Listing Thumbnail

    Fortinet FortiGate VM Next-Generation Firewall | Network Security

     Info
    Deployed on AWS
    Free Trial
    Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
    4.4

    Overview

    Play video

    FortiGate-VM on AWS delivers next-generation firewall and VPN/SD-WAN capabilities for organizations of all sizes. It enables broad network protection and automated security management for consistent enforcement and visibility across your AWS VPCs and hybrid cloud infrastructure. FortiGate natively integrates with AWS Gateway Load Balancer, AWS Transit Gateway and other AWS security services to simplify and deliver enterprise-class security for applications and workloads running on AWS.

    FortiGate-VM reduces complexity by combining secure connectivity with advanced threat protection capabilities such as powerful intrusion prevention (IPS), malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services. It offers a management console that provides comprehensive network automation and unified visibility across multi-cloud environments.

    FortiGate-VM, in concert with other elements of the Fortinet Security Fabric, enables common deployment scenarios such as cloud security services hub, secure remote access, container security, web application security, and critical workload protection.

    Visit the FortiGate-VM on AWS Community Resource Hub to find onboarding, deployment, and technical information and join in discussions: https://community.fortinet.com/t5/FortiGate-VM-on-AWS/gh-p/fortigate-vm-on-aws 

    Please contact awssales@fortinet.com  with any questions.

    Highlights

    • FortiGate offers protection from a broad array of threats, with support for all of the security and networking services offered by the FortiOS operating system.
    • Delivers complete content and network protection by combining stateful inspection with a comprehensive suite of powerful security features to meet PCI DSS compliance.
    • IPS technology protects against current and emerging network-level threats. In addition to signature-based threat detection, IPS performs anomaly-based detection which alerts users to any traffic that matches attack behavior profiles.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 7.6.7

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Fortinet FortiGate VM Next-Generation Firewall | Network Security

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (96)

     Info
    • ...
    Dimension
    Cost/hour
    c6in.xlarge
    Recommended
    $1.02
    c8in.xlarge
    $1.02
    m7i.16xlarge
    $5.16
    t2.small
    $0.36
    c6a.4xlarge
    $3.29
    c8in.32xlarge
    $6.19
    c7a.4xlarge
    $3.29
    c6a.2xlarge
    $1.60
    m5.8xlarge
    $4.10
    c5n.xlarge
    $1.02

    AI Insights

     Info

    Dimensions summary

    You pay by the hour based on the AWS EC2 instance type you run the firewall on. Pricing is usage-based, so you are billed only for the hours each instance runs. The options span many instance families — general-purpose, compute-optimized, memory-optimized, and network-optimized — in sizes from large through 32xlarge. Larger instances offer more vCPUs and processing capacity for heavier traffic. Your hourly rate scales with the instance size and family you select. This lets you match capacity to your workload and scale up or down as traffic changes.

    Top-of-mind questions for buyers

    The hourly rate covers the firewall software running on your chosen EC2 instance. You pay this on top of the underlying AWS compute charges for that instance. This on-demand billing bundles the licence, so you do not need a separate purchased licence key to run it.
    The software charge meters running hours only. A stopped instance stops accruing the hourly software fee. However, AWS may still bill you for attached storage or reserved resources while the instance is stopped. To halt software charges, stop or terminate the instance.
    Larger instances add vCPUs and processing capacity for heavier traffic. Match the instance family and size to your expected throughput. You can move to a different instance type as traffic grows or shrinks, and your hourly rate adjusts to the new instance you run.
    www.fortinet.com
    Helpful?

    Vendor refund policy

    You may terminate the instance at anytime to stop incurring charges.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443 ) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.

    After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiGate-VM. Connect to the secured Web UI via the public DNS address: https:// <public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiGate-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/aws-administration-guide/ 

    Support

    Vendor support

    This product is intended for On-Demand subscription. Please contact Customer Support with the following information instead of trying to register in FortiGate management GUI:

    1. The serial number of your FortiGate instance
    2. The email ID of your Fortinet account. If you do not have an account yet, please sign using the link below

