I am the network administrator at THK Rhythm Automotive.
Fortinet FortiGate-VM delivers robust security services and advanced network management suitable for cloud environments, providing solutions like firewall and SD-WAN, with seamless integration across Fortinet devices.

| Product | Mindshare (%) |
|---|---|
| Fortinet FortiGate-VM | 2.2% |
| Fortinet FortiGate | 15.1% |
| OPNsense | 8.5% |
| Other | 74.2% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Firewalls | Jun 21, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Jun 21, 2026 | Download |
| Comparison | Fortinet FortiGate-VM vs Fortinet FortiGate | Jun 21, 2026 | Download |
| Comparison | Fortinet FortiGate-VM vs Netgate pfSense | Jun 21, 2026 | Download |
| Comparison | Fortinet FortiGate-VM vs Sophos Firewall | Jun 21, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Fortinet FortiGate | 4.2 | 15.1% | 92% | 592 interviewsAdd to research |
| Netgate pfSense | 4.3 | 8.0% | 94% | 221 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 64 |
| Midsize Enterprise | 29 |
| Large Enterprise | 34 |
| Company Size | Count |
|---|---|
| Small Business | 331 |
| Midsize Enterprise | 168 |
| Large Enterprise | 282 |
FortiGate-VM is designed for enterprise security, offering comprehensive features like intrusion prevention and application filtering. It's known for its scalability and flexibility, supporting cloud platforms such as Azure and AWS. It enhances threat response and network management efficiency, thanks to real-time threat response, intuitive integration with existing systems, and cost-effectiveness.
What are the key features of Fortinet FortiGate-VM?Fortinet FortiGate-VM is predominantly employed in industries requiring stringent data center security, enabling network segmentation and VPN services. It's particularly favored by organizations using virtual and cloud networks due to its Unified Threat Management capabilities, making it an efficient solution for protecting virtual environments from threats.
Fortinet FortiGate-VM was previously known as FortiGate Virtual Appliance, FortiGate-VM.
Security7 Networks, COOPENAE
| Author info | Rating | Review Summary |
|---|---|---|
| Network Administrator at THK Co Ltd | 4.0 | As a network administrator, I value Fortinet FortiGate-VM's IPS, web, and DNS filters, using it for over 10 years. Setup was challenging without prior experience, and my current device is underpowered, requiring replacement. I chose it for its price. |
| CISO at Orient Technologies Pvt. Ltd. | 4.5 | I find Fortinet FortiGate-VM a stable, scalable cloud firewall, offering rapid deployment, real-time threat response, and improved security. Its ease of integration and value surpass competitors, earning a 9/10 despite minor VM availability concerns. |
| Founder at a tech services company with 11-50 employees | 3.5 | I see Fortinet FortiGate-VM as a cost-effective, feature-rich solution, comparable to competitors. However, I stress careful sizing as enabling all security features significantly degrades throughput, potentially needing a higher-grade model. |
| Technical Consultant Network and Cybersecurity at Redington | 4.5 | I highly recommend Fortinet FortiGate-VM for virtual data center security, citing its easy deployment, excellent threat detection, and stability. However, I believe its limited FortiWAF features need enhancement and pricing could be more flexible. |
| Head Of Security Management at Ipko Telecommunications | 4.0 | We find Fortinet FortiGate-VM excellent for security, network visibility, and internet gateway functionality, using it for IDS/IPS, WAF, and VPN. Implementation was straightforward with our team. While very good, we feel the licensing cost could potentially be lower. |
| EMEA Enterprise Solutions Architect at a tech vendor with 1,001-5,000 employees | 4.0 | I use Fortinet FortiGate-VM for customer VPN and SSL VPN connections in hybrid cloud disaster recovery. It's user-friendly and cost-effective for SMBs, though high-level security visibility needs improvement. I rate it 8/10. |
| System Engineer at A-Networks | 4.0 | I find Fortinet FortiGate-VM excellent for cloud security, offering real-time threat response, accurate signatures, and good visibility. Its Security Fabric and IPS are strong, and setup is easy. While affordable and flexible, firmware upgrades occasionally introduce bugs, which is an area for improvement. |
| CEO at Kapstone Technological Services LLP | 5.0 | I highly recommend Fortinet FortiGate as an excellent, proven product. It offers unique VDOMs, strong threat management, and reliable support, being stable, scalable, and easy to set up for various customers. |
| Senior Escalation Engineer at a tech services company with 201-500 employees | 3.5 | I primarily use Fortinet FortiGate-VM in Azure, appreciating its hardware-like feel and granular security policies over SonicWall. Setup is easy, and it's very scalable. However, logging could be improved for better root cause analysis. I rate it 7/10. |
| Re Manager at a computer software company with 201-500 employees | 4.5 | I utilize Fortinet FortiGate-VM for cloud migration, finding it a superior, primary firewall. It improves security with ZTNA/SASE and adapts to evolving threats. Much better than open-source, I rate it nine out of ten. |
I am the network administrator at THK Rhythm Automotive.
The features and capabilities of Fortinet FortiGate-VM that I have found most valuable are not only specific to Fortinet FortiGate-VM, but generally for most sites: a valuable web filter and DNS filter work together. For some sites, application filtering is important. The most important feature is IPS, which is the main reason for using Fortinet FortiGate firewalls. The current solution is only on the border of our network, between the company network and the internet.
I spent much time finding exact firmware on Aruba which was working with these guns, but it is not optimal because it is not the latest version, so there could be potential security problems. We decided to replace those access points with another one. I personally have trouble because I don't know the exact life cycle of Fortinet FortiGate-VM boxes. I don't know if the life of boxes is five years or something else; we moved from our previous company, which sold us to other companies.
