Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
FortiGate-VM on AWS delivers next-generation firewall and VPN/SD-WAN capabilities for organizations of all sizes. It enables broad network protection and automated security management for consistent enforcement and visibility across your AWS VPCs and hybrid cloud infrastructure. FortiGate natively integrates with AWS Gateway Load Balancer, AWS Transit Gateway and other AWS security services to simplify and deliver enterprise-class security for applications and workloads running on AWS.
FortiGate-VM reduces complexity by combining secure connectivity with advanced threat protection capabilities such as powerful intrusion prevention (IPS), malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services. It offers a management console that provides comprehensive network automation and unified visibility across multi-cloud environments.
FortiGate-VM, in concert with other elements of the Fortinet Security Fabric, enables common deployment scenarios such as cloud security services hub, secure remote access, container security, web application security, and critical workload protection.
FortiGate offers protection from a broad array of threats, with support for all of the security and networking services offered by the FortiOS operating system.
Delivers complete content and network protection by combining stateful inspection with a comprehensive suite of powerful security features to meet PCI DSS compliance.
IPS technology protects against current and emerging network-level threats. In addition to signature-based threat detection, IPS performs anomaly-based detection which alerts users to any traffic that matches attack behavior profiles.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the AWS EC2 instance you run the firewall on. There are no tiers or bundles here. Instead, each priced dimension maps to one instance type across several families, including compute-optimized (c-series), general-purpose (m-series), memory-optimized (r-series), and burstable (t-series) options. Within each family, larger instance sizes carry a higher hourly rate. You choose the instance that matches your throughput and workload needs, then pay only for the hours you use. This usage-based model lets you scale capacity up or down without a fixed commitment.
Top-of-mind questions for buyers
What does the hourly instance rate cover, and does it include the security services and bundles?
The hourly rate covers the FortiGate VM firewall software running on your chosen EC2 instance. AI-powered security services like IPS, antivirus, and URL filtering come as separate ATP, UTP, and ENT bundles. Check your listing subscription to confirm which services are included with this usage-based option.
Am I charged when the firewall instance is stopped or powered off, such as a standby DR node?
Software charges meter running instance-hours only. A fully stopped instance stops accruing the FortiGate VM hourly software fee. You may still pay underlying AWS fees for attached storage or reserved resources while the instance is stopped, but the firewall license bills for active running time.
How does hourly usage-based billing differ from a bring-your-own-license approach for the same instance?
This listing meters actual instance-hours with no upfront license commitment; you pay only for hours the firewall runs. A bring-your-own-license approach separates the license purchase from compute and suits continuous, predictable workloads. Usage-based billing fits variable traffic where you scale instances up or down.
www.fortinet.com
Helpful?
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Please ensure the connectivity to FortiCare (https://directregistration.fortinet.com:443) by checking all related setup on security groups, ACLs, IGW, route tables, public IP address...etc.
After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiGate-VM. Connect to the secured Web UI via the public DNS address: https:// <public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiGate-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortigate-public-cloud/7.6.0/aws-administration-guide/
This product is intended for On-Demand subscription. Please contact Customer Support with the following information instead of trying to register in FortiGate management GUI:
The serial number of your FortiGate instance
The email ID of your Fortinet account.
If you do not have an account yet, please sign using the link below
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
IPS technology with signature-based and anomaly-based detection to protect against current and emerging network-level threats and attack behavior profiles
Threat Protection Capabilities
Advanced threat protection including intrusion prevention, malware detection and protection, and continuous threat intelligence from FortiGuard Labs security services
AWS Native Integration
Native integration with AWS Gateway Load Balancer, AWS Transit Gateway, and other AWS security services for VPC and hybrid cloud infrastructure protection
Stateful Inspection and Content Filtering
Stateful inspection combined with comprehensive security features including content and network protection to meet PCI DSS compliance requirements
Unified Management and Visibility
Management console providing comprehensive network automation and unified visibility across multi-cloud environments
Advanced Threat Prevention Capabilities
Includes firewall, Data Loss Prevention (DLP), Intrusion Prevention System (IPS), application control, IPsec VPN, URL filtering, antivirus, and anti-bot features for multi-layered network security.
Traffic Inspection and Control
Inspects and controls encrypted data flows between on-premises networks and AWS VPCs, including North-South traffic entering and exiting private subnets and East-West traffic between VPCs.
Infrastructure-as-Code Integration
Integrates with infrastructure-as-code tools including Terraform and Ansible for policy automation, with dynamic security policy adaptation based on real-time cloud metadata.
