Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
FortiGate-VM on AWS delivers next-generation firewall and VPN/SD-WAN capabilities for organizations of all sizes. It enables broad network protection and automated security management for consistent enforcement and visibility across your AWS VPCs and hybrid cloud infrastructure. FortiGate natively integrates with AWS Gateway Load Balancer, AWS Transit Gateway and other AWS security services to simplify and deliver enterprise-class security for applications and workloads running on AWS.
FortiGate-VM reduces complexity by combining secure connectivity with advanced threat protection capabilities such as powerful intrusion prevention (IPS), malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services. It offers a management console that provides comprehensive network automation and unified visibility across multi-cloud environments.
FortiGate-VM, in concert with other elements of the Fortinet Security Fabric, enables common deployment scenarios such as cloud security services hub, secure remote access, container security, web application security, and critical workload protection.
FortiGate offers protection from a broad array of threats, with support for all of the security and networking services offered by the FortiOS operating system.
Delivers complete content and network protection by combining stateful inspection with a comprehensive suite of powerful security features to meet PCI DSS compliance.
IPS technology protects against current and emerging network-level threats. In addition to signature-based threat detection, IPS performs anomaly-based detection which alerts users to any traffic that matches attack behavior profiles.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Fortinet FortiGate VM Next-Generation Firewall | Network Security
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the AWS EC2 instance type you run the firewall on. Pricing is usage-based, so you are billed only for the hours each instance runs. The options span many instance families — general-purpose, compute-optimized, memory-optimized, and network-optimized — in sizes from large through 32xlarge. Larger instances offer more vCPUs and processing capacity for heavier traffic. Your hourly rate scales with the instance size and family you select. This lets you match capacity to your workload and scale up or down as traffic changes.
Top-of-mind questions for buyers
What does the hourly rate cover, and what do I need to bring separately?
The hourly rate covers the firewall software running on your chosen EC2 instance. You pay this on top of the underlying AWS compute charges for that instance. This on-demand billing bundles the licence, so you do not need a separate purchased licence key to run it.
Am I charged when the firewall instance is stopped or paused?
The software charge meters running hours only. A stopped instance stops accruing the hourly software fee. However, AWS may still bill you for attached storage or reserved resources while the instance is stopped. To halt software charges, stop or terminate the instance.
How do I pick the right instance size, and can I change it later?
Larger instances add vCPUs and processing capacity for heavier traffic. Match the instance family and size to your expected throughput. You can move to a different instance type as traffic grows or shrinks, and your hourly rate adjusts to the new instance you run.
www.fortinet.com
Helpful?
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.
After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiGate-VM. Connect to the secured Web UI via the public DNS address: https:// <public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiGate-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/aws-administration-guide/
This product is intended for On-Demand subscription. Please contact Customer Support with the following information instead of trying to register in FortiGate management GUI:
The serial number of your FortiGate instance
The email ID of your Fortinet account.
If you do not have an account yet, please sign using the link below
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
IPS technology with signature-based and anomaly-based detection to protect against current and emerging network-level threats and attack behavior profiles
Stateful Inspection and Content Filtering
Stateful inspection combined with comprehensive security features including malware detection and protection for content and network protection
VPN and SD-WAN Capabilities
VPN and SD-WAN functionality for secure connectivity and remote access across hybrid cloud infrastructure
Cloud Platform Integration
Native integration with AWS Gateway Load Balancer, AWS Transit Gateway, and other AWS security services for VPC and multi-cloud environments
Threat Intelligence and Management
Continuous threat intelligence from FortiGuard Labs security services with unified management console providing network automation and visibility across multi-cloud environments
Advanced Threat Prevention Capabilities
Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
Traffic Inspection and Control
Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
Infrastructure-as-Code Integration
Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
Traffic Identification and Classification
Powerful traffic identification technology for complete visibility and control over network traffic
Malware Prevention
Malware prevention capabilities to protect applications and data from known and unknown attacks
Dynamic Policy Management
Dynamically updated whitelisting and segmentation policies based on AWS tags for reduced attack surface
High-Performance Processing
DPDK support on C5, C5n, M5, and M5n instances running on AWS Nitro System for efficient traffic processing
Cloud-Native Integration
AWS Auto Scaling, ELB integration, Transit VPC with AWS Transit Gateway, and Gateway Load Balancer support for large-scale deployments
Easy Virtual Deployment and a User-Friendly, Responsive Interface
Reviewed on Aug 25, 2026
Review provided by G2
What do you like best about the product?
What I like best about FortiGate-VM NGFW is how easy it is to deploy in virtual environments. The setup process is straightforward, and routing configuration is simple and clear compared to other firewalls I’ve used. The user interface is very user-friendly and responsive, which makes daily management and policy changes much faster and less complicated. FortiGate-VM NGFW works well with other tools in our environment. We use it alongside Microsoft Azure, Microsoft Sentinel, and Fortinet FortiAnalyzer. The integration is smooth, especially with logging and monitoring tools, which helps us centralize security visibility and manage policies more efficiently.
What do you dislike about the product?
One thing I dislike is that the HA setup can be a bit complicated, especially when configuring it for the first time in a virtual environment. Some advanced features also take time to fully understand. Additionally, the licensing and feature activation process could be more straightforward, and the documentation for certain HA and virtual deployment scenarios is not always clear enough.
What problems is the product solving and how is that benefiting you?
FortiGate-VM NGFW helps us secure our virtual and cloud environments by providing strong firewall protection, intrusion prevention, and traffic control. It solves the problem of managing security across different virtual infrastructures in a simple way. The main benefit is better network security with easier policy management and good performance, which gives us more confidence in protecting our systems without needing complex physical hardware.