Before 10 years, we had a special department that took care of core networks, including firewalls. After that, this responsibility fell to me and my colleague. It is not easy to set up these Fortinet FortiGate-VM boxes properly because we didn't have previous experience with this kind of solution. At first, we set up only a few rules that were not secure enough, and over a couple of years, we improved the settings and security of these Fortinet FortiGate-VM boxes.
Currently, I have one Fortinet FortiGate-VM that needs to be replaced next year, and this box is not so powerful, so I need to redirect some traffic to another Fortinet FortiGate-VM. It is stable, but because the CPU processor of this box is not powerful, I need to redirect some traffic to another box. In the future, I need to choose a higher-level box to prevent potential troubles with the power of this box.
We have been using this solution for more than 10 years. We are currently running version 7.2.
Currently each company needs a firewall. All types of firewalls such as Fortinet FortiGate-VM, Cisco, and others have different capabilities, but regarding our financial situation, when we compare the price of Fortinet FortiGate-VM firewalls against other firewalls from other companies, we choose Fortinet FortiGate-VM because of price. Other firewalls have better capabilities, but we have a limited amount of money for that.
I expect that many threats are blocked by the IPS system because dynamic temporary rules are created. It works adequately, but I am not a security expert to compare this kind of firewall against another.
The customer service experience has been rated 5 out of 5.
Positive
Ten years ago we started with Fortinet FortiGate-VM. I don't have experience with other firewalls.
General settings are very easy and could work in about half an hour. But after the initial setup, it is necessary to create security rules according to the company's needs. I am glad that the default settings block all traffic, and only directly set up traffic is allowed.
After 10 years, we had a special department that took care of core networks, including firewalls. After that, this responsibility fell to me and my colleague.
There are only initial costs and after that yearly maintenance for the exact level of hardware support and hardware and security support. I am from Czech Republic, and I have experience that prices for our area are a little bit lower than in other areas for some goods. I don't have this experience with Fortinet FortiGate-VM because my colleagues in Germany are reaching better prices than me.
In the past, we were using that technology, but we had a problem with some wireless guns and found a solution with Aruba Networks. We are using Microsoft 365 with some version E5 license. Regarding the network, we are mainly using Cisco systems. My colleague is working on the SIEM and SOC system with some external companies that support us after the ransomware attack. I am referring to hardware boxes and also virtual machines.
I expect that generally logs can improve our security because currently we don't have someone who works through these firewall logs, so we don't have information about potential security problems. We are expecting that it will be better after these logs will be connected to the SIEM system.
These firewalls are very easy to set up or manage. It is easy to set up each box individually, but currently, I don't have experience or training for central management of these Fortinet FortiGate-VM firewalls. I have been working as an IT specialist for about 30 years. I use it only for the backup of the firewall configuration. It is helpful because I have a backup of each firewall configuration every day, and I can return back several days. However, it is another difficulty because if the configuration of Fortinet FortiGate-VM changes, many other items will change. Generally, all passwords are regenerated, so it is not easy to find changes when comparing two configurations of one firewall. I can see this feature, but it is not so important because everything is working adequately. I start to focus on the logs only when I have problems or if I need to set up new applications or allow new traffic. I only look at how much percentage of connections are used, and if it is below some limits, it is acceptable. This solution has received a rating of 31 out of 100.

I am still working with all these vendors today: Scion, Kaseya, and SolarWinds, as I use these products for usage as well as I support these products because we sell the solutions also. We sell Fortinet FortiGate-VM, we sell Palo Alto, and we sell most of them. I have been selling it probably in the last five years.
When you say VM, Fortinet FortiGate-VM is essentially a firewall in a cloud, which is Fortinet on a cloud, eliminating the need for a physical apparatus or physical appliance to run this solution. In the old days, you required a physical box in your environment to install physically in your data center and configure that box and communicate with wherever you wanted to do. Now with Fortinet FortiGate-VM kind of a system, the physical appliance is no longer required. All you require is a cloud-based or a software firewall that you can utilize anywhere, anyhow. The advantage here is you can start the implementation within no time; as soon as the order is received and the tenant is ready to start implementation, you do not require a mandatory delivery time of six to eight weeks. This can happen within probably four or five days or maybe two days itself after the confirmed order. That is one of the biggest advantages of having a VM-based firewall because you do not require any physical configuration. You can do a virtual or a software configuration, and you can be in business within the shortest possible time. Customers appreciate that because the delay in terms of deliveries is no longer available. Either you can install it on customer premises or we can install it on a cloud also.
Hybrid Mesh Firewall feature is beneficial because even if you have a Mesh Firewall, how it works is if you have an architecture designed in such a way that it will be controlled from centrally but utilized locally. You have a mesh of ten firewalls, but you are located at ten different locations and you want to go to the internet and you probably have a local gateway. In the older design, you have to come through a central location and then access your internet and go out, which becomes problematic because your latency would be very high. You will get a delayed response for anything and everything you want to access. However, with a meshed environment and a proper internet POP, you can have the standard controls implemented across. At the same time, since you are accessing the systems locally over the internet, the response time or latency is fast. That is one of the biggest advantages one gets with a mesh firewall and centralized management.
I also speak about real-time threat response capability, and it is real time. You get fast access and people are happy because when they ask for any query, you get an immediate response rather than waiting earlier for a longer time. That is the advantage.
Fortinet FortiGate-VM definitely improves overall security posture because it has better features in terms of better management or better configuration options and parameters. Any firewall cannot be configured with default parameters because it will probably give you issues. If you can configure it properly, and it has a GUI interface, the graphical interface actually helps you configure things much faster and in a better manner.
One benefit with such VM-based solutions is that if you are connected to the internet, all the updates and all the threat intelligence platforms are always kept online and up to the mark. You do not have to wait for an update which will happen probably a week, ten days, or a month later. Whatever updates are required are instantly available. Therefore, threat detection, even if it is a zero-day, can occur in a much better way because if it gets updated at the central Fortinet level, it gets percolated directly to the firewall's database, making it a better option.
