Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Network Engineer at a tech services company with 501-1,000 employees
Consultant
Controlling and tracing with web console works nicely for windows systems, but for Linux, only IP can be obtained.

What is most valuable?

  • Policy control
  • Web filtering
  • Application filter works smoothly.
  • Controlling and tracing with web console works nicely for windows systems.
  • Better QoS than Checkpoint, I believe.

How has it helped my organization?

Previously, my organization had the Checkpoint firewall solution, which has been replaced by the Fortinet Fortigate solution, which is cost effective and more manageable from a beginner's perspective.

Fine QoS and Web based filtering solution is a plus.

What needs improvement?

  • Maybe Linux system monitoring can be improved by the developers of the product.
  • Although it has policy control and web filtering, these could be better.
  • Application filter needs more control options.
  • IP tracing works only so-so.
  • Controlling and tracing with web console for Linux only obtains IP addresses.
Disclosure: My company has a business relationship with this vendor other than being a customer. My company provides tech services that include this product.
PeerSpot user
PeerSpot user
Project Manager at a tech vendor with 1,001-5,000 employees
Vendor
For price criteria, Fortinet wins over competitors. That being said, certain areas of the product need improvement

What is most valuable?

  • Performances
  • VDOM
  • UTM
  • Consolidated Management
  • FortiGuard

    How has it helped my organization?

    • Endpoint control of mobile devices with Security Profiles compliancy checking, captive portal redirection, Antivirus, IPS and Web Filtering enabled on outgoing traffic (coupled to FortiClient solution)
    • Identity-based policies used to authenticated and profile users and guests whatever the media used to access the network (ie. Wired and WiFi)
    • Dynamic BGP routes injections to divert traffic requiring UTM inspection or DDOS mitigation
    • Two-Factor Authentication VPN SSL for itinerant users (coupled to FortiToken solution)
    • Active/Active cluster load-balancing http/https traffic
    • GTP tunnels inspections over GPRS backbones for pure-player telco operators
    • Distributed WiFi infrastructure with UTM enabled and managed from the central console like signatures and firmware updates
    • Classical IP/IPv6 Firewall with consolidated-management

    What needs improvement?

    • Fix all pending bugs present in 5.0.x branch
    • Improve the testing process of newly published firmware like using real and representative configurations submitted to consequent traffic load during a while
    • Support SNMPv3 INFORM requests
    • Uniform the scheduled backup between FortiGate, FortiManager and FortiAnalyzer
    • Integrate graphical troubleshoot tools for policies based on devices or user identities

    For how long have I used the solution?

    4.5 years

    What was my experience with deployment of the solution?

    Some few non-blocking bugs present in the latest release and which are now solved. In the past I encountered serious bug regarding SCTP and GTP supports. Fortinet helped me to qualify the bug, implement a temporary workaround and then published appropriate patches rapidly.

    What do I think about the stability of the solution?

    No. I always used the latest qualified-stable firmware recommended by Fortinet and check by own testing methods the stability of HW and SW before deploying anything into customer premises.

    What do I think about the scalability of the solution?

    With design and dimensioning parts well achieved I never encountered scalability issue. However it happened I had to troubleshoot some slowness and latency issues on existing projects already running live. Most of the time they were due to some design issues and non-optimized configurations like for instance “in” and “out” ports not handled by the same NP, policy rules non-optimized and non-used features enabled.

    How are customer service and technical support?

    Customer Service:

    Very good.

    Technical Support:

    Very good.

    Which solution did I use previously and why did I switch?

    • CISCO ASA: Too expensive, performances issues, non-consolidated management between traditional ASA and inspection ASA CX, not the best security engines
    • Checkpoint: Very expensive but good solutions, not the leader in UTM segment
    • Juniper: Expensive but good solutions, not the leader in UTM segment
    • Cyrberoam: Attractive prices but not yet tested, looks like promising
    • Arkoon/Netasq: Obsoletes (Stormshield not yet tested)

    How was the initial setup?

    It was quite simple if you have at least a minimum of experiment with Firewalls integration. It is now even simpler thanks to the FortiExplorer application.

