Fortinet FortiGate is strong in SMB and mid-market, approaching SD-WAN from a security perspective. Customers have requirements for internet as many are moving away from private connectivity and migrating to Teams, making security a top priority. They've chosen Fortinet FortiGate as it offers both a comprehensive security portfolio, including intrusion detection, deep packet inspection, and VPNs. It provides robust SD-WAN capability, eliminating the need for two vendors. Additionally, they offer a SASE solution for smaller sites where a virtual Fortinet FortiGate can be used instead of a physical one, saving space for retail locations.
Fortinet FortiGate Next-Generation Firewall
Fortinet Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Enables comprehensive security and routing for SMB and mid-market
What is our primary use case?
How has it helped my organization?
These features resonate with small to medium-sized organizations, attracting more people to the Fortinet FortiGate solution since it's security-first while also providing SD-WAN capability. Unlike competitors such as Meraki that limit connections to two, Fortinet FortiGate allows up to 100 connections as their focus is on security rather than SD-WAN.
What is most valuable?
Fortinet FortiGate SD-WAN capabilities typically require redundancy depending on the carrier. There are two types of redundancy: network redundancy with different carriers, such as Bell and Telus, or Verizon and AT&T, both connecting to the same Fortinet FortiGate box. In traditional setups, when there were two connections, one would be active and the second passive, activating only during failover. This wasn't cost-effective as customers paid for both connections while one remained passive.
In the SD-WAN environment, both connections become active, allowing application-specific routing. For instance, voice traffic can be directed to one connection while data traffic uses the other. Rules can be created specifying alternative routes if the primary connection is unavailable.
The impact on service availability and overall network performance is significant. It provides customers with assurance against single points of failure. However, capacity management remains crucial. If both networks operate at 80% capacity and one fails, the secondary connection would face a 160% load, causing blockages. Ideally, connections should operate at 50-60% capacity to handle full load during failures.
Fortinet FortiGate has been successful and ranks high on the Magic Quadrant since they're innovators with appropriate pricing. They offer a best-in-breed solution for their target market. While they're not focused on large enterprises they excel in the mid-market SMB segment, offering comprehensive solutions from endpoint protection to VPNs and deep packet inspection.
What needs improvement?
Fortinet FortiGate has started implementing AI, however, it hasn't reached full maturity. Their AI solution doesn't compare to solutions such as Microsoft Copilot and SharePoint, primarily since AI relies on data, and Fortinet FortiGate focuses on perimeter defense and security rather than internal network data.
One notable limitation is the absence of honeypot capabilities, which competitors such as Palo Alto offer. These capabilities entice and trap attackers, allowing analysis of attack vectors. Fortinet FortiGate focuses purely on defense mechanisms without actively gathering intelligence about potential threats. This approach aligns with their mid-market focus, where such advanced threat intelligence features might be less critical than in enterprise environments.
For how long have I used the solution?
I have architected Fortinet FortiGate over the last 12 months.
What do I think about the stability of the solution?
Fortinet FortiGate performs at 100% effectiveness when customers have the right skill sets and policies in place, making it a very reliable solution.
What do I think about the scalability of the solution?
Scaling-wise, there have been no problems with Fortinet FortiGate. In the mid-market, which typically handles up to 50 to 100 sites and campus environments, there haven't been any scaling issues.
How are customer service and support?
From an implementation and partner support perspective, Fortinet FortiGate's support deserves a rating of seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The setup requires understanding of security and is not plug-and-play, but it isn't complex when implemented by certified Fortinet engineers.
What about the implementation team?
We provide professional services to install Fortinet FortiGate through our Fortinet-certified engineers, who handle installation services for companies.
What was our ROI?
The return on investment is 100% guaranteed. Similar to car insurance, security investment proves valuable when incidents occur. For small businesses, average losses can reach $300,000 per week, while mid-market companies face potential losses of $500,000 to a million. This makes the annual security investment of approximately $100,000 worthwhile. Furthermore, cyber insurance requirements often necessitate solutions such as Fortinet FortiGate rather than simpler alternatives.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiGate pricing varies based on hardware specifications, size, and quantity purchased. Many companies access these solutions through managed service providers, who add their management fees to the hardware and license costs. Due to security being a specialized skill set and the various types of attacks (phishing, DDoS, hacks), having Fortinet FortiGate represents just one component of the total security investment.
