high availability configuration, and manage security policy. Fortinet FortiGate provides multiple security and networking features within a single platform, which makes it easier to manage and maintain customer environments efficiently.
The best features of Fortinet FortiGate are SD-WAN, VPN capability, high availability, and integrated security features. I particularly appreciate the SD-WAN functionality because it provides intelligent traffic routing and better link utilization.
What stands out most about Fortinet FortiGate's SD-WAN functionality is its ability to intelligently use multiple internet links and automatically steer traffic based on link performance. In one deployment, I configured two ISP links in an SD-WAN setup. When one link experienced high latency or packet loss, traffic was automatically shifted to the healthier link without manual intervention.
The VPN and high availability features of Fortinet FortiGate make it easy to deploy and manage both site-to-site IPsec VPN and remote access VPN. The HA functionality provides redundancy and minimizes downtime during failure or maintenance activity. I also appreciate the integrated security approach where firewalling, VPN, application control, web filtering, and intrusion prevention are available on a single platform, which simplifies management and improves overall security.
Fortinet FortiGate has had a positive impact by improving network security, reliability, and operational efficiency. Features such as SD-WAN and VPNs have helped ensure stability and connectivity across sites, while high availability has reduced downtime during maintenance or unexpected failures. From an administrative perspective, the centralized management and integrated security features have simplified troubleshooting and reduced the time required to manage and secure the network.
We have seen reduced downtime through HA and SD-WAN deployment as traffic automatically switches to the healthy ISP link during outages. Fortinet FortiGate has also improved troubleshooting by providing centralized visibility into network traffic, VPN, and link performance, helping us resolve issues faster and manage the network more efficiently.
Fortinet FortiGate is moving in the right direction with its AI-driven security features. I appreciate how it helps with threat detection, security analysis, and identifying suspicious activity more quickly. From a governance and security perspective, it provides better visibility and helps security teams respond faster to potential threats.
What needs improvement?
Fortinet FortiGate is a strong solution overall, but I believe the reporting and analysis features could be improved to provide more detailed insights without relying on additional products. Additionally, some advanced configurations can have a learning curve for a new administrator. Simplifying certain workflows and enhancing troubleshooting visibility would make the platform even more user-friendly.
More detailed reporting often requires additional products such as FortiAnalyzer. The documentation for some advanced features could be more straightforward, especially for new users. While support is generally good, faster resolution for complex technical issues would be beneficial. Overall, these are minor improvements and the platform remains reliable and easy to manage.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
What was our ROI?
What other advice do I have?
Integrated security has improved perimeter protection and simplifies centralized policy control
What is our primary use case?
The primary use case for Fortinet FortiGate is to secure the organization and network perimeters. I use it to control the inbound and outbound traffic and implement firewall policies, providing secure VPN access to remote users and protecting the network from cyber threats using features such as IPS and antivirus, web filtering, and application controls. It also helps me with segmenting the network and centrally managing the security policies, making day-to-day administration more efficient.
What is most valuable?
Fortinet FortiGate has positively impacted my organization by improving the overall security posture while simplifying network management. It has helped us reduce security incidents by blocking malicious traffic and enforcing security policies. It has also improved operational effectiveness because the IT team can manage firewall rules, VPN access, and security monitoring from a single platform. This has reduced manual effort, improved visibility into the network, and enabled us to respond to security events much more easily.
The best features of Fortinet FortiGate are its security fabric integration. It brings multiple security functions together, including firewall, IPS, antivirus, web filtering, VPN, and application controls, into a single platform, making security management much simpler. I also appreciate the centralized dashboard because it provides excellent visibility into the network traffic, security events, and user activity in real-time. It helps me identify and respond to potential threats quickly without switching between multiple tools.
The feature I rely on most is the real-time monitoring dashboard. It gives me a clear view of network traffic, active users, security events, VPN status, and blocked threats all in one place. I also frequently use the log and traffic analysis sections for troubleshooting and investigating security incidents. It makes it easier to identify unusual activity, check which firewall policy was triggered, and quickly determine the root cause of connectivity and security issues. This saves considerable time during day-to-day operations.
For user management, Fortinet FortiGate has also made things much easier. I integrated it with my Active Directory, so access policies are applied based on user groups instead of configuring each user individually. Whenever a new employee joins or changes departments, I simply update the AD group members and the correct network access is applied automatically. This has reduced my manual effort and minimized configuration errors.
