I use the solution in my company for the data center's server protection to segregate the data center VLANs and the other VLANs used in the production, testing, and development phases, including the areas consisting of DMZ and VLAN. We are using Fortinet FortiGate-VM as a software-based tool and as a firewall for our data center.
External reviews
External reviews are not included in the AWS star rating for the product.
Helps segregate the VLANs in the data center, but it needs to improve on the security part
What is our primary use case?
What is most valuable?
It filters out the unnecessary connectivity that I would probably expect to be connected from the end user site or from external to the data center site. It is also used to filter unauthorized access to sites and to mitigate risks if, in cases, because of the asset policy, the remote desktop connectivity or remote connectivity is not allowed to restrict something. It is used to deal with phishing or something that may not pass through the network. The tool serves as an industrial firewall so that we can use it as a filter more efficiently.
What needs improvement?
The security offered by the tool has certain shortcomings, making it in area where improvements are required. Security, by nature, is very dynamic, and continuous improvement is required. Every time, the policy and the configuration need to be checked in that aspect now, so in that aspect, it needs some improvement, especially when it comes to some filtering mechanisms, and protocols.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM for more than three years.
What do I think about the stability of the solution?
In terms of stability, it is stable. Stability-wise, I rate the solution an eight out of ten.
What do I think about the scalability of the solution?
It is scalable because it is a virtual appliance. You can probably scale it up more.
Fortinet FortiGate-VM is a security solution, so users are not expected to access it. It is actually required to protect the network and the environment, so there is no need for actual user access for the solution.
How was the initial setup?
The product's initial setup phase requires some special expertise. The initial setup phase might not be complex, but it requires experts since it is a security solution.
If there is an expertise that is actually doing the implementation or deployment, then it is a straightforward process.
What's my experience with pricing, setup cost, and licensing?
The solution requires a license. The tool is neither expensive nor cheap, so it is okay.
What other advice do I have?
The product's implementation does affect our compliance with industry regulations, and it is one of the reasons why we prefer using Fortinet FortiGate-VM.
My suggestion to other people related to the tool depends on their requirements because there are other different solutions in terms of cost, efficiency, security, reliability, and security. Depending on the requirements, the tool is recommendable. Fortinet is one of the top security solutions in the market. Anybody can choose from multiple tools in the market, including Palo Alto products and other solutions. Fortinet is usually recommended to others.
I think that Fortinet FortiGate-VM has some solutions that offer AI features. For our use case, we don't actually use the AI functionalities since we want to control everything. In my company, we are the ones who are actually dealing with the product and are just not supported by AI.
I rate the tool a seven out of ten.
Efficiently manages subscription-based licensing and ensures compliance with regulatory requirements for banking environments
What is our primary use case?
We use the product primarily in environments requiring robust network security and compliance, especially in the banking and enterprise sectors.
How has it helped my organization?
The platform has enhanced our organization's security posture by providing effective threat protection, bandwidth management, and SDN capabilities.
What needs improvement?
They could enhance the product's functionality for more comprehensive threat detection and mitigation, especially for large-scale deployments.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM for several years.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The product is scalable.
How was the initial setup?
The initial setup of FortiGate was straightforward. It involved detailed planning for appliance selection based on user numbers, throughput requirements, firewall, IPS capacity, and VPN needs.
What about the implementation team?
We managed the implementation in-house, leveraging our expertise in network configuration.
What was our ROI?
FortiGate offers a favorable ROI due to its competitive pricing structure and effective network security capabilities, making it a cost-effective choice for our organization.
Which other solutions did I evaluate?
We evaluated alternatives like Checkpoint and Palo Alto. We chose FortiGate for its cost-effectiveness, robust performance in our specific use cases, and the comprehensive support provided by Fortinet.
What other advice do I have?
The product's threat protection features have been instrumental in managing subscription-based licensing and ensuring compliance with regulatory requirements, especially in banking environments.
I rate Fortinet FortiGate-VM an eight out of ten.
An easy to configure and manage solution with fabric features
What is our primary use case?
We use Fortinet FortiGate-VM as an edge firewall for Internet traffic control and as the main firewall for cloud environments. Whether they're on AWS, Alibaba Cloud, or another platform, FortiGate-VM serves as the primary firewall.
What is most valuable?
One notable feature is the SD-WAN, which is a strong component of the FortiGate-VM. The fabric feature is also good, but not all customers use FortiGate's networking components, such as the switches. We enable various protection features on FortiGate, such as IPS and web application security. Most customers utilize these protection features to enhance their security.
What needs improvement?
