Fortinet FortiGate Next-Generation Firewall
Fortinet Inc. | 7.6.3Linux/Unix, Other 7.6.3 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
Plateforme de gestion centralisée sur le cloud Fortinet
Effective and easy to set up
Provides as good if not better coverage as our on premise NGFW. Easy to deploy and set up.
Unique Master-Slave sync in HA mode as well as API calls to the AWS infrastructure which means we don't need to run a lambda to supervise the state of the master and change the routing. The API calls take care of this.
Good
Nice and tried with TRANSIT VPC, Good performance. Only Issues with Remote VPN part. CLI part is good, will get more options there.
Great firewall, On-Demand not available for GovCloud ?!
These are great firewalls, they work great for VPC Transit designs. Unavailable for Gov-Cloud as an On-Demand as of August 2018
Great product!
All the features I need, Fortigate's features are covered, and now I can use Fortigate products in multiple clouds to help us achieve hybrid clouds.
Easy to set up
I am testing this product at the AWS re:Invent 2017 in Las Vegas. The free trial was pretty easy to set up, and the support was adequate.
Not operationally ready with autoscaling.
Tried the cloud formation template for autoscaling and found the worker node was not working. Logs showed it crashing out when trying to do an API call to the Firewalls. Updated the worker code, started again, and crashed again.
Without the worker node your not even getting the two on demand nodes sync'd.
Traceback (most recent call last):
File "./Fortigate.py", line 3504, in
exit(main())
File "./Fortigate.py", line 2882, in main
rc = ChangeDHCP(fgt, 'apiadmin', encrypted_password, verbose, debug)
File "./Fortigate.py", line 721, in ChangeDHCP
values = status.json()
File "/usr/lib/python2.7/dist-packages/requests/models.py", line 651, in json
return json.loads(self.text or self.content, **kwargs)
File "/usr/local/lib64/python2.7/site-packages/simplejson/__init__.py", line 516, in loads
return _default_decoder.decode(s)
File "/usr/local/lib64/python2.7/site-packages/simplejson/decoder.py", line 370, in decode
obj, end = self.raw_decode(s)
File "/usr/local/lib64/python2.7/site-packages/simplejson/decoder.py", line 400, in raw_decode
return self.scan_once(s, idx=_w(s, idx).end())
simplejson.scanner.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
Impossible to get support
1. I have a fortinet account
2. I have my serial number for the Fortigate VM (directly copied from the Fortigate Console - I know it is correct).
I click on the contact support link mentioned under the Support section of the AWS marketplace listing. It asks me to login. I login with my fortinet account. I try to create a technical support ticket. To create a ticket, it asks for a serial number. I enter the serial number but it says the serial number is invalid (i took the serial number directly from the Fortigate console, so I know it is correct).
In my Fortigate Admin screen, I try to "register" the product - every time i register, it says "Unknown Error".
My issues are the following
1. I cant register the product with my fortinet account - I get an "An Unexpected Error Occurred" message.
2. Because I can't register the product with my fortinet account, I am unable to submit a support ticket. When I try to create a support ticket in the portal, it says "Invalid Input Data. The Serial Number is Not Registered."
So how are we supposed to get support?
Works like the real device
If you are used to the fortigate firewall line there is nothing new here, the interface is the same and works the same way. Good entry level device, easy to setup and works fine.
Easy to launch and test!
I wish we had this sooner but better late than never. I really like the idea of spinning up the fortinet instance on EC2 to test configuration quickly.
It was really easy to set up like any oterh EC2 instance. It loads with the basic SSH, Telent access which is nice and has some useful configuration preloaded
on the initial build. Hoping to have fun with this.
Thanks!