Fortinet FortiGate Next-Generation Firewall
Fortinet Inc. | 7.2.9Linux/Unix, Other 7.2.9 - 64-bit Amazon Machine Image (AMI)
Extremely flexible & scalable.
I can automate every aspect of deployment. Central management through FortiManager is perfect for my needs as I can manage all my firewalls across my hybrid deployment from a single console.
- Leave a Comment |
- Mark review as helpful
Very easy to use. Great value
It's an easy security solution to deploy and added great value protecting our workloads from known vulnerabilities. We used it as a hub spoke topology.
Effective and easy to set up
Provides as good if not better coverage as our on premise NGFW. Easy to deploy and set up.
Unique Master-Slave sync in HA mode as well as API calls to the AWS infrastructure which means we don't need to run a lambda to supervise the state of the master and change the routing. The API calls take care of this.
Good
Nice and tried with TRANSIT VPC, Good performance. Only Issues with Remote VPN part. CLI part is good, will get more options there.
Great firewall, On-Demand not available for GovCloud ?!
These are great firewalls, they work great for VPC Transit designs. Unavailable for Gov-Cloud as an On-Demand as of August 2018
Great product!
All the features I need, Fortigate's features are covered, and now I can use Fortigate products in multiple clouds to help us achieve hybrid clouds.
Easy to set up
I am testing this product at the AWS re:Invent 2017 in Las Vegas. The free trial was pretty easy to set up, and the support was adequate.
Not operationally ready with autoscaling.
Tried the cloud formation template for autoscaling and found the worker node was not working. Logs showed it crashing out when trying to do an API call to the Firewalls. Updated the worker code, started again, and crashed again.
Without the worker node your not even getting the two on demand nodes sync'd.
Traceback (most recent call last):
File "./Fortigate.py", line 3504, in
exit(main())
File "./Fortigate.py", line 2882, in main
rc = ChangeDHCP(fgt, 'apiadmin', encrypted_password, verbose, debug)
File "./Fortigate.py", line 721, in ChangeDHCP
values = status.json()
File "/usr/lib/python2.7/dist-packages/requests/models.py", line 651, in json
return json.loads(self.text or self.content, **kwargs)
File "/usr/local/lib64/python2.7/site-packages/simplejson/__init__.py", line 516, in loads
return _default_decoder.decode(s)
File "/usr/local/lib64/python2.7/site-packages/simplejson/decoder.py", line 370, in decode
obj, end = self.raw_decode(s)
File "/usr/local/lib64/python2.7/site-packages/simplejson/decoder.py", line 400, in raw_decode
return self.scan_once(s, idx=_w(s, idx).end())
simplejson.scanner.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
Impossible to get support
1. I have a fortinet account
2. I have my serial number for the Fortigate VM (directly copied from the Fortigate Console - I know it is correct).
I click on the contact support link mentioned under the Support section of the AWS marketplace listing. It asks me to login. I login with my fortinet account. I try to create a technical support ticket. To create a ticket, it asks for a serial number. I enter the serial number but it says the serial number is invalid (i took the serial number directly from the Fortigate console, so I know it is correct).
In my Fortigate Admin screen, I try to "register" the product - every time i register, it says "Unknown Error".
My issues are the following
1. I cant register the product with my fortinet account - I get an "An Unexpected Error Occurred" message.
2. Because I can't register the product with my fortinet account, I am unable to submit a support ticket. When I try to create a support ticket in the portal, it says "Invalid Input Data. The Serial Number is Not Registered."
So how are we supposed to get support?
Works like the real device
If you are used to the fortigate firewall line there is nothing new here, the interface is the same and works the same way. Good entry level device, easy to setup and works fine.