Fortinet FortiGate VM Next-Generation Firewall
Integrated security has strengthened branch protection and simplifies daily VPN and threat management
What is our primary use case?
My main use case for Fortinet FortiGate is that I use it as the primary security gateway for protecting our branch and data center network. It is responsible for traffic inspection, application control, site-to-site VPN, connectivity, internet access control and threat prevention.
A quick specific example of how I use Fortinet FortiGate in my daily operations is that I monitor security events, manage VPN connectivity, and review internet usage and implement the security policies. The centralized visibility helps me to quickly identify suspicious traffic and respond before it affects business operations.
How has it helped my organization?
Fortinet FortiGate has positively impacted my organization by strengthening our overall security posture while simplifying network management. It has helped us gain better visibility into network traffic, secure remote access for users and reduce the time required to identify and respond to security incidents.
A specific outcome from using Fortinet FortiGate is that we have reduced VPN-related incidents by approximately 40% and improved visibility into network traffic. Troubleshooting connectivity issues is also significantly faster than before, around 50 to 60% faster.
Fortinet FortiGate has reduced the amount of manual troubleshooting required; security policy and VPN management and threat monitoring are handled through a single platform, making operations more efficient and easy to manage.
What is most valuable?
The best features Fortinet FortiGate offers for me are SD-WAN, SSL VPN, application control, web filtering and security fabric integration. Together they provide strong security while keeping network management straightforward.
The SD-WAN feature helps my organization specifically by optimizing traffic across multiple internet links, improving application performance and reducing dependency on a single ISP connection.
What needs improvement?
Overall, I am very satisfied with Fortinet FortiGate. If I had to suggest one improvement, it would be to have more flexible reporting and dashboard customization. While the existing features are good, additional customization options would make monitoring and reporting even more efficient for the administrator.
My suggestion is to customize the dashboard and have more advanced reporting.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than one year.
What do I think about the stability of the solution?
Fortinet FortiGate is stable.
Fortinet FortiGate performs smoothly under heavy network loads or during peak traffic periods.
What do I think about the scalability of the solution?
Fortinet FortiGate is highly scalable. It scales effectively from small branch deployments to larger enterprise environments, accommodating our growth without requiring major architecture changes.
How are customer service and support?
Customer support for Fortinet FortiGate is very good. They are humble and knowledgeable, especially during complex deployment and troubleshooting scenarios.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; from the start, we have been using Fortinet FortiGate firewall.
How was the initial setup?
Managing and configuring Fortinet FortiGate for my team is easy because the UI is user-friendly, which makes management and integration straightforward.
What was our ROI?
I have seen a return on investment with Fortinet FortiGate. Faster incident response, reduced downtime and simplified management have improved operational efficiency. The solution has helped save both time and administrative effort.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Fortinet FortiGate is that the pricing is competitive compared to many enterprise firewall vendors. Initial deployment was straightforward and the licensing options provide flexibility based on business requirements.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, I evaluated other options including Sophos, Palo Alto, and Check Point. Fortinet FortiGate is the best fit for my organization regarding price and advanced features.
What other advice do I have?
Fortinet FortiGate is deployed in my organization on-premises.
I would describe Fortinet FortiGate's integration capabilities with other security tools or platforms as effective since I am using Fortinet FortiGate on-premises.
Regarding Fortinet FortiGate's AI capabilities, I think its governance and security are enhanced by the AI-driven security insights, which are useful for identifying abnormal behavior and prioritizing potential threats. While human validation is still important, the recommendations help speed up the investigation.
I find that the accuracy and reliability of its output are generally good. The threat intelligence and security detection have been accurate, though false positives occur occasionally, but overall, the alerts are reliable and actionable.
My advice for others looking into using Fortinet FortiGate is that if you are looking for a security platform that combines firewalling, VPN, SD-WAN, and threat protection in a single solution, Fortinet FortiGate is definitely worth evaluating. Proper sizing and planning during deployment will help you get the best results from the platform. Additionally, Fortinet FortiGate's pricing is reasonable for small, medium, and large enterprises compared to other vendors. I give this solution a rating of 9 out of 10.
