What is our primary use case?
Fortinet FortiGate is used primarily for network security and secure internet access, with primary applications in firewall policy management, VPN connectivity, SD-WAN, application and URL filtering, NAT, and protecting the internal network and servers from external threats.
A common example involves using Fortinet FortiGate to provide secure internet access for different departments by creating firewall policies based on the user, application, and destination while applying security profiles such as URL filtering, application control, and IPS. Traffic logs are monitored to identify and block suspicious activities. For VPN connectivity, IPsec VPN is used for site-to-site connectivity between offices and SSL VPN is used for remote user access when required. Recently, an IPsec VPN was configured and tested between a branch office and main office to securely access internal applications and servers over the internet.
Beyond secure internet access and VPN connectivity, Fortinet FortiGate is relied upon for day-to-day firewall policy management, NAT, SD-WAN, application control, URL filtering, traffic monitoring, and troubleshooting connectivity issues. It is also used for security monitoring, firmware upgrades, HA management, and checking CPU, memory, and interface utilization. Overall, Fortinet FortiGate is an important part of daily network security and operations.
How has it helped my organization?
Fortinet FortiGate has improved overall network security and made day-to-day network management more efficient. Better visibility into network traffic is available through detailed logs and monitoring, and features such as IPS, application control, URL filtering, and security policies help to control and protect internet access. Reliability has been improved through HA and SD-WAN capabilities, while VPN features make secure connectivity between sites and remote users easier to manage. Overall, faster troubleshooting, better control over network traffic, and more consistent security across the organization have been achieved.
One of the main improvements noticed is faster troubleshooting because Fortinet FortiGate provides detailed traffic logs, session information, and real-time monitoring. This helps to identify whether an issue is related to firewall policies, application or VPN connectivity, or network traffic much more quickly.
What is most valuable?
The features that stand out most are centralized policy management, IPS, application control, web and URL filtering, SSL or IPsec VPN, SD-WAN, and high availability. The traffic log and monitoring tools are very useful for troubleshooting and security analysis. Another strong point is the integration of multiple security capabilities in a single platform, which makes day-to-day network security management easier and more efficient.
Fortinet FortiGate's UI is intuitive and makes day-to-day administration easier, as firewall policies, interfaces, VPN, SD-WAN, security policies, and traffic logs can be quickly navigated without relying heavily on the CLI. The dashboard also gives a quick view of CPU, memory, session, and interface utilization, which helps with monitoring and troubleshooting. For high availability, Fortinet FortiGate HA is very useful because two firewalls can be configured in an active-passive cluster, and if the primary firewall experiences a failure, the secondary firewall takes over, which helps to minimize downtime.
Fortinet FortiGate combines multiple security functions into one platform, including firewall, IPS, application control, web filtering, VPN, and SD-WAN. The detailed logging and reporting are also helpful for troubleshooting and security analysis. Overall, these features provide good visibility and control over network traffic while reducing the need to manage multiple separate security solutions.
What needs improvement?
Fortinet FortiGate is generally easy to manage, but there are a few areas where it could be improved. The interface can become complex when managing a large number of firewall policies, and better policy search organization and reporting would be helpful. Firmware upgrades can also require careful planning and testing, especially in production environments. Troubleshooting some advanced issues may require deeper CLI knowledge or assistance from Fortinet support, and more advanced automation and AI-assisted troubleshooting within the management interface would be beneficial, such as clear recommendations for policy optimization, configuration issues, and security events. These improvements could make day-to-day administration even more efficient.
More AI-driven capabilities for day-to-day administration would be valuable, especially for troubleshooting, policy optimization, and identifying potential configuration issues. More intelligent recommendations based on traffic patterns and security events could help administrators respond faster. More advanced reporting and dashboards that can be easily customized for different teams and management requirements would also be helpful, while better automation for routine tasks, firmware planning, and configuration validation would further reduce manual effort.
For how long have I used the solution?
There is approximately two years of hands-on experience working with Fortinet FortiGate firewall, including configuration, troubleshooting, and managing firewall, SD-WAN policies, security profiles, and firmware upgrades.
What do I think about the stability of the solution?
Fortinet FortiGate is stable and working fine.
What do I think about the scalability of the solution?
Fortinet FortiGate has good scalability and can support different network sizes, from smaller branch offices to large enterprise networks with a range of hardware models and Fortinet FortiGate VM options for virtual and cloud deployment. It also scales well through features such as HA, SD-WAN, centralized management, and segmentation. As the organization grows, firewall capacity can be increased or additional Fortinet FortiGate devices can be deployed without completely redesigning the security architecture. The combination of different hardware options, cloud flexibility, and HA makes Fortinet FortiGate suitable for both current requirements and future network growth.
How are customer service and support?
