We use Fortinet FortiGate to help protect and secure mission-critical data. There are policies and rules that we apply, and there is an intrusion prevention system that notifies if there are critical vulnerabilities on some clients.
Fortinet FortiGate Next-Generation Firewall
Fortinet Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Integrates seamlessly with the team for quick threat remediation and cost benefits
What is our primary use case?
What is most valuable?
I assess the security services provided by Fortinet FortiGate, such as URL filtering and DNS filtering, as quite good; they are quite effective. Fortinet FortiGate is rather sustainable; it's a good, stable product that gets faster and uses less power with new versions.
It helps us remediate threats more quickly because we have specialists who can work with it rather effectively. When there is an alert on the Fortinet FortiGate, they work together with our FortiAnalyzer and can quickly remediate the incidents.
What needs improvement?
They should do a better job in testing when they put out a new release because when a new software version is released, it is not always stable or does not always have all the previous features working correctly. They should do more testing or launch a new version later when they have tested it more thoroughly.
They already did a good job in their GUI, but they can make more features available in the GUI that are still only accessible through the command line.
For how long have I used the solution?
My proper experience is only two or three years, but in the company, they have been using it for over 10 years.
What do I think about the stability of the solution?
In terms of network and security convergence, they are there, but we are not currently using them because in the office itself, we have other brands of switches and access points. It's now not quite stable in the demo lab environment; we are now on the latest version, but in the production environment, we are not. Production is always on a lower version.
What do I think about the scalability of the solution?
It is scalable.
How are customer service and support?
I would give Fortinet's technical support an eight out of 10; they are responsive and helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Sophos before Fortinet FortiGate.
How was the initial setup?
If you first implement Fortinet FortiGate to get it up and running, it takes just a couple of minutes, but to get all the policies configured correctly, it takes a couple of days.
What about the implementation team?
For my company, Exclusive Networks, the whole company had three or four engineers involved.
What was our ROI?
We have seen a return on investment from using Fortinet FortiGate for integration with the SOC team. The automation part is giving us a cost benefit and speed; we can react faster.
What's my experience with pricing, setup cost, and licensing?
The price-to-performance ratio from using Fortinet FortiGate is very good; I would give it a nine out of 10. It has helped save on costs due to reduced power consumption.
Which other solutions did I evaluate?
Performance is the reason I switched from Sophos to Fortinet FortiGate. It has good value for money, ease of use, and a higher security level, with better security solutions. It's more expensive, but it offers a really good total cost of ownership and is still considerably cheaper than Palo Alto.
What other advice do I have?
I would suggest to anyone considering purchasing Fortinet FortiGate's data center firewall to get training to understand very thoroughly how FortiOS works, and if you have several Fortinet FortiGates, to go for a FortiManager with the necessary training.
The users who work with Fortinet FortiGate are only the IT people, around three or four. Locally, we have around 60 end-users for Fortinet FortiGate. The biggest lesson would be that Fortinet FortiGate provides a high level of security at a good total cost of ownership.
I would give Fortinet FortiGate an overall rating of nine.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
What is our primary use case?
I use Fortinet FortiGate for SD-WAN, specifically for branches, and for firewall purposes.
Fortinet FortiGate is sold to everyone, including banks, mining companies, and oil companies, as it's one of the most popular SD-WAN products that we sell. These are mainly medium-sized businesses or enterprise businesses because we only sell business-to-business, B2B, and we don't sell to normal clients, only businesses.
How has it helped my organization?
We usually do not have any problems. It's a very easy-to-use product. We also have a SOC or service operations center. They are certified in Fortinet FortiGate.
From the point of view of a reseller, Fortinet FortiGate improves our business because it is one of the products that we sell the most. We also use it on our backend because the devices have many slots and support substantial bandwidth.
What is most valuable?
The most valuable features of Fortinet FortiGate are its SD-WAN capabilities, such as dynamic routing, and other features, including security options such as antivirus, IPS, and IDS—all integrated into one device.
Another beneficial aspect of using Fortinet FortiGate is that if you have a LAN network, you can integrate it with FortiSwitch. You can manage everything from Fortinet FortiGate. It is easy to manage and integrate with other Fortinet devices.