Integrated security has strengthened our defenses and simplifies branch connectivity management
What is our primary use case?
Fortinet FortiGate is used to secure the organization's network perimeter, manage site-to-site and remote access VPN, control application traffic, and protect users from cyber threats through IPS, antivirus, web filtering, and application control features.
In my day-to-day work, I use Fortinet FortiGate for ongoing checks on online traffic from the user to the internet and from outside to inside to access the server. One example was when Fortinet FortiGate IPS detected and blocked suspicious traffic targeting internal servers, allowing our team to investigate before any impact occurred.
What is most valuable?
All the features Fortinet FortiGate offers are the best, but the standout feature for me is its next-generation firewall capability, which includes IPS, SSL VPN, SD-WAN for ISP load balancing, web filtering, application control, and centralized security management. Site-to-site VPN is the best feature for me because we use it for our branch connectivity.
Fortinet FortiGate's site-to-site VPN configuration is very user-friendly, allowing even new users to configure it easily. The troubleshooting is also excellent, and the logs provide valuable details.
The application control feature from Fortinet FortiGate is also valuable because we can manage user access. For example, we can allow users to access Facebook while restricting commenting, downloading, or uploading. Application control has many features, including controlling download, upload, and commenting.
Fortinet FortiGate has positively impacted our organization by strengthening our security posture, improving visibility into network traffic, simplifying security management, and providing reliable connectivity for both users and the branch office.
What needs improvement?
Although Fortinet FortiGate is excellent and comprehensive, I feel that reporting needs to be more customizable, with options for further simplification of some advanced configuration workflows. The main concern is reporting, as without FortiAnalyzer, we have limited reports and cannot customize them.
I have no major concerns regarding the needed improvements, as overall, the solution is mature, reliable, and meets our requirements well.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than three years.
What do I think about the stability of the solution?
Fortinet FortiGate has been very stable and reliable in our environment.
What do I think about the scalability of the solution?
Fortinet FortiGate scales very well and supports growing network requirements without significant performance concerns.
How are customer service and support?
Customer support for Fortinet FortiGate is knowledgeable, responsive, and helpful during troubleshooting and implementation activities. I would rate customer support for Fortinet FortiGate a 10 out of 10.
Which solution did I use previously and why did I switch?
What was our ROI?
We have seen a positive return on investment through improved operational efficiency, reduced incident response time, and simplified management, with security operations being approximately 40 to 50 percent more efficient.
What's my experience with pricing, setup cost, and licensing?
Our experience with pricing, setup cost, and licensing for Fortinet FortiGate has been positive as the setup process was straightforward, the UI is user-friendly, and the license options provided flexibility based on organizational requirements. The overall value justifies the investment.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, we evaluated other options such as Sophos firewall, SonicWall, and Check Point firewall, but Fortinet FortiGate fit better in our organization.
What other advice do I have?
My advice for others looking into using Fortinet FortiGate is to properly plan your security policy and architecture before deployment, as an organization that fully utilizes Fortinet FortiGate's integrated security features can achieve excellent visibility and security. I give this product a rating of 9 out of 10.
Unified security platform has improved multi-site VPN access and simplified network management
What is our primary use case?
My main use case for Fortinet FortiGate is as a UTM to distribute our IP DHCP, to segment our VLAN, and to manage our network infrastructure.
I also use Fortinet FortiGate as a VPN and for site-to-site connection between our multiple sites, such as my head office, our developer office, and data center. It acts as a network security tool where we use an IPS to filter attacks from the outside public to our server.
Regarding my main use cases, I would like to add that it has quite a good GUI and dashboard, making it easy to use. Additionally, we use DNS filtering and application filtering to filter the applications that users can access to the internet.
What is most valuable?
The best features Fortinet FortiGate offers include reliability and a good user interface and user experience.
The user interface is the most valuable to me because it is easy to use, easy to manage, and quite easy for a newcomer to operate. The features are quite good for filtering applications and for addressing our needs, such as blocking social media or other unwanted content.
Fortinet FortiGate has positively impacted our organization by improving our security workflow and network security, as it is quite reliable compared to traditional routers or traditional switch cores from MikroTik or Cisco.
