Sold by
Fortinet FortiGate VM Next-Generation Firewall | Network Security
Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
Reviews (532)
Information Technology and Services
Easy, Hardware-Free Deployment with Flexible Backup and Restore
Reviewed on Sep 03, 2026
Review provided by G2
What do you like best about the product?
What I like most about FortiGate-VM NGFW is how it combines strong security features with the flexibility of a virtual appliance. It delivers next-generation firewall capabilities—such as intrusion prevention, application control, web filtering, VPN, and advanced threat protection—within a single platform, which makes overall security management much easier. The user interface is intuitive, and day-to-day administration stays straightforward even in more complex environments. Another key advantage is its smooth integration with cloud and virtualized infrastructures. We’ve been able to deploy it quickly and scale as needed without adding hardware, which saves time and reduces operational costs. Performance has been consistent, and the visibility into network traffic and security events helps us spot and respond to potential threats more effectively. Overall, FortiGate-VM NGFW strikes a solid balance between security, performance, and ease of management, and it has become a valuable part of our network security strategy.With flexible pricing options and premium support and integrated ai features
What do you dislike about the product?
While FortiGate-VM NGFW is a strong security solution overall, there are a few areas that could be improved. One limitation I have experienced is that restoring configurations from a physical FortiGate appliance to a VM deployment is not always seamless. In some cases, I had to manually reconfigure settings, which increased deployment time and operational effort. VM management can also be challenging, especially in larger environments where multiple virtual firewalls need to be monitored and maintained. Although the interface provides a good range of features, some workflows could be more intuitive and require several steps to complete routine administrative tasks. Integration with certain third-party platforms and cloud environments may require additional customization compared to what some competing products offer. From a performance perspective, resource utilization can become high under heavy traffic loads, requiring careful sizing of CPU and memory resources. Licensing and pricing can be difficult to understand, particularly when multiple security services and subscriptions are involved. The initial onboarding process also has a learning curve for administrators who are new to the Fortinet ecosystem. Finally, while FortiGuard's threat intelligence is valuable, I would like to see more AI-driven automation and smarter recommendations for threat analysis and policy optimization to reduce manual effort and improve operational efficiency.
What problems is the product solving and how is that benefiting you?
Before implementing FortiGate-VM NGFW, managing network security across our virtual and cloud environments was becoming increasingly complex. We needed a solution that could provide strong protection without adding more physical hardware or creating additional management overhead. FortiGate-VM NGFW has helped us centralize security controls by combining firewalling, IPS, web filtering, VPN, and application control into a single platform. This has made it much easier to monitor traffic, enforce security policies, and respond to potential threats. The deployment process was straightforward, and the flexibility of the virtual appliance allowed us to scale as our requirements changed. One of the biggest benefits has been improved visibility into network activity and better control over remote access. We spend less time managing multiple security tools, and troubleshooting is much faster because everything is available from a single console. Overall, it has strengthened our security posture while reducing operational complexity and infrastructure costs.
Mani s.
Flexible, Easy-to-Deploy FortiGate VM for Cloud and Virtual Firewalls
Reviewed on Sep 02, 2026
Review provided by G2
What do you like best about the product?
FortiGate VM is Fortinet's virtualized next-generation firewall, essentially the same FortiOS software that runs on their physical appliances, but packaged to run on hypervisors (VMware, Hyper-V, KVM) or in cloud environments (AWS, Azure, GCP, OCI). Here's what makes it valuable:
What do you dislike about the product?
Great for flexible, cloud-based firewall needs — easy to deploy and cost-effective. Performance drops under heavy traffic. Best for small/medium setups overall.
What problems is the product solving and how is that benefiting you?
FortiGate VM NGFW helps secure cloud and virtualized environments without needing physical hardware. It solves problems like protecting multi-cloud/hybrid infrastructure, segmenting workloads (VPC/VNet), enabling secure remote access (VPN), enforcing consistent security policies across on-prem and cloud, and reducing hardware costs while scaling firewall capacity as business grows. It's especially useful for organizations expanding into cloud, needing quick disaster recovery setups, or managing distributed branch offices without deploying physical appliances everywhere.
Computer & Network Security
Future of Fortigate VM NGFW
Reviewed on Sep 01, 2026
Review provided by G2
What do you like best about the product?
FortiGate VM is basically the full FortiOS firewall packaged as a virtual machine instead of dedicated hardware. It runs on the usual hypervisors (VMware, KVM, Hyper-V) and all the major public clouds, and because it’s the same OS as the physical boxes, the CLI, policies, and features are identical — nothing to relearn or reconfigure differently.