What other advice do I have?
There's always room for improvement with Fortinet FortiGate, as no vendor achieves perfection. In their market segment, considering their offering and price point, they merit an eight out of ten rating.
Integrating communications ensures operational continuity and cost-effective agility
What is our primary use case?
We have a Fortinet FortiGate 900 series that is a big UTM. We also have 10 Gig switches, all fiber, for distribution of the service provider's connections.
What is most valuable?
The key features include SD-WAN, firewall use, intrusion prevention, intrusion detection, and application control.
I have tested 90% of the features that Fortinet FortiGate offers. This type of solution helps us integrate all communications of our company. They guarantee operational continuity of our company and reduce risks by eliminating and detecting threats. This solution gives us agility.
What needs improvement?
The area that Fortinet may improve is customer support. When you have an incident, situation, or open a case, the support is not as good as Cisco or other platforms I have tested. There are many opportunities for improvement.
For how long have I used the solution?
I've been using the solution for eight years.
What do I think about the stability of the solution?
Currently, we are experiencing a general outage of one of the main internet service providers of the Dominican Republic, and we have not been impacted in our operations because with SD-WAN, we have another internet service provider and we are working with the second WAN connection without any disruption.
How are customer service and support?
The area that Fortinet may improve is customer support. When you have an incident, situation, or open a case, the support is not as good as Cisco or other platforms I have tested.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Fortinet FortiGate, we had Cisco.
How was the initial setup?
It was not easy. While it might be easier now than eight years ago, you have to be careful and ensure you use a great partner that helps you implement this solution as easily as possible.
What about the implementation team?
The experience is good when you use a quality partner or integrator. We use an integrator, located in the Dominican Republic. They have great support here and extensive knowledge.
What was our ROI?
The return on investment is great. Previously, we were using a dedicated point-to-point connection from the service provider that cost approximately $3,000 a month. When we implemented Fortinet FortiGate, we changed to two internet high-speed dedicated connections, costing approximately $2,000 in total, resulting in significant cost savings.
What's my experience with pricing, setup cost, and licensing?
The cost efficiency is notable because it is an overall product with a mid-range price point, and you receive more value for the price.
Which other solutions did I evaluate?
Before Fortinet FortiGate, we had Cisco.
What other advice do I have?
The only product that I have not integrated yet is the Unified SASE. This gives my team agility because as the Chief Information Security Officer, I do not have frequent contact with the platform, but my team has this interaction.
On a scale of one to ten, I rate this solution a nine.
Response time and throughput have improved network efficiency
What is our primary use case?
We are currently using Fortinet FortiGate firewall instead of Cisco.
What is most valuable?
The best features of Fortinet FortiGate include good functionality, though the licensing cost is a bit higher. Their response time and throughput are very good advantages.
What needs improvement?
Some websites or proxies are not embedded in the correct category, and we need to update the Fortinet FortiGate database because numerous websites are appearing every day. Some websites are embedded in the wrong category which we can block, resulting in everything being blocked, so this database needs improvement.
The licensing cost should be more affordable than it is currently. The SD-WAN of Fortinet FortiGate needs improvement; when we create a group address, sometimes the rule doesn't work properly.
Regarding the Fortinet FortiGate database issues, some websites or categories that should be classified as proxy are in different categories. When we open that category due to some other website that needs to be accessed, some proxies are also opened. The FortiGate web filter categories need to improve their database for better control.
For how long have I used the solution?
I joined the current company two and a half years ago, and we have been using Fortinet FortiGate for about three or four years.
How are customer service and support?
I have only required technical support from Fortinet FortiGate once or twice in two and a half years, and I have had a good experience with them. Their technical team is very knowledgeable. Their response time is very good; whenever we open a case, they respond promptly.