A specific example of how my workflow and network security has improved is that because we have multiple sites, Fortinet FortiGate has a multitude of signature-based features and multiple default policies, so we only have to add that to the profile. It is quite simple and easy to manage.
What needs improvement?
I think Fortinet FortiGate is quite good for now, though it could improve with the virtual IP, as it occasionally has a bug. They have a lot of CVE and updates to their system, and they need to be more concerned about their security.
For how long have I used the solution?
I have been using Fortinet FortiGate for about one year.
What do I think about the stability of the solution?
In my experience, Fortinet FortiGate is quite stable.
When the RAM or memory reaches 70% or 80%, the firewall is more likely unstable and may struggle to forward traffic. I think that is one of the areas where Fortinet FortiGate has room for improvement.
What do I think about the scalability of the solution?
Fortinet FortiGate's scalability is limited because it is on-premises, so we would have to change the type of Fortinet FortiGate as we grow.
How are customer service and support?
The customer support is really helpful for their principle, but they lack technical competency at layer one, as they tend to only look for logs before promoting issues to layer two for resolution.
Which solution did I use previously and why did I switch?
Previously, we used Aruba as a firewall and switch core, but it lacked security features, so we had to move to the next-generation firewall.
What was our ROI?
I am afraid I cannot say that I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that I think the price is quite good besides the leader in Gartner's next-generation firewall.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, we evaluated a lot of competitors at that moment, and we chose Fortinet FortiGate.
What other advice do I have?
My advice to others looking into using Fortinet FortiGate is that you need to think carefully about your usage and calculate your business needs. If you miscalculate, you might end up buying a Fortinet FortiGate that cannot meet your needs, leading to potential downtimes or failures.
I have no additional thoughts about Fortinet FortiGate except that I mentioned the easy user interface and experience for beginners. However, I noted that when the memory reaches up to 80%, the firewall does not function as well. I would rate this product a 9 out of 10.
Strong content filtering has isolated lab traffic and has reduced security costs significantly
What is our primary use case?
My main use case for Fortinet FortiGate is content filtering, and content filtering is the primary function. I am also doing East and West traffic filtering.
I use content filtering and East-West traffic filtering by creating groups based on separate projects in Active Directory, and on the firewall side, I create policies, web application profiles, and category-based profiles tailored to each project's requirements.
We have separate projects, and I isolate those subnets from one subnet to another so that both subnets do not communicate directly and only communicate via Fortinet FortiGate itself, with policies created to manage the East and West traffic.
What is most valuable?
Some of the best features of Fortinet FortiGate are its ease of use compared to other vendors, and from a troubleshooting point of view, it is also very useful and easy to troubleshoot. It stands out as easy to use and troubleshoot because I do not need to create separate NAT policies; with Fortinet FortiGate, I align my NAT policies and content filtering within a single policy, making management straightforward, and the logs are clearly visible, making troubleshooting much easier.
Compared to other firewalls, Fortinet FortiGate offers easily manageable features such as vulnerability profiles and threat profiles, which I believe is one of its main advantages.
Fortinet FortiGate has positively impacted my organization with its cost-effectiveness because it provides features that are very similar to others, but at a much lower cost, and everything my organization needs is available with Fortinet FortiGate.
Being cost-effective has allowed us to save a lot of money, which is particularly useful since I was exploring firewalls to secure my internal labs, and finding Fortinet FortiGate was a revelation as I could achieve my requirements without the additional costs of other firewalls.
What needs improvement?
I wish Fortinet would explore SASE solutions more, as it has become very popular and people are increasingly using it.
For how long have I used the solution?
I have been using Fortinet FortiGate for around the last seven years.
What do I think about the stability of the solution?
Fortinet FortiGate is stable, and I have never experienced issues similar to those from the ASA.
What do I think about the scalability of the solution?
Fortinet FortiGate's scalability is very good, and I believe there are no issues.
How are customer service and support?
I have faced challenges related to support, as I have encountered issues where support engineers are not aligned within the time frame, and sometimes they request multiple logs unnecessarily, causing delays and leaving a bad impression on my end users.
I have had a bad experience with customer support many times.
Which solution did I use previously and why did I switch?