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Network Infrastructure, Security
    Top
    10
    In Log Analysis, Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Intrusion Prevention System
    IPS technology with signature-based and anomaly-based detection to protect against current and emerging network-level threats and attack behavior profiles
    Stateful Inspection and Content Filtering
    Stateful inspection combined with comprehensive security features including malware detection and protection for content and network protection
    VPN and SD-WAN Capabilities
    VPN and SD-WAN functionality for secure connectivity and remote access across hybrid cloud infrastructure
    Cloud Platform Integration
    Native integration with AWS Gateway Load Balancer, AWS Transit Gateway, and other AWS security services for VPC and multi-cloud environments
    Threat Intelligence and Management
    Continuous threat intelligence from FortiGuard Labs security services with unified management console providing network automation and visibility across multi-cloud environments
    Advanced Threat Prevention Capabilities
    Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
    Traffic Inspection and Control
    Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
    Infrastructure-as-Code Integration
    Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
    AWS Service Integration
    Supports integration with AWS Transit Gateway, Gateway Load Balancer, AWS Security Hub, VPC Ingress Routing, AWS Traffic Mirroring, AWS Outposts, and Amazon Macie.
    Centralized Security Management
    Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
    Traffic Identification and Classification
    Powerful traffic identification technology for complete visibility and control over network traffic
    Malware Prevention
    Malware prevention capabilities to protect applications and data from known and unknown attacks
    Dynamic Policy Management
    Dynamically updated whitelisting and segmentation policies based on AWS tags for reduced attack surface
    High-Performance Processing
    DPDK support on C5, C5n, M5, and M5n instances running on AWS Nitro System for efficient traffic processing
    Cloud-Native Integration
    AWS Auto Scaling, ELB integration, Transit VPC with AWS Transit Gateway, and Gateway Load Balancer support for large-scale deployments

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.4
    532 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    62%
    35%
    1%
    1%
    1%
    47 AWS reviews
    |
    485 external reviews
    External reviews are from G2  and PeerSpot .
    Information Technology and Services

    Easy, Hardware-Free Deployment with Flexible Backup and Restore

    Reviewed on Sep 03, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about FortiGate-VM NGFW is how it combines strong security features with the flexibility of a virtual appliance. It delivers next-generation firewall capabilities—such as intrusion prevention, application control, web filtering, VPN, and advanced threat protection—within a single platform, which makes overall security management much easier. The user interface is intuitive, and day-to-day administration stays straightforward even in more complex environments. Another key advantage is its smooth integration with cloud and virtualized infrastructures. We’ve been able to deploy it quickly and scale as needed without adding hardware, which saves time and reduces operational costs. Performance has been consistent, and the visibility into network traffic and security events helps us spot and respond to potential threats more effectively. Overall, FortiGate-VM NGFW strikes a solid balance between security, performance, and ease of management, and it has become a valuable part of our network security strategy.With flexible pricing options and premium support and integrated ai features
    What do you dislike about the product?
    While FortiGate-VM NGFW is a strong security solution overall, there are a few areas that could be improved. One limitation I have experienced is that restoring configurations from a physical FortiGate appliance to a VM deployment is not always seamless. In some cases, I had to manually reconfigure settings, which increased deployment time and operational effort. VM management can also be challenging, especially in larger environments where multiple virtual firewalls need to be monitored and maintained. Although the interface provides a good range of features, some workflows could be more intuitive and require several steps to complete routine administrative tasks. Integration with certain third-party platforms and cloud environments may require additional customization compared to what some competing products offer. From a performance perspective, resource utilization can become high under heavy traffic loads, requiring careful sizing of CPU and memory resources. Licensing and pricing can be difficult to understand, particularly when multiple security services and subscriptions are involved. The initial onboarding process also has a learning curve for administrators who are new to the Fortinet ecosystem. Finally, while FortiGuard's threat intelligence is valuable, I would like to see more AI-driven automation and smarter recommendations for threat analysis and policy optimization to reduce manual effort and improve operational efficiency.
    What problems is the product solving and how is that benefiting you?
    Before implementing FortiGate-VM NGFW, managing network security across our virtual and cloud environments was becoming increasingly complex. We needed a solution that could provide strong protection without adding more physical hardware or creating additional management overhead. FortiGate-VM NGFW has helped us centralize security controls by combining firewalling, IPS, web filtering, VPN, and application control into a single platform. This has made it much easier to monitor traffic, enforce security policies, and respond to potential threats. The deployment process was straightforward, and the flexibility of the virtual appliance allowed us to scale as our requirements changed. One of the biggest benefits has been improved visibility into network activity and better control over remote access. We spend less time managing multiple security tools, and troubleshooting is much faster because everything is available from a single console. Overall, it has strengthened our security posture while reducing operational complexity and infrastructure costs.
    Mani s.