On the NGFW side you get full Layer 7 inspection: IPS, application control, SSL inspection, antivirus, web filtering, plus built-in SD-WAN and support for BGP/OSPF and overlay tunnels like IPsec, GRE, and VXLAN. Licensing scales by vCPU, so you size it to the throughput you actually need rather than being stuck with a fixed hardware tier.
Practically, it’s most useful for cloud edge firewalling, DR sites where you can’t wait on hardware lead times, lab testing before pushing changes to production units, and management of FortiManager/FortiAnalyzer across a mixed fleet of physical and virtual firewalls.
On the NGFW side you get full Layer 7 inspection: IPS, application control, SSL inspection, antivirus, web filtering, plus built-in SD-WAN and support for BGP/OSPF and overlay tunnels like IPsec, GRE, and VXLAN. Licensing scales by vCPU, so you size it to the throughput you actually need rather than being stuck with a fixed hardware tier.
Practically, it’s most useful for cloud edge firewalling, DR sites where you can’t wait on hardware lead times, lab testing before pushing changes to production units, and management of FortiManager/FortiAnalyzer across a mixed fleet of physical and virtual firewalls.
What do you dislike about the product?
The biggest downside of FortiGate VM, in my experience, is performance. Without the dedicated ASICs (NP/CP chips) found in physical FortiGates, all packet processing is handled in software on the hypervisor’s CPU. That means throughput is ultimately constrained by the host’s available resources as well as the vCPU licensing tier you’re on. SSL inspection is especially impacted, since there’s no hardware crypto offload to absorb that workload.
Licensing is vCPU-based, which initially sounds flexible, but it can get expensive fast if you need additional cores to achieve the throughput you’re aiming for. In practice, scaling up this way can end up costing more over time than buying an equivalent physical appliance.
Licensing is vCPU-based, which initially sounds flexible, but it can get expensive fast if you need additional cores to achieve the throughput you’re aiming for. In practice, scaling up this way can end up costing more over time than buying an equivalent physical appliance.
What problems is the product solving and how is that benefiting you?
FortiGate VM addresses the challenge of extending consistent, enterprise-grade NGFW security into environments where physical hardware either can’t be deployed or simply doesn’t make sense.
For cloud coverage, there’s no rack to mount a box in, so VM firewalls can inspect traffic directly inside AWS/Azure/GCP VPCs. It also helps maintain consistency across hybrid infrastructure by keeping the same policies, logging, and FortiManager/FortiAnalyzer-based management across on-prem, colo, and multiple clouds, rather than juggling different tools in each environment.
Another big advantage is speed and elasticity: you can deploy in minutes instead of waiting weeks for hardware procurement, shipping, and racking. That’s especially useful for DR sites, temporary environments, M&A integration, or scaling up and down with demand. On the cost side, vCPU-based licensing provides flexibility to pay for what you actually need, instead of over-provisioning hardware for peak capacity—helpful when traffic is unpredictable or seasonal.
Finally, FortiGate VM supports east-west segmentation by inspecting traffic between VMs and microservices inside a virtual network, which a perimeter hardware appliance can’t effectively cover.
Overall, it delivers enterprise-grade firewalling that’s quick to deploy, consistent across environments, and elastic—ideal for places where physical hardware can’t go or isn’t practical.
For cloud coverage, there’s no rack to mount a box in, so VM firewalls can inspect traffic directly inside AWS/Azure/GCP VPCs. It also helps maintain consistency across hybrid infrastructure by keeping the same policies, logging, and FortiManager/FortiAnalyzer-based management across on-prem, colo, and multiple clouds, rather than juggling different tools in each environment.
Another big advantage is speed and elasticity: you can deploy in minutes instead of waiting weeks for hardware procurement, shipping, and racking. That’s especially useful for DR sites, temporary environments, M&A integration, or scaling up and down with demand. On the cost side, vCPU-based licensing provides flexibility to pay for what you actually need, instead of over-provisioning hardware for peak capacity—helpful when traffic is unpredictable or seasonal.
Finally, FortiGate VM supports east-west segmentation by inspecting traffic between VMs and microservices inside a virtual network, which a perimeter hardware appliance can’t effectively cover.
Overall, it delivers enterprise-grade firewalling that’s quick to deploy, consistent across environments, and elastic—ideal for places where physical hardware can’t go or isn’t practical.