Integrating multi-factor authentication with FortiGate-VM can be challenging. While multi-factor authentication is important, not all customers have it enabled. Integration with third-party solutions like ManageEngine or Duo can be complex and sometimes problematic during testing. However, high availability works smoothly with FortiGate-VM. We use high availability, and SD-WAN features effectively; overall, the performance is good.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM as a reseller for eight years.
What do I think about the stability of the solution?
The stability is good.
I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
We implemented it for more than one thousand users.
I rate the solution’s scalability a ten out of ten.
How are customer service and support?
Support from the engineering team has some weaknesses. Sometimes, they focus on closing tickets quickly or asking for logs without thoroughly addressing the issue. However, the support team includes knowledgeable and responsive individuals, especially those from non-Arabic backgrounds.
How would you rate customer service and support?
Positive
How was the initial setup?
Setting up FortiGate-VM is straightforward, but there is a step that can be a bit tricky. After installing the VM, you need to log into the CLI for the first time to set a static IP address if you have multiple interfaces. By default, interfaces will receive IP addresses via DHCP from the cloud service provider. You must disable DHCP on the additional interfaces and set static IPs to ensure proper access and configuration. You may have trouble accessing the firewall if you don't do this.
Issues with certificates and licenses often arise from the distributor, not Fortinet.
The setup process is generally easy. FortiGate is becoming popular in Saudi Arabia due to its user-friendly interface and ease of configuration compared to other vendors like Palo Alto. High availability setup is also simple and not overly complicated.
What's my experience with pricing, setup cost, and licensing?
When comparing Fortinet to other vendors in Saudi Arabia, like Palo Alto, Fortinet stands out positively. In comparison to Sophos, many customers are currently switching to Fortinet. Fortinet's pricing is competitive, making it an attractive option.
What other advice do I have?
To block HTTPS management traffic from the WAN, you must carefully manage the HTTPS settings. If HTTPS is not enabled on the WAN interface, you won't be able to block management traffic effectively. Some customers require HTTPS because of NAT services and use public IPs. Disabling HTTPS can disrupt management access. Better controls for managing the interface from the WAN side would be helpful.
Fortinet FortiGate is easier to configure and manage compared to Palo Alto. Setting up policies, routing, and VPN tunnels on FortiGate is more straightforward and faster. Palo Alto can be complex, requiring multiple steps to create a policy and manage interfaces.
FortiGate also excels in troubleshooting and logging. The logs are easier to read and provide better classification, making it simpler to troubleshoot issues. In contrast, Sophos is less effective for larger-scale operations and doesn’t match Fortinet’s capabilities.
In cloud environments, we recommend FortiGate-VM because it integrates well with cloud service providers. On-premises, many customers prefer physical FortiGate hardware, particularly with VMware setups. However, FortiGate-VM is more commonly used for service providers like SCC, Alibaba, and AWS.
Overall, I rate the solution a ten out of ten.
I like the solution's IPS, IDS, and URL filtering
What is our primary use case?
We use FortiGate-VM as a firewall. My company has more than 4,000 users, and we plan to increase usage.
What is most valuable?
I like FortiGate's IPS, IDS, and URL filtering.
What needs improvement?
I think Fortinet should provide us with more reporting from the AI/ML point of view. They could also offer the SaaS application in a single box. The VPN and ZTNA have so many verticals that they work as a standalone solution. They need to be in a single box.
For how long have I used the solution?
I have worked with FortiGate-VM for the last three years.
What do I think about the stability of the solution?
I rate FortiGate-VM eight out of 10 for stability.
What do I think about the scalability of the solution?
From a scalability point of view, we have a physical user license. If we need to upgrade, we can get a box. There is presently sufficient formal organization to scale up.
How are customer service and support?
I have no problems with Fortinet support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Check Point and Palo Alto firewalls.
How was the initial setup?
We deployed FortiGate-VM with the help of a partner and the vendor. The deployment process took three months. We previously used Cisco ASA and had no migration tool, so we had to start from scratch.
What's my experience with pricing, setup cost, and licensing?
FortiGate-VM is affordable. In terms of operating costs, we contract with the OEM for a three-year contract and then renew. We haven't received any notice from them because all of our infrastructure is under contract. Every three years, if we cannot get a good price from the vendor, we replace the box.
What other advice do I have?
I rate Fortinet FortiGate-VM eight out of 10. It has all the features. The only recommendation is to combine the vertical into a single box. To improve performance, they should build an engine in the box that enables them to scale per the user requirement.