I previously used a Cisco ASA but switched due to certain performance-related issues.
How was the initial setup?
My experience with pricing, setup cost, and licensing went smoothly, with no issues related to licensing or installation, and the overall cost is definitely cheaper than other prominent firewalls along with phenomenal features.
What about the implementation team?
I do not have a business relationship with the vendor other than being a customer, but I do have partners to buy network equipment such as firewalls and switches.
What was our ROI?
I cannot share exact numbers for ROI, but I saved a lot of money, which made management very happy, especially knowing that I achieved my functional goals with Fortinet FortiGate that might have incurred more costs with other firewalls.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiGate has positively impacted my organization with its cost-effectiveness because it provides features that are very similar to others, but at a much lower cost, and everything my organization needs is available with Fortinet FortiGate.
My experience with pricing, setup cost, and licensing went smoothly, with no issues related to licensing or installation, and the overall cost is definitely cheaper than other prominent firewalls along with phenomenal features.
Which other solutions did I evaluate?
I evaluated options including Palo Alto, Cisco, and other products before choosing Fortinet FortiGate.
What other advice do I have?
I would rate Fortinet FortiGate a nine overall, as I only deduct one point for the support issues I have experienced.
I selected nine because, feature-wise, the product is excellent and cost-effective compared to others, but I deducted a point due to the disappointing support from Fortinet.
I advise others looking into using Fortinet FortiGate to check their requirements first, as it provides all kinds of services other firewalls do and is very cost-effective.
People looking for a firewall should definitely evaluate Fortinet FortiGate, as it is very cost-effective and offers all the features they are likely looking for. I gave this review a rating of nine out of ten.
Unified security gateway has streamlined monitoring and troubleshooting for faster resolutions
What is our primary use case?
Fortinet FortiGate serves as my gateway device where I manage all my security. I use Fortinet FortiGate as a gateway for the NATing part for LAN to WAN communication. Along with that, I manage security profiles from the gateway only, and all my switches and Wi-Fi also work with Fortinet FortiGate.
I work on RE VPN and SSL RE VPN on Fortinet FortiGate.
What is most valuable?
In my opinion, the best features Fortinet FortiGate offers are monitoring and troubleshooting. Along with that, its security services are also a key point for me. For example, I need to manage features including IPS, antivirus, web filtering, and application control via Fortinet FortiGate only.
I appreciate the security feature of Fortinet FortiGate. For example, I can take real-time logs and session monitoring along with VPN, event logs, data usage monitoring, and related features.
I have noticed faster troubleshooting and reduced downtime of around fifty percent. My operational efficiency has improved. For a real example, a client experienced frequent internet drops, and this was resolved more efficiently.
What needs improvement?
One suggested improvement I would recommend is more simplified troubleshooting. Although logs are powerful, troubleshooting can sometimes be complex for new users. A more guided or AI-based troubleshooting feature would help reduce resolution time. Fortinet FortiGate should incorporate AI-based solutions to improve the troubleshooting experience.
For how long have I used the solution?
I have been using Fortinet FortiGate for two years.
What do I think about the stability of the solution?
Fortinet FortiGate is stable. It demonstrates excellent stability in various terms including network utilization.
What do I think about the scalability of the solution?
Fortinet FortiGate offers strong scalability and can support environments ranging from small businesses to large businesses. There is a wide range of models from entry level to high end levels. Flexible deployment options include physical appliances, virtual, and cloud deployments, which is beneficial.
How are customer service and support?
Customer support needs improvement. I have had to take the direct internal sources, such as sales contacts, and after that I rarely see support response.
I would rate the customer support at a six out of ten.
Which solution did I use previously and why did I switch?
I have used Sophos before, and several of my criteria were missing with that solution. Fortinet FortiGate achieved the features I was looking for, which is why I shifted to Fortinet FortiGate firewall.
How was the initial setup?
My experience is very positive regarding pricing, setup cost, and licensing for Fortinet FortiGate. The pricing is also competitive compared to other vendors in the market. Along with that, setup is very easy. I implemented it in my network myself. For the licensing part, it is somewhat confusing, but overall it is good.
What was our ROI?