One issue I encountered was with FortiToken, which we configured on the admin profile. While managing four firewalls, I discovered that FortiToken was not enabling due to an issue on one firewall. I opened a case, but it has not been resolved yet. Despite this, my overall experience with them has been very good.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
In my previous company, we were using Sophos, which had better licensing costs compared to Fortinet FortiGate.
Which other solutions did I evaluate?
We are not using enhanced SD-WAN Cisco SD-WAN; we are just using the SD-WAN for load balancing.
What other advice do I have?
We are using Ubiquiti for wireless. One drawback about UniFi is that it lacks BeamFlexing, which is available in Ruckus, and the AP radius or Wi-Fi signals are not as strong as Ruckus. However, UniFi is still a good option, though not as robust as Ruckus.
Fortinet FortiGate is quite expensive, but according to the Gartner report, it ranks second or third. My experience with Fortinet FortiGate firewall has been quite good.
I would rate Fortinet FortiGate 9 out of 10 overall.
Monitors systems effectively and integrates security devices seamlessly
What is our primary use case?
The main use case for Fortinet FortiGate is to monitor different systems of our customers. The solution handles the security of the company, manages VPNs, handles inside security, and integrates with NAC solutions while integrating every security device inside the company to ensure data protection. We are utilizing Fortinet FortiGate's SD-WAN capabilities. The network performance is handled effectively by the Fortinet FortiGate solution, and depending on the capacity of the solution, it can manage all traffic inside the company.
What is most valuable?
The main benefits of Fortinet FortiGate are security and the ability to manage all information throughout the company. This includes managing all data inside the company to prevent intrusions from outside.
What needs improvement?
There is always room for improvement. They could enhance their support in different ways, such as having technical support available during night hours.
For how long have I used the solution?
I have used the Fortinet FortiGate solution for about seven to eight years.
What do I think about the stability of the solution?
Fortinet FortiGate is very stable. We have experienced no problems with the hardware, updated software, or management of the solution, with stability over 99%, making it a very good solution for us.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The Fortinet FortiGate service is very good in Chile, making it difficult to improve upon.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use both Fortinet solutions and Cisco solutions, depending on customer needs. The primary difference between Fortinet FortiGate and Cisco's firewall is pricing, with Cisco being more expensive.
How was the initial setup?
It is a medium-sized deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing is competitive at this moment, and customers recognize that Fortinet solutions offer good pricing while providing a very good product. The stability is excellent for customers, and the capacity to integrate different solutions of the same brand is also very good.
Which other solutions did I evaluate?
They use other products to integrate information with different brands, including the NAC solution, which can be used for every brand in the market since it's based on the SNMP protocol.
What other advice do I have?
We are not currently using the Fortinet FortiGate's data center solution. We are not using any AI or machine learning enhanced services at this moment as it's very new in Chile. Overall, I would rate Fortinet FortiGate a nine out of ten.
Enables seamless SD-WAN deployment and offers robust security features
What is our primary use case?
Majorly, I use Fortinet FortiGate for establishing SD-WAN in different remote locations. I also use it for segmenting wireless from LAN and implementing basic policy routing for departments. The next-gen features on Fortinet FortiGate permit proxy access, where URLs can be specified for specific users or departments to access.
What is most valuable?
Fortinet FortiGate has several valuable features. The configuration and policy setup are easy to implement. There are embedded features in Fortinet FortiGate, including DLP features, WAF presence in the firewall, and proxy capabilities. It has security profiles that can be set for various functions. In terms of security, it is particularly strong.
SD-WAN offers better reach, good reachability, and enhanced performance for network optimization. People implement SD-WAN today because of reachability and network optimization capabilities.
Fortinet FortiGate is effective in protecting against malicious access. It has a robust security architecture, which is something I truly like about FortiGate.
The SD-WAN integration is very simple. I appreciate the simplicity of the FortiGate system. It's one of the things I like most about it. With FortiAI, it's very easy to input your queries, and the system helps you set it up. If you prefer to do it manually, there is excellent documentation and step-by-step guides available to assist you. For me, the experience has been seamless and straightforward.
What needs improvement?
I cannot think of many improvements needed for Fortinet FortiGate. However, the pricing compared to competitors is quite high, though you get value for what you pay with Fortinet FortiGate.