What needs improvement?
Overall, Fortinet FortiGate is a strong secure solution, but there are a few areas that could be improved. The user interface can be overwhelming for new administrators because of the large number of configuration options. A more organized layout and simplified navigation would improve the overall experience. Another area is reporting and logging analysis. While the built-in reports are used, more customizable reports and dashboards would make it easier to generate management and compliance reports without relying on additional tools. Firmware upgrades could also be made smoother with fewer compatibility concerns across different versions. Additionally, the analyzer could be much better so that I can stop using third-party tools for analyzing logs for unused rules specifically.
If Fortinet FortiGate can offer such improvements in the dashboard and if I can get the unused rules that I submit to compliance and regulatory requirements from the Fortinet FortiGate dashboard itself, I would not need to rely on third-party tools. This could be improved.
If I had to add one more point, it would be better AI-driven reports and automations. More intelligent recommendations for policies, optimization, and automatic response to common security events would make day-to-day administration even more effective.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than three to four years.
What other advice do I have?
From my experience, Fortinet FortiGate's AI capability has good governance and security. The AI-driven threats, detections, and analysis help in identifying suspicious activity faster and reduce the manual effort required by my security team. I also appreciate that the AI features are integrated into the existing security framework rather than operating as a separate tool. This allows me to maintain consistent security policies and gives me better visibility into potential threats, while keeping administrator controls in the hands of security teams. Overall, I find the AI capability useful, but there is still room for improvement.
My advice is to spend time planning the deployment and firewall policies before implementing. A well-designed network architecture and proper configuration of security policies make a significant difference in getting the best performance and protection from Fortinet FortiGate. I would also recommend enabling features such as IPS, web filtering, application control, and VPN, and keeping the firmware up-to-date. Additionally, make sure that administrators are properly trained, as Fortinet FortiGate offers many advanced features that can provide significant value when configured correctly. Overall, it is a solid choice for an organization looking for a competitive network security solution. I rate this product a 9 out of 10.
Integrated security has strengthened branch protection and simplifies daily VPN and threat management
What is our primary use case?
My main use case for Fortinet FortiGate is that I use it as the primary security gateway for protecting our branch and data center network. It is responsible for traffic inspection, application control, site-to-site VPN, connectivity, internet access control and threat prevention.
A quick specific example of how I use Fortinet FortiGate in my daily operations is that I monitor security events, manage VPN connectivity, and review internet usage and implement the security policies. The centralized visibility helps me to quickly identify suspicious traffic and respond before it affects business operations.
How has it helped my organization?
Fortinet FortiGate has positively impacted my organization by strengthening our overall security posture while simplifying network management. It has helped us gain better visibility into network traffic, secure remote access for users and reduce the time required to identify and respond to security incidents.
A specific outcome from using Fortinet FortiGate is that we have reduced VPN-related incidents by approximately 40% and improved visibility into network traffic. Troubleshooting connectivity issues is also significantly faster than before, around 50 to 60% faster.
Fortinet FortiGate has reduced the amount of manual troubleshooting required; security policy and VPN management and threat monitoring are handled through a single platform, making operations more efficient and easy to manage.
What is most valuable?
The best features Fortinet FortiGate offers for me are SD-WAN, SSL VPN, application control, web filtering and security fabric integration. Together they provide strong security while keeping network management straightforward.
The SD-WAN feature helps my organization specifically by optimizing traffic across multiple internet links, improving application performance and reducing dependency on a single ISP connection.
What needs improvement?
Overall, I am very satisfied with Fortinet FortiGate. If I had to suggest one improvement, it would be to have more flexible reporting and dashboard customization. While the existing features are good, additional customization options would make monitoring and reporting even more efficient for the administrator.
My suggestion is to customize the dashboard and have more advanced reporting.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than one year.
What do I think about the stability of the solution?
Fortinet FortiGate is stable.
Fortinet FortiGate performs smoothly under heavy network loads or during peak traffic periods.
What do I think about the scalability of the solution?
Fortinet FortiGate is highly scalable. It scales effectively from small branch deployments to larger enterprise environments, accommodating our growth without requiring major architecture changes.
How are customer service and support?
Customer support for Fortinet FortiGate is very good. They are humble and knowledgeable, especially during complex deployment and troubleshooting scenarios.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; from the start, we have been using Fortinet FortiGate firewall.
