What is our primary use case?
The main use cases for Fortinet FortiGate usually include security to filter traffic to inside the network, load balancing and QoS for the user side, as well as Zero Trust Network Access, allowing users outside and inside the network fabric to connect to our application that is under the firewall.
What is most valuable?
The most useful features in Fortinet FortiGate are the security features, where we can analyze what kind of traffic is inside our network, and we also utilize ZTNA for limiting and managing our network access.
What needs improvement?
The issue with Fortinet FortiGate is the many security CVEs around; I have read there are probably multiple critical CVEs above 9.0 in Fortinet FortiGate products. There appear to be fewer issues with other brands such as Palo Alto or Check Point, but especially with Fortinet FortiGate, there are many vulnerabilities that can be found. The way we manage this is by applying updates whenever new ones are available, but the high critical CVEs generate concern, as we buy security products for our safety and when we find that attackers can easily breach them, it makes us question the safety of the product itself.
I hope we can deploy the product in an active-active configuration since we currently have two units in an active and passive setup. There are limitations when trying to install it with active-active, but we hope to run it that way.
For how long have I used the solution?
I have been working with the Fortinet FortiGate firewall for two years.
What do I think about the stability of the solution?
Stability wise, Fortinet FortiGate is quite good; we rarely have issues with stability, and compared to the previous solution we had, which was much worse, Fortinet FortiGate has had no issues so far.
What do I think about the scalability of the solution?
Fortinet FortiGate is not very scalable. We use the appliance, and once we are out of capacity, we have to buy a new one, as there is no way through scalability. I would rate scalability as a seven out of ten.
How are customer service and support?
I rarely use customer support, but there are a few cases where I tried to reach out before, and it was handled and closed properly, so I had no issues. I would rate the support as nine, based on my experience.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
The previous solution we used was Sophos. Sophos had stability problems.
How was the initial setup?
The setup is not complex. It's quite straightforward.
What was our ROI?
The return on investment after implementing Fortinet FortiGate has been quite okay, allowing us to get the value of what we paid for.
The benefit is more like we are buying insurance. All of the security products may be optional, but having them helps us feel safer and assures us that our network is protected from attackers.
What's my experience with pricing, setup cost, and licensing?
It's affordable. We usually pay about 10K USD annually for the license on a yearly basis.
What other advice do I have?
We have experience with integrating SD-WAN capabilities in Fortinet FortiGate. It is only useful if we have multiple internet operators; if we use a one-to-one connection, there are no benefits. Some of our sites do have multiple internet access, allowing us to use SD-WAN to manage the connection, making it easier to treat it as a single connection while SD-WAN helps manage and load balance between those two.
We do not use Fortinet Unified SASE now, but we are considering implementing it. In the data center, we actually have another solution, but Fortinet FortiGate is used only for our customer-facing side.
My advice to those planning to use Fortinet FortiGate is to check for updates often. We had several issues before due to the firmware we used, but after upgrading to the 7.4 firmware, a lot of issues were resolved just by applying the update regularly. Actually, compared to other firewalls, it is on the very affordable side.
I would rate Fortinet FortiGate an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.