With FortiSIEM, I have experienced some challenges. It has been suspended and is not available for utilization now. They should work on improving FortiSIEM.
For how long have I used the solution?
I have worked with both virtual appliances and physical devices, primarily with hardware devices, for over five years. The models I have used include 60, 100, and 201 series.
What do I think about the stability of the solution?
Fortinet FortiGate is one of the best firewalls available. There are no crashes or performance issues. It is very stable and reliable.
What do I think about the scalability of the solution?
The solution is scalable.
Which solution did I use previously and why did I switch?
I have worked with Sophos and Check Point firewalls. Fortinet FortiGate leads compared to other solutions. Based on customer requests, we provide different options. I recommend people should consider Fortinet or Sophos, depending on their needs. Fortinet FortiGate performs well against other firewalls in the market.
How was the initial setup?
The hardware is easy to set up. I have only had issues with the activation of the evaluation license.
What was our ROI?
There has definitely been a return on investment with Fortinet FortiGate.
What's my experience with pricing, setup cost, and licensing?
The pricing depends on the capacity required. There are 100 series, 200 series, and 500 series options. The prices are moderate and reasonable for each series.
What other advice do I have?
For organizations using Fortinet FortiGate, it is important to utilize the security profiles properly. Make sure anti-spoofing is set up and networks are well-segmented on the Fortinet. Ensure proxy configuration is based on URL access stability.
I would rate this solution a nine out of ten.
Easy interface and resilience against power interruptions improve network security
What is our primary use case?
We are using Fortinet FortiGate firewall as a data center firewall.
What is most valuable?
Two aspects I'm happy with regarding Fortinet FortiGate firewall are the easy user interface and its resilience during power interruptions. We experienced two power interruptions where the firewall got disconnected from electricity, but it resumed working normally without any issues.
The firewall provides enhanced security for our network, and as administrators, we are satisfied with the friendly interface. We are particularly pleased with the Fortinet FortiGate firewall's ability to provide network and security convergence.
For how long have I used the solution?
We have been using it for three years.
What do I think about the scalability of the solution?
It is scalable.
Which solution did I use previously and why did I switch?
We did not use any solution before Fortinet FortiGate.
What was our ROI?
The price-to-performance ratio that we get from using Fortinet FortiGate firewall is very good.
What's my experience with pricing, setup cost, and licensing?
The pricing is affordable. We are satisfied with the Fortinet FortiGate firewall.
What other advice do I have?
I would highly recommend Fortinet FortiGate firewall. We feel more secure after implementing it. We are securing the whole network with the Fortinet FortiGate firewall, not specifically the data.
On a scale of one to ten, I rate this solution a nine.
SD-WAN configuration streamlines network management and reduces IT workload
What is our primary use case?
We are using Cisco for the core switch, and for the firewall and WAN security, we are using Fortinet FortiGate. For distribution switches, we are using Ubiquiti.
We are using the 200F series of Fortinet FortiGate for our main branch and model 60 for our branch offices at five locations. We have connected a site-to-site VPN with Fortinet FortiGate.
What is most valuable?
We have used multiple WAN ASPs and set up SD-WAN. It's quite interesting and user-friendly; essentially, anyone can configure it. All you need to do is go through the documentation, and you'll be able to set it up directly. We experimented with Cisco and other devices, but found them to be somewhat challenging. Additionally, there are commercial aspects to consider. However, with FortiGate, everything is bundled together, eliminating the need to pay extra for SD-WAN management.
Performance-wise, we have great output with SD-WAN in our network. Earlier, when we were using it without SD-WAN, it was very difficult, and our IT team's effort was greater. After this SD-WAN configuration, we have no need to worry about whether the link is going down or not. We just get the notification, and at that time, we work on it. There is no need to run behind that.
What needs improvement?
The only issue is their renewal pricing. For more than 10 years, we have been customers of multiple Fortinet FortiGate security devices, and every time, it's at a high price. It is very difficult for small companies, especially in India. If Fortinet can reduce the renewal price a little bit, it can expand and target small businesses as well. Currently, only medium and large-scale organizations can afford it. Startups and small companies cannot afford it. The renewal cost is very high. When we get the equipment along with the license, it's acceptable, but the next renewal after one or three years is very expensive compared to other firewalls.