Helps secure complex environments through strong integration and security features
What is our primary use case?
I primarily use it for the Nextiva SIM firewall and the website application firewall. We strive to serve our customers, including utilizing the SD-WAN feature in FortiGate in our office.
What is most valuable?
The features that are beneficial for failure mitigation and security include PPN and firewall security. The integration of multiple networks, especially in complex environments such as the finance and manufacturing industries, makes FortiGate valuable. In these industries, it can be difficult to implement and integrate several applications.
What needs improvement?
Currently, I am working on improvements. One of the main areas is the processing and integration of new features. In my opinion, refreshing the CPM technology with zero-trust access could enhance its performance.
For how long have I used the solution?
I have used the solution mostly for maybe ten years.
What do I think about the stability of the solution?
The product has been very stable, based on my ten to eleven years of experience. When I propose FortiGate to customers, hardware problems have been minimal, which suggests a reliable performance.
What do I think about the scalability of the solution?
Scalability is well-supported, with the notable ability to implement features easily. FortiGate offers robust scalability options.
How are customer service and support?
I find the customer service to be good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup typically takes three to five days.
What other advice do I have?
Sometimes, questions arise about the backup position, especially regarding firewall operations. FortiGate, placed next to Nextiva SIM, excels in terms of pricing and operational efficiency. Customers can easily troubleshoot with great technical support. I would rate it nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
A value-for-money appliance that provides good security and technical support
What is our primary use case?
Fortinet FortiGate-VM is used for the firewall. Some clients would like to go for the solution because of pricing. They feel they can run it on their own hardware, cut down costs, and manage it.
What is most valuable?
I can vouch for the security aspect of Fortinet FortiGate-VM. It's a value-for-money appliance. Fortinet has always been our number one firewall appliance regarding recommendations to customers. The solution is very secure, and its technical support is on point.
I like Fortinet FortiGate-VM for tutorial purposes. You can set up the solution on your personal computer for apps and teaching.
What needs improvement?
Fortinet FortiGate-VM should improve its asset identification, wherein the device can identify assets on the network, like computers. We should be able to identify a device and the user account used to log on to that device.
For how long have I used the solution?
I have been using Fortinet FortiGate-VM for more than five to six years.
What do I think about the stability of the solution?
Since it is a VM, the solution runs on a client-provided host machine. Most of the time, the host machine gives issues that affect the VM.
I rate the solution a five out of ten for stability.
What do I think about the scalability of the solution?
Around 20 users are using Fortinet FortiGate-VM in our organization.
I rate the solution an eight out of ten for scalability.
How are customer service and support?
The solution's technical support is responsive, but the only issue is you need to be specific with your problem. If you are not specific with your problem, it will take longer to resolve the issue because of time zone differences. All the engineers would like to know exactly the problem before they offer solutions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously worked with pfSense. We switched to Fortinet FortiGate-VM because pfSense was giving us issues.
How was the initial setup?
Fortinet FortiGate-VM is easy to implement, provided you know your network architecture and the basics.
On a scale from one to ten, where one is complex and ten is easy, I rate the solution's initial setup a nine out of ten.
What about the implementation team?
The solution can be deployed in less than ten minutes.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiGate-VM is a very expensive solution. It's a value-for-money appliance. You don't have every client going in for the solution unless there are some specific points.
You need to know exactly what you need at the point of purchase. That will guide you in purchasing the required license. If you miss and purchase the wrong license, you can wait and purchase another license during renewal. You can also negotiate with Fortinet to have your license changed to get the feature you want.
On a scale from one to ten, where one is expensive and ten is cheap, I rate the solution's pricing a three out of ten.
What other advice do I have?
We used to troubleshoot for Fortinet FortiGate-VM, but now the new firmware doesn't really give issues. We do maintain the solution by checking on devices and updating the firmware. We have seven engineers in our technical team to deploy and maintain the solution.
I would not recommend Fortinet FortiGate-VM to other users because most users don't have the infrastructure. They will tell you they want to cut down costs. You get them the solution, and at the end of the day, as a technical person, you will be bothered by the solution.
Regarding the upgrade, the only time we've had an issue is when the customer gave the wrong information. The utilization exceeded what they actually needed. Aside from that, Fortinet FortiGate-VM is a good appliance for us.
Overall, I rate the solution an eight out of ten.
Provides ease of management and has a simple setup process
What is our primary use case?
The primary use case for Fortinet FortiGate-VM involves formulating policies and services within the environment.
What needs improvement?
They could provide more integration options with different platforms.
For how long have I used the solution?