What needs improvement?
Fortinet FortiGate is a very good device overall, though it can be improved in certain areas regarding the licenses, particularly the big one called unified threat management, which has many capabilities. The big license options have web filtering, IDS, and a lot of other things, but it's not like they are all good. That's the only thing I would change because the rest is very good.
For how long have I used the solution?
I have about 4 or 5 years of experience with Fortinet FortiGate.
What do I think about the stability of the solution?
I find Fortinet FortiGate to be quite stable, as I have never heard of any issues where they broke or malfunctioned; they are always working. I would rate the stability of Fortinet FortiGate a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability for Fortinet FortiGate as an eight out of ten
How are customer service and support?
We don't usually use that service. We only engage with Fortinet support when a device is broken and needs RMA, so I am not familiar with their operational teams.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used to use Cisco firewalls and devices, which are also quite good. However, Cisco is more expensive, approximately twice their prices, but they are similar in functionality. With Fortinet, we are partner experts, which is a big advantage, whereas with Cisco, we are premium partners, which is not the biggest status, so if we are going to resell to our clients, we don't have the best discount or prices.
How was the initial setup?
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point.
We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
What about the implementation team?
For deployments at one site, it usually requires only one person, and if we are talking about 1 to 50 sites, it still only takes one person because the same template is used for all sites.
In Argentina, we service about 100 locations. There are about 200 companies in Colombia and Brazil.
What was our ROI?
We service about 100 locations with Fortinet FortiGate in Argentina, but if we account for all the company's clients, it can be around 2,000 across Colombia and Brazil, since we have clients in all of these countries.
What's my experience with pricing, setup cost, and licensing?
Fortinet prices are around $600 for the small 40F model, and for licenses, the simplest option is about $300 for a year. They sell licenses that can last for 1, 2, 3, or 5 years.
Which other solutions did I evaluate?
Before using Fortinet, we evaluated other options such as Versa and Meraki, but Meraki is also from Cisco. Fortinet is better than Versa. One of the main differences between them is that we don't have many partners or distributors for Versa here in Argentina, making it difficult to sell something that you cannot pay for locally. It has been easier in the past to handle payments, but Versa doesn't have many providers or distributors in Latin America, making it a less viable option. Fortinet offers more products that are easier to integrate into our clients' networks, such as firewalls and access points, so that was one of the main reasons we didn't use Versa.
What other advice do I have?
My advice to other businesses or people considering using Fortinet FortiGate is that it is the starting product from Fortinet, and when you start using Fortinet FortiGate, you can then move on to the next products they offer, which are numerous.
We sell the 40F, 60F, 80F, 100F, and 200F models. There are the ones we sell readily from the bottom to the top. Sometimes, we sell bigger ones such as the 300 model.
Overall, I would rate Fortinet FortiGate around a nine out of ten.
Which deployment model are you using for this solution?
Extensive web controls enhance our security posture
What is our primary use case?
We use Fortinet FortiGate for the firewall as well as for the VPN. Any of the users outside the organization use the VPN. Any staff members working outside the office headquarters or our office location use the VPN.
The main aspect that I deal with is URL blocking and web access. I don't work with other aspects of this firewall.
How has it helped my organization?
It has upscaled our security posture, especially regarding external connectivity, because any access or connection from the company has to go through the Fortinet FortiGate firewall. It's doing a pretty good job. We do not have any complaints there.
Anything that we don't want to allow is not coming in. Anything we want to allow is not being blocked. We always have the granular control where we can block malicious IPs or subnets if needed.
Geofencing allows us to limit the countries from which we allow IP connections. There are many features that I may not even know or haven't explored, but in general, Fortinet FortiGate is doing a pretty good job for us.
What is most valuable?
The web controls are what I appreciate about Fortinet FortiGate. We have extensive controls over areas where we could block external-facing IPs, external URLs. We can do geo-fencing with the firewalls, which is a good feature.
What needs improvement?
There are too many updates coming for VPN, and the VPN keeps disconnecting frequently, which I find problematic. It does what it's supposed to do, but I practically face reconnection issues with the VPN.
Regarding the Fortinet FortiGate firewall, I don't have any input. My scope is limited.