Recommendations to others considering the product:
To maximize the benefits of FortiGate VM, consider the following recommendations:
1. **Resource Allocation**: Ensure that your hypervisor has sufficient resources to handle the expected traffic load, especially if SSL inspection is a priority.
2. **Licensing Strategy**: Plan your vCPU licensing carefully to avoid unexpected costs. Consider your current and future throughput needs.
3. **Hybrid Deployment**: Use FortiGate VM in conjunction with physical appliances to balance performance and flexibility.
4. **Regular Updates**: Keep your FortiGate VM updated with the latest firmware to benefit from security patches and new features.
5. **Monitoring and Management**: Utilize FortiManager and FortiAnalyzer for centralized management and monitoring to streamline operations across your network.
6. **Testing Environment**: Leverage the VM for testing configurations and updates before deploying them to production environments.
By following these recommendations, you can effectively leverage FortiGate VM to enhance your network security posture.
1. **Resource Allocation**: Ensure that your hypervisor has sufficient resources to handle the expected traffic load, especially if SSL inspection is a priority.
2. **Licensing Strategy**: Plan your vCPU licensing carefully to avoid unexpected costs. Consider your current and future throughput needs.
3. **Hybrid Deployment**: Use FortiGate VM in conjunction with physical appliances to balance performance and flexibility.
4. **Regular Updates**: Keep your FortiGate VM updated with the latest firmware to benefit from security patches and new features.
5. **Monitoring and Management**: Utilize FortiManager and FortiAnalyzer for centralized management and monitoring to streamline operations across your network.
6. **Testing Environment**: Leverage the VM for testing configurations and updates before deploying them to production environments.
By following these recommendations, you can effectively leverage FortiGate VM to enhance your network security posture.
Thabet A.
Easy Virtual Deployment and a User-Friendly, Responsive Interface
Reviewed on Aug 25, 2026
Review provided by G2
What do you like best about the product?
What I like best about FortiGate-VM NGFW is how easy it is to deploy in virtual environments. The setup process is straightforward, and routing configuration is simple and clear compared to other firewalls I’ve used. The user interface is very user-friendly and responsive, which makes daily management and policy changes much faster and less complicated. FortiGate-VM NGFW works well with other tools in our environment. We use it alongside Microsoft Azure, Microsoft Sentinel, and Fortinet FortiAnalyzer. The integration is smooth, especially with logging and monitoring tools, which helps us centralize security visibility and manage policies more efficiently.
What do you dislike about the product?
One thing I dislike is that the HA setup can be a bit complicated, especially when configuring it for the first time in a virtual environment. Some advanced features also take time to fully understand. Additionally, the licensing and feature activation process could be more straightforward, and the documentation for certain HA and virtual deployment scenarios is not always clear enough.
What problems is the product solving and how is that benefiting you?
FortiGate-VM NGFW helps us secure our virtual and cloud environments by providing strong firewall protection, intrusion prevention, and traffic control. It solves the problem of managing security across different virtual infrastructures in a simple way. The main benefit is better network security with easier policy management and good performance, which gives us more confidence in protecting our systems without needing complex physical hardware.
E-Learning
FortiGate-VM: Full Security Stack in One Lightweight VM with Fast Deployment
Reviewed on Aug 25, 2026
Review provided by G2
What do you like best about the product?
What I appreciate most is the seamless integration of the full security stack into a single VM. Unlike physical appliances or other virtual solutions that require separate boxes for different functions, the FortiGate-VM gives me IPS, web filtering, application control, and SSL inspection all in one lightweight instance. Deployment on our VMware cluster took under 10 minutes, and the Security Fabric visibility across our hybrid environment has been a game-changer for troubleshooting traffic flows. The SD-WAN features are also surprisingly robust—we're load-balancing two ISPs without needing an extra device.
What do you dislike about the product?
The licensing model is my biggest headache—the performance tiers (VM-02 vs. VM-04, etc.) are confusing, and upgrading to a higher tier requires a full VM reboot, which means scheduling maintenance windows just to adjust throughput. Also, the GUI is great for basic policies, but once you need advanced SD-WAN rules or policy-based routing, you're forced into the CLI, and the documentation often assumes you're coming from a physical box. The learning curve there is frustratingly steep. Lastly, onboard logging fills up way too fast—you practically need a separate FortiAnalyzer or external syslog server if you want to keep more than a few days of historical data.
What problems is the product solving and how is that benefiting you?