Provides unified, centralized management through Check Point Security Management Server with consistent policy, logging, and reporting across AWS, hybrid, and on-premises environments.
Traffic Identification and Classification
Powerful traffic identification technology for complete visibility and control over network traffic
Malware Prevention
Malware prevention capabilities to protect applications and data from known and unknown attacks
Dynamic Policy Management
Dynamically updated whitelisting and segmentation policies based on AWS tags for reduced attack surface
High-Performance Processing
DPDK support on C5, C5n, M5, and M5n instances running on AWS Nitro System for efficient traffic processing
Cloud-Native Integration
AWS Auto Scaling, ELB integration, Transit VPC with AWS Transit Gateway, and Gateway Load Balancer support for large-scale deployments
Easy Site-to-Site VPN Setup with a User-Friendly FortiGate UI
Reviewed on Aug 13, 2026
Review provided by G2
What do you like best about the product?
the ability to easily setup site to site VPN's. Ability to configure this on any cloud or virtual environment. FortiGate UI is probably one of the easiest to use and understand
What do you dislike about the product?
when it comes to licensing it is not the most straightforward. licensing activation can be tricky at some times. The cost to licensing is also high compared to others i have used.
What problems is the product solving and how is that benefiting you?
Site to Site VPN to connect different office buildings. Web Filtering certain content that is not allowed by company policies for end users. Assist with remote employees to connect directly. I must say the performance on VPN is good. Administration and integration to current network was easy
Information Technology and Services
Single Pane of Glass for IPS, VPN, SD-WAN, and Segmentation
Reviewed on Aug 12, 2026
Review provided by G2
What do you like best about the product?
A single pane of glass for everything IPS, VPN, SD-WAN, and segmentation. It gives me consistent policies across both cloud and on-prem environments. There are no hardware hassles, the performance is solid, and everything runs through one management interface. Overall, it keeps my workload light and my networks tight.
What do you dislike about the product?
The license is quite pricey, especially with feature add-ons. Logging and monitoring could be more intuitive; going through CLI for certain features is a hassle sometimes. Occasional upgrade between versions. Great box, but not perfect.
What problems is the product solving and how is that benefiting you?
A virtual firewall that locks down multi-cloud workloads, removes the policy sprawl between AWS and Azure, handles IPS, VPN, and SD-WAN on the same box, scales up with a single click, costs is high but saves me from late night problem calls, and gives me a dashboard to keep all traffic in check so I can stop babysitting the network and focus on actually building things.
Ramanaji B.
Robust Security with Top-notch Performance
Reviewed on Aug 12, 2026
Review provided by G2
What do you like best about the product?
I use FortiGate-VM NGFW to secure enterprise networks by managing firewall policies, VPNs, IPS, web filtering, and traffic monitoring. I appreciate its ability to protect our network from cyber threats by enforcing security policies. What I like most about FortiGate-VM NGFW is its security and performance, which stand out the most for me. Additionally, the initial setup was easy and straightforward.
What do you dislike about the product?
I find the usability of FortiGate-VM NGFW to be an area that could be improved.
What problems is the product solving and how is that benefiting you?
I use FortiGate-VM NGFW to secure enterprise networks by managing firewall policies, VPNs, and traffic monitoring, protecting our network from cyber threats.
Andrew R.
Strong Security, Easy Management, and Reliable Performance
Reviewed on Aug 08, 2026
Review provided by G2
What do you like best about the product?
Its strong security features, easy management, and good performance. It provides effective protection while being flexible and scalable for different network environment.
What do you dislike about the product?
The main thing I dislike is that some advanced features can be complex to s configure, especially for new users. The licensing and costs can also be a little difficult to manage.
What problems is the product solving and how is that benefiting you?
It actually helps protect the network from cyber threats, control network traffic, and improve visibility. This benefits me by making security management easier, reducing risks, and helping maintain a more secure and reliable network.
Media Production
Easy to Deploy and Test, but Support Can Be Slow
Reviewed on Aug 07, 2026
Review provided by G2
What do you like best about the product?
The solution is easy to deploy and fast to spin up a test system. A great community to get help from if you run into a problem. The price is ok compared to other solutions.
What do you dislike about the product?
Getting help from support can be a bit bureaucratic. You have to be careful when upgrading to a new release, as it can sometimes affect the existing setup.
What problems is the product solving and how is that benefiting you?
One of the leaders in NGFW. The AI is being implemented more and more in the product, and that is, of course, important for staying safe in today's AI threats.