For how long have I used the solution?
I have been using Fortinet FortiGate for around three years.
What do I think about the stability of the solution?
Fortinet FortiGate is stable. We haven't seen any latency issues related to it, though we do experience latency from ISPs.
What do I think about the scalability of the solution?
I would rate the scalability as eight out of ten based purely on my exposure to security controls relating to URL blocking and website access.
How are customer service and support?
I haven't had a chance to work with Fortinet FortiGate technical support, but from my colleagues' experience, they say the Fortinet FortiGate people are easy to reach but hard to schedule time with. It's not as easy as having the Fortinet FortiGate engineer on the call and getting other teams involved; it requires careful arrangements to join in with the Fortinet team. I would give their support a neutral score of maybe five.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I don't know why we switched to Fortinet FortiGate from Juniper; it's a management decision.
How was the initial setup?
I was not involved in the deployment. I think it's not that difficult; there's no complexity involved as long as we are clear on what we want to do.
We have it on both cloud and on-premises.
What was our ROI?
I was not part of the team that implemented it. I don't know how much they invested, but it would be worth the investment.
What other advice do I have?
My overall experience with Fortinet FortiGate rates as eight out of ten.
A solid firewall with straightforward management and robust capabilities
What is our primary use case?
We primarily use Fortinet FortiGate as endpoint firewalls for our campuses. Nothing too extravagant, just providing access out and limiting access to certain applications and restricting unauthorized access from external sources. I have recently been using it also as the controller for the wireless access points.
What is most valuable?
It is pretty straightforward to manage and has robust capabilities. I appreciate that Fortinet FortiGate can be a central controller for other Fortinet products, such as switches and access points. I have used its VPN abilities a little bit, but not a great deal. I appreciate that it has some SD-WAN capabilities, though I've only used that to a limited degree. It is a solid, usable, reliable solution.
What needs improvement?
It's one of the more expensive brands.
FortiManager has not been my favorite. I don't use it and cannot say I really care for FortiManager for managing the firewalls. I primarily just access and manage the firewalls individually. Nothing else particularly comes to mind, as it has been a pretty good experience.
For how long have I used the solution?
I have about four and a half years of experience with Fortinet FortiGate.
What do I think about the stability of the solution?
The stability has been very good. I have had very few issues. I had one unit that required some reboots and eventually needed a factory reset. But outside of one issue, I've never had stability issues or problems with them going down or disconnecting or having other issues. They have been very stable and reliable.
What do I think about the scalability of the solution?
I have experienced no scalability problems thus far. We expand out with other campuses as needed. If there are any scalability problems, I think that would probably be with making FortiManager a little bit better. Otherwise, scalability is fine.
We are a medium-sized business with 17 campuses. We plan to increase its usage. We'll probably continue with FortiGate for any other campuses that we extend out to, as well as keeping them when we do our hardware refresh.
How are customer service and support?
Fortinet FortiGate has very good support. I've been able to contact them on a couple of things for FortiGate and other products, and I've never had an issue. They've always been polite and helpful and worked to get me to solutions. I've had a good experience with Fortinet support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've always had Fortinet FortiGate in place, so I don't have a previous firewall here to compare it to, but it has basically done its job. It's manageable, and it has not created a lot of problems. Only once, I had to call their support to apply a patch update across a couple of them. One of the best features is that it does not require a lot of extra attention for me to fix problems. It's not a problem generator, so that's probably the best quality.
How was the initial setup?
I've set up several Fortinet FortiGate firewalls, and it's a pretty straightforward setup. I haven't ever really had any particular issue with getting them in place.
It's deployed physically at the locations for our campuses. To deploy one, it takes approximately an hour to program and then another hour or so to install. It can get deployed within three hours.
Just one person can manage Fortinet FortiGate; I'm able to manage everything by myself.
What about the implementation team?
The implementation was done by me, one person. Sometimes I need to walk through someone else to physically install it because it might be at a site remote from me. If I'm not physically there, it requires a second person. However, if that was not the case, I could do it as a single person.
What's my experience with pricing, setup cost, and licensing?
It's one of the more expensive brands.