We were stuck with aging physical firewalls that were hitting CPU limits during peak traffic, and upgrading meant costly hardware replacements and long shipping delays. The FortiGate-VM completely solved that by letting us spin up additional capacity on our existing ESXi hosts in minutes—no hardware wait times. It's also helping us consolidate multiple point solutions; we no longer run separate proxy servers and intrusion detection boxes because the VM handles everything inline. The biggest benefit has been agility—when our remote offices grew, we deployed new virtual instances in under 15 minutes instead of waiting days for hardware to ship. Plus, the centralized policy management via FortiManager has cut our rule-review time by half, which frees me up for actual infrastructure improvements rather than just firefighting.
Anonymous
Cost-Effective Firewall with CLI Familiarity, GUI Challenges
Reviewed on Aug 24, 2026
Review provided by G2
What do you like best about the product?
I mainly use FortiGate-VM NGFW as the main firewall for our AWS environment. I really like the price and performance of FortiGate-VM NGFW. The cost is a significant factor because at renewal, IPS and web filtering are bundled, so we're not paying per feature. The CLI is another aspect I appreciate; for admins coming from a Cisco background, it feels quite comfortable and familiar.
What do you dislike about the product?
The GUI slows down under load, so I end up in the CLI more than I'd like. It's worst when I'm pulling logs or big policy lists; pages take several seconds. I would like better pagination and faster log search.
What problems is the product solving and how is that benefiting you?
It replaced our VPN setup that didn't scale and was hard to manage. The price is great since IPS and web filtering are bundled, and the CLI is familiar for those with a Cisco background.
Computer & Network Security
Centralized, All-in-One Security for Virtualized Environments
Reviewed on Aug 19, 2026
Review provided by G2
What do you like best about the product?
FortiGate-VM NGFW stands out for centralized security management, comprehensive threat protection, and smooth integration with Fortinet’s security ecosystem. Having firewalling, IPS, web filtering, application control, and strong visibility all in one platform makes it well suited for monitoring and protecting virtualized environments, while keeping security operations consolidated and easier to manage.
What do you dislike about the product?
The main drawbacks are the complexity and cost of licensing, as well as the learning curve for more advanced configurations. The interface can also feel somewhat complicated when you’re managing larger environments, and troubleshooting certain issues may require fairly detailed knowledge of Fortinet-specific features and logs.
What problems is the product solving and how is that benefiting you?
FortiGate-VM NGFW provides centralized network security by bringing together firewalling, IPS, application control, web filtering, and traffic visibility in one place. It helps us detect and block threats, manage and control network traffic, investigate security events more effectively, and improve overall visibility across our environment. As a result, it reduces manual effort for our SOC, speeds up incident investigation, and strengthens our overall security posture.
Mohammad Aktham Obaid A.
Great GUI and Realistic VM Emulation with EVE-NG and PnetLab
Reviewed on Aug 18, 2026
Review provided by G2
What do you like best about the product?
it can be connected to any virtual machine app like eveng and pnetlab with success real life emulation
and we can add as much ram as wanted to emulate real life speed with a great, easy and helpful GUI
and we can add as much ram as wanted to emulate real life speed with a great, easy and helpful GUI
What do you dislike about the product?
when i use the VM i could not buy the licence i need, for example i could not buy the ICS/OT license
also when i connect it to a software like PnetLab sometimes i lose the access to my GUI and i lose the whole configurations i made
but i am not sure if this is a pnetlab problem
also when i connect it to a software like PnetLab sometimes i lose the access to my GUI and i lose the whole configurations i made
but i am not sure if this is a pnetlab problem
What problems is the product solving and how is that benefiting you?
its solve the "feel worried about changing problems" where you can safely build/emulate your own network to safely test the new configurations and testing new features
Banking
Consistent Hybrid-Cloud Security and All-in-One Features with FortiGate VM
Reviewed on Aug 17, 2026
Review provided by G2
What do you like best about the product?
Several standout aspects make this a preferred choice for IT and security professionals.
Consistent security across hybrid and multi-cloud environments is a big one. The same FortiOS everywhere means FortiGate VM runs the exact same operating system as physical FortiGate appliances, so administrators face virtually no learning curve when moving between on-premises hardware and cloud instances like AWS, Azure, Google Cloud, VMware, and KVM. With unified policies, organizations can enforce the same security posture, firewall rules, and threat protection standards no matter where workloads live.