Fortinet FortiGate has saved me both money and time. It is easy to manage and the troubleshooting part is also very easy, making it more time-saving than money-saving.
What's my experience with pricing, setup cost, and licensing?
In terms of cost savings, it has reduced the need for multiple tools. Fortinet FortiGate combines firewall, VPN, IPS, web filtering, and SD-WAN into a single device, which has given me lower operational overhead.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, I tried various options. I obtained the POC from Palo Alto as well as Check Point. After that, I switched to Fortinet FortiGate because it was the best option for my network.
What other advice do I have?
My advice for others looking into using Fortinet FortiGate is that focusing on proper planning, sizing, and understanding of features before deployment will be a good approach.
Integrating SD-WAN with Fortinet FortiGate has allowed me to create an SLA according to which my ISPs define the traffic and the best path utilized.
I would rate this product a ten out of ten overall.
Centralized security management has improved policy control and simplified daily operations
What is our primary use case?
I use Fortinet FortiGate in security and policy for security profiles, blocking and allowing for certification on a day-to-day basis.
I block Gmail and personal mail along with other applications. We block webmail and allow corporate mail, Microsoft 365, and block unwanted categories such as pornography and weapons while implementing URL filtering.
Global systems use standard Fortinet terminology. We use FortiManager and FortiAnalyzer, where FortiAnalyzer is used for logging and FortiManager is used for centralized management across multiple gateway devices.
By implementing Fortinet FortiGate in our organization, we can control applications and block unauthorized apps.
Control security platform features such as policy enforcement and SD-WAN streaming particularly improve our work by reducing manual configuration across multiple devices, allowing faster change implementation, and reducing troubleshooting time.
This control typically leads to measurable outcomes across operations, security, and performance.
We use Fortinet FortiGate on-premises and in the public cloud.
What is most valuable?
In my experience, the best feature Fortinet FortiGate provides is its impressive logging system, which is very easy to read to understand what the issue is.
The SD-WAN feature is very valuable for us. By integrating SD-WAN, we can manage our ISP links and SD-WAN rules.
Using SD-WAN on Fortinet FortiGate provides lower latency and stability improvements, critical application routing via lower latency links, reduction in jitter and packet loss, with both links actively used instead of one idle backup, leading to better bandwidth utilization.
The biggest strength is the consolidated platform that combines firewall, SD-WAN, VPN, and security stack in one device.
What needs improvement?
We can improve the UI readability when working with large configurations. I chose a rating of nine because of the troubleshooting power and launch issues. We need CLI debug capabilities in addition to the UI.
For how long have I used the solution?
I have been working in my current field for the last three years.
What do I think about the stability of the solution?
Fortinet FortiGate is a stable and scalable firewall.
What do I think about the scalability of the solution?
Fortinet FortiGate is manageable on one platform, but scalability depends on how we scale. Model ranges for small branches and high-end applications are delivered easily by moving to a higher model.
How are customer service and support?
Support is also good.
Which solution did I use previously and why did I switch?
I previously used Sophos firewall before moving to Fortinet FortiGate.
What about the implementation team?
We evaluated other options such as Palo Alto before choosing Fortinet FortiGate. We evaluated both Palo Alto and Sophos firewalls during our selection process.
What was our ROI?
It is a time-saving product.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Fortinet FortiGate is generally positive from a value perspective.
What other advice do I have?
I advise others to use Fortinet FortiGate, considering the firewall size, throughput including IPS, SSL-VPN, web filtering throughput, VPN load, and UTM versus Enterprise bundle.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security has improved with deep inspection and vpn access, but reporting and upgrades need work
What is our primary use case?
I have been using Fortinet FortiGate for the past six years.
I have been using Fortinet FortiGate to provide security for network and perimeter networks and gateways, and I rely on Fortinet FortiGate to protect my applications from various Layer 4 and Layer 7 attacks and traffic from malicious IPs while blocking traffic from unwanted IPs.
Fortinet FortiGate is also mainly used to establish IPsec tunnel connectivity with other networks, and users from outside the office network can connect to resources via IPsec VPN as well as site-to-site and client-to-site VPN, which leverages access and resource availability across various networks and simplifies resource accessibility worldwide.