    What about the implementation team?

    In-house.

    Which other solutions did I evaluate?

    Taking into account the price criteria, nowadays Fortinet always wins offers in front of competitors like CISCO and Checkpoint. Mixing this key-point with other success keys like UTM features and performances.

    What other advice do I have?

    Contact Fortinet or Fortinet’s partner and ask for a POC.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Fortinet FortiGate
    June 2025
    Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
    860,168 professionals have used our research since 2012.
    PeerSpot user
    CEO with 51-200 employees
    Vendor
    I've been using it for 6 years. I like the security profiles and vulnerability assessment.

    Valuable Features

    • Load Sharing
    • VDOM
    • Security Profiles
    • Vulnerability Assessment

    Use of Solution

    6 Years

    Deployment Issues

    Yes, bugs.

    Stability Issues

    No.

    Customer Service and Technical Support

    Poor.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    it_user275226 - PeerSpot reviewer
    IT Director with 501-1,000 employees
    Vendor
    I don't need to have a cluster because it's stable, but rules are not intuitive and the admin UI needs improvement.

    What is most valuable?

    It offers a proxy and a firewall.

    How has it helped my organization?

    It has a better processor than CheckPoint.

    What needs improvement?

    It's not intuitive, as the rules will be in the last place you look. You can look for a report for an hour, eventually getting a blank page. User experience for the administrator is basically not good as it needs to be more proficient.

    For how long have I used the solution?

    I've used it for two years.

    What was my experience with deployment of the solution?

    I have five ISPs, and it was hard to connect the LAN to the WAN. It did not go well and I had do to a roll-back.

    What do I think about the stability of the solution?

    The product is so stable I don't need to have a cluster.

    How are customer service and technical support?

    Customer Service:

    I use a service given by the integrator and it's better than Fortigate’s. The integrator gives me a guarantee that they will immediately replace my machine if a problem occurs.

    Technical Support:

    I use a service given by the integrator and it's better than Fortigate’s. The integrator gives me a guarantee that they will immediately replace my machine if a problem occurs.

    Which solution did I use previously and why did I switch?

    I used an open-source product name Squid.

    How was the initial setup?

    It's straightforward, and was transparent for the users.

    What about the implementation team?

    We did it in-house.

    What was our ROI?

    It costs $200,000 and is only a bit better than the open source solution, which was free.

    What's my experience with pricing, setup cost, and licensing?

    You don’t have to buy the Fortigate analyzer, as you can also get the reports using Fortinet.

    What other advice do I have?

    It's fine as a firewall and as a proxy. You need to configure the rules right or else it will be hard to keep up with the logs.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Andrew S. Baker (ASB) - PeerSpot reviewer
    Andrew S. Baker (ASB)Cybersecurity & IT Operations Professional (VirtualCxO) at BrainWave Consulting Company, LLC
    Consultant

    The v5.6 GUI is much improved, IMO. Very happy to see the changes there. Some things are still a little hard to find, but not as many.

    See all 5 comments
    PeerSpot user
    Security Consultant at Webernetz.net - Network Security Consulting
    Consultant
    Cisco ASA vs. Fortinet FortiGate vs. Palo Alto vs. Juniper SSG

    Since IPv6 gets more and more important, I am using it by default on all my test firewalls, which of course support IPv6. However, when comparing the different functions and administration capabilities, they vary significantly.

    Here comes my short evaluation of the IPv6 functions on the following four firewalls: Cisco ASA, Fortinet FortiGate, Juniper SSG, and Palo Alto.

    Criteria

    I was merely interested in the basic IPv6 usage and not in the typical firewall categories:

    • Interface: IPv6 address and link-local address configurable?
    • Router Advertisement and DHCPv6: Whether the firewalls support nothing (–), only RA (-), DHCPv6 relay (ο), stateless DHCPv6 (+), or stateful DHCPv6 (++). The existence of stateless DHCPv6 is vital for delivering the DNS server IPv6 addresses to the clients. (The “IPv6 Router Advertisement Options for DNS Configuration”, RFC 6106, is not supported by any of these devices.)
    • Security Policy: Whether IPv4 and IPv6 addresses can be used in the same policy and whether address groups can have objects from both protocols.
    • Administration: How easy are the IPv6 functions to manage? Only via the CLI (–), fifty-fifty (ο), GUI but complicated (+) , or fully via the GUI (++).