How was the initial setup?
Managing and configuring Fortinet FortiGate for my team is easy because the UI is user-friendly, which makes management and integration straightforward.
What was our ROI?
I have seen a return on investment with Fortinet FortiGate. Faster incident response, reduced downtime and simplified management have improved operational efficiency. The solution has helped save both time and administrative effort.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Fortinet FortiGate is that the pricing is competitive compared to many enterprise firewall vendors. Initial deployment was straightforward and the licensing options provide flexibility based on business requirements.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, I evaluated other options including Sophos, Palo Alto, and Check Point. Fortinet FortiGate is the best fit for my organization regarding price and advanced features.
What other advice do I have?
Fortinet FortiGate is deployed in my organization on-premises.
I would describe Fortinet FortiGate's integration capabilities with other security tools or platforms as effective since I am using Fortinet FortiGate on-premises.
Regarding Fortinet FortiGate's AI capabilities, I think its governance and security are enhanced by the AI-driven security insights, which are useful for identifying abnormal behavior and prioritizing potential threats. While human validation is still important, the recommendations help speed up the investigation.
I find that the accuracy and reliability of its output are generally good. The threat intelligence and security detection have been accurate, though false positives occur occasionally, but overall, the alerts are reliable and actionable.
My advice for others looking into using Fortinet FortiGate is that if you are looking for a security platform that combines firewalling, VPN, SD-WAN, and threat protection in a single solution, Fortinet FortiGate is definitely worth evaluating. Proper sizing and planning during deployment will help you get the best results from the platform. Additionally, Fortinet FortiGate's pricing is reasonable for small, medium, and large enterprises compared to other vendors. I give this solution a rating of 9 out of 10.
Integrated security has strengthened our defenses and simplifies branch connectivity management
What is our primary use case?
Fortinet FortiGate is used to secure the organization's network perimeter, manage site-to-site and remote access VPN, control application traffic, and protect users from cyber threats through IPS, antivirus, web filtering, and application control features.
In my day-to-day work, I use Fortinet FortiGate for ongoing checks on online traffic from the user to the internet and from outside to inside to access the server. One example was when Fortinet FortiGate IPS detected and blocked suspicious traffic targeting internal servers, allowing our team to investigate before any impact occurred.
What is most valuable?
All the features Fortinet FortiGate offers are the best, but the standout feature for me is its next-generation firewall capability, which includes IPS, SSL VPN, SD-WAN for ISP load balancing, web filtering, application control, and centralized security management. Site-to-site VPN is the best feature for me because we use it for our branch connectivity.
Fortinet FortiGate's site-to-site VPN configuration is very user-friendly, allowing even new users to configure it easily. The troubleshooting is also excellent, and the logs provide valuable details.
The application control feature from Fortinet FortiGate is also valuable because we can manage user access. For example, we can allow users to access Facebook while restricting commenting, downloading, or uploading. Application control has many features, including controlling download, upload, and commenting.
Fortinet FortiGate has positively impacted our organization by strengthening our security posture, improving visibility into network traffic, simplifying security management, and providing reliable connectivity for both users and the branch office.
What needs improvement?
Although Fortinet FortiGate is excellent and comprehensive, I feel that reporting needs to be more customizable, with options for further simplification of some advanced configuration workflows. The main concern is reporting, as without FortiAnalyzer, we have limited reports and cannot customize them.
I have no major concerns regarding the needed improvements, as overall, the solution is mature, reliable, and meets our requirements well.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than three years.
What do I think about the stability of the solution?
Fortinet FortiGate has been very stable and reliable in our environment.
What do I think about the scalability of the solution?
Fortinet FortiGate scales very well and supports growing network requirements without significant performance concerns.
How are customer service and support?
Customer support for Fortinet FortiGate is knowledgeable, responsive, and helpful during troubleshooting and implementation activities. I would rate customer support for Fortinet FortiGate a 10 out of 10.
Which solution did I use previously and why did I switch?
Before Fortinet FortiGate, we were using Cisco ASA, but we switched because Fortinet FortiGate has better pricing and is a next-generation firewall compared to the older Cisco ASA solution.
What was our ROI?
We have seen a positive return on investment through improved operational efficiency, reduced incident response time, and simplified management, with security operations being approximately 40 to 50 percent more efficient.