One of the main features that I use in real time with Fortinet FortiGate is web filtering and App IDs based on application control. Previously, I allowed application access policies based on ports, but it could not prevent traffic based on the same application port with different use cases. For example, port 443 can be used for various purposes, but it could not restrict access for some specific applications. The App ID based control is useful for me to restrict traffic based on application usage and user access, which is the primary purpose of Fortinet FortiGate in real time.
What is most valuable?
Fortinet FortiGate offers next-generation firewall features and security features that restrict access for malicious traffic, URLs, and IPs, which is a major feature that Fortinet FortiGate offers.
The next-generation firewall capabilities including deep packet inspection and application controls via App IDs, Intrusion Prevention Systems, web filtering, URL filtering, and anti-malware protections are essential features that are present in Fortinet FortiGate to prevent various cyber attacks and threats in the network.
Fortinet FortiGate is also mainly used to establish IPsec tunnel connectivity with other networks, and users from outside the office network can connect to resources via IPsec VPN as well as site-to-site and client-to-site VPN, which leverages access and resource availability across various networks and simplifies resource accessibility worldwide.
What needs improvement?
The security features could have been more similar to those in the Palo Alto firewall with major data protections and WildFire, and deeper inspection capabilities, which Fortinet FortiGate lacks. Additionally, I notice that Fortinet FortiGate often experiences resource utilization problems where memory is heavily occupied regularly, necessitating cleanup tasks.
During firmware upgrades, the process is not smooth; one of the VMs often goes out of sync and exits the HA cluster. Therefore, I separate the HA between the firewalls and perform upgrade activities one by one manually. The graphical dashboard representation of the data is frequently inaccurate, leading me to rely on syslogs for more dependable information. The log retention period on the device seems too short despite having ample memory and disk capacity, which is a major issue.
For how long have I used the solution?
I have been working in my current field for the past seven years.
What do I think about the scalability of the solution?
The scalability experience indicates that if I need additional features or security capabilities, such as sandbox features, I can add them by opting for separate licenses, making it convenient for me.
How are customer service and support?
Fortinet FortiGate customer support appears somewhat good, but for complex cases or major incidents, I often do not receive prompt support from the OEM, resulting in multiple follow-ups to get the necessary assistance.
Which solution did I use previously and why did I switch?
Previously, I used to have a Cisco ASA firewall, which had fewer security features for protecting the network from day-to-day attacks and threats. Fortinet FortiGate firewall has next-generation capabilities with various security features including deep inspections, filters, URL filters, URL categories, and IPS protections while controlling application access based on application IDs, along with anti-malware protections to safeguard applications from malicious threats and attacks. By using Fortinet FortiGate, I significantly reduced major attacks that could exploit my network.
What other advice do I have?
I would advise others considering Fortinet FortiGate, particularly those concerned about budget and pricing with decent performance and support, to proceed with Fortinet FortiGate, as compared to other next-generation firewall products, Fortinet FortiGate has lower license support costs, which is a significant advantage. Moreover, from my experience, it performs its job effectively with no major issues related to performance or functionalities including policy control, VPN, and security features. I would rate this product a 7 out of 10.
Long-term deployment has supported flexible security services for diverse customer needs
What is our primary use case?
I integrate service with Fortinet FortiGate. I integrate service, and some manage service, so the customer already has the firewall and we manage them, or we sell the hardware. But mostly for hardware, there are a lot of sellers, so mostly we do the services.
If the customer wants Fortinet FortiGate, I give Fortinet FortiGate. If the customer wants Sophos, I give Sophos. Both have a different market and different customer profile.
Whatever the customer asks, we provide. I'm running Fortinet FortiGate now because a customer wants that in my data center.
What is most valuable?
I find Fortinet FortiGate valuable due to Fortinet's ASIC, as I have known Fortinet FortiGate since a long time ago, from the first time they ran. They use ASIC. While Sophos also has a special hardware solution such as Xstream, they have all different purposes and different advantages, so I can utilize both. It depends on the customer.