The 100 series costs around $4,000. They are similar in pricing to what you might get from Cisco solutions and probably other similar ones. They're not more expensive than other similar solutions, but they're certainly not cheaper either.
What other advice do I have?
The advice is to go ahead and try it out and see how it works. The product speaks for itself.
I would rate Fortinet FortiGate a nine out of ten, as I always prefer to leave a little bit of room for improvement.
Which deployment model are you using for this solution?
Ensures business continuity with reliable internet connectivity and robust security features
What is our primary use case?
We are using it for perimeter security. By implementing Fortinet FortiGate, we wanted to have secure internet access to our network and prevent cyber risks.
How has it helped my organization?
The content filtering and URL filtering capabilities, along with packet content filtering, are very good. It helps us restrict internet traffic during working hours to legitimate work-related traffic. Workers are only able to access social media, YouTube, and similar sites after work hours.
It helps in protecting the edge significantly because we are able to determine what must be accepted and what must not be accepted. We also have FortiAnalyzer, which is the log analyzer for Fortinet FortiGate. Being AI-driven, it helps us see what is happening and new emerging threats quickly. We are able to make the necessary interventions to protect the network.
We are using QRadar as a SIEM, and Fortinet FortiGate integrates with it seamlessly. FortiAnalyzer picks all logs from Fortinet FortiGate, integrates with QRadar, and allows us to see everything. It also integrates beautifully with our EDR from WithSecure.
It also helps reduce power consumption. Fortinet FortiGate is a greener listing in terms of power consumption.
What is most valuable?
Stateful packet inspection is valuable. It also does SSL packet inspection. It is able to provide a VPN for remote users with secure connectivity. Being a next-generation firewall, it helps.
It has been able to host internet feeds from two different ISPs, with one as a backup. We've two internet services on Fortinet FortiGate. We have been able to deploy it in a high-availability mode. We have redundancy. When there is a problem with one, the other picks up quickly, ensuring business continuity.
What needs improvement?
I wish that they could integrate zero-trust technology into Fortinet FortiGate. I am not sure whether it has been done already, but if they could implement that, it would help significantly.
For how long have I used the solution?
I have been using it for about ten years now.
How are customer service and support?
Their support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I didn't use any similar solution previously.
How was the initial setup?
I wasn't involved in the recent deployment.
It was quite quick. The last deployment was more of a migration, where we migrated from an old platform to a new platform. It was a matter of hours because the configs had been backed up. In eight hours, we were done completely.
What about the implementation team?
We had two people from my side and two from Fortinet's side.
What was our ROI?
If we look at the average revenue loss due to downtime, even if I conservatively put it at $10,000 an hour, we have paid back the investment within six months.
Compared to a sister company that did not take security seriously and lost significant money through ransomware attacks and outages, we have not experienced a single successful ransomware attack. In one instance, we were able to thwart an attack by detecting the initial steps quickly through EDR and FortiAnalyzer. We saw the footprints and stopped it before it reached the encryption phase of the ransomware attack.
The analysis being AI-based helped us quickly pick up unusual activity. Once alerted, we were able to quickly identify the affected nodes, isolate them, and stop the attack.
It has reduced the total cost of ownership by 10%.
What's my experience with pricing, setup cost, and licensing?
For the performance that we get, the price is reasonable. There are cheaper options, but they may not deliver the same kind of performance that we want. For the performance they provide, the price is acceptable.
What other advice do I have?
Currently, there is a project we are doing to converge OT and IT using Fortinet FortiGate, because of the cluster we have. Fortinet FortiGate is going to broker the convergence between IT and OT. We want to make the convergence one-way, with only read-only data coming from OT into IT.
They keep bringing new versions and firmware updates, making sure that their products are always relevant. They are always providing what the industry needs.
We have implemented FortiAnalyzer. We are also looking seriously at FortiIdentity to help us with enterprise single sign-on and multi-factor authentication. Because we already have Fortinet FortiGate in the system, we are seriously considering other Fortinet solutions.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Cloud features enhance security measures and simplify network management
What is our primary use case?
We use Fortinet FortiGate for any of our customers or clients that need to have more security features built-in, whether licensed or not.