Computer & Network Security
Centralized, All-in-One Security for Virtualized Environments
Reviewed on Aug 19, 2026
Review provided by G2
What do you like best about the product?
FortiGate-VM NGFW stands out for centralized security management, comprehensive threat protection, and smooth integration with Fortinet’s security ecosystem. Having firewalling, IPS, web filtering, application control, and strong visibility all in one platform makes it well suited for monitoring and protecting virtualized environments, while keeping security operations consolidated and easier to manage.
What do you dislike about the product?
The main drawbacks are the complexity and cost of licensing, as well as the learning curve for more advanced configurations. The interface can also feel somewhat complicated when you’re managing larger environments, and troubleshooting certain issues may require fairly detailed knowledge of Fortinet-specific features and logs.
What problems is the product solving and how is that benefiting you?
FortiGate-VM NGFW provides centralized network security by bringing together firewalling, IPS, application control, web filtering, and traffic visibility in one place. It helps us detect and block threats, manage and control network traffic, investigate security events more effectively, and improve overall visibility across our environment. As a result, it reduces manual effort for our SOC, speeds up incident investigation, and strengthens our overall security posture.
Mohammad Aktham Obaid A.
Great GUI and Realistic VM Emulation with EVE-NG and PnetLab
Reviewed on Aug 18, 2026
Review provided by G2
What do you like best about the product?
it can be connected to any virtual machine app like eveng and pnetlab with success real life emulation and we can add as much ram as wanted to emulate real life speed with a great, easy and helpful GUI
What do you dislike about the product?
when i use the VM i could not buy the licence i need, for example i could not buy the ICS/OT license also when i connect it to a software like PnetLab sometimes i lose the access to my GUI and i lose the whole configurations i made but i am not sure if this is a pnetlab problem
What problems is the product solving and how is that benefiting you?
its solve the "feel worried about changing problems" where you can safely build/emulate your own network to safely test the new configurations and testing new features
Banking
Consistent Hybrid-Cloud Security and All-in-One Features with FortiGate VM
Reviewed on Aug 17, 2026
Review provided by G2
What do you like best about the product?
Several standout aspects make this a preferred choice for IT and security professionals.
Consistent security across hybrid and multi-cloud environments is a big one. The same FortiOS everywhere means FortiGate VM runs the exact same operating system as physical FortiGate appliances, so administrators face virtually no learning curve when moving between on-premises hardware and cloud instances like AWS, Azure, Google Cloud, VMware, and KVM. With unified policies, organizations can enforce the same security posture, firewall rules, and threat protection standards no matter where workloads live.
Another strength is deep feature consolidation. Instead of stitching together separate tools for routing, SD-WAN, VPN, intrusion prevention, and web filtering, FortiGate VM integrates these capabilities natively. Being able to manage firewall rules, review threat logs, and control secure access from a single dashboard reduces operational complexity and can save hours of management time each week.
Built-in Secure SD-WAN is also a highlight. FortiGate VM includes robust Secure SD-WAN capabilities out of the box, enabling seamless and secure site-to-site connectivity along with intelligent path selection for cloud applications, without needing added hardware costs.
What do you dislike about the product?
Performance Drop with Full Security Features EnabledTurning on intensive security inspection features (such as deep packet inspection, antivirus, intrusion prevention, and web filtering) can cause a noticeable drop in throughput capacity. Careful sizing and resource allocation are required to prevent performance bottlenecks. High Cost and Complex Licensing StructureBoth the software licenses and the required security subscriptions (FortiGuard services) are expensive. Additionally, managing license activation files and tying them to specific virtual machine instances or cloud environments can sometimes be an overly rigid and frustrating process.Resource and Cloud Networking ComplexitiesInitial setup and networking configuration in public cloud environments (like AWS, Azure, or Google Cloud) can be complex compared to traditional on-premises deployments. Administrators also report occasional CPU utilization spikes and packet latency during high-traffic events or simultaneous administrator logins.
What problems is the product solving and how is that benefiting you?
The FortiGate VM Next Generation Firewall solves several critical infrastructure and security challenges, and those solutions translate into major operational benefits:
Solving Cloud Security Blind Spots and Inconsistency Problem: Managing security across a mix of on premises data centers and public clouds like AWS or Azure usually means dealing with disjointed tools and different vendor interfaces. Benefit: Because FortiGate VM runs the exact same operating system everywhere, it allows organizations to enforce uniform firewall rules and security policies across hybrid environments, eliminating blind spots and reducing human error.
Solving Fragmented Infrastructure and Tool Sprawl Problem: Relying on separate point products for routing, virtual private networks, web filtering, and intrusion prevention creates high overhead and complex maintenance. Benefit: By consolidating these features natively into a single virtual appliance, it slashes the time spent managing multiple security vendors and simplifies daily administrative workflows.
Paper & Forest Products
All the Fortinet Features in a Fast, Impressive Virtual Machine
Reviewed on Aug 16, 2026
Review provided by G2
What do you like best about the product?
The fact that you have basically all the features and settings of the other Fortinet physical devices. The performances of the virtual machine are also quite impressive
What do you dislike about the product?
The pricing isn’t very competitive compared to physical firewalls. On top of that, the licensing model feels quite complex and difficult to navigate. The VM also lacks acceleration performance for decryption, which impacts overall efficiency.
What problems is the product solving and how is that benefiting you?
Sometimes, for specific deployments, we can’t use a hardware firewall, so having a single ESXi node with the firewall embedded is essential for our organization.