FortiGate Next-Generation Firewall (ARM64/Graviton)
Fortinet Inc. | 7.6.3Linux/Unix, Other 7.6.3 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
A reasonably priced product that can be used by small, medium, and enterprise-sized businesses
What is our primary use case?
What is most valuable?
FortiGate Next Generation Firewall can be described as the most complete solution.
What needs improvement?
When considering the policy of the vendors, they do not offer much of a discount policy, making the licensing model an area that needs improvement.
For how long have I used the solution?
I have experience with FortiGate Next Generation Firewall for many years. My company is a reseller of the solution.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
I recommend FortiGate Next Generation Firewall for small, medium, and enterprise-sized companies.
It is a scalable solution since Fortinet offers many other products.
How are customer service and support?
My customers are satisfied with the technical support provided by Fortinet.
What's my experience with pricing, setup cost, and licensing?
In my opinion, the pricing of the product is reasonable.
What other advice do I have?
FortiGate Next Generation Firewall is a good product.
I rate the overall product between eight to ten out of ten.
A brilliant next-generation device with an SD-WAN that facilitates remote access
What is most valuable?
The most valuable feature of FortiGate Next Generation Firewall is its SD-WAN. The way it has been structured makes life easier. We have used it for remote access, especially at the height of COVID. It works very well.
What needs improvement?
There are times when we would want to set an IP address on a physical interface and then attach secondary IPs or sub-interfaces on that. I'd like to have as many as possible. There's a limitation wherein you can only have about 30 virtual or secondary IPs on a particular interface. I would like that to be expanded to 254 or 256 secondary IPs.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall (NGFW) for five years.
What do I think about the stability of the solution?
I rate FortiGate Next Generation Firewall ten out of ten for stability.
What do I think about the scalability of the solution?
The good part of the solution is that you can have Virtual Domains (VDOMs) that allow you to use it for multiple use cases. Around 20,000 users are using FortiGate Next Generation Firewall in our organization.
I rate FortiGate Next Generation Firewall an eight out of ten for scalability.
How are customer service and support?
Whenever I have a problem and have to call their technical support team, I can email them. In the next few minutes, we'll get on a Zoom or Teams call and exchange notes.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup was easy. I rate FortiGate Next Generation Firewall an eight out of ten for the ease of its initial setup.
What about the implementation team?
The solution's deployment does not take long. If everything goes fine, you will complete the initial configuration in an hour and test afterward. The testing phase is where you face issues. If you are migrating from another device to FortiGate, you would want everything that was running previously to run even on the newer one.
Three people were required for the solution's deployment, including an external person, myself, and a colleague.
What's my experience with pricing, setup cost, and licensing?
I rate FortiGate Next Generation Firewall a five out of ten for pricing.
Which other solutions did I evaluate?
I learned from some reviews that FortiGate ranks quite highly compared to Palo Alto and Check Point. Considering our budget, we thought we could manage with FortiGate Next Generation Firewall.
What other advice do I have?
I would strongly recommend FortiGate Next Generation Firewall to others because it's a brilliant next-generation device.
Overall, I rate FortiGate Next Generation Firewall a nine out of ten.
Which deployment model are you using for this solution?
A highly scalable product with an amazing support team and a user-friendly interface
What is our primary use case?
We use the solution for multiple firewalls like edge and data center firewalls.
What is most valuable?
The solution’s interface is pretty user-friendly. It's easy to come up with policies and basic configurations. It is pretty straightforward.
What needs improvement?
Once in a few months, there is a vulnerability in the OS. The product has to be upgraded every few weeks.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
I rate the stability an eight out of ten.
What do I think about the scalability of the solution?
Our customers range from small to medium businesses. I rate the tool’s scalability a ten out of ten.
How are customer service and support?
Support is amazing.
How would you rate customer service and support?
Positive
How was the initial setup?
I rate the ease of setup a nine and a half out of ten.
What about the implementation team?
On average, deployment takes two or three days. Usually, a person from the customer’s side and I deploy the solution.
What other advice do I have?
The product is a good choice. It will not be a headache for the IT team. It is very common on the market. Overall, I rate the solution an eight out of ten.
The solution helped improve our security through its encryption and integrated security features
What is our primary use case?
I use FortiGate Next Generation Firewall for network protection using its DMZ network.
How has it helped my organization?
The solution has helped our network security.
What is most valuable?
There are multiple features I have found to be valuable, such as encryption and integrated security features.
What needs improvement?
The management consoles can be improved. I have used them before, and they are not so good.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall for over two years.
What do I think about the stability of the solution?
I would rate the solution eight out of ten points for stability.