For instance, if it's a medical firm doing VPN to ensure no traffic leaks, that would be a use case. We use Fortinet FortiGate for anything that needs specific features, such as SD-WAN or other security features, including malware checking and blocking. We also use it for Zero Trust.
How has it helped my organization?
It differs for everyone with Fortinet FortiGate, but one benefit was checking for malware on incoming traffic or security issues, compared to a users using a residential router off the shelf.
The second benefit was properly dividing up the network, which helps us significantly.
Users benefit from a recognizable brand and good security features.
What is most valuable?
Ease of use is one feature of Fortinet FortiGate, and the Cloud Controller and Cloud Connector are the second one; these are the two main features that are quite useful. For example, with the Cloud Connector in Fortinet FortiGate, if a user has an issue, we can see it directly without having to build a VPN tunnel or something of that nature.
From time of deployment, users tend to see benefits once there's a major event that stops. From my end, I see benefits right away.
What needs improvement?
For Fortinet FortiGate, their code development would definitely be something they need to improve on to reduce vulnerabilities that need to be patched.
Additionally, if I were to suggest another improvement, it would be their competitive pricing.
For how long have I used the solution?
I have had experience with Fortinet FortiGate for six years.
What do I think about the scalability of the solution?
With Fortinet FortiGate, scalability is good; it's very easy to scale with them.
The only downside is sometimes you can't just cut over, so if you go from a bigger model. Or if you need to upgrade the model, you would have to reprogram it, compared to just importing and exporting, which can be time-consuming.
The scalability is easy with switches and access points that are basically plug-and-play for the most part.
How are customer service and support?
I've never had a problem with Fortinet FortiGate support, so I'd rate it ten out of ten. However, if you don't have a support contract, it's not easy to get support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I've dealt with many firewalls, such as SonicWalls, UniFi, pfSense, and Cisco. We found SonicWall very confusing for the average network engineer or network administrator. I don't recommend SonicWall due to its hard-to-find auditing process for exploits. Although they have fewer exploits, when they do occur, they're significant.
With Fortinet FortiGate, you can access the whole firewall, with no hidden spots. pfSense is great, however, it requires a lot of manual work and has no Cloud Connect or easy management from an MSP's perspective.
Palo Alto is another option that's great, but their price point isn't for everyone, especially for medium and small businesses; a $10,000 investment doesn't necessarily fit into most budgets.
UniFi is another product we've started to use more alongside Fortinet FortiGate, as they have almost all features without a license, with advanced rules that are relatively inexpensive compared to Fortinet FortiGate's $1,500 a year.
Fortinet FortiGate and UniFi are the two firewalls we primarily deal with. My opinion is that UniFi has better integration and oversight of the environments compared to Fortinet FortiGate.
How was the initial setup?
From an average user's perspective, setting up Fortinet FortiGate is quite complex; most people don't understand the terminology, so I'd rate that complexity at a high nine out of ten. From an MSP's perspective, it's probably about a five or six out of ten in terms of difficulty; it's easy for us as an MSP. For the end-user, it would be really complicated.
For Fortinet FortiGate, deployment takes approximately two to three hours.
What about the implementation team?
From our side, as an MSP, we require one person for Fortinet FortiGate. That job role is network administration.
What was our ROI?
For Fortinet FortiGate, calculating the return on investment is complex.
The ROI is seen almost immediately in terms of security and protection against malicious attacks. While you never really get your money back in terms of direct investment, you get the security and protection benefits immediately.
Fortinet FortiGate provides cost savings since you wouldn't need extra security features; you don't have to have four other programs for all the other parts of the environment, as it takes care of most of that.
What's my experience with pricing, setup cost, and licensing?
I'd rate the pricing eight out of ten.
The Fortinet FortiGate security features cost approximately $1,500 a year. The firewall itself doesn't have a recurring cost. It's the security features on top of that that you pay for.
What other advice do I have?
I recommend Fortinet FortiGate.
It's always updating the security package and security features.
I have not looked into the solution's AI features.
Overall, on a scale of one to ten, I would rate Fortinet FortiGate a nine. I'd recommend the solution to others. It's always updating its security features.
Offers good security and ease of use and integration
What is most valuable?
It is easy to use and update the software version. It is also useful for integration with other Fortinet products, because my office and company use Fortinet solutions. We are also using Fortinet FortiManager and FortiMail.