I have been using Security Fabric Automation features to generate alerts or automate threat response because that is essential. When you have a fabric implemented, any issues with the firewalls can be immediately known, and you can take actions accordingly. That is a good feature.
Negatives are it could be the same as physical, because if the physical box has some defects, obviously it does not work. The same thing happens if the cloud has issues or a VM is not working well. Those are typical unavailability problems. Usually when it is VM or a cloud, you get better availability. But you never know what problems can happen. At least what I have seen is if the configuration is right and if you have a decent way of doing things, usually there are no issues. If the configuration has challenges then obviously configuration and availability are the main keys in terms of having a better one. They could be negatives also because if you do not configure, you have a problem. If the VM is not available, then also you have a problem because you cannot communicate. Those are the negatives I would address.
The general stability of Fortinet FortiGate-VM is very stable.
The scalability of Fortinet FortiGate-VM depends on the VM configuration. Assuming I know that there are twenty, I am giving an example. Let us say the solution requires the base one supports five locations, and if you want to increase the number of locations and the bandwidth requirements, then obviously I can just increase my VM CPU or the basic. Alternatively, I can create a bigger VM or the larger VM and just implement this, which will take lesser time. It is not that complicated to do it, but it is possible to do it without much downtime.
I rate customer support and technical support from Fortinet at a nine because we have certified people on our roles for such products. Most of the problems are troubleshot by my own team. Only when there are some peculiar issues do I have to talk to support and get the necessary done. Once the tickets are raised and severity is defined, then they are pretty prompt in supporting also.
Positive
The implementation and deployment part is really straightforward because there is no hardware involved. If there is no hardware, then obviously software-wise you can configure it much faster and much better because as soon as you get the license. All these things are controlled by an activation key which is at Fortinet's side. When I am talking about Fortinet FortiGate-VM, the VM requirements are already set. I can immediately implement that, download the part, and for activation, if I get the key, I can be starting in no time. If I had to wait for an appliance, the appliance takes probably six to eight weeks to deliver. I should not have to wait for six to eight weeks when I can get things done without much of a challenge.
The accessibility of integration across various environments in Fortinet FortiGate-VM is very easy, I would say, because we integrate with multiple SIEM systems. We have found that integration is relatively easier. As soon as you integrate with your SIEM, even we have integrated with our ticketing system, that is also possible, and we have done that. All you require is a little bit of understanding regarding parameters, and if you know what to look for and where to look, I think those are possible to do.
In terms of how the price of Fortinet compares to other products on the market, I think Fortinet is a much better product in terms of availability and support from Fortinet's side as well. My company has a long relationship with Fortinet. We deal mostly with Palo Alto on an appliance basis. They may be having such a product, but at least my experience with Fortinet is better than others.
Regarding TCO related to Fortinet, I think the customer is the right person to talk about that because I can only talk from a features point of view. In terms of similar size equipment, the customer must have a comparison with, let us say, Palo Alto or Juniper versus Fortinet. I think Palo and other products are a little expensive. Unless you go with some cheaper options, maybe a Cisco or Sophos kind of thing, those are cheaper options but still give you value for money. That is why I believe a customer chooses Fortinet. There is also an architecture thought process that goes behind. An enterprise customer will always go with an internal firewall and external firewall architecture and frequently choose one OEM for internal and another for external. Therefore, they will have a mixed bag kind of a thing, like Fortinet and Check Point or Fortinet and Juniper. It all depends on the architecture as well. To answer that question in terms of TCO is relative compared to the customer, and I will not be in a right position to provide an incorrect answer. I would rate this solution a nine overall.
Network and infrastructure security can be used depending on the environment which a customer has, but it is usually more useful in virtual data center protection. Fortinet FortiGate-VM can protect VM infrastructure, virtual infrastructure, or cloud infrastructure in AWS, Azure, or other cloud vendor providers, as well as virtual infrastructure on premises in your own private data center.
I would say that it is cheaper than other vendors. In comparison of features, it is at the same level as Palo Alto and Check Point. It is a leader in the Gartner quadrant with the same feature set but at a lower price. However, it also has some weak points that require careful sizing of the solution before using it with all security features switched on, because it has a significant downgrade of throughput capacity when switching on more security features. If you need all features switched on with all signatures and SSL inspection, then you need to check for a higher grade model.
Fortinet FortiGate-VM provides integration across various environments, which is important especially for integration with domain controllers and authentication services. This is very important nowadays. All other integrations depend on the project and company needs.
With this solution, you can apply the zero trust concept in place with role-based access to the internet. URL filtering works well, and it is flexible. At the same time, with integration with other security solutions, you can quickly respond to incidents if anything happens. In total, fewer security incidents appear and you can respond more quickly.
After deployment, you have better visibility. You can see who, where, when, and how, and you can make reports.
I would say that it is cheaper than other vendors. In comparison of features, it is at the same level as Palo Alto and Check Point. It is a leader in the Gartner quadrant with the same feature set but at a lower price. However, it also has some weak points that require careful sizing of the solution before using it with all security features switched on, because it has a significant downgrade of throughput capacity when switching on more security features. If you need all features switched on with all signatures and SSL inspection, then you need to check for a higher grade model.
Real-time threat response is better in Palo Alto because they have an embedded machine learning engine which can detect viruses. In Check Point, you have to have a sandbox or be connected to the sandbox to check for unknown threats.
These are not problems per se, but you need to be more careful and more experienced when choosing this solution. You should not look just at a data sheet, but also look at real tests in the field and load tests from companies who are making them. The best way to choose is to test in your environment, see the capacity and throughput which you need, and then choose the model after a proof of concept.