    Results

    These are the results. They range from — via ο to ++.


    Cisco ASA
    Fortinet FortiGate
     Juniper ScreenOS
    Palo Alto
    Version
    9.2(3)
    5.2.2
    6.3.0r18.0
    6.1.3
    Interface
    ++
    +
    ++
    ++
    RA, DHCPv6
    -
    ++
    +
    0
    Security Policy
    ++
    -
    -
    ++
    Administration + - + ++

    Details

    Cisco ASA

    The Cisco ASA has no DHCPv6 instance running. That is: there is no way to run an IPv6-only network because clients won’t get the DNS server. The security policy is capable of both protocols. Everything is configurable via the GUI, which is not the best at all.

    Fortinet FortiGate

    The FortiGate is the only firewall with a stateful DHCPv6 server. Great. However, two distinct security policies must be used and nothing of the IPv6 settings are configurable via the GUI. WHAT???

    Juniper SSG (ScreenOS)

    ScreenOS is dead. However, most of the IPv6 functions are working quite good, except the protocol dependent security policies. Everything is accessible via the GUI, but sometimes on confusing positions.

    Palo Alto

    Palo Alto did a good job on the IPv6 interfaces and security policies. The GUI is quite intuitive and the policy accepts both protocols at the same time. Unluckily, there is no DHCPv6 server which makes it impossible to operate an IPv6-only client network behind a Palo Alto (without further servers).

    Conclusion

    It’s interesting to see the differences between those firewalls. While the Fortinet und Juniper firewalls support the whole SLAAC process incl. DNS servers, they have no single security policy for both protocols and are horrable to configure.

    The Palo Alto is quite good to configure but lacks the DHCPv6 server. Same for the Cisco.

    In summary, all firewalls position in the middle of my scale. From an IPv6-only view, I cannot say which one is the best. It depends….

    Originally published on blog.webernetz.net

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user245154 - PeerSpot reviewer
    Customer Support engineer at a healthcare company with 51-200 employees
    Vendor
    It helps to come up with the requirements of proxy servers, but it does not have that much troubleshooting & network testing features.

    What is most valuable?

    The key features of this product are:

    • Network security
    • UTM Features
    • Configuration and ease of deployment.
    • IP/User/Device Mac ID/Device Type based policy configuration
    • Traffic shaping
    • Load balancing
    • Ease of VPN configurations
    • Explicit proxy
    • Link segregation
    • Application signatures
    • Network object based HTTPS/SSL inspection etc.

    How has it helped my organization?

    In many organizations it helps to come up with the requirements of proxy servers, defining network traffic and the amount of bandwidth for any network object or specified user(s). It has also provided us with security compatibility with other network devices such as IP cameras, the video conferencing system, VOIP phones. It also logs & reports on individual users network activities.

    What needs improvement?

    The FortiGate series does not have that much troubleshooting & network testing features in its GUI, hence we’ll definitely be looking for some add-on features in near future.

    For how long have I used the solution?

    I have been using this solution for the past year.

    What was my experience with deployment of the solution?

    No issues yet.

    What do I think about the stability of the solution?

    No issues yet.

    What do I think about the scalability of the solution?

    For massive logs & reports (over a month) we have to go for a separate logging & reporting device i.e. FortiAnalyzer/FortiCloud, as this is not available in Fortigate itself.

    How are customer service and technical support?

    Customer Service:

    7/10.

    Technical Support:

    8/10.

    Which solution did I use previously and why did I switch?

    We started with FortiGate itself.

    How was the initial setup?

    This product has a setup wizard (FortiExplorer) for the initial configuration, while the physical connectivity is done via a USB cable which is very easy to use.

    What about the implementation team?

