Unified security has protected diverse environments and supports consistent policies everywhere
What is our primary use case?
I used to work with Fortinet FortiGate and I am using Fortinet solutions as well. I still use Fortinet FortiGate. Everything regarding Fortinet FortiGate, I was working in a telecom operator who was a partner to Fortinet FortiGate and we were reselling Fortinet solutions to our enterprise customers. Plus, Fortinet has a lot of solutions for telecom network operators as well. So we have deployed a Fortinet solution for protecting our infrastructure as well. In my current role also, we are using Fortinet solutions as security operation center tools.
So we were using SD-WAN of Fortinet FortiGate as well and we used to sell Fortinet FortiGate SD-WAN to our enterprise clients as well, and the feedback is pretty good. The box is quite good, especially on the throughput. So usually for other vendors and the market leader vendors, whenever SD-WAN is activated on the box, the throughput of the box reduces while in Fortinet FortiGate boxes, the throughput remains consistent and you can turn on and off the features as you want, and it is quite intuitive to use Fortinet FortiGate solutions.
So we use Fortinet FortiGate data center firewall and with IDPS functionality. FortiAI is the add-on on top of Fortinet FortiGate firewall. So we use those solutions which help us to protect our setup from cyber attacks and in near real time it gives a lot of visibility using machine learning and helps us remediate the incident in near real time basis.
I work with other solutions such as VMware, Cisco, and a few more SD-WAN vendors.
What is most valuable?
Fortinet FortiGate has started as a firewall solution for branch locations and protecting a smaller branch of say 50 or 100 users to start with. Then Fortinet FortiGate has enhanced their offerings and now they are offering solutions for protecting data centers, branches, head offices, cloud infrastructure and everything. So Fortinet is one of the players who is having the full bucket of solutions for protecting applications across the deployment locations, being a branch or a head office or a data center or in the cloud as well.
Regarding Fortinet FortiGate, one of the key fundamental principles they are following while creating products is affordability. Second one is a uniform software code which they use for creating products and the interoperability with the Fortinet ecosystem. So as I said, Fortinet has started as a firewall vendor and then now Fortinet is offering SD-WAN, software-defined LAN, Wi-Fi, plus a lot of solutions for protecting cloud-based deployments and applications. I understand that I am using a few of the solutions which are required for running a managed security service provider setup and security operations center. So those products are also quite promising. To summarize, one is affordability and the efficacy of solutions. Plus I understand Fortinet keeps on investing high in their R&D budget. So that's where they are able to bring a lot of innovation and they make their product quite contemporary in that sense.
Regarding the effectiveness of Fortinet unified SASE, it provides necessary uniform security policies across multiple locations, being in the cloud or in a branch location or in some data center or anywhere in the world actually. So that's where SASE plays a pretty important part and Fortinet has achieved that objective very well.
Regarding the experience with the unified agent in Fortinet unified SASE, it impacts our operations mostly positively. That helps us reduce our overhead for managing the endpoint deployment. With the agent, it is a single agent that does multiple jobs. And this agent signals very well with Fortinet FortiGate SASE deployments and the overall experience is pretty good. It is easy to deploy, easy to manage, and most effective.
Regarding the dynamic segmentation feature, it is a very fantastic feature and one has to have that feature for protecting the lateral movement of cyber threats or maybe when hackers are trying to orchestrate the larger cyber attacks. So this dynamic segmentation really helps us provide a segregation of the application landscape as well as ensuring that the cross talk between the applications does not go uncontrolled. Secondly, if any malware is deployed somewhere, it helps us protect those malware implications within a certain segment only and not span across the data center.
Regarding DDoS protection for managing data center traffic, I understand Fortinet has solutions for DDoS but I do not see those being used in the market. The market is controlled, rather dominated by two or three vendors, and I guess Fortinet is not a preferred vendor for having DDoS solutions.
What needs improvement?
I would say 8 out of 10 regarding the stability of Fortinet FortiGate. It requires a lot of bug fixing and what I understand, Fortinet is fast enough to provide bug fixes and patches, but usually I suggest Fortinet should do thorough testing of their releases and software releases and once probably they can reduce the frequency of new releases but make it stable. That's what my recommendation is.
As far as the core objective of Fortinet FortiGate is concerned, I think they are meeting the targets but I guess for rolling out new features and new updates, they are doing a bit of hurry just to cope with the market dynamics. But possibly, I understand that they are compromising on the quality of the software and stability. So over there they have to improve. Rest of the aspects, I guess they are doing pretty good. We are happy.
Regarding my experience with Fortinet FortiGate in comparison to maybe some other vendors such as CyberArk, Fortinet is in the top three and they give a lot of competition to their nearest peers in the market. But I guess Fortinet is really struggling in software-defined LAN, Wi-Fi, and FortiSwitches space. So they have to make their products more affordable in Forti-switching and Forti-WiFi space. They are not able to compete effectively with the nearest competitor HP Enterprise and HP Aruba.