It depends on the project. If you need just an internet connection for a few people, you just plug it in and it is done. You write two rules which allow access and apply basic URL filtering. If it is a data center segmentation solution, you need to plan a lot before you deploy it, and deployment would be complicated with any product. For basic setups for small businesses, it is easy and plug and play. However, for big projects like data center protection, it is complicated with any vendor, not just easy.
I work with the product both as a customer and as a partner integrator, and also as a reseller.
There is a significant impact because you see full network visibility from layer three to layer seven, all threats, and all vulnerability exploitation attempts. With SIEM integration, it highlights a lot of data which can be used with PI solutions and also for incident response.
It is scalable. As for technical support, I was a tech support person, so I did not have a chance to escalate. I faced issues and fixed them myself. I did not escalate to the second level, so I do not closely work with their support team.
Regarding real-time threat response capabilities, I think they are better in Palo Alto because they have an embedded machine learning engine which can detect viruses. In Check Point, you have to have a sandbox or be connected to the sandbox to check for unknown threats.
The impact of threat detection on IT security operations is significant because you see full network visibility from layer three to layer seven, all threats, and all vulnerability exploitation attempts. With SIEM integration, it highlights a lot of data which can be used with PI solutions and for incident response.
As a reseller and a user, the biggest benefit that stands out is that it is cheaper than other vendors. In comparison of features, it is at the same level as Palo Alto and Check Point. It is a leader in the Gartner quadrant with the same feature set but at a lower price. However, it also has some weak points that require careful sizing of the solution before using it with all security features switched on, because it has a significant downgrade of throughput capacity when switching on more security features. If you need all features switched on with all signatures and SSL inspection, then you need to check for a higher grade model.
Fortinet FortiGate-VM has some embedded features for automation such as tagging and dynamic groups. Using the API, you can respond and integrate with SIEM solutions. However, this requires technical background and work effort.
My overall review rating for this product is seven out of ten.

Fortinet FortiGate-VM is used for virtual machine deployment within data centers to protect applications. Some customers do not want to deploy hardware firewalls due to budget constraints. With a good hypervisor, they can deploy Fortinet FortiGate-VM firewall in their data center as a virtual firewall.
For example, if you have applications hosted in a data center and do not want to deploy Fortinet FortiGate hardware firewalls due to budget constraints and have a good hypervisor, you can secure your application by deploying Fortinet FortiGate-VM on your hypervisor in the data center to protect the application directly. Traffic comes first to Fortinet FortiGate-VM, and then clean or secure traffic reaches the data center server.
Fortinet FortiGate-VM is similar to a Fortinet FortiGate hardware firewall, and we can get all the same features. It is a good solution with Fortinet FortiGate-VM firewall.
Deployment is easy within any hypervisor cloud, whether Citrix Xen, VMware, or Nutanix.
The threat detection capabilities are excellent. I would rate this as ten out of ten because of the good features that come with the services and FortiGuard connection. You can get signatures every hour, including IPS signatures, anti-malware signatures, web filters, and application filters. These signatures come directly from the firewalls. An additional feature is the ability to create custom signatures in Fortinet FortiGate-VM, such as application signatures and IPS signatures.
Regarding the solutions, more features need to be introduced. Fortinet FortiGate-VM has FortiWAF features, but they are limited. These features need to be enhanced in Fortinet FortiGate-VM itself. Although Fortinet FortiGate has FortiWAF feature as a standalone feature, more features need to be onboarded into this firewall. Additionally, some features should be offered for free. For example, the minimum comes with two CPU, but at least four CPU license-based or still two CPU should be free.
I have been using Fortinet FortiGate-VM for the last six to seven years.
Stability is ten out of ten. Stability and scalability are both ten out of ten.
Stability and scalability are both ten out of ten.
The technical support of Fortinet FortiGate-VM and Fortinet FortiGate is eight or nine out of ten.
Positive
Regarding Fortinet FortiGate-VM, I do not see any virtual machine of Cisco firewall to deploy in any hypervisor. This is the only time I have seen Fortinet FortiGate-VM with the feature to deploy on any hypervisor. Usually, these features are not available in other vendors.
Setup can be completed within ten to fifteen minutes. Operational tasks and maintenance are very easy.
Five people, all technical staff, are capable of deploying Fortinet FortiGate-VM.
Integration capabilities are very good. I deployed and integrated Fortinet FortiGate-VM with Microsoft AD server. Integration is very easy and can be completed within two to three minutes with Microsoft AD or any other third-party servers.
Pricing cannot be said to be cheap because the pricing is not fixed. Pricing varies based on the size of the deal. If you have a good size deal, you can get more discount from Fortinet FortiGate team. If you buy a single Fortinet FortiGate-VM, you will not get as much discount from the Fortinet team. This can be marked as six, seven, or eight.
Many organizations, enterprises, oil and gas companies, public sector, and commercial sector are all using these firewalls. The banking sector is also using them.
Automation can be configured in Fortinet FortiGate-VM. For example, if someone logs into Fortinet FortiGate-VM from an IP address, I can receive an email with the user login IP address, username, login time, and date.
I recommend this one hundred percent if you want to deploy a solution, have budget constraints, and do not want to buy hardware Fortinet FortiGate-VM. I will recommend using Fortinet FortiGate-VM deployed on your hypervisor. I would rate this solution ten out of nine. My overall review rating for this product is nine out of ten.
We are using Fortinet FortiGate-VM on one VM, and two we are using as a dedicated appliance.
The features that we actually use are the IDS/IPS or IPS feature. We also use Intrusion Detection and WAF, Web Application Firewall. They have their own VDOM. We are using FortiAnalyzer for that separately and FortiBackup.
We are not using it yet. What we are focusing on first was migrating to a new VPN. That was one of the first steps. Then enabling the firewall and moving all the subnets as a gateway through Fortinet FortiGate-VM. If I remember correctly, we also are enabling WAF, enabling SSL inspection, and introducing FortiAnalyzer and so on.