What do I think about the scalability of the solution?
I rate the solution eight out of ten points for scalability. Over 200 people use it, some of whom are in IT.
Which solution did I use previously and why did I switch?
I used Palo Alto more than a year ago at my previous job.
How was the initial setup?
The initial setup was easy, I rate it a nine out of ten. Deployment took several days, involving one or two people. The steps involved in the process are design, configuration and implementation, testing and implementation, and also some fine-tuning.
What's my experience with pricing, setup cost, and licensing?
I would rate pricing to be about four or five out of ten, it is reasonable.
What other advice do I have?
I recommend this solution because the price is reasonable and the performance is quite good. Overall I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
A feature-rich solution that offers application blocking, web protection, and IPS, with a need to improve its support and pricing
What is our primary use case?
The main use case of FortiGate Next Generation Firewall (NGFW) is that it is used to search for a firewall whenever we need to connect multiple sites to a VPN. At times, the solution needs a web filter or a particular filter. With the IPS and the cloud protection on the gateway, we are also looking for a firewall that can act as zero-depth protection.
What is most valuable?
The solution's most important feature is that it will work on the app whenever we block the application order, making it a plus point for the NGFW firewall. The solution also works with all the other web protection aspects, because of which we get everything in a single box.
What needs improvement?
There are multiple firewalls, and I mainly worked with Sophos and FortiGate. To weigh the pros and cons, different types and aspects should be considered in different firewalls.
The support for FortiGate in the Indian region can be improved along with the scalability. The pricing of the solution is expensive, so it could be cheaper.
For how long have I used the solution?
I have worked as a system integrator with FortiGate Next Generation Firewall (NGFW) for five years.
What do I think about the scalability of the solution?
We can say that the solution's scalability is moderate. It is not that easy, nor too hard. If the technician is sound, then he can understand the solution easily.
Our customers include small, medium, and enterprise businesses.
How are customer service and support?
In India, support takes some time. If the call gets connected outside India, then it is very good. SonicWall has the best support, and Sophos also offers good support. For FortiGate, the support in the Indian region can be improved.
As for the rating, I would say that FortiGate offers very good support. Once we get the support, it is very good. However, the support team is not connecting as easily as we require. If the issue is too critical, the process becomes more complicated for us. I rate the support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I mainly worked with Sophos and FortiGate. I have used different solutions depending on the customer's requirements. We can suggest a particular solution to a customer based on their needs. Every firewall solution has its own pros and cons, which we just bifurcate as per the customer's requirement.
How was the initial setup?
The initial setup is easy if I am going to talk about Sophos' and FortiGate's installation. It is easy to install. There is not much complexity involved.
As for deployment, it depends on the customer's requirements. But the average time is 3 to 4 hours. At times, deployment takes 12 to 13 hours, but it depends on the model and the configuration.
It takes two engineers to deploy the product. One of them is the deployment engineer, and one is an architect.
The solution is deployed on-premises.
What's my experience with pricing, setup cost, and licensing?
The solution is more expensive than Sophos. It could be cheaper. The licensing is on a yearly basis. We have had it for about three years. We must only pay extra for the license, additional requirements, and the hardware box.
What other advice do I have?
I am fine with the solution's interface. The solution is easy to use. FortiGate Next Generation Firewall (NGFW) is a base product, and anyone can use it. I recommend it to those planning to use it.
There is not much maintenance for FortiGate Next Generation Firewall (NGFW). OEM provides the support. Whenever it becomes complicated or any issues come up, we can call OEM directly, and they are always available to help.
Overall, I would rate it ten out of ten.
Which deployment model are you using for this solution?
A simple firewall solution that helps to protect networks
What is our primary use case?
FortiGate NGF is used to protect customer networks.
What is most valuable?
FortiGate NGF is simple compared to other firewalls. It is easy to use and you don't need any training. Any person with basic firewall knowledge can use it.
What needs improvement?
The solution needs to integrate VPN features.
For how long have I used the solution?
I have been working with the product for two years.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
FortiGate NGF is scalable. The number of users depends on the project and can be around three users.
How are customer service and support?
FortiGate NGF's support responds fast.
Which solution did I use previously and why did I switch?
I use Palo Alto and Check Point as well.
How was the initial setup?
The tool's setup is easy. We used one resource to handle the deployment. The tool's deployment can take around one to two days to complete and depends on customer requirements.
What other advice do I have?
I would rate the product a nine out of ten.
Which deployment model are you using for this solution?
A high performing Solution with a valuable GUI configuration feature
What is our primary use case?
The solution is being used as a firewall.
What is most valuable?