Fortinet customer support is excellent overall. Fortinet technical support is useful for troubleshooting complex issues, firmware-related problems, and integration questions. The support team can also help with detailed log analysis and provide recommendations when an issue cannot be resolved through normal troubleshooting.
Which solution did I use previously and why did I switch?
Before using Fortinet FortiGate, other firewall platforms were used, including Check Point and Palo Alto, depending on customer requirements. The move to Fortinet FortiGate was mainly driven by the combination of security and networking features, straightforward management, VPN and SD-WAN capabilities, and the ability to manage multiple security functions from a single dashboard or single platform. The graphical user interface and the monitoring capabilities were found helpful for day-to-day administration and troubleshooting. Overall, Fortinet FortiGate provided a good balance of functionality, operational efficiency, and scalability for the environment.
What was our ROI?
A positive return on investment has been seen, mainly due to improved efficiency and reduced troubleshooting effort. Fortinet FortiGate combines firewall, VPN, SD-WAN, IPS, application control, and web filtering capabilities on one platform, so fewer separate security solutions need to be managed. The detailed logs, monitoring, and centralized management also help to identify and resolve network issues faster, which saves engineering time. HA and SD-WAN improve availability and reduce the potential impact of connectivity or firewall failures. An exact percentage for cost saving or reduction has not been formally calculated, but the time saved in daily administration and troubleshooting has been a clear benefit.
What's my experience with pricing, setup cost, and licensing?
The experience with Fortinet FortiGate pricing and licensing has been generally positive. The initial setup cost depends on the firewall model, required performance, and the security feature or subscription selected. The licensing is straightforward, with additional security services such as IPS, antivirus, web filtering, and application control available through subscription packages. The main consideration is the recurring cost of the security subscription and the support renewal, and for an organization using multiple Fortinet FortiGate devices, budgeting for this renewal is important. Overall, the pricing is reasonable considering the number of security and networking capabilities provided in a single platform.
Which other solutions did I evaluate?
Other firewall solutions were evaluated, mainly Check Point and Palo Alto, as well as Fortinet FortiGate. They were compared based on security capabilities, firewall and VPN functionality, SD-WAN, ease of management, monitoring and reporting capabilities, scalability, support, and overall cost. Fortinet FortiGate stood out because it provides a broad set of security and networking features in a single platform while being relatively straightforward to manage for day-to-day operations.
What other advice do I have?
The combination of reliability, security features, and ease of management stands out most. Fortinet FortiGate provides a single platform for firewall, security, SD-WAN, IPsec, IPS, application control, URL filtering, and traffic monitoring. The usability in day-to-day operations is valued, and the visibility provided through logs and dashboards makes troubleshooting much faster. HA capabilities are another important factor because they help to maintain network availability. Overall, the combination of strong security capabilities, reliable performance, and practical day-to-day management makes Fortinet FortiGate stand out.
Fortinet FortiGate's AI capabilities are useful when combined with strong security controls and governance. AI-driven threat detection and security analysis can help identify suspicious activity and provide useful insights, while administrators still have control over policies and security decisions. From the governance perspective, clear visibility into how AI-based recommendations are generated is important, along with strong access control, logging, and auditing. Security is especially important when AI is involved, so having control access and keeping human oversight in the decision-making process is crucial. Overall, AI is seen as a useful enhancement to Fortinet FortiGate's security capabilities, particularly for faster threat detection, analysis, and troubleshooting.
Fortinet FortiGate's AI-assisted capabilities can provide useful and relevant insights, particularly for identifying suspicious activity, analyzing security events, and supporting threat detection. The recommendations are helpful as a starting point and can reduce the time required to investigate issues. However, AI recommendations alone should not be relied upon for critical security decisions, as recommendations should still be validated against traffic logs, existing policies, and the actual network environment before making changes. Overall, the AI capabilities are useful and reliable for assisting security operations, while human validation remains important for production environments.
Fortinet FortiGate is primarily deployed on-premises in the organization, where it is used as a perimeter firewall for securing internet traffic, internal network segments, servers, and VPN connectivity. There is also experience with Fortinet FortiGate VM deployment in cloud environments when required. The on-premises deployment gives direct control over network security, firewall policies, monitoring, and HA, while virtual and cloud deployment provides flexibility for workloads hosted in cloud environments.
Fortinet FortiGate would be recommended to organizations looking for a comprehensive firewall and network security solution. Before purchasing, it is important to clearly define network requirements, expected traffic volume, VPN users, security features, and future scalability so the right Fortinet FortiGate model and licensing can be selected. Testing the required security policies, profiles, VPN, SD-WAN, and HA configuration in a lab or proof-of-concept environment before deploying them in production is also crucial. Proper planning, configuration, monitoring, and regular firmware upgrades are important to get the most value from the platform. A rating of 10 out of 10 would be given for Fortinet FortiGate.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure