Overview
Video 1
Video 1
Video 2

Product video
FortiGate-VM on AWS delivers next-generation firewall and VPN/SD-WAN capabilities for organizations of all sizes. It enables broad network protection and automated security management for consistent enforcement and visibility across your AWS VPCs and hybrid cloud infrastructure. FortiGate natively integrates with AWS Gateway Load Balancer, AWS Transit Gateway and other AWS security services to simplify and deliver enterprise-class security for applications and workloads running on AWS.
FortiGate-VM reduces complexity by combining secure connectivity with advanced threat protection capabilities such as powerful intrusion prevention (IPS), malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services. It offers a management console that provides comprehensive network automation and unified visibility across multi-cloud environments.
FortiGate-VM, in concert with other elements of the Fortinet Security Fabric, enables common deployment scenarios such as cloud security services hub, secure remote access, container security, web application security, and critical workload protection.
Visit the FortiGate-VM on AWS Community Resource Hub to find onboarding, deployment, and technical information and join in discussions: https://community.fortinet.com/t5/FortiGate-VM-on-AWS/gh-p/fortigate-vm-on-aws
Please contact awssales@fortinet.com with any questions.
Highlights
- FortiGate offers protection from a broad array of threats, with support for all of the security and networking services offered by the FortiOS operating system.
- Delivers complete content and network protection by combining stateful inspection with a comprehensive suite of powerful security features to meet PCI DSS compliance.
- IPS technology protects against current and emerging network-level threats. In addition to signature-based threat detection, IPS performs anomaly-based detection which alerts users to any traffic that matches attack behavior profiles.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
- ...
Dimension | Cost/hour |
|---|---|
c6in.xlarge Recommended | $1.02 |
c8in.xlarge | $1.02 |
m7i.16xlarge | $5.16 |
t2.small | $0.36 |
c6a.4xlarge | $3.29 |
c8in.32xlarge | $6.19 |
c7a.4xlarge | $3.29 |
c6a.2xlarge | $1.60 |
m5.8xlarge | $4.10 |
c5n.xlarge | $1.02 |
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443 ) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.
After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiGate-VM. Connect to the secured Web UI via the public DNS address: https:// <public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiGate-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/aws-administration-guide/
Support
Vendor support
This product is intended for On-Demand subscription. Please contact Customer Support with the following information instead of trying to register in FortiGate management GUI:
- The serial number of your FortiGate instance
- The email ID of your Fortinet account. If you do not have an account yet, please sign using the link below
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Integrated security and SD-WAN have improved network resilience and simplify daily operations
What is our primary use case?
What is most valuable?
My experience with Fortinet FortiGate has been very positive. In addition to firewall security, VPNs, and SD-WAN, I regularly perform firmware upgrades, troubleshoot network issues, implement high availability configuration, and manage security policy. Fortinet FortiGate provides multiple security and networking features within a single platform, which makes it easier to manage and maintain customer environments efficiently.
The best features of Fortinet FortiGate are SD-WAN, VPN capability, high availability, and integrated security features. I particularly appreciate the SD-WAN functionality because it provides intelligent traffic routing and better link utilization.
What stands out most about Fortinet FortiGate's SD-WAN functionality is its ability to intelligently use multiple internet links and automatically steer traffic based on link performance. In one deployment, I configured two ISP links in an SD-WAN setup. When one link experienced high latency or packet loss, traffic was automatically shifted to the healthier link without manual intervention.
The VPN and high availability features of Fortinet FortiGate make it easy to deploy and manage both site-to-site IPsec VPN and remote access VPN. The HA functionality provides redundancy and minimizes downtime during failure or maintenance activity. I also appreciate the integrated security approach where firewalling, VPN, application control, web filtering, and intrusion prevention are available on a single platform, which simplifies management and improves overall security.