For how long have I used the solution?
We have been using Fortinet FortiGate for more than 10 years. It's the fifth device we are using. Earlier devices reached the end of life. After that, we moved to the next product.
What do I think about the scalability of the solution?
Fortinet FortiGate is absolutely scalable enough for our needs.
We have more than 400 employees, and there are six branch offices connected. The branch offices are connected with site-to-site VPN, and multiple roaming employees or working from home employees are connected with SSL VPN. More than 100 people are connecting at a time. We only need two IT people to maintain the security devices.
How are customer service and support?
We very rarely raised tickets with Fortinet. Only on one occasion, when the FortiCloud account was locked, we raised a ticket. Apart from the configuration part, we never contacted them. They were very supportive. With that particular ticket, we got help immediately.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are also customers of Cisco and Ubiquiti. We have a core switch, 9000 series switches, and Ubiquiti equipment.
I have earlier worked with Cyberoam and Sophos as a partner. They have a range of devices, and the renewal price is also lower in Sophos compared to Fortinet FortiGate.
How was the initial setup?
I was involved in the deployment of Fortinet FortiGate. The deployment process of Fortinet FortiGate is very straightforward, and since we have experience, it's very easy for us. Even for freshers, if they have basic theoretical knowledge of the setup, they can easily implement it.
It's deployed on-premises. We are not planning for the cloud. Our clients are not comfortable with the cloud solutions.
What about the implementation team?
We deployed it ourselves with one or two people for the deployment.
What's my experience with pricing, setup cost, and licensing?
The renewal cost is much higher than other firewalls. It is not reasonable.
What other advice do I have?
I would definitely recommend Fortinet FortiGate to others.
My experience with Fortinet FortiGate has been good overall. I would rate Fortinet FortiGate an eight out of ten.
Provides advanced threat protection and helps ensure compliance
What is our primary use case?
My customer's main use cases for Fortinet FortiGate are mainly for threat blocking, compliance requirements, firewall functionality, and basic security.
How has it helped my organization?
It's focused on defending against advanced threats and providing better throughput. Additionally, it can accommodate both enterprise companies and independent users. Bandwidth is one of the issues, but there are many benefits. Overall, it's a solid solution that is scalable in terms of throughput.
What is most valuable?
The best features of this tool include threat protection, email filtering, and web filtering. FortiAnalyzer's integration with the firewall and FortiSASE is beneficial. The integration helps detect the most advanced threats, such as APTs.
Fortinet FortiGate stable solution has made systems more compliant in the cyber industry for several customers.
What needs improvement?
They can improve the backend functionality of Fortinet FortiGate, particularly how the policies work in a real-time environment. Improving this aspect can ensure that policies work effectively.
For how long have I used the solution?
I have been working with this solution for around one year.
What do I think about the stability of the solution?
The stability can be rated as eight out of ten.
What do I think about the scalability of the solution?
Fortinet FortiGate has very good scalability in terms of bandwidth, throughput, and everything else. It's scalable without any problems.
How are customer service and support?
I would rate Fortinet support a six out of ten. The immediate response is not that good, particularly when raising a critical or P1 ticket; they lag in the immediate response. They can improve on that front, especially in their support service.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of Fortinet FortiGate is straightforward.
What was our ROI?
My customers have seen ROI with Fortinet FortiGate. The investment they made has provided returns.
What's my experience with pricing, setup cost, and licensing?
I'm not sure about the exact license cost, but generally, it's a reasonable price. If the hardware or the machine is advanced, it will be expensive. However, for medium-sized machines or hardware, it maintains a reasonable price.
What other advice do I have?
I recommend that those who want to use Fortinet FortiGate need to plan ahead. If they are upgrading or expanding their user base in their company, they should purchase a one-level higher version. It would provide good throughput and withstand the number of users in their company.
Fortinet FortiGate can be a bit expensive, but the price is reasonable. I would rate this solution an eight out of ten.
Works well and provides a good return on investment
What is our primary use case?