The GUI configuration is its most valuable feature.
What needs improvement?
The licensing model and pricing need improvement.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall for the last four years.
What do I think about the stability of the solution?
FortiGate Next Generation Firewall is a stable solution. I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Fifty users are using the solution. I rate the scalability a ten out of ten.
How are customer service and support?
The technical support team is good, but we haven't reached out to them on our own.
How was the initial setup?
FortiGate's initial setup is easy. The solution's deployment depends on the projects and the way clients use it. It takes approximately five days to deploy the solution. I rate the setup an eight out of ten.
What's my experience with pricing, setup cost, and licensing?
It is an expensive solution.
What other advice do I have?
I rate the overall solution a nine out of ten.
Which deployment model are you using for this solution?
A tool that is easy to use and implement, which can be useful for routing and reporting purposes
What is our primary use case?
The use cases of the solution depend on what the customer wants from the tool. If a customer is looking for a core firewall, I provide them with FortiGate Next Generation Firewall (NGFW). Suppose a customer is looking for a tool from a patch connectivity perspective with multiple branches and wants those branches to be connected to the data center. In that case, we can suggest FortiGate Next Generation Firewall's features to them.
What is most valuable?
Routing and reporting are two areas where the product has an added advantage compared to any other product.
What needs improvement?
Vulnerabilities owing to viruses in the OS need to be reduced in FortiGate Next Generation Firewall from an improvement perspective.
Some vulnerabilities get added to the system every two months, which may be code execution or backend and backdoor issues.
In the future, the product should be able to tackle vulnerabilities. Research and development to increase the product's security capabilities is needed.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall for a year now. My company has a partnership with Fortinet.
What do I think about the stability of the solution?
From a stability perspective considering OS and if the vulnerabilities are present, I rate the stability a seven out of ten since it creates a lot of issues in general.
What do I think about the scalability of the solution?
We suggest FortiGate Next Generation Firewall to small and medium businesses.
When it comes to enterprise-level businesses, and considering the need for two-layer security, consider a perimeter firewall, while I can suggest FortiGate only at a level of a core firewall. Suppose an enterprise customer has multiple branches and more branch networks. In that case, they need SD-WAN connectivity with security, for which I suggest they go for FortiGate's SD-WAN feature.
In general, it will not be enough for enterprise companies to have only Next Generation Firewall alone.
How are customer service and support?
I am not familiar with the technical support team because my support team works with them. The solution's technical support is good. We do not face many issues when dealing with the solution's technical support team.
Which solution did I use previously and why did I switch?
Previously, we were using Check Point in our company.
Compared to Check Point, FortiGate Next Generation Firewall needs to look at how to improve the way it deals with the vulnerabilities which are not there at Check Point and the security effectiveness provided by Check Point.
How was the initial setup?
It is easy to use and implement since anyone can do its configuration part, but there is some requirement for someone with proper technical skills to implement it properly. I can implement anything in any way, but that doesn't mean I can implement any product properly. The implementation requires certain technical expertise.
The implementation of the solution can take two days.
One person is required for the implementation phase.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is competitive.
What other advice do I have?
The usefulness of the product is an aspect that depends on the customers using the tool. We cannot even compare two products and say one is good for the customer and the other is bad. If a customer asks me to be an architect for their data center, I would say that for a perimeter firewall, they need to go for Check Point. Coming to a core firewall, if a customer says that they need two layers of security and two different vendors, it should be Check Point on the perimeter level. At the core level, a customer can go for Fortinet. Certain customers prefer the SD-WAN feature from Fortinet if they have branch firewalls and want an SD-WAN feature too. FortiGate has an added advantage because they have an SD-WAN feature with security that we can provide to their branch devices.
I don't have any suggestions for those planning to use the solution since we are pretty new to the solution, and we need to devote time to be able to comment on the solution.
I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
With a good design in place, the tool also offers SNAT and DNAT functionalities to its users
What is most valuable?
FortiGate Next Generation Firewall's design is good. Technically, I haven't used many of its features. The primary purpose we use the solution in our organization is for its SNAT and DNAT functionalities. The solution is also used for its vulnerability patching mechanism.
What needs improvement?
The solution's GUI is not very appealing. When using a tool from another vendor, we found the GUI of that tool to be quite appealing. FortiGate Next Generation Firewall uses a very old type of GUI, which is not very appealing. The GUI can be improved.
For how long have I used the solution?
I have been using FortiGate Next Generation Firewall (NGFW) for six months. My company is just a customer of the product.
What do I think about the stability of the solution?
I am very impressed with the product's stability. Stability-wise, I rate the solution an eight and a half out of ten.