Fortinet FortiGate has had a positive impact by improving network security, reliability, and operational efficiency. Features such as SD-WAN and VPNs have helped ensure stability and connectivity across sites, while high availability has reduced downtime during maintenance or unexpected failures. From an administrative perspective, the centralized management and integrated security features have simplified troubleshooting and reduced the time required to manage and secure the network.
We have seen reduced downtime through HA and SD-WAN deployment as traffic automatically switches to the healthy ISP link during outages. Fortinet FortiGate has also improved troubleshooting by providing centralized visibility into network traffic, VPN, and link performance, helping us resolve issues faster and manage the network more efficiently.
Fortinet FortiGate is moving in the right direction with its AI-driven security features. I appreciate how it helps with threat detection, security analysis, and identifying suspicious activity more quickly. From a governance and security perspective, it provides better visibility and helps security teams respond faster to potential threats.
What needs improvement?
Fortinet FortiGate is a strong solution overall, but I believe the reporting and analysis features could be improved to provide more detailed insights without relying on additional products. Additionally, some advanced configurations can have a learning curve for a new administrator. Simplifying certain workflows and enhancing troubleshooting visibility would make the platform even more user-friendly.
More detailed reporting often requires additional products such as FortiAnalyzer. The documentation for some advanced features could be more straightforward, especially for new users. While support is generally good, faster resolution for complex technical issues would be beneficial. Overall, these are minor improvements and the platform remains reliable and easy to manage.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
What was our ROI?
What other advice do I have?
Integrated security has improved perimeter protection and simplifies centralized policy control
What is our primary use case?
The primary use case for Fortinet FortiGate is to secure the organization and network perimeters. I use it to control the inbound and outbound traffic and implement firewall policies, providing secure VPN access to remote users and protecting the network from cyber threats using features such as IPS and antivirus, web filtering, and application controls. It also helps me with segmenting the network and centrally managing the security policies, making day-to-day administration more efficient.
What is most valuable?
Fortinet FortiGate has positively impacted my organization by improving the overall security posture while simplifying network management. It has helped us reduce security incidents by blocking malicious traffic and enforcing security policies. It has also improved operational effectiveness because the IT team can manage firewall rules, VPN access, and security monitoring from a single platform. This has reduced manual effort, improved visibility into the network, and enabled us to respond to security events much more easily.
The best features of Fortinet FortiGate are its security fabric integration. It brings multiple security functions together, including firewall, IPS, antivirus, web filtering, VPN, and application controls, into a single platform, making security management much simpler. I also appreciate the centralized dashboard because it provides excellent visibility into the network traffic, security events, and user activity in real-time. It helps me identify and respond to potential threats quickly without switching between multiple tools.
The feature I rely on most is the real-time monitoring dashboard. It gives me a clear view of network traffic, active users, security events, VPN status, and blocked threats all in one place. I also frequently use the log and traffic analysis sections for troubleshooting and investigating security incidents. It makes it easier to identify unusual activity, check which firewall policy was triggered, and quickly determine the root cause of connectivity and security issues. This saves considerable time during day-to-day operations.
For user management, Fortinet FortiGate has also made things much easier. I integrated it with my Active Directory, so access policies are applied based on user groups instead of configuring each user individually. Whenever a new employee joins or changes departments, I simply update the AD group members and the correct network access is applied automatically. This has reduced my manual effort and minimized configuration errors.
What needs improvement?
Overall, Fortinet FortiGate is a strong secure solution, but there are a few areas that could be improved. The user interface can be overwhelming for new administrators because of the large number of configuration options. A more organized layout and simplified navigation would improve the overall experience. Another area is reporting and logging analysis. While the built-in reports are used, more customizable reports and dashboards would make it easier to generate management and compliance reports without relying on additional tools. Firmware upgrades could also be made smoother with fewer compatibility concerns across different versions. Additionally, the analyzer could be much better so that I can stop using third-party tools for analyzing logs for unused rules specifically.