What's my experience with pricing, setup cost, and licensing?
Our experience with pricing, setup cost, and licensing for Fortinet FortiGate has been positive as the setup process was straightforward, the UI is user-friendly, and the license options provided flexibility based on organizational requirements. The overall value justifies the investment.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, we evaluated other options such as Sophos firewall, SonicWall, and Check Point firewall, but Fortinet FortiGate fit better in our organization.
What other advice do I have?
My advice for others looking into using Fortinet FortiGate is to properly plan your security policy and architecture before deployment, as an organization that fully utilizes Fortinet FortiGate's integrated security features can achieve excellent visibility and security. I give this product a rating of 9 out of 10.
Unified security platform has improved multi-site VPN access and simplified network management
What is our primary use case?
My main use case for Fortinet FortiGate is as a UTM to distribute our IP DHCP, to segment our VLAN, and to manage our network infrastructure.
I also use Fortinet FortiGate as a VPN and for site-to-site connection between our multiple sites, such as my head office, our developer office, and data center. It acts as a network security tool where we use an IPS to filter attacks from the outside public to our server.
Regarding my main use cases, I would like to add that it has quite a good GUI and dashboard, making it easy to use. Additionally, we use DNS filtering and application filtering to filter the applications that users can access to the internet.
What is most valuable?
The best features Fortinet FortiGate offers include reliability and a good user interface and user experience.
The user interface is the most valuable to me because it is easy to use, easy to manage, and quite easy for a newcomer to operate. The features are quite good for filtering applications and for addressing our needs, such as blocking social media or other unwanted content.
Fortinet FortiGate has positively impacted our organization by improving our security workflow and network security, as it is quite reliable compared to traditional routers or traditional switch cores from MikroTik or Cisco.
A specific example of how my workflow and network security has improved is that because we have multiple sites, Fortinet FortiGate has a multitude of signature-based features and multiple default policies, so we only have to add that to the profile. It is quite simple and easy to manage.
What needs improvement?
I think Fortinet FortiGate is quite good for now, though it could improve with the virtual IP, as it occasionally has a bug. They have a lot of CVE and updates to their system, and they need to be more concerned about their security.
For how long have I used the solution?
I have been using Fortinet FortiGate for about one year.
What do I think about the stability of the solution?
In my experience, Fortinet FortiGate is quite stable.
When the RAM or memory reaches 70% or 80%, the firewall is more likely unstable and may struggle to forward traffic. I think that is one of the areas where Fortinet FortiGate has room for improvement.
What do I think about the scalability of the solution?
Fortinet FortiGate's scalability is limited because it is on-premises, so we would have to change the type of Fortinet FortiGate as we grow.
How are customer service and support?
The customer support is really helpful for their principle, but they lack technical competency at layer one, as they tend to only look for logs before promoting issues to layer two for resolution.
Which solution did I use previously and why did I switch?
Previously, we used Aruba as a firewall and switch core, but it lacked security features, so we had to move to the next-generation firewall.
What was our ROI?
I am afraid I cannot say that I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that I think the price is quite good besides the leader in Gartner's next-generation firewall.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, we evaluated a lot of competitors at that moment, and we chose Fortinet FortiGate.
What other advice do I have?
My advice to others looking into using Fortinet FortiGate is that you need to think carefully about your usage and calculate your business needs. If you miscalculate, you might end up buying a Fortinet FortiGate that cannot meet your needs, leading to potential downtimes or failures.
I have no additional thoughts about Fortinet FortiGate except that I mentioned the easy user interface and experience for beginners. However, I noted that when the memory reaches up to 80%, the firewall does not function as well. I would rate this product a 9 out of 10.
Strong content filtering has isolated lab traffic and has reduced security costs significantly
What is our primary use case?
My main use case for Fortinet FortiGate is content filtering, and content filtering is the primary function. I am also doing East and West traffic filtering.
I use content filtering and East-West traffic filtering by creating groups based on separate projects in Active Directory, and on the firewall side, I create policies, web application profiles, and category-based profiles tailored to each project's requirements.
We have separate projects, and I isolate those subnets from one subnet to another so that both subnets do not communicate directly and only communicate via Fortinet FortiGate itself, with policies created to manage the East and West traffic.
What is most valuable?