Security is of course a major improvement, and we have more visibility on the network. We can probably say that the cost is manageable with four or five people managing those since we are a telecom and we also have our SOC. Comparing with others, it's straightforward and simplicity. We are not paying for features we are not using right now, but for the future, probably the Fabric and so on, but we only have those now.
From our perspective, it's quite good. When we have the visibility, we will make our policies depending on the threats that are coming because we are using many different other security measures. Fortinet FortiGate-VM as an internet gateway or firewall is very good for us.
We use an on-premises deployment.
The features that we actually use are the IDS/IPS or IPS feature. We also use Intrusion Detection and WAF, Web Application Firewall. They have their own VDOM. We are using FortiAnalyzer for that separately and FortiBackup.
I'm not entirely sure because I have to check now. What we purchased is a licensing for three years. I have to check now because in the coming year, we will be checking those. Probably, I'm not sure what the price is. It might be that it should be a little cheaper for us.
We have been using Fortinet FortiGate-VM for two years for the firewalls, and I think four years with our mail, FortiMail.
There are not really complexities, so I would say that it's straightforward.
It does not cause issues because actually it makes it longer. We do not only work with Fortinet FortiGate-VM, but I think it was around three months when we established everything. We were not in a hurry, which is why we did it ourselves. We had some kind of process first to determine our design and so on, the basic design. Because we are a telecom, we have to involve a lot of units and so on. But for deployment, it was straightforward. Until we had what we needed, and then we created everything ourselves from firewall. It does not take one hour or one day because we work partially on that and mostly focused on other jobs that we have, then we come back to Fortinet FortiGate-VM and so on. Probably we can say that within three months, we have started moving VLANs and people making through the gateway and so on. We implemented VPNs and some other things.
We have had several cases with some support, but we can make it somewhere around eight.
Positive
We are part of Telekom Slovenia. From our mother company, they have infrastructure that we took all the hardware from. I think it's a regional setup on the Adriatic part of East Europe, but I'm not sure.
There are not really complexities, so I would say that it's straightforward.
We did it with our team. We are about four members in my unit who are dealing with Fortinet FortiGate-VM. In the beginning, when we introduced FortiMail, it was from Forti itself with support from them, establishing the first setup. This is regarding the FortiMail VMs. It was some kind of lessons or training. We were together with them, and regarding the Forti Firewall, we did it alone with our team.
My team is mostly dealing with it. I only get some reports from them as my duty. I am not involved directly in implementing it and so on. But I am aware of the functionality and so on from Fortinet FortiGate-VM. We have a team of four people mostly who are dealing with Fortinet FortiGate-VM. There are also two or three others who are dealing with the FortiMail. We also have a SOC here who is dealing with the FortiAnalyzer. As a Head of Security, I am getting those reports and so on. My input or my role is very low on some occasions, but I am not typically managing directly those firewalls.
It might be positive.
From our perspective, it's quite good. When we have the visibility, we will make our policies depending on the threats that are coming because we are using many different other security measures. Fortinet FortiGate-VM as an internet gateway or firewall is very good for us.
I'm not entirely sure because I have to check now. What we purchased is a licensing for three years. I have to check now because in the coming year, we will be checking those. Probably, I'm not sure what the price is. It might be that it should be a little cheaper for us.
We are part of Telekom Slovenia. From our mother company, they have infrastructure that we took all the hardware from. I think it's a regional setup on the Adriatic part of East Europe, but I'm not sure.
From our perspective, it's quite good. When we have the visibility, we will make our policies depending on the threats that are coming because we are using many different other security measures. Fortinet FortiGate-VM as an internet gateway or firewall is very good for us. I would rate this review as an eight out of ten.

Being a cloud service provider with data centers using VMware technology, we primarily use it as a firewall and for Disaster Recovery in Hybrid Cloud Solution. We faced some issues with changes from NSX-V to NSX-T on VMware Cloud Foundation Infrastructure, which is no longer able to provide SSL VPN remote connections for end-users, so we replaced it with Fortinet FortiGate-VM for our customers as a new endpoint in the cloud, enabling us to create a VPN and utilize SSL VPN solutions. My customers mostly deploy Fortinet FortiGate-VM on the cloud.
We are using VM01 most of the time, as we have more customers, although sometimes we can use VM02. In the EMEA region, we mainly have customers related to Fortinet FortiGate-VM. My favorite capabilities are VM01 and VM02.
We use it in a hybrid cloud solution, meaning the customer on-premise is using another technology or the same. It's better for us if they are using Fortinet, and we don't face issues with this solution. For what we need to do, which is setting up a VPN connection between both sides and using it for SSL VPN connections for remote users, it works effectively and we haven't encountered vulnerabilities.
It's user-friendly and easy to set up. It's designed with the customer in mind. As someone who is precise, I understand the importance of selling the solution effectively while ensuring it meets the customer's needs. This means that my focus is on gathering customer feedback. It's not just about what I see; it's about understanding the customer's perspective. Customers often want to know how they can use the solution and how to set it up, which is the main concern I address.
Fortinet Security Fabric's Real-time Threat Response capabilities are satisfactory; it's a good solution.
There are vulnerabilities to address regarding security, as customers often ask about that. The main concerns are vulnerability detection and identification. Regarding the effectiveness of Fortinet FortiGate-VM in providing high-level security for high-level customers, we have some visibility issues, so it doesn't seem high level; there's definitely room for enhancement.
I have been working with Fortinet FortiGate-VM for two years.
We provide reliability; if one VM is up, the other can be down, so if there's a problem with the first, the backup can be activated. It's more about the design than the solution itself.
For SMB customers, it is a very good solution; I am unsure about enterprise customers.