We have been using Fortinet FortiGate-VM for six months.
What do I think about the stability of the solution?
I rate the platform's stability an eight out of ten.
What do I think about the scalability of the solution?
We have 200 Fortinet FortiGate-VM users in our organization. I rate the scalability a ten out of ten.
How was the initial setup?
The initial setup process is simple. It involves defining the parameters for deployment, such as the number of sites, PCs, and Wi-Fi users.
What's my experience with pricing, setup cost, and licensing?
We don't have to pay for the licenses. But we might purchase licenses in the future.
What other advice do I have?
FortiGate improved security within our virtualized environment by providing robust first-line defense capabilities and optimized cost-effectiveness.
It provides an ease of management and configuration as well. I rate it a nine out of ten.
Ccomprehensive security features, easy deployment, and a user-friendly GUI
What is our primary use case?
We employ Fortinet FortiGate-VM solely for testing purposes, similar to how we employ virtual machines in a virtual lab environment to evaluate solutions. When customers inquire about potential solutions, we typically construct and thoroughly test these solutions in our lab environment before providing confirmation. Once we've successfully conducted a proof of concept, we then extend an offer to the customer.
How has it helped my organization?
Both the hardware and virtual versions offer comprehensive capabilities required for perimeter network protection. Positioned at the network perimeter, they provide profiles that can be easily configured, including antivirus, DNS protection, web filtering, IPS, and application awareness for over five thousand applications. This allows for tailored configurations based on specific application usage within our network.
The scalability and flexibility of FortiGate VM have greatly benefited our organization. Its exceptional scalability allows us to adapt and expand according to our evolving needs.
Integrating FortiGate VM with our existing systems was straightforward, as I recall no difficulties during the process. I would rate it a solid ten out of ten for ease of integration.
The performance and availability of FortiGate-VM in our setup vary depending on the specific models chosen. We refer to data sheets and comparison tables to identify devices that meet our specific requirements. This involves considering factors such as performance metrics, encryption and decryption capabilities, and the number of secure connections supported. By comparing different models, we can select the one that best suits our needs.
The GUI of FortiGate is exceptional.
What is most valuable?
The features of FortiGate VM that we find most effective for network security include its universal operating system, which is the same across both hardware and virtual machine deployments. This consistency ensures that both real boxes and virtual machines run on identical images, accessible via both command line and graphical interfaces for convenience.
What needs improvement?
SD-WAN could be enhanced to provide a clear division between control and data planes, utilizing controllers to manage tasks within the network.
For how long have I used the solution?
We have been using it for more than three years.
What do I think about the stability of the solution?
I am satisfied with its stability. I would rate it ten out of ten.
What do I think about the scalability of the solution?
It provides outstanding scalability capabilities. I would rate it ten out of ten.
We serve a diverse range of customers, including large government organizations in Ukraine and small businesses. FortiGate is suitable for a variety of customer types, accommodating the needs of both large enterprises and smaller organizations.
How are customer service and support?
We haven't encountered any open trouble tickets in the past three years, so we don't have firsthand experience with how Fortinet handles cases.
How was the initial setup?
The initial setup is straightforward, earning a rating of ten out of ten for ease of use. Compared to other options, it stands out as exceptionally simple, largely due to the extensive documentation provided by Fortinet. Additionally, numerous YouTube tutorials are available online, making it easy to find solutions without necessarily having to consult the documentation.
What about the implementation team?
For deployment, FortiGate can be utilized in both on-premises and cloud environments, offering flexibility in its application. It can serve as a client-side perimeter device within a customer's network or function as a cloud-based service. Our organization predominantly offers cloud-based solutions, leveraging FortiGate installations at our Sentinel node facility. Here, we manage customer traffic by configuring it to pass through FortiGate, allowing us to provide next-generation firewall services to customers who lack their infrastructure. We tailor configurations to suit each customer's specific needs.
Alternatively, if a customer requires an on-premises solution, we may deploy a physical appliance at their site. In such cases, where the customer lacks the expertise to manage the firewall effectively, we offer a managed service option.
Deployment typically takes no more than a few hours, thanks to the straightforward installation process and the clarity of the documentation provided. Especially in simple configurations with uncomplicated topologies, deployment can be completed within minutes.
What's my experience with pricing, setup cost, and licensing?
The price falls somewhere in the middle; it's neither cheap nor expensive. I would rate it five out of ten.
When purchasing an appliance, it's essential to acquire the accompanying subscription. This is crucial because frequent updates to antivirus profiles and other features are necessary, often occurring daily. Operating the device effectively requires a subscription from Fortinet, which we consistently purchase.