Some of the best features of Fortinet FortiGate are its ease of use compared to other vendors, and from a troubleshooting point of view, it is also very useful and easy to troubleshoot. It stands out as easy to use and troubleshoot because I do not need to create separate NAT policies; with Fortinet FortiGate, I align my NAT policies and content filtering within a single policy, making management straightforward, and the logs are clearly visible, making troubleshooting much easier.
Compared to other firewalls, Fortinet FortiGate offers easily manageable features such as vulnerability profiles and threat profiles, which I believe is one of its main advantages.
Fortinet FortiGate has positively impacted my organization with its cost-effectiveness because it provides features that are very similar to others, but at a much lower cost, and everything my organization needs is available with Fortinet FortiGate.
Being cost-effective has allowed us to save a lot of money, which is particularly useful since I was exploring firewalls to secure my internal labs, and finding Fortinet FortiGate was a revelation as I could achieve my requirements without the additional costs of other firewalls.
What needs improvement?
I wish Fortinet would explore SASE solutions more, as it has become very popular and people are increasingly using it.
For how long have I used the solution?
I have been using Fortinet FortiGate for around the last seven years.
What do I think about the stability of the solution?
Fortinet FortiGate is stable, and I have never experienced issues similar to those from the ASA.
What do I think about the scalability of the solution?
Fortinet FortiGate's scalability is very good, and I believe there are no issues.
How are customer service and support?
I have faced challenges related to support, as I have encountered issues where support engineers are not aligned within the time frame, and sometimes they request multiple logs unnecessarily, causing delays and leaving a bad impression on my end users.
I have had a bad experience with customer support many times.
Which solution did I use previously and why did I switch?
I previously used a Cisco ASA but switched due to certain performance-related issues.
How was the initial setup?
My experience with pricing, setup cost, and licensing went smoothly, with no issues related to licensing or installation, and the overall cost is definitely cheaper than other prominent firewalls along with phenomenal features.
What about the implementation team?
I do not have a business relationship with the vendor other than being a customer, but I do have partners to buy network equipment such as firewalls and switches.
What was our ROI?
I cannot share exact numbers for ROI, but I saved a lot of money, which made management very happy, especially knowing that I achieved my functional goals with Fortinet FortiGate that might have incurred more costs with other firewalls.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiGate has positively impacted my organization with its cost-effectiveness because it provides features that are very similar to others, but at a much lower cost, and everything my organization needs is available with Fortinet FortiGate.
My experience with pricing, setup cost, and licensing went smoothly, with no issues related to licensing or installation, and the overall cost is definitely cheaper than other prominent firewalls along with phenomenal features.
Which other solutions did I evaluate?
I evaluated options including Palo Alto, Cisco, and other products before choosing Fortinet FortiGate.
What other advice do I have?
I would rate Fortinet FortiGate a nine overall, as I only deduct one point for the support issues I have experienced.
I selected nine because, feature-wise, the product is excellent and cost-effective compared to others, but I deducted a point due to the disappointing support from Fortinet.
I advise others looking into using Fortinet FortiGate to check their requirements first, as it provides all kinds of services other firewalls do and is very cost-effective.
People looking for a firewall should definitely evaluate Fortinet FortiGate, as it is very cost-effective and offers all the features they are likely looking for. I gave this review a rating of nine out of ten.
Unified security gateway has streamlined monitoring and troubleshooting for faster resolutions
What is our primary use case?
Fortinet FortiGate serves as my gateway device where I manage all my security. I use Fortinet FortiGate as a gateway for the NATing part for LAN to WAN communication. Along with that, I manage security profiles from the gateway only, and all my switches and Wi-Fi also work with Fortinet FortiGate.
I work on RE VPN and SSL RE VPN on Fortinet FortiGate.
What is most valuable?
In my opinion, the best features Fortinet FortiGate offers are monitoring and troubleshooting. Along with that, its security services are also a key point for me. For example, I need to manage features including IPS, antivirus, web filtering, and application control via Fortinet FortiGate only.
I appreciate the security feature of Fortinet FortiGate. For example, I can take real-time logs and session monitoring along with VPN, event logs, data usage monitoring, and related features.
I have noticed faster troubleshooting and reduced downtime of around fifty percent. My operational efficiency has improved. For a real example, a client experienced frequent internet drops, and this was resolved more efficiently.
What needs improvement?