    We implemented the solution ourselves.

    What was our ROI?

    It is value for money product as we’ve purchased it with Fortinet's three-year warranty package.

    Which other solutions did I evaluate?

    We have evaluated Dell’s Sonicwall & Cyberoam.

    What other advice do I have?

    Analyze your needs first before implementing this product.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user241746 - PeerSpot reviewer
    Software Test Engineer with 501-1,000 employees
    Vendor
    The product has lived up to its expectations but the web interface needs to be improved.

    What is most valuable?

    • Anti-virus
    • NAT
    • VPN

    How has it helped my organization?

    It's the only security product in place that is responsible for guarding the network infrastructure deployed within the premises. The product has lived up to its expectation with no issues whatsoever.

    What needs improvement?

    The web interface could be made better.

    For how long have I used the solution?

    I've used it for eight years.

    What was my experience with deployment of the solution?

    No issues encountered.

    What do I think about the stability of the solution?

    No issues encountered.

    How are customer service and technical support?

    We have managed to maintain the device without getting in touch with technical support. Credit can be given to the documentation provided.

    Which solution did I use previously and why did I switch?

    This was the first security device that was deployed.

    How was the initial setup?

    Setup was straightforward and the documentation was very clear which meant that there were no issues during the initial setup.

    What about the implementation team?

    We had a vendor assist us who had decent knowledge about the product.

    Which other solutions did I evaluate?

    We also looked at pfSense.

    What other advice do I have?

    The product has reached its end of life.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user241101 - PeerSpot reviewer
    Network Administrator at a real estate/law firm with 51-200 employees
    Vendor
    It offers unlimited VPN licensing but it needs a real-time log viewer in the GUI.

    What is most valuable?

    The unlimited VPN licensing. All of our remote locations (1000+) used IPSec VPN and SSL to connect to the cluster.

    How has it helped my organization?

    We went from being terrified about our firewalls screwing up to completely forgetting we had firewalls. I slept better and so did my manager.

    What needs improvement?

    A real-time log viewer in the GUI with the capability to filter traffic displayed. Cisco ASA's have this and it's fantastic.

    For how long have I used the solution?

    I used it for four years. We had two devices that were clustered together in a high availability pair as the front end of an country wide, high visibility solution.

    What was my experience with deployment of the solution?

    No issues encountered.

    What do I think about the stability of the solution?

    No issues encountered.

    What do I think about the scalability of the solution?

    No issues encountered.

    How are customer service and technical support?

    Customer Service:

    Customer service was decent with Fortinet - they were helpful and got the product to our doorstep quickly.

    Technical Support:

    This is where Fortinet stumbles. The support is farmed out overseas to techs that are not very knowledgeable about the Fortinet products. The response time for a critical priority one issue was over four hours and they only responded because we threatened legal action for them violating our support contract.

    Which solution did I use previously and why did I switch?

    They used to have Juniper products, which are terrible. The enterprise class firewalls do not support any sort of packetflow gathering such as netflow, and the devices didn't even support Juniper's proprietary jflow. Their SRX series routers, meant for home office use, had more features and capabilities.

    How was the initial setup?

    It was very straightforward and we encountered very little problems. Fail-over occurred within a second with zero outages or anyone actually taking notice. Firmware updates were easy to apply in a live environment if required, and the GUI was very easy to understand.

    What about the implementation team?

    I deployed it - I'm FCNSA certified.

    What was our ROI?

    If we used a similar solution that required a "per seat" license per VPN, we would have literally spent over 100x what the solution cost us.

    What's my experience with pricing, setup cost, and licensing?

    We implemented the clustered firewalls for around $30,000, and each office had another Fortigate device at a cost of around $1,000.

    Which other solutions did I evaluate?

    Cisco was evaluated but we didn't want to pay for the VPN licensing.

    What other advice do I have?

    It's an absolutely fantastic product. Just get your support contract clarified, and confirm the response times.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Fortinet FortiGate Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2025
    Buyer's Guide
    Download our free Fortinet FortiGate Report and get advice and tips from experienced pros sharing their opinions.