I don't have any problem with Fortinet Unified SASE. Mostly in Indonesia, in our market, customers buy the brand without knowing the full capability of it. So actually with Fortinet FortiGate, you also have to implement FortiManager, FortiAnalyzer and for hardware control, FortiNAC and so on. But because it's so modular, sometimes customers mistakenly just buy the firewall. The firewall doesn't work right. That's a problem. I understand that this product design philosophy of Fortinet FortiGate is meant to serve very big corporations which have established SOC teams. They put segmentation of who is the manager and who is the analyzer. That's why they put the separate server for that. But because the brand is so famous, even small customers want to buy it.
What needs improvement?
For how long have I used the solution?
I have been working with Fortinet FortiGate for maybe five or six years, or maybe longer than that. It could be 10 years as well.
What other advice do I have?
I have been working with Fortinet FortiGate for quite a long time, but I am not a partner yet. Last year I took partnership with Sophos, so we do both.
I don't have experience integrating SD-WAN capabilities with Fortinet FortiGate yet, as we had a case but the project didn't go. SD-WAN is not mostly firewall. Yesterday, I just had a discussion with a new customer that wants to buy ZTNA and NAC.
I think the pricing of Fortinet FortiGate is affordable to some small customers, but they can only afford the firewall without the other components. Mostly firewall, so it's just selling products, not selling a security system.
In my opinion, Fortinet FortiGate doesn't need to be improved. It's because it has a different market. I had a case maybe five or six years ago. There was a tender of SD-WAN implementation for 10,000 mini marts. A company that has 10,000 outlets of mini marts needs security. In the data center at their headquarters, they need a very big firewall, up to 500 Gbps. But in the outlet, which is a small store or mini mart, they need a very small firewall that's capable to do SD-WAN, authentication, security, VPN and so on. Fortinet FortiGate has it all. Fortinet FortiGate is suitable for that kind of organization. They have a special SOC, so they buy FortiManager, FortiAnalyzer and so on. I rate this review an 8.
Security platform has strengthened multi-purpose protection and supports AI-driven threat defense
What is our primary use case?
There are many main use cases for Fortinet FortiGate for my clients, including network firewall, VPN, ZTNA, and SD-WAN. The firewall is basically the primary function and one of the best features in Fortinet FortiGate.
How has it helped my organization?
The AI aspect has helped to protect data centers at scale by improving the reduction of false positive errors and handling unknown threats.
What is most valuable?
I have hands-on experience with demos and implementation of Fortinet FortiGate. The AI and ML enhanced FortiGuard services are quite new, and I have some experience but not much since they are a new feature.
What needs improvement?
The stability and performance of Fortinet FortiGate are mixed, as some features are quite good and very stable while others are quite new and very buggy.
There are quite a lot of bugs in Fortinet FortiGate, and they introduce new features every day that come with problems. I think they introduce them too fast.
Fortinet brings in new products every year and acquires new companies while inventing new products, which is good but also bad because they introduce a lot of workload and problems or bugs onto the table.
For how long have I used the solution?
I have been using Fortinet FortiGate for almost three years.
What do I think about the stability of the solution?
The stability and performance of Fortinet FortiGate are mixed, as some features are quite good and very stable while others are quite new and very buggy.
What do I think about the scalability of the solution?
Scalability highly depends on the purchase decision. If the user bought the appliance, then it is not scalable, but for the VM on the software side, it can expand.
How are customer service and support?
I have some experience with Fortinet's customer service and technical support. I would rate the technical support of Fortinet on a scale of 1 to 10 around a 7 or 8, primarily because they have local operations in Thailand, so they have at least some people who can speak Thai.
Which solution did I use previously and why did I switch?
I do have experience in working with technologies other than email security solutions.
How was the initial setup?
If talking about the general product, the initial setup of Fortinet FortiGate is quite straightforward, simple, and easy. However, it depends on the DNA of the product. If the Fortinet product was acquired from another company, that is a different story.
What about the implementation team?
My role is usually on the pre-sales and the POC role in integrating SD-WAN capabilities with Fortinet FortiGate. I am not involved in the implementation side and cannot tell much about it.
What other advice do I have?
In Thailand, the concept of unified SASE is not very popular because the traffic has to go through the cloud, and they are not very afraid of the cloud or highly adopting it at this time.