If Fortinet FortiGate can offer such improvements in the dashboard and if I can get the unused rules that I submit to compliance and regulatory requirements from the Fortinet FortiGate dashboard itself, I would not need to rely on third-party tools. This could be improved.
If I had to add one more point, it would be better AI-driven reports and automations. More intelligent recommendations for policies, optimization, and automatic response to common security events would make day-to-day administration even more effective.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than three to four years.
What other advice do I have?
From my experience, Fortinet FortiGate's AI capability has good governance and security. The AI-driven threats, detections, and analysis help in identifying suspicious activity faster and reduce the manual effort required by my security team. I also appreciate that the AI features are integrated into the existing security framework rather than operating as a separate tool. This allows me to maintain consistent security policies and gives me better visibility into potential threats, while keeping administrator controls in the hands of security teams. Overall, I find the AI capability useful, but there is still room for improvement.
My advice is to spend time planning the deployment and firewall policies before implementing. A well-designed network architecture and proper configuration of security policies make a significant difference in getting the best performance and protection from Fortinet FortiGate. I would also recommend enabling features such as IPS, web filtering, application control, and VPN, and keeping the firmware up-to-date. Additionally, make sure that administrators are properly trained, as Fortinet FortiGate offers many advanced features that can provide significant value when configured correctly. Overall, it is a solid choice for an organization looking for a competitive network security solution. I rate this product a 9 out of 10.
Integrated security has strengthened branch protection and simplifies daily VPN and threat management
What is our primary use case?
My main use case for Fortinet FortiGate is that I use it as the primary security gateway for protecting our branch and data center network. It is responsible for traffic inspection, application control, site-to-site VPN, connectivity, internet access control and threat prevention.
A quick specific example of how I use Fortinet FortiGate in my daily operations is that I monitor security events, manage VPN connectivity, and review internet usage and implement the security policies. The centralized visibility helps me to quickly identify suspicious traffic and respond before it affects business operations.
How has it helped my organization?
Fortinet FortiGate has positively impacted my organization by strengthening our overall security posture while simplifying network management. It has helped us gain better visibility into network traffic, secure remote access for users and reduce the time required to identify and respond to security incidents.
A specific outcome from using Fortinet FortiGate is that we have reduced VPN-related incidents by approximately 40% and improved visibility into network traffic. Troubleshooting connectivity issues is also significantly faster than before, around 50 to 60% faster.
Fortinet FortiGate has reduced the amount of manual troubleshooting required; security policy and VPN management and threat monitoring are handled through a single platform, making operations more efficient and easy to manage.
What is most valuable?
The best features Fortinet FortiGate offers for me are SD-WAN, SSL VPN , application control, web filtering and security fabric integration. Together they provide strong security while keeping network management straightforward.
The SD-WAN feature helps my organization specifically by optimizing traffic across multiple internet links, improving application performance and reducing dependency on a single ISP connection.
What needs improvement?
Overall, I am very satisfied with Fortinet FortiGate. If I had to suggest one improvement, it would be to have more flexible reporting and dashboard customization. While the existing features are good, additional customization options would make monitoring and reporting even more efficient for the administrator.
My suggestion is to customize the dashboard and have more advanced reporting.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than one year.
What do I think about the stability of the solution?
Fortinet FortiGate is stable.
Fortinet FortiGate performs smoothly under heavy network loads or during peak traffic periods.
What do I think about the scalability of the solution?
Fortinet FortiGate is highly scalable. It scales effectively from small branch deployments to larger enterprise environments, accommodating our growth without requiring major architecture changes.
How are customer service and support?
Customer support for Fortinet FortiGate is very good. They are humble and knowledgeable, especially during complex deployment and troubleshooting scenarios.
Which solution did I use previously and why did I switch?
I did not previously use a different solution; from the start, we have been using Fortinet FortiGate firewall.
How was the initial setup?
Managing and configuring Fortinet FortiGate for my team is easy because the UI is user-friendly, which makes management and integration straightforward.