Flexibility and scalability are very important for our customers. They primarily use this solution for SSL VPN and VPN connections, and most of the time it's for disaster recovery as a service in our cloud, functioning as a hybrid solution where they use something in their on-premise environment and just need an endpoint in the cloud.
We provide managed services, handling the setup to create the necessary VPN connections for secure data transfer. If a customer wants to move from VM01 to VM02, it's not difficult for us to manage. Fortinet FortiGate-VM adapts effectively; for example, you have a limited number of VPN connections on VM01, accommodating around 1,000 remote users, and if the customer needs another endpoint, we can deploy VM02 and manage that transition effectively.
Our support is good; we are the ones providing technical support to our customers. As a cloud service provider, our value is in offering solutions with our expertise, so we don't rely on Fortinet for support.
Positive
We moved to this new solution at the end of 2024. I have three customers using Fortinet solutions and haven't faced any issues.
It's user-friendly, and we can set it up easily with customers.
Most of our customers appreciate FortiManager, as the tools are interesting for easy setup of the product. Feedback regarding the interface is good; it's easy to understand, and the documentation from the Fortinet partner portal provides comprehensive information on product setup and management, which is beneficial for them.
My customers mainly use a managed services solution, meaning they don't have a lot to do by themselves; our services provide the solution. If customers want to deploy it by themselves and are already Fortinet customers, we just provide resources on the cloud. They can directly set up what they want on the VM we provide in the cloud.
The price is interesting for the customer; if you compare this solution with Competitors, it is maybe more suitable for SMB customers. The price is better than the competition.
We also provide EDR, XDR, SD WAN solutions around Fortinet, but we don't have customers in South EMEA using this solution.
I would rate Fortinet FortiGate-VM an eight out of ten.

We are mainly using Fortinet FortiGate-VM firewalls which are particularly hosted in cloud environments. It will connect cloud environments with on-premise networks and secure cloud-hosted VM traffic, both outgoing and incoming traffic. Those are the main requirements we are receiving.
Real-time threat response is really good, and sandboxing and all the signatures are most of the time accurate. They are aligned with recent threats, and Fortinet also has Fortinet Labs where they do their own research and publish new signatures and threats in real-time to the firewalls and all the devices, so I think it is pretty good.
When comparing with Sophos, I think Fortinet's Security Fabric is really nice because they do have more signatures. When we talk about IPS and all these security features, I think Fortinet is good in that aspect.
Fortinet does provide a lot of visibility in Fortinet FortiGate-VM, and some devices do not have an inbuilt HDD. For logs and data retention, they provide the FortiCloud free service for seven days. Using those features, we gather information to troubleshoot and find root causes. They also have a FortiView section, which is very useful to find out the top sources, top destinations, and which sessions are running. It is very useful.
We mainly get firmware upgrades from time to time, and there are bugs. For the moment, I do not have any features in my mind to mention regarding improvements.
Since I have not worked with VMs so frequently, I cannot tell exact points. Overall, you are asking about the improvements which have to be done on the VM side. They are updating frequently, but sometimes it depends on internet connectivity. Those databases are not getting updated in such cases, so external threat feeds are helpful.
I can say it has been about one to two years using it as a company. We use both the platforms.
I have not experienced any stability issues.
It is scalable, but as per my knowledge, the license is bound to the hardware it comes with, which I have read.
I have worked with the customer team and also the technical team. When we come to technical support, they provide very professional support to mitigate threats or troubleshoot issues. They provide the expected support.
Three years ago, I worked in a different company. Now I work in a different one.
I think someone who is new to firewalls can do the initial setup without any issue if they follow the guide. It is not that complex.
Most of the time, we are purchasing it through our local partners and local distributors.
Obviously, when a customer hosts their firewalls in VMs, they will get ROI because they do not need that many specifications or hardware requirements to host a firewall.
It is reasonable.
I am actually working with Fortinet and Sophos, and also I am looking partially for a rival to Checkpoint as well.
Both Fortinet FortiGate-VM and appliance are available. The difference between Fortinet FortiGate-VM and appliance is the platform which you are hosting. In the appliance, I am really seeing the appliance already with the required OS and everything. When we go to the VM side, we have to host the VM according to the defined specifications, and we have to get the licensing for it. Basically, in the firewall maintenance and configuration part, I cannot see any huge difference. It is the same. When we go to the VM side, all the network cable management and some things are happening virtually.
Feature-wise, as per my knowledge, there are no additional features when you go to the VM or the appliance. You can have the same features either you go with the appliance or VM.
Fortinet FortiGate-VM, mainly affordability and flexibility because some customers do have their infrastructure in cloud environments. Some customers do not prefer to use the cloud platform's native firewalls. In those cases, customers are listing to host their own firewall. For cases in those situations, the customer can get the benefit for those areas since it is affordable. I think it is more affordable than cloud-native firewalls.
Benefits mean the main benefit is when a customer is trying to purchase a firewall. They do not need to pay a price for the appliance. They only need to purchase a license. For the appliance, they can use their own platform to host the firewall. I think that is the main benefit when it comes to the VM side.
Overall network security posture: when a customer implements their firewall in the VM in the cloud environment, they can monitor their hosted VMs' outgoing and incoming traffic. They can restrict access, and they can include IPS, AV, ATP, all these things to secure the traffic. I think it is a huge benefit rather than using the native cloud firewall that is provided by the platform.
When we come to threat detection, I can mention IPS as well. Also under the threat landscape, since as I remember, Fortinet FortiGate-VM has the largest signature base in the IPS. They help us to prevent a lot of known threats using their signature database, which updates continuously.
When we compare it with Sophos, I think the most benefits are their security posture. They have a strong security posture in Fortinet FortiGate-VM compared to Sophos. Also the utilization: Fortinet FortiGate-VM OS is very suitable for small hardware because Sophos OS runs on Linux, which requires huge CPU and RAM utilization. Those are the pros and cons when you compare it with Sophos.