Fortinet FortiGate is considered the best in the European market for security reasons. I wouldn’t want to change to any other firewall.
What needs improvement?
At the moment, the main concern is the pricing and the type of licensing. Fortinet offers different types of licensing, and my idea is that the best approach is to have only one, two, or a maximum of three types of licensing.
What do I think about the stability of the solution?
It is very easy to use, and I don't have any issues at the moment. I also don't anticipate having any issues in the future.
There has not been any impact on my network performance by implementing SD-WAN.
Which solution did I use previously and why did I switch?
I have only used Fortinet FortiGate.
Which other solutions did I evaluate?
I have evaluated some options that could be tested in the future, but at this moment, I only use Fortinet FortiGate.
What other advice do I have?
Fortinet is currently one of the five top players for security firewalls.
I would rate Fortinet FortiGate an eight out of ten.
Meets various needs and it's cost-effective and simple
What is our primary use case?
We are using Fortinet FortiGate for enterprises. We are a partner of Fortinet.
How has it helped my organization?
Its features are very good for the price. Their support is also very good. A lot of expertise is available in the market in terms of engineers.
What is most valuable?
The best features of Fortinet FortiGate are its simplicity, ease of installation, and ease of functionality. It is very easy to learn and implement, and everything is clear. The deployment of Fortinet FortiGate is very straightforward.
What needs improvement?
I would like to see improvements in Fortinet FortiGate regarding the active-active scenario. The active-active scenario is supported but not recommended, whereas other vendors are implementing active-active without issues. Perhaps in the future, we could effectively use both firewalls to increase the throughput. If there are two boxes, they both should be able to work.
Other than that, I don't have anything. I'm very happy with the features.
For how long have I used the solution?
I have been working with Fortinet FortiGate regularly for a few months only, though I have previously encountered one or two installations.
What do I think about the stability of the solution?
Fortinet FortiGate is very stable.
What do I think about the scalability of the solution?
There are multiple options available for small, mid-sized, and large-scale deployments.
How are customer service and support?
My experience with the technical support for Fortinet FortiGate is very good. I only had one bad experience. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
It is very straightforward to deploy.
In terms of maintenance, many features are automated, including antivirus updates that happen regularly without intervention. Simply connecting the firewall to the internet enables automatic downloads of everything.
What was our ROI?
It was recently implemented, so it is too early for that assessment.
What's my experience with pricing, setup cost, and licensing?
It is very cost-effective. You get features similar to other firewalls, such as Palo Alto, but at a lower price.
Which other solutions did I evaluate?
I have not worked extensively with Palo Alto, but from various comparisons, Fortinet FortiGate is understood to be a cost-effective version of Palo Alto. While Palo Alto has more features, Fortinet FortiGate offers similar functionality.
What other advice do I have?
Currently, we are not using SD-WAN, but we will implement it as it is a very impressive built-in feature. We will implement it for one of our customers in the near future.
Fortinet FortiGate is a very good next-generation firewall. It is not very expensive and offers plenty of models to suit various needs. The licensing options are extensive. The day-zero protection is very good. FortiCloud is also excellent. The geo-protection is effective and serves its purpose.
I would rate Fortinet FortiGate a nine out of ten.
Which deployment model are you using for this solution?
User-friendly features boost network security and threat prevention
What is our primary use case?
We put FortiGate Next Generation Firewall (NGFW) after the ISP; we use the internet, and before we put our server through the internet, we put FortiGate Next Generation Firewall (NGFW) as a firewall in our internal network.
We follow ISO 27001, which includes web filtering, spam, and IPS functionality.
What is most valuable?
We sometimes face challenges if we have new server configurations and need to consider compatibility with FortiGate.
We hope that FortiGate uses AI to carefully identify something abnormal, and we believe that will be helpful.
The multi-threat protection feature helps us secure our organization.
What needs improvement?
We understand that FortiGate cannot be standalone without others, such as FortiManager, so for small businesses, if FortiGate can provide something similar to FortiManager, it will be better.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall (NGFW) for about nine years.
What do I think about the stability of the solution?