One suggested improvement I would recommend is more simplified troubleshooting. Although logs are powerful, troubleshooting can sometimes be complex for new users. A more guided or AI-based troubleshooting feature would help reduce resolution time. Fortinet FortiGate should incorporate AI-based solutions to improve the troubleshooting experience.
For how long have I used the solution?
I have been using Fortinet FortiGate for two years.
What do I think about the stability of the solution?
Fortinet FortiGate is stable. It demonstrates excellent stability in various terms including network utilization.
What do I think about the scalability of the solution?
Fortinet FortiGate offers strong scalability and can support environments ranging from small businesses to large businesses. There is a wide range of models from entry level to high end levels. Flexible deployment options include physical appliances, virtual, and cloud deployments, which is beneficial.
How are customer service and support?
Customer support needs improvement. I have had to take the direct internal sources, such as sales contacts, and after that I rarely see support response.
I would rate the customer support at a six out of ten.
Which solution did I use previously and why did I switch?
I have used Sophos before, and several of my criteria were missing with that solution. Fortinet FortiGate achieved the features I was looking for, which is why I shifted to Fortinet FortiGate firewall.
How was the initial setup?
My experience is very positive regarding pricing, setup cost, and licensing for Fortinet FortiGate. The pricing is also competitive compared to other vendors in the market. Along with that, setup is very easy. I implemented it in my network myself. For the licensing part, it is somewhat confusing, but overall it is good.
What was our ROI?
Fortinet FortiGate has saved me both money and time. It is easy to manage and the troubleshooting part is also very easy, making it more time-saving than money-saving.
What's my experience with pricing, setup cost, and licensing?
In terms of cost savings, it has reduced the need for multiple tools. Fortinet FortiGate combines firewall, VPN, IPS, web filtering, and SD-WAN into a single device, which has given me lower operational overhead.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, I tried various options. I obtained the POC from Palo Alto as well as Check Point. After that, I switched to Fortinet FortiGate because it was the best option for my network.
What other advice do I have?
My advice for others looking into using Fortinet FortiGate is that focusing on proper planning, sizing, and understanding of features before deployment will be a good approach.
Integrating SD-WAN with Fortinet FortiGate has allowed me to create an SLA according to which my ISPs define the traffic and the best path utilized.
I would rate this product a ten out of ten overall.
Centralized security management has improved policy control and simplified daily operations
What is our primary use case?
I use Fortinet FortiGate in security and policy for security profiles, blocking and allowing for certification on a day-to-day basis.
I block Gmail and personal mail along with other applications. We block webmail and allow corporate mail, Microsoft 365, and block unwanted categories such as pornography and weapons while implementing URL filtering.
Global systems use standard Fortinet terminology. We use FortiManager and FortiAnalyzer, where FortiAnalyzer is used for logging and FortiManager is used for centralized management across multiple gateway devices.
By implementing Fortinet FortiGate in our organization, we can control applications and block unauthorized apps.
Control security platform features such as policy enforcement and SD-WAN streaming particularly improve our work by reducing manual configuration across multiple devices, allowing faster change implementation, and reducing troubleshooting time.
This control typically leads to measurable outcomes across operations, security, and performance.
We use Fortinet FortiGate on-premises and in the public cloud.
What is most valuable?
In my experience, the best feature Fortinet FortiGate provides is its impressive logging system, which is very easy to read to understand what the issue is.
The SD-WAN feature is very valuable for us. By integrating SD-WAN, we can manage our ISP links and SD-WAN rules.
Using SD-WAN on Fortinet FortiGate provides lower latency and stability improvements, critical application routing via lower latency links, reduction in jitter and packet loss, with both links actively used instead of one idle backup, leading to better bandwidth utilization.
The biggest strength is the consolidated platform that combines firewall, SD-WAN, VPN, and security stack in one device.
What needs improvement?
We can improve the UI readability when working with large configurations. I chose a rating of nine because of the troubleshooting power and launch issues. We need CLI debug capabilities in addition to the UI.
For how long have I used the solution?
I have been working in my current field for the last three years.
What do I think about the stability of the solution?
Fortinet FortiGate is a stable and scalable firewall.
What do I think about the scalability of the solution?
Fortinet FortiGate is manageable on one platform, but scalability depends on how we scale. Model ranges for small branches and high-end applications are delivered easily by moving to a higher model.
How are customer service and support?
Support is also good.
Which solution did I use previously and why did I switch?