We are using that. Recently we have done an implementation where when someone tries to scan our ports in the firewall for a few times, we have scripts to block those IPs. It is very useful and user-friendly. We can get a lot of tasks done through that automation feature.
Rather than depending on Fortinet's security posture, they provide us the possibility to integrate our firewalls with external threat feeds, which is a huge benefit. If Fortinet misses any host or signature update, we can get it updated through the external threat database.
It is very flexible. We can use several external authentication platforms to integrate with our firewall, for example, SAML or LDAP. They provide so many integration points, and as I remember, they are free of charge as well.
You have to size your firewall depending on your connection types and the threat sources. Fortinet FortiGate-VM firewall is based on that. You have to do proper sizing on the VM that you are putting the firewall on.
In our country, Sri Lanka, most of the customers use their internal firewall and perimeter firewalls. When we take all the customers, it is about more than thirty to forty percent using Fortinet FortiGate-VM as their internal or perimeter firewalls. Huge customers, so we do have a high demand for Fortinet for the internal and perimeter levels.
I would rate this product a seven out of ten overall.

I was called regarding a review on Fortinet FortiGate, FortiSOAR, and I mentioned working with it, so it is acceptable for me to answer some questions. I have just initiated one requirement with FortiSOAR. The impact of SD-WAN on the network performance is significant, and SD-WAN is the basic feature today offered by every firewall OEM. Previously, we worked with Fortinet FortiGate for IPsec VPN tunneling, and today we have implemented SD-WAN as well. We are implementers with many customers for whom we have been working. Some customers are big, some are small, but we have been working with many companies. My customers work in varied industries, including banking, finance, manufacturing, and IT, because cybersecurity is the need of the hour. Every company requires it, and firewalls are basic; companies choose either Fortinet FortiGate, Check Point, Palo Alto, or SonicWall. We have integrated SD-WAN capabilities with Fortinet FortiGate for our customers' networks. We have not partnered with any company for that matter. We implement and do the servicing. People purchase, and we do the servicing and integration to their network.
One feature of Fortinet FortiGate that I find very unique is the virtual domain, VDOM. The VDOM feature allows you to integrate multiple domains; if you have multiple domains, you can create multiple VDOMs. VDOMs are a feature that is very unique and not available with other competitors. Fortinet FortiGate has that feature, which I really appreciate. Regarding Fortinet Unified SASE, the effectiveness of security policies across multiple locations is managing efficiently with FortiManager. The stability of Fortinet FortiGate is excellent.
For Fortinet FortiGate firewall, I have been working for the last 15 years.
The stability of Fortinet FortiGate is excellent. It is a very stable product.
It is easy to scale Fortinet FortiGate. There are no problems with scalability.
I had a chance to work with Fortinet support. My impression of the support is really good. It rates 9 out of 10 for support. If you consider it, 10 out of 10 is acceptable. I don't see any challenge with the support center. The support needs to be maintained at a high standard.
Positive
Setting up Fortinet FortiGate is really very easy.
People purchase, and we do the servicing and integration to their network.
My customers' return on investment after implementing Fortinet FortiGate depends on how they analyze it. Quantifying it is complicated, and Fortinet FortiGate is definitely a proven product with strong threat handling and management. The value of Fortinet FortiGate is significant, with a huge database of signatures that effectively blocks attacks. However, quantifying the return on investment in percentage terms is very subjective.
As an implementer, I don't sell devices, so I may not know about pricing. However, I interact with pre-sales and support teams, and I find their adaptability and support to be very good.
My customers work in varied industries, including banking, finance, manufacturing, and IT, because cybersecurity is the need of the hour. Every company requires it, and firewalls are basic; companies choose either Fortinet FortiGate, Check Point, Palo Alto, or SonicWall.
We feel that Fortinet FortiGate is a very proven product that has undergone many changes in the market and has added many products. I recommend Fortinet FortiGate as a proven product that needs to be sized properly for proper implementation. It is easily integrable, especially for us. I strongly suggest Fortinet FortiGate. On a scale of 1-10, I rate this solution a 10.
My use cases primarily involve cloud environments for Azure or AWS, and 90% of my usage would be in the Azure environment.
What I appreciate the most about Fortinet FortiGate-VM is that it is not much different than hardware appliances. I have worked with other VMs in Azure that are firewalls, and the SSH capabilities on those devices lack functionality, whereas I don't have that problem with Fortinet FortiGate-VM. I can SSH into the firewall without issues.
The Security Fabric real-time threat response capabilities are great if customers have all the products to go with it. In most cases, they may have two firewalls or they may have one firewall and FortiAnalyzer. If a customer is utilizing FortiMail, all these components can integrate together, allowing logs to be centralized and feeding back to one another in the event of a potential threat. It's great, yet unfortunately, we don't have enough customers using different products from Fortinet to really take advantage.
In terms of room for improvement, logging could be improved. Sometimes the logs are more difficult to read and to identify root cause analysis. Another enhancement that would be great, but wouldn't just be on VMs, could target the VM—the addition of a syslog table we could view to better identify what to expect from logging.
I have been using it for the last three to four years in my career.
Fortinet FortiGate-VM is a very scalable product, especially from an HA standpoint.
I have contacted technical support and customer support. When I compare them to SonicWall, they are about equal in contrast, as we have about the same number of challenges between both of them.
Positive
I have used alternatives to this VM.
The initial deployment of Fortinet FortiGate-VM was easy for me. To deploy the VM took maybe an hour.
Fortinet FortiGate-VM requires ongoing maintenance on my end. I have to keep track of the CVEs that may be out there, and that's probably one thing that Fortinet is plagued by, having a number of CVEs out there. The good thing is they patch them quickly and let their customer base know about them as soon as they do, or at least as it appears compared to other vendors that try to hide them.