I know about dynamic segmentation in Fortinet FortiGate from the book and theory side, but on the implementation side, there are not many projects that implement it that way. It is probably never done.
There are several benefits that Fortinet FortiGate brings to the table, and I cannot speak of only one or two as it is too extensive. It highly depends on the use case, and the only word I can tell is that it is very multi-purpose or all-purpose and highly usable in many use cases.
Fortinet FortiGate is quite a mix for organizations considering it, as some products are very easy and straightforward to start, making it easy to sell, and then they can expand to other more complex and advanced products.
Reliable security has improved internet routing and optimized multi-site traffic performance
What is our primary use case?
As a customer, we work with Fortinet FortiGate. Our major use case for Fortinet FortiGate is our Internet, serving as the main device for routing, firewall features, and everything.
What is most valuable?
Fortinet FortiGate is one of the best firewalls in the market currently, with a lot of next generation firewall features embedded into it, including SD WAN, which is one of the best services for traffic steering, managing packet log jitter and latency for any applications, making it unbeatable in terms of pricing compared to other firewalls.
It has a significant impact on our network performance as we are a health care company where users access health care business website URLs, and any latency is managed by SD WAN without manual intervention, benefiting the operation as we have more than a thousand users across different locations.
Fortinet FortiGate Unified SASE is effective in providing security policies across multiple locations, incorporating zero touch provisioning that is very impactful and beneficial in managing network problems.
In terms of hardware-assisted DDoS protection with Fortinet FortiGate, it is performance-based, depending on the number of concurrent sessions, users, and the specifications of the hardware product.
What needs improvement?
The one concern I have with Fortinet FortiGate is the firmware versions, which often have many bugs when upgraded, leading us to revert back to older versions multiple times in my lifecycle.
For example, when upgrading the firmware version, we noticed that one of the services was not working, resulting in no packet flow for a VLAN until we reverted back.
The main area for improvement in Fortinet FortiGate is the firmware versions, as we face uncertainties regarding upgrades and frequent bugs that require self-fixing of problems.
For how long have I used the solution?
We have been using Fortinet FortiGate since two thousand three.
What do I think about the scalability of the solution?
Fortinet FortiGate is very much scalable, with all models from Fortinet being impactful.
How are customer service and support?
Technical support from Fortinet is generally good, though there are times when it could be better.
Which solution did I use previously and why did I switch?
We have used other firewalls, including Palo Alto, which we find to be very pricey compared to Fortinet FortiGate.
How was the initial setup?
The deployment process for Fortinet FortiGate is straightforward.
What about the implementation team?
We conducted the deployment ourselves without the help of an integrator or consultant.
What was our ROI?
The return on investment with Fortinet FortiGate is very good, as it is one of the best products available in the market.
What's my experience with pricing, setup cost, and licensing?
In terms of price for Fortinet FortiGate, it is not considered that expensive when compared to other products; it is medium priced for SMB businesses.
Which other solutions did I evaluate?
Palo Alto is a premier product, but both solutions have their unique advantages, making it difficult to declare one superior to the other.
What other advice do I have?
We have Fortinet FortiGate in different locations, where every location serves as a data center using hub and spoke technology, connecting all spokes to a primary hub and a secondary hub for reliability.
We use segmentation in core switches; however, the segmentation features are primarily managed by Cisco switches and not by Fortinet FortiGate firewall.
The effects of SD WAN integration on remote users and application performance are very positive, as we integrate all traffic through Fortinet FortiGate SD WAN and aim for configurations that enhance efficiency across locations.
We have been using SD WAN with Fortinet FortiGate for more than five or six years.
Fortinet FortiGate Unified SASE is effective in providing security policies across multiple locations, incorporating zero touch provisioning that is very impactful and beneficial in managing network problems.
The effects of SD WAN integration on remote users and application performance are very positive, as we integrate all traffic through Fortinet FortiGate SD WAN and aim for configurations that enhance efficiency across locations.
With Fortinet FortiGate, the SD WAN feature is included with no additional costs, which stands in contrast to other products like Cisco and Palo Alto, which charge extra for similar features.
I would rate this review an eight out of ten.