I previously used Sophos firewall before moving to Fortinet FortiGate.
What about the implementation team?
We evaluated other options such as Palo Alto before choosing Fortinet FortiGate. We evaluated both Palo Alto and Sophos firewalls during our selection process.
What was our ROI?
It is a time-saving product.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Fortinet FortiGate is generally positive from a value perspective.
What other advice do I have?
I advise others to use Fortinet FortiGate, considering the firewall size, throughput including IPS, SSL-VPN, web filtering throughput, VPN load, and UTM versus Enterprise bundle.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security has improved with deep inspection and vpn access, but reporting and upgrades need work
What is our primary use case?
I have been using Fortinet FortiGate for the past six years.
I have been using Fortinet FortiGate to provide security for network and perimeter networks and gateways, and I rely on Fortinet FortiGate to protect my applications from various Layer 4 and Layer 7 attacks and traffic from malicious IPs while blocking traffic from unwanted IPs.
Fortinet FortiGate is also mainly used to establish IPsec tunnel connectivity with other networks, and users from outside the office network can connect to resources via IPsec VPN as well as site-to-site and client-to-site VPN, which leverages access and resource availability across various networks and simplifies resource accessibility worldwide.
One of the main features that I use in real time with Fortinet FortiGate is web filtering and App IDs based on application control. Previously, I allowed application access policies based on ports, but it could not prevent traffic based on the same application port with different use cases. For example, port 443 can be used for various purposes, but it could not restrict access for some specific applications. The App ID based control is useful for me to restrict traffic based on application usage and user access, which is the primary purpose of Fortinet FortiGate in real time.
What is most valuable?
Fortinet FortiGate offers next-generation firewall features and security features that restrict access for malicious traffic, URLs, and IPs, which is a major feature that Fortinet FortiGate offers.
The next-generation firewall capabilities including deep packet inspection and application controls via App IDs, Intrusion Prevention Systems, web filtering, URL filtering, and anti-malware protections are essential features that are present in Fortinet FortiGate to prevent various cyber attacks and threats in the network.
Fortinet FortiGate is also mainly used to establish IPsec tunnel connectivity with other networks, and users from outside the office network can connect to resources via IPsec VPN as well as site-to-site and client-to-site VPN, which leverages access and resource availability across various networks and simplifies resource accessibility worldwide.
What needs improvement?
The security features could have been more similar to those in the Palo Alto firewall with major data protections and WildFire, and deeper inspection capabilities, which Fortinet FortiGate lacks. Additionally, I notice that Fortinet FortiGate often experiences resource utilization problems where memory is heavily occupied regularly, necessitating cleanup tasks.
During firmware upgrades, the process is not smooth; one of the VMs often goes out of sync and exits the HA cluster. Therefore, I separate the HA between the firewalls and perform upgrade activities one by one manually. The graphical dashboard representation of the data is frequently inaccurate, leading me to rely on syslogs for more dependable information. The log retention period on the device seems too short despite having ample memory and disk capacity, which is a major issue.
For how long have I used the solution?
I have been working in my current field for the past seven years.
What do I think about the scalability of the solution?
The scalability experience indicates that if I need additional features or security capabilities, such as sandbox features, I can add them by opting for separate licenses, making it convenient for me.
How are customer service and support?
Fortinet FortiGate customer support appears somewhat good, but for complex cases or major incidents, I often do not receive prompt support from the OEM, resulting in multiple follow-ups to get the necessary assistance.
Which solution did I use previously and why did I switch?
Previously, I used to have a Cisco ASA firewall, which had fewer security features for protecting the network from day-to-day attacks and threats. Fortinet FortiGate firewall has next-generation capabilities with various security features including deep inspections, filters, URL filters, URL categories, and IPS protections while controlling application access based on application IDs, along with anti-malware protections to safeguard applications from malicious threats and attacks. By using Fortinet FortiGate, I significantly reduced major attacks that could exploit my network.
What other advice do I have?
I would advise others considering Fortinet FortiGate, particularly those concerned about budget and pricing with decent performance and support, to proceed with Fortinet FortiGate, as compared to other next-generation firewall products, Fortinet FortiGate has lower license support costs, which is a significant advantage. Moreover, from my experience, it performs its job effectively with no major issues related to performance or functionalities including policy control, VPN, and security features. I would rate this product a 7 out of 10.