For how long have I used the solution?
Around now it's almost 18 years that I've been working specifically with Fortinet FortiGate.
What do I think about the stability of the solution?
Regarding technical support from Fortinet, whenever the bug has been reported or stability issues are reported, we see the support provided by Fortinet is good. But again, rather than controlling damage, I guess they should be working more towards preventing the damage rather than controlling the damage.
What do I think about the scalability of the solution?
Regarding scalability for Fortinet FortiGate, my experience says for branch networking, the product is excellent and it supports the scalability of 2X or 3X at times. But for data centers, one has to size the components and size the solution very carefully because these components are deployed one time and remain in life for at least five to seven years. So one has to keep in mind, it is not so easy to replace the boxes. For Fortinet cloud solution, I guess they have achieved the required elastic scales. One has to only upgrade the licenses and go for a higher tier of subscription and then the scalability is achieved in a very seamless way. But for hardware products, especially in data center and head office environments, one has to carefully size the products because they are not so elastic actually. One has to size it well.
How are customer service and support?
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I work with HP to some extent.
How was the initial setup?
Regarding deployment process, Fortinet has a component called FortiManager and FortiAnalyzer. So these two platforms are providing many templates to automate workflows and achieve zero-touch provisioning. So that way deployment is pretty straightforward and easy.
What about the implementation team?
I have deployed a lot of Fortinet solutions on AWS cloud using FortiManager's FortiAnalyzer, Manager, and FortiGate virtual appliances on the AWS Marketplace.
What was our ROI?
This is clear good ROI wherever Fortinet is used as a security product, but not in the Forti-WiFi and Forti-Switching products for sure.
What's my experience with pricing, setup cost, and licensing?
It's quite affordable for Fortinet FortiGate. It's quite affordable for branch networking for sure. For core security components such as firewall, IDPS, and all those things, they are pretty affordable. That's why they won the market and are now market leaders. But some solutions, such as running SOC tools, Fortinet SIM, or Forti-WiFi and Forti-switches, they are coming on a higher side. They're more expensive than their better competitors.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized security has simplified remote site protection and reduced staffing needs
What is our primary use case?
My main use case for Fortinet FortiGate is for VPN and its appliances and for securing all of our remote locations.
A specific example of how I use Fortinet FortiGate to secure my remote locations is that we set rules on each of our locations about what traffic can and cannot go in, so we can allow certain connections for our partners such as Frontiers.
What is most valuable?
The best features Fortinet FortiGate offers are the built-in security functions, which I think are very nice.
We find the built-in security functions most valuable in Fortinet FortiGate, particularly web filtering, as it is all hands-on. Web filtering is our standout feature, and I don't want to add anything else about the features.
Fortinet FortiGate has positively impacted my organization by centralizing the way to access all of our network firewalls.
What needs improvement?
I wish Fortinet FortiGate's UI updates would be done in a more simplified way to improve it.
I choose nine for my rating because I think there's always room for improvement, and I think some of the things in the UI need to be adjusted so they're a little bit more simplified and not overcomplicated.
For how long have I used the solution?
I have been using Fortinet FortiGate for at least three and a half, maybe four years now.
What do I think about the stability of the solution?
In my experience, Fortinet FortiGate is very stable, and it has been quite consistent during times of downtime.
What do I think about the scalability of the solution?
Fortinet FortiGate's scalability has been keeping up well with my organization's growth or changes, as each location gets larger and we feel the need to put a Fortinet FortiGate in each one.
How are customer service and support?
We have had to reach out multiple times to Fortinet engineers for customer support, and it has been great every time; they always seem to get to the bottom of it within one to two calls.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We did use a different solution before Fortinet FortiGate, but it has been so long that I cannot remember who it was; it may have been Palo Alto.
What was our ROI?
I believe we have seen a return on investment in terms of fewer employees needed, but otherwise, it is outside of my scope.
What's my experience with pricing, setup cost, and licensing?
I was not directly involved in the pricing, setup cost, and licensing for Fortinet FortiGate.
Which other solutions did I evaluate?
We did consider other options before choosing Fortinet FortiGate, but it was a straightforward decision, and I am not quite sure what the other options were.
What other advice do I have?
I do not have anything that is unique to us about how we use Fortinet FortiGate in our setup.
We do not utilize Fortinet FortiGate's data center solution, and we do not feel the need to consider AI and ML enhanced FortiGuard services within Fortinet FortiGate.
I would advise others looking into using Fortinet FortiGate to make sure that they get their configurations right from the start, as that means they have less of a need to get support involved. I would rate this product a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?