What other advice do I have?
Fortinet FortiGate-VM is purpose-built as a next-generation firewall, excelling in its performance of this specific function. Its designated place in the network aligns perfectly with its capabilities, making it an ideal device for its intended purpose. Overall, I would rate it ten out of ten.
Provides robust web filtering capabilities and has an easy setup process
What needs improvement?
They could simplify the troubleshooting process. Troubleshooting requires expertise, often necessitating the command-line interface (CLI). It could be more advanced and easier to use than other products.
Additionally, they could enhance support capabilities and a facility to communicate efficiently with the team.
For how long have I used the solution?
We have been using Fortinet FortiGate-VM for seven years.
What do I think about the stability of the solution?
The product is stable. However, there are a few areas of improvement. I rate the stability an eight out of ten.
What do I think about the scalability of the solution?
It is best in terms of pricing for small and medium-sized companies, where it stands out as a cost-effective and feature-rich solution. For larger enterprises, we emphasize the potential benefits of complementing FortiGate-VM with additional firewalls, such as Palo Alto, to enhance security and address potential vulnerabilities.
I rate the scalability a nine out of ten.
How was the initial setup?
The initial setup process is easy. It can deployed on the cloud and premises based on the client's requirements.
What's my experience with pricing, setup cost, and licensing?
There are products like Cisco Meraki that are more inexpensive than Fortinet FortiGate-VM. However, it provides better security features. Palo Alto's pricing is similar to that of the FortiGate-VM regarding quality for security features. It is reasonable.
What other advice do I have?
FortiGate VM in a cloud infrastructure provides security benefits. It offers the same robust features and functionality in virtual, on-premise, and traditional data center environments. It protects against external attacks and internal threats through features such as web filtering, secure application filtering, and antivirus capabilities. These functionalities collectively enhance security measures, safeguarding against various potential risks.
It is extensible, as we can add as much functionality as we require. It is simple to add more resources. It has a flexible pay-as-you-go pricing model.
I rate it an eight out of ten.
A tool to help businesses create a blockage for external traffic
What is our primary use case?
My company had once deployed multiple firewalls and switches in an organization.
My company uses the firewall capabilities of the product for L1, L2, and L3 switches, along with FortiClient VPN.
My company mostly deals with an organization that works with on-premises software. My company uses the tool to block the traffic from the outside area that may reach our infrastructure or network. My company uses the product as a firewall to create a blockage for outside traffic.
What is most valuable?
The most likable feature of the firewall functionalities stemmed from the fact that it did not allow anyone from outside the organization to have any kind of access to the company's information, and it ensured that it blocked outside traffic.
What needs improvement?
The product's setup is quite complex, making it an area where improvements are required.
For how long have I used the solution?
I have experience with Fortinet FortiGate-VM for four to five years.
What do I think about the stability of the solution?
Stability-wise, I rate the solution an eight out of ten.
My company is involved in research and development activities, and some of our employees or teams are constantly involved in research or development, owing to which some product features are not implemented in our organization. In general, the product is not used to its 100 percent potential.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a ten out of ten.
Which solution did I use previously and why did I switch?
I have experience with Palo Alto Networks.
How was the initial setup?
The product's initial setup phase is a bit complex.
The solution is deployed on an on-premises model.
The solution can be deployed in three working days.
What about the implementation team?
The deployment process can be carried out with the help of our company's in-house team.
What was our ROI?
Though I cannot give any numbers, I can say that the product's ROI is good. The tool is able to give good returns considering the amount of money that my company invested in the product for our infrastructure.
I rate the tool's benefits a nine out of ten since the product always helps to maintain security and safety in our company.
What's my experience with pricing, setup cost, and licensing?
There is a need to make payments towards the licensing costs attached to the solution.
What other advice do I have?
The tool improved the security in our company's virtualized environment, as it was helpful in creating an additional layer of security for the organization and for the use of the internet. The tool was the most important product to be implemented in the organization.
To be able for our organization to build our services, we need to operate inside a certain network while ensuring that the outside traffic gets blocked by using the firewall services from the tool, as it helps to create a secure network inside our company. Without the tool in our organization, our network would have been compromised. The aforementioned area consists of details related to how the tool helps with the workload protection aspect.
I recommend the solution to others who plan to use it since it helps in areas where it helps block a particular website with the help of the firewall functionalities that it possesses. The tool also helps block outside traffic, and it is mandatory to implement a firewall as an organization grows for the smooth operations of business.
I rate the tool a ten out of ten.