We are using Fortinet FortiGate 200F. Our main use cases are firewall and security.
What is most valuable?
It is very stable and scalable.
We are utilizing SD-WAN by Fortinet FortiGate. My experience in integrating SD-WAN capabilities with Fortinet FortiGate in my network is good, and it has worked well with no cases so far.
The effectiveness of Fortinet's unified SASE in providing consistent security policies rates at nine on a scale of ten.
What needs improvement?
I find the management console not very straightforward, so that's an area where Fortinet FortiGate can improve. They should simplify it and make it more user-friendly. In the next release, I would prefer a more simplified GUI; that's one area I would want to see a quick change.
For how long have I used the solution?
I have been working with Fortinet FortiGate for three years.
What do I think about the stability of the solution?
I would rate the stability of Fortinet FortiGate a ten out of ten because it hasn't had an outage.
What do I think about the scalability of the solution?
In terms of scalability, it has excellent features. I would give it a ten out of ten because there's still more we can do with it.
How are customer service and support?
We have not contacted Fortinet directly for technical support. Currently, we are working through the local dealers, and our local dealer is Safaricom Telkom. We also purchased Fortinet FortiGate through them.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Fortinet FortiGate, we had a South African product called Kerio. We also had a Cisco router, which we had configured to provide some of those benefits, but the problem is it's cumbersome to configure, scalability is limited, and it's very expensive to acquire the hardware and the licenses, so in terms of ROI, I wouldn't recommend it.
How was the initial setup?
We outsourced the initial setup of Fortinet FortiGate. We had the vendor do it. The implementation took about three weeks.
What was our ROI?
I have seen a return on investment with Fortinet FortiGate. Before this, we used to have many manual systems with overheads in terms of manpower, licenses, and so on, but now there's a lot we have automated, so ROI is exceptionally good.
What other advice do I have?
We are also using FortiAnalyzer and Fortinet VPN, and I have been generally satisfied with them.
I would rate Fortinet FortiGate a nine out of ten, with the only drawback being the management interface.
User interface offers improved control and smoother connections across branches
What is our primary use case?
The main use cases for Fortinet FortiGate are mostly for an industrial company firewall, focusing on firewall, web server, and new-gen, next-gen firewall.
What is most valuable?
What I appreciate about Fortinet FortiGate is that the UI is easier than what I've previously known from Sophos. Compared to Sophos, I prefer Fortinet, and the system and configuration settings are easier.
The main benefits I have seen from using Fortinet FortiGate for the organization are due to the other branch in another country, as the connection is smoother than the previous firewall.
What needs improvement?
For Fortinet FortiGate, I am not sure yet what can be improved or enhanced because currently, I am comfortable with this solution.
For how long have I used the solution?
I have been working with Fortinet FortiGate for less than six months.
What do I think about the stability of the solution?
I think Fortinet FortiGate is stable because previously it had a hiccup around a bug within the authentication VPN due to the firmware, but after updating, it's easier to control.
What do I think about the scalability of the solution?
In terms of scalability, I find Fortinet FortiGate scalable. There are no issues yet with scalability in Fortinet FortiGate.
How are customer service and support?
Regarding the technical support of Fortinet FortiGate, I have already tried to contact them previously for a problem. I would evaluate the technical support of Fortinet FortiGate as friendly and easily understandable for our problem, as they have a high understanding of the Fortinet FortiGate system.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I prefer Fortinet FortiGate over Sophos because of the connection system, the web GUI, and I think Fortinet is much more secure than Sophos.
How was the initial setup?
The initial setup of Fortinet FortiGate was easy. The setup needs around a few days to test before deploying to the customer, and while deploying, it's easy to contact customer service to help us with it.
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
We are utilizing SD-WAN capabilities in Fortinet FortiGate, but not extensively, just a few times. I have not yet seen any impact on the network performance with the SD-WAN, as we're just monitoring it.
My experience with integrating SD-WAN capabilities within Fortinet FortiGate is that the project for SD-WAN is not very long, approximately one month of testing, so for now, the connection is clear with a bit of misconnection.
I would personally recommend Fortinet FortiGate.
On a scale of one to ten, I rate this solution an eight.