    Flexible, Easy-to-Deploy FortiGate VM for Cloud and Virtual Firewalls

    Reviewed on Sep 02, 2026
    Review provided by G2
    What do you like best about the product?
    FortiGate VM is Fortinet's virtualized next-generation firewall, essentially the same FortiOS software that runs on their physical appliances, but packaged to run on hypervisors (VMware, Hyper-V, KVM) or in cloud environments (AWS, Azure, GCP, OCI). Here's what makes it valuable:
    What do you dislike about the product?
    Great for flexible, cloud-based firewall needs — easy to deploy and cost-effective. Performance drops under heavy traffic. Best for small/medium setups overall.
    What problems is the product solving and how is that benefiting you?
    FortiGate VM NGFW helps secure cloud and virtualized environments without needing physical hardware. It solves problems like protecting multi-cloud/hybrid infrastructure, segmenting workloads (VPC/VNet), enabling secure remote access (VPN), enforcing consistent security policies across on-prem and cloud, and reducing hardware costs while scaling firewall capacity as business grows. It's especially useful for organizations expanding into cloud, needing quick disaster recovery setups, or managing distributed branch offices without deploying physical appliances everywhere.
    Computer & Network Security

    Future of Fortigate VM NGFW

    Reviewed on Sep 01, 2026
    Review provided by G2
    What do you like best about the product?
    FortiGate VM is basically the full FortiOS firewall packaged as a virtual machine instead of dedicated hardware. It runs on the usual hypervisors (VMware, KVM, Hyper-V) and all the major public clouds, and because it’s the same OS as the physical boxes, the CLI, policies, and features are identical — nothing to relearn or reconfigure differently.

    On the NGFW side you get full Layer 7 inspection: IPS, application control, SSL inspection, antivirus, web filtering, plus built-in SD-WAN and support for BGP/OSPF and overlay tunnels like IPsec, GRE, and VXLAN. Licensing scales by vCPU, so you size it to the throughput you actually need rather than being stuck with a fixed hardware tier.

    Practically, it’s most useful for cloud edge firewalling, DR sites where you can’t wait on hardware lead times, lab testing before pushing changes to production units, and management of FortiManager/FortiAnalyzer across a mixed fleet of physical and virtual firewalls.
    What do you dislike about the product?
    The biggest downside of FortiGate VM, in my experience, is performance. Without the dedicated ASICs (NP/CP chips) found in physical FortiGates, all packet processing is handled in software on the hypervisor’s CPU. That means throughput is ultimately constrained by the host’s available resources as well as the vCPU licensing tier you’re on. SSL inspection is especially impacted, since there’s no hardware crypto offload to absorb that workload.

    Licensing is vCPU-based, which initially sounds flexible, but it can get expensive fast if you need additional cores to achieve the throughput you’re aiming for. In practice, scaling up this way can end up costing more over time than buying an equivalent physical appliance.
    What problems is the product solving and how is that benefiting you?
    FortiGate VM addresses the challenge of extending consistent, enterprise-grade NGFW security into environments where physical hardware either can’t be deployed or simply doesn’t make sense.

    For cloud coverage, there’s no rack to mount a box in, so VM firewalls can inspect traffic directly inside AWS/Azure/GCP VPCs. It also helps maintain consistency across hybrid infrastructure by keeping the same policies, logging, and FortiManager/FortiAnalyzer-based management across on-prem, colo, and multiple clouds, rather than juggling different tools in each environment.

    Another big advantage is speed and elasticity: you can deploy in minutes instead of waiting weeks for hardware procurement, shipping, and racking. That’s especially useful for DR sites, temporary environments, M&A integration, or scaling up and down with demand. On the cost side, vCPU-based licensing provides flexibility to pay for what you actually need, instead of over-provisioning hardware for peak capacity—helpful when traffic is unpredictable or seasonal.

    Finally, FortiGate VM supports east-west segmentation by inspecting traffic between VMs and microservices inside a virtual network, which a perimeter hardware appliance can’t effectively cover.