Deployment would be a team effort due to it being in the Azure environment. You have to have the Azure engineer deploy the VM itself, and then I would gain access and do the initial provisioning of the firewall.
Regarding the pricing, it tends to be a bit higher compared to SonicWall. That's why we end up having customers go the SonicWall path when they would be much better off going the Fortinet FortiGate-VM path.
The closest solution I would compare it to would be SonicWall NSVs, which I've worked with the most, although I wouldn't compare it in a positive light.
For a small office or a small company, the NSV may be fine, but I appreciate the granularity of Fortinet FortiGate-VM. Granularity in security policies is where Fortinet FortiGate-VM stands out. I prefer Fortinet FortiGate-VM over SonicWall NSV because of the granularity. The ability to have security policies is a major plus, as each firewall policy can have its own security policy, which I can't do with SonicWall. This makes Fortinet FortiGate-VM the much better product.
I do not use the Hybrid Mesh Firewall feature by default. Regarding the downsides of the VM, I haven't run into any problems to suggest improvements. I use it just as if it's a physical appliance, and I don't have any offset differences.
I rate Fortinet FortiGate-VM a seven out of ten.
Majorly, we have cloud migration solutions where we connect Fortinet FortiGate-VM with, usually for the FortiGate of the customer, an in-house solution. We have been through many different kinds of projects where we had to adapt the customer firewall solution.
A significant portion of our clients comes from the retail sector, particularly grocery stores. In the grocery market here in Brazil, there is generally low maturity in IT solutions and cybersecurity overall. MikroTik is commonly used for networking. Many of our clients utilize MikroTik or pfSense as their primary solution for their stores. Occasionally, they may also use Sophos or Fortinet at their headquarters. Through numerous projects, we have identified various vulnerabilities during penetration tests conducted in their environments. One of the primary concerns is usually the firewall, which prompts us to explore different security options. For example, we have a strong partnership with Trend Micro for Endpoint Detection and Response (EDR).
From there, we establish a connection between the customer's solutions and Fortinet. Sometimes, we implement SD-WAN to connect every store securely. This allows them to connect even with firewalls and SASE solutions, enabling connections via 5G to integrate the entire company with our cloud solutions. In summary, the foundation of our projects typically revolves around cloud migration, starting with security solutions or penetration tests that identify vulnerabilities. This leads us to implement both physical appliances and VM appliances as needed.
Our visibility into network traffic has improved since implementing Fortinet FortiGate-VM, at least based on the feedback from the operations team.
Fortinet adapts to evolving threats based on what I've seen. With AI implemented, they can analyze how new threats behave, enhancing their ability to respond. Nowadays, the prevalence of AI as a threat vector makes security harder; therefore, having a partner that's developing AI features for improved security is commendable.
My background is primarily in cloud infrastructure rather than security. When considering Zero Trust Network Access (ZTNA) or SASE solutions, I believe it effectively closes many gaps in a customer's connectivity and environment. For me, this level of security is crucial.
There are areas for improvement because usually, most policies don't change much. There's always room for enhancements, whether for VM or physical appliances, because threats evolve, necessitating adaptation and a different approach to the security environment.
I have about two years of experience with Fortinet FortiGate-VM. We primarily used to work with open-source solutions. Three years ago, we established a strong partnership with Fortinet. Since then, we have been working with Fortinet FortiGate as our primary solution for firewalls. I am familiar with both Fortinet FortiGate-VM and FortiGate physical appliance.
I can't rate technical support or customer service because I'm in the commercial area. From my perspective, I would rate it an eight out of ten. We are primarily supported by our own sales team, and recently we gained help from a Fortinet partner account manager, who has been assisting us with key customers and opportunities.
Positive
Our clients used different solutions. I believe that Fortinet has a larger installed base, which means they are exposed to more threats. This exposure helps them evolve more quickly and develop new solutions and protections against emerging threats. As a result, their response to issues is generally faster than that of their competitors. While I wouldn’t say they have more features than all the others, they do tend to introduce new solutions, policies, and tools more rapidly because of their extensive installed base. This allows them to be more responsive to new threats than other companies.
The initial setup used to be complex, but with the addition of features, potentially involving AI, it has become more straightforward. As far as I know, that was a challenge previously, but with recent releases, the setup process is increasingly automated.
We have a direct contract with Fortinet, but we primarily use the OCI environment. While we also partner with AWS, Azure, and GCP, about 90% of our infrastructure is in OCI. We are an ISV for Oracle. We offer a platform that enhances scalability for client-server solutions in the cloud. Over time, we have developed capabilities in integration, data management, and AI agent building. Our platform not only manages the infrastructure but also incorporates security tools like Fortinet and other solutions for phishing protection. In terms of integration, we provide an iPad solution along with a data warehouse and lake house construction process. This allows users to create their own data pipelines and ultimately deliver information to Business Intelligence (BI) tools or DataView tools. Additionally, users can build their own AI agents that operate entirely within their environment, using their own data without the need to export it to external tools. Oracle recognized us as an ISV capable of managing our customers' environments within our own accounts. Currently, we have more than 20,000 companies integrated into our operations within OCI.
What's more important than just having good policies in place is to have a security operations center that monitors all the KPIs and thresholds. This allows us to use that feature wisely and take timely measures to position ourselves effectively. If all the policies are well-placed, we can even automate responses, locking parts of the network to prevent attacks based on vulnerabilities or threats detected within our policies.
I would rate Fortinet FortiGate-VM a nine out of ten. It's much better compared to the open source solutions we've used before. Not only is my average ticket a bit lesser due to the licensing and other factors, but I also experience fewer issues with my customers, at least when it comes to the Fortinet products.