What was our ROI?
I have seen a return on investment with Fortinet FortiGate. Faster incident response, reduced downtime and simplified management have improved operational efficiency. The solution has helped save both time and administrative effort.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Fortinet FortiGate is that the pricing is competitive compared to many enterprise firewall vendors. Initial deployment was straightforward and the licensing options provide flexibility based on business requirements.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, I evaluated other options including Sophos, Palo Alto, and Check Point. Fortinet FortiGate is the best fit for my organization regarding price and advanced features.
What other advice do I have?
Fortinet FortiGate is deployed in my organization on-premises.
I would describe Fortinet FortiGate's integration capabilities with other security tools or platforms as effective since I am using Fortinet FortiGate on-premises.
Regarding Fortinet FortiGate's AI capabilities, I think its governance and security are enhanced by the AI-driven security insights, which are useful for identifying abnormal behavior and prioritizing potential threats. While human validation is still important, the recommendations help speed up the investigation.
I find that the accuracy and reliability of its output are generally good. The threat intelligence and security detection have been accurate, though false positives occur occasionally, but overall, the alerts are reliable and actionable.
My advice for others looking into using Fortinet FortiGate is that if you are looking for a security platform that combines firewalling, VPN, SD-WAN, and threat protection in a single solution, Fortinet FortiGate is definitely worth evaluating. Proper sizing and planning during deployment will help you get the best results from the platform. Additionally, Fortinet FortiGate's pricing is reasonable for small, medium, and large enterprises compared to other vendors. I give this solution a rating of 9 out of 10.
Integrated security has strengthened our defenses and simplifies branch connectivity management
What is our primary use case?
Fortinet FortiGate is used to secure the organization's network perimeter, manage site-to-site and remote access VPN, control application traffic, and protect users from cyber threats through IPS, antivirus, web filtering, and application control features.
In my day-to-day work, I use Fortinet FortiGate for ongoing checks on online traffic from the user to the internet and from outside to inside to access the server. One example was when Fortinet FortiGate IPS detected and blocked suspicious traffic targeting internal servers, allowing our team to investigate before any impact occurred.
What is most valuable?
All the features Fortinet FortiGate offers are the best, but the standout feature for me is its next-generation firewall capability, which includes IPS, SSL VPN , SD-WAN for ISP load balancing, web filtering, application control, and centralized security management. Site-to-site VPN is the best feature for me because we use it for our branch connectivity.
Fortinet FortiGate's site-to-site VPN configuration is very user-friendly, allowing even new users to configure it easily. The troubleshooting is also excellent, and the logs provide valuable details.
The application control feature from Fortinet FortiGate is also valuable because we can manage user access. For example, we can allow users to access Facebook while restricting commenting, downloading, or uploading. Application control has many features, including controlling download, upload, and commenting.
Fortinet FortiGate has positively impacted our organization by strengthening our security posture, improving visibility into network traffic, simplifying security management, and providing reliable connectivity for both users and the branch office.
What needs improvement?
Although Fortinet FortiGate is excellent and comprehensive, I feel that reporting needs to be more customizable, with options for further simplification of some advanced configuration workflows. The main concern is reporting, as without FortiAnalyzer, we have limited reports and cannot customize them.
I have no major concerns regarding the needed improvements, as overall, the solution is mature, reliable, and meets our requirements well.
For how long have I used the solution?
I have been using Fortinet FortiGate for more than three years.
What do I think about the stability of the solution?
Fortinet FortiGate has been very stable and reliable in our environment.
What do I think about the scalability of the solution?
Fortinet FortiGate scales very well and supports growing network requirements without significant performance concerns.
How are customer service and support?
Customer support for Fortinet FortiGate is knowledgeable, responsive, and helpful during troubleshooting and implementation activities. I would rate customer support for Fortinet FortiGate a 10 out of 10.
Which solution did I use previously and why did I switch?