    Overall, it delivers enterprise-grade firewalling that’s quick to deploy, consistent across environments, and elastic—ideal for places where physical hardware can’t go or isn’t practical.
    Recommendations to others considering the product:
    To maximize the benefits of FortiGate VM, consider the following recommendations:

    1. **Resource Allocation**: Ensure that your hypervisor has sufficient resources to handle the expected traffic load, especially if SSL inspection is a priority.

    2. **Licensing Strategy**: Plan your vCPU licensing carefully to avoid unexpected costs. Consider your current and future throughput needs.

    3. **Hybrid Deployment**: Use FortiGate VM in conjunction with physical appliances to balance performance and flexibility.

    4. **Regular Updates**: Keep your FortiGate VM updated with the latest firmware to benefit from security patches and new features.

    5. **Monitoring and Management**: Utilize FortiManager and FortiAnalyzer for centralized management and monitoring to streamline operations across your network.

    6. **Testing Environment**: Leverage the VM for testing configurations and updates before deploying them to production environments.

    By following these recommendations, you can effectively leverage FortiGate VM to enhance your network security posture.
    Thabet A.

    Easy Virtual Deployment and a User-Friendly, Responsive Interface

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about FortiGate-VM NGFW is how easy it is to deploy in virtual environments. The setup process is straightforward, and routing configuration is simple and clear compared to other firewalls I’ve used. The user interface is very user-friendly and responsive, which makes daily management and policy changes much faster and less complicated. FortiGate-VM NGFW works well with other tools in our environment. We use it alongside Microsoft Azure, Microsoft Sentinel, and Fortinet FortiAnalyzer. The integration is smooth, especially with logging and monitoring tools, which helps us centralize security visibility and manage policies more efficiently.
    What do you dislike about the product?
    One thing I dislike is that the HA setup can be a bit complicated, especially when configuring it for the first time in a virtual environment. Some advanced features also take time to fully understand. Additionally, the licensing and feature activation process could be more straightforward, and the documentation for certain HA and virtual deployment scenarios is not always clear enough.
    What problems is the product solving and how is that benefiting you?
    FortiGate-VM NGFW helps us secure our virtual and cloud environments by providing strong firewall protection, intrusion prevention, and traffic control. It solves the problem of managing security across different virtual infrastructures in a simple way. The main benefit is better network security with easier policy management and good performance, which gives us more confidence in protecting our systems without needing complex physical hardware.
    E-Learning

    FortiGate-VM: Full Security Stack in One Lightweight VM with Fast Deployment

    Reviewed on Aug 25, 2026
    Review provided by G2
    What do you like best about the product?
    What I appreciate most is the seamless integration of the full security stack into a single VM. Unlike physical appliances or other virtual solutions that require separate boxes for different functions, the FortiGate-VM gives me IPS, web filtering, application control, and SSL inspection all in one lightweight instance. Deployment on our VMware cluster took under 10 minutes, and the Security Fabric visibility across our hybrid environment has been a game-changer for troubleshooting traffic flows. The SD-WAN features are also surprisingly robust—we're load-balancing two ISPs without needing an extra device.
    What do you dislike about the product?
    The licensing model is my biggest headache—the performance tiers (VM-02 vs. VM-04, etc.) are confusing, and upgrading to a higher tier requires a full VM reboot, which means scheduling maintenance windows just to adjust throughput. Also, the GUI is great for basic policies, but once you need advanced SD-WAN rules or policy-based routing, you're forced into the CLI, and the documentation often assumes you're coming from a physical box. The learning curve there is frustratingly steep. Lastly, onboard logging fills up way too fast—you practically need a separate FortiAnalyzer or external syslog server if you want to keep more than a few days of historical data.
    What problems is the product solving and how is that benefiting you?
    We were stuck with aging physical firewalls that were hitting CPU limits during peak traffic, and upgrading meant costly hardware replacements and long shipping delays. The FortiGate-VM completely solved that by letting us spin up additional capacity on our existing ESXi hosts in minutes—no hardware wait times. It's also helping us consolidate multiple point solutions; we no longer run separate proxy servers and intrusion detection boxes because the VM handles everything inline. The biggest benefit has been agility—when our remote offices grew, we deployed new virtual instances in under 15 minutes instead of waiting days for hardware to ship. Plus, the centralized policy management via FortiManager has cut our rule-review time by half, which frees me up for actual infrastructure improvements rather than just firefighting.
    View all reviews