I would rate the stability of FortiGate Next Generation Firewall (NGFW) as a nine.
What do I think about the scalability of the solution?
I would rate the scalability as a nine also.
How are customer service and support?
I would rate the technical support as a seven.
How was the initial setup?
The installation of FortiGate Next Generation Firewall (NGFW) is actually moderate; it depends on the needs, so it's not so easy but it's not so difficult.
The installation requires a couple of days, and actually, it takes about one day because some parameters need to be set, especially if there are a lot of users.
What about the implementation team?
I have a person in charge of that.
What's my experience with pricing, setup cost, and licensing?
From a cost perspective, I think it's quite reasonable, not so cheap, but I think it's quite similar compared to others.
What other advice do I have?
Two people are involved in the maintenance.
We use many FortiGates. We are using the 60F and 100F, which are the newest versions.
Our staff handles maintenance ourselves; we are not using a third-party service.
About 30 people are using this product in our organization.
We are payroll outsourcing consultants, so basically they calculate payroll.
I would recommend FortiGate Next Generation Firewall (NGFW) to others.
I would rate FortiGate Next Generation Firewall (NGFW) in general as an eight.
Which deployment model are you using for this solution?
Comprehensive traffic management and explore improve initial setup processes
What is our primary use case?
I'm using Fortinet FortiGate for consultancy, implementation, and troubleshooting after device implementation. We serve as both reseller and consultant, providing search support and consultancy support. I usually recommend Fortinet FortiGate for small and small-sized businesses.
How has it helped my organization?
I have experience with Fortinet FortiGate SD-WAN, as it is a method for routing traffic. We can assign profiles with specific conditions to create best practices or optimal experiences for customers. These profiles can manage traffic balance or link balancing. We can detect users or specific links for particular services, including load balancing.
What is most valuable?
Fortinet FortiGate provides superior protection compared to other firewalls, with high processing capabilities. In comparison to Sophos devices, Fortinet FortiGate offers enhanced protection through network protection, IPS, and application protection.
What needs improvement?
They could simplify their deployment process, especially when customers have existing devices. The configuration approach depends on whether customers need to start from scratch or can utilize existing backups and rules.
I would seek to improve Fortinet FortiGate by exploring additional features, such as SASE solutions that we are currently studying and implementing. The configuration could be made easier, particularly during initial setup. We need to ensure comprehensive utilization of all device features and learn best practices from other cases.
For how long have I used the solution?
I have been working with Fortinet FortiGate for approximately one year.
What do I think about the stability of the solution?
Fortinet FortiGate is overall stable. When compared with Sophos, particularly regarding remote access and SSL VPN, Fortinet FortiGate proves much easier to use. While Sophos presented port-related challenges in Egypt, Fortinet FortiGate operates more smoothly.
What do I think about the scalability of the solution?
Fortinet FortiGate is scalable, with capacity depending on firewall sizing. We determine sizing based on multiple factors: number of users, available links, traffic types, server count, services in use, and whether services will be published. We consider parameters such as VPN requirements, remote access needs, side-to-side VPN configuration, and overall traffic volume to determine device capacity.
How are customer service and support?
We tend to handle support.
Which solution did I use previously and why did I switch?
I have experience with Fortinet products and limited experience with Cisco.
I provide other firewalls, such as Sophos, and I have worked with endpoint protection solutions. I have experience with backup solutions such as Veeam, and endpoint security solutions including Kaspersky and ESET.
How was the initial setup?
I have created many profiles for SD-WAN capabilities while integrating with Fortinet FortiGate. We assess customer needs and make recommendations accordingly. If customers aren't using SD-WAN, I suggest implementing it due to its effective load balancing capabilities and additional firewall features.
What was our ROI?
Regarding the evaluation of changes in return on investment after implementing the Fortinet solution for SD-WAN hybrid workforce, we work on a case-by-case basis. ROI is monitored by management, and we do not directly track ROI in the systems.
Which other solutions did I evaluate?
Fortinet FortiGate is among the best options in the market, though alternatives exist, including Sophos. Fortinet FortiGate demonstrates stronger performance and protection compared to Sophos, though its device and license costs are higher.
What other advice do I have?
I'd rate the solution eight out of ten.