What was our ROI?
We have seen a positive return on investment through improved operational efficiency, reduced incident response time, and simplified management, with security operations being approximately 40 to 50 percent more efficient.
What's my experience with pricing, setup cost, and licensing?
Our experience with pricing, setup cost, and licensing for Fortinet FortiGate has been positive as the setup process was straightforward, the UI is user-friendly, and the license options provided flexibility based on organizational requirements. The overall value justifies the investment.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, we evaluated other options such as Sophos firewall, SonicWall, and Check Point firewall, but Fortinet FortiGate fit better in our organization.
What other advice do I have?
My advice for others looking into using Fortinet FortiGate is to properly plan your security policy and architecture before deployment, as an organization that fully utilizes Fortinet FortiGate's integrated security features can achieve excellent visibility and security. I give this product a rating of 9 out of 10.
Unified security platform has improved multi-site VPN access and simplified network management
What is our primary use case?
My main use case for Fortinet FortiGate is as a UTM to distribute our IP DHCP, to segment our VLAN, and to manage our network infrastructure.
I also use Fortinet FortiGate as a VPN and for site-to-site connection between our multiple sites, such as my head office, our developer office, and data center. It acts as a network security tool where we use an IPS to filter attacks from the outside public to our server.
Regarding my main use cases, I would like to add that it has quite a good GUI and dashboard, making it easy to use. Additionally, we use DNS filtering and application filtering to filter the applications that users can access to the internet.
What is most valuable?
The best features Fortinet FortiGate offers include reliability and a good user interface and user experience.
The user interface is the most valuable to me because it is easy to use, easy to manage, and quite easy for a newcomer to operate. The features are quite good for filtering applications and for addressing our needs, such as blocking social media or other unwanted content.
Fortinet FortiGate has positively impacted our organization by improving our security workflow and network security, as it is quite reliable compared to traditional routers or traditional switch cores from MikroTik or Cisco.
A specific example of how my workflow and network security has improved is that because we have multiple sites, Fortinet FortiGate has a multitude of signature-based features and multiple default policies, so we only have to add that to the profile. It is quite simple and easy to manage.
What needs improvement?
I think Fortinet FortiGate is quite good for now, though it could improve with the virtual IP, as it occasionally has a bug. They have a lot of CVE and updates to their system, and they need to be more concerned about their security.
For how long have I used the solution?
I have been using Fortinet FortiGate for about one year.
What do I think about the stability of the solution?
In my experience, Fortinet FortiGate is quite stable.
When the RAM or memory reaches 70% or 80%, the firewall is more likely unstable and may struggle to forward traffic. I think that is one of the areas where Fortinet FortiGate has room for improvement.
What do I think about the scalability of the solution?
Fortinet FortiGate's scalability is limited because it is on-premises, so we would have to change the type of Fortinet FortiGate as we grow.
How are customer service and support?
The customer support is really helpful for their principle, but they lack technical competency at layer one, as they tend to only look for logs before promoting issues to layer two for resolution.
Which solution did I use previously and why did I switch?
Previously, we used Aruba as a firewall and switch core, but it lacked security features, so we had to move to the next-generation firewall.
What was our ROI?
I am afraid I cannot say that I have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that I think the price is quite good besides the leader in Gartner's next-generation firewall.
Which other solutions did I evaluate?
Before choosing Fortinet FortiGate, we evaluated a lot of competitors at that moment, and we chose Fortinet FortiGate.
What other advice do I have?
My advice to others looking into using Fortinet FortiGate is that you need to think carefully about your usage and calculate your business needs. If you miscalculate, you might end up buying a Fortinet FortiGate that cannot meet your needs, leading to potential downtimes or failures.
I have no additional thoughts about Fortinet FortiGate except that I mentioned the easy user interface and experience for beginners. However, I noted that when the memory reaches up to 80%, the firewall does not function as well. I would rate this product a 9 out of 10.