Another strength is deep feature consolidation. Instead of stitching together separate tools for routing, SD-WAN, VPN, intrusion prevention, and web filtering, FortiGate VM integrates these capabilities natively. Being able to manage firewall rules, review threat logs, and control secure access from a single dashboard reduces operational complexity and can save hours of management time each week.
Built-in Secure SD-WAN is also a highlight. FortiGate VM includes robust Secure SD-WAN capabilities out of the box, enabling seamless and secure site-to-site connectivity along with intelligent path selection for cloud applications, without needing added hardware costs.
Consistent security across hybrid and multi-cloud environments is a big one. The same FortiOS everywhere means FortiGate VM runs the exact same operating system as physical FortiGate appliances, so administrators face virtually no learning curve when moving between on-premises hardware and cloud instances like AWS, Azure, Google Cloud, VMware, and KVM. With unified policies, organizations can enforce the same security posture, firewall rules, and threat protection standards no matter where workloads live.
Another strength is deep feature consolidation. Instead of stitching together separate tools for routing, SD-WAN, VPN, intrusion prevention, and web filtering, FortiGate VM integrates these capabilities natively. Being able to manage firewall rules, review threat logs, and control secure access from a single dashboard reduces operational complexity and can save hours of management time each week.
Built-in Secure SD-WAN is also a highlight. FortiGate VM includes robust Secure SD-WAN capabilities out of the box, enabling seamless and secure site-to-site connectivity along with intelligent path selection for cloud applications, without needing added hardware costs.
What do you dislike about the product?
Performance Drop with Full Security Features EnabledTurning on intensive security inspection features (such as deep packet inspection, antivirus, intrusion prevention, and web filtering) can cause a noticeable drop in throughput capacity. Careful sizing and resource allocation are required to prevent performance bottlenecks. High Cost and Complex Licensing StructureBoth the software licenses and the required security subscriptions (FortiGuard services) are expensive. Additionally, managing license activation files and tying them to specific virtual machine instances or cloud environments can sometimes be an overly rigid and frustrating process.Resource and Cloud Networking ComplexitiesInitial setup and networking configuration in public cloud environments (like AWS, Azure, or Google Cloud) can be complex compared to traditional on-premises deployments. Administrators also report occasional CPU utilization spikes and packet latency during high-traffic events or simultaneous administrator logins.
What problems is the product solving and how is that benefiting you?
The FortiGate VM Next Generation Firewall solves several critical infrastructure and security challenges, and those solutions translate into major operational benefits:
Solving Cloud Security Blind Spots and Inconsistency
Problem: Managing security across a mix of on premises data centers and public clouds like AWS or Azure usually means dealing with disjointed tools and different vendor interfaces.
Benefit: Because FortiGate VM runs the exact same operating system everywhere, it allows organizations to enforce uniform firewall rules and security policies across hybrid environments, eliminating blind spots and reducing human error.
Solving Fragmented Infrastructure and Tool Sprawl
Problem: Relying on separate point products for routing, virtual private networks, web filtering, and intrusion prevention creates high overhead and complex maintenance.
Benefit: By consolidating these features natively into a single virtual appliance, it slashes the time spent managing multiple security vendors and simplifies daily administrative workflows.
Solving Cloud Security Blind Spots and Inconsistency
Problem: Managing security across a mix of on premises data centers and public clouds like AWS or Azure usually means dealing with disjointed tools and different vendor interfaces.
Benefit: Because FortiGate VM runs the exact same operating system everywhere, it allows organizations to enforce uniform firewall rules and security policies across hybrid environments, eliminating blind spots and reducing human error.
Solving Fragmented Infrastructure and Tool Sprawl
Problem: Relying on separate point products for routing, virtual private networks, web filtering, and intrusion prevention creates high overhead and complex maintenance.
Benefit: By consolidating these features natively into a single virtual appliance, it slashes the time spent managing multiple security vendors and simplifies daily administrative workflows.
Paper & Forest Products
All the Fortinet Features in a Fast, Impressive Virtual Machine
Reviewed on Aug 16, 2026
Review provided by G2
What do you like best about the product?
The fact that you have basically all the features and settings of the other Fortinet physical devices. The performances of the virtual machine are also quite impressive
What do you dislike about the product?
The pricing isn’t very competitive compared to physical firewalls. On top of that, the licensing model feels quite complex and difficult to navigate. The VM also lacks acceleration performance for decryption, which impacts overall efficiency.
What problems is the product solving and how is that benefiting you?
Sometimes, for specific deployments, we can’t use a hardware firewall, so having a single ESXi node with the firewall embedded is essential for our organization.