What do I think about the scalability of the solution?
Scalability-wise, I rate the solution a six out of ten.
My company has 2,000 users of the product.
How are customer service and support?
I didn't need any support. The support is good. I wouldn't say the support is bad. I rate the support a seven and a half out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
My company seeks the help of vendors to do the initial setup of the product. After that, we just work on policies, SNAT, DNAT, and virtual IPs.
The setup phase was neither difficult nor easy. I rate the setup phase as three or four out of ten on a scale where one is difficult, and ten is easy.
The solution is deployed on-premises.
The solution's deployment took two to three weeks.
Two people were required for the deployment of the product.
What about the implementation team?
The solution's vendor executed the setup phase.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is quite high when compared to other vendors. I rate the pricing an eight and a half on a scale of one to ten, where one is low, and ten is high.
What other advice do I have?
I highly recommend the solution to those planning to use it.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
It is a scalable solution that offers stellar out-of-the-box management
What is our primary use case?
I work for an integrator in Nigeria, and we implement all these solutions for our clients. I've done a lot of deployments on Fortinet, deploying all from FortiAP to FortiSwitch. I integrated it with FortiGate, FortiManager, SD-WAN, deployment, security, and the like.
What is most valuable?
I found the upgrades valuable. Normally, when you want to upgrade an enterprise firewall, the customer always requests a box swap, whereby we look at the new firmware and compare it to know if there will be any configuration changes. These are the parts where we have to bring in the OEM to do it. But with the new FortiGate firmware, it helps do that by providing reporting and helps you to give the customer the comfort of saying you can upgrade the firewall and describe what changes and issues you would expect. Basically, out-of-the-box management.
What needs improvement?
One area for improvement is the IPS engine, which is something that needs to be improved on. I've had so many issues whereby I have high CPU usage, and when I check, I see it's being consumed by the IPS engine. I have to upgrade the IPS engine firmware and all that. That has been the main pain point with FortiGate. Likewise, customer support could improve.
For how long have I used the solution?
I've been working on FortiGate for about five years now, and I'm working with the latest version.
What do I think about the stability of the solution?
The solution is stable apart from the IPS engine issue, so I rate stability a seven out of ten. Stability depends on the operational team. If you have a good operational team that knows what you are doing, you always gain stability with most of your solutions. But if you have an operational team that is not so strong, you will always have issues with that solution because they will keep making human errors that will keep disrupting the services you offer. For example, in 2021, I was working as the cyber delivery manager for MTN, and I was managing the FortiGate infrastructure. In that one year, I never had any incident on FortiGate. But after I left, they started having frequent issues because of human errors. From a management perspective, if I were the CTO during that period, I would assume that FortiGate Firewall is not a good firewall. But that is not the case. It is the person who handles it that determines the stability. If you know how to do your health check properly and how to output the firewall properly, I'm sure FortiGate will be stable. I'm rating the stability as seven just to be in the middle. If it's being handled by a less experienced operational team, I'm sure you will have issues because they always perform changes, they don't know when to perform the kind of change they are performing, and that might disrupt the services. But if I rate FortiGate based on myself, I give it a nine out of ten.
What do I think about the scalability of the solution?
I rate FortiGate's scalability a nine out of ten. Out of every ten enterprises in Africa, six currently use FortiGate. MTN is one of our major customers, and we helped them migrate from Cisco and Juniper to FortiGate.
How was the initial setup?
The ease with the initial setup depends on the deployment. I've deployed FortiGate for different use cases. I've deployed it using internal segmentation. I've deployed it using it as a data center firewall, doing east and west. I've deployed FortiGate on the perimeter edge, whereby we have the SSL VPN and site-to-site VPN. But overall, I rate the initial setup an eight out of ten because it's always been very easy.
There are timelines with projects, so the time taken to deploy the solution depends on the scale of the project. If it's just a perimeter firewall where I have to migrate from one firewall, like the Cisco firewall, to the Fortinet firewall, it takes me nothing less than a week. It takes a day using the FortiConverter to convert the configuration from Cisco to Fortinet and maybe another two days to look at the configuration properly on my FortiGate before I'm confident enough to tell the customer to schedule maintenance for us to migrate the services. It depends on the customer, so in a nutshell, from kickoff to the close date is not always an exact amount, but generally no more than a month.
The deployment time taken depends on the customer's availability and their response because it's not totally dependent on me being the technical engineer. It depends on how fast they provide me with all the information I need to complete the deployments and determines how fast I can close the project. If the customer is very responsive, it takes us about three weeks to close the project.
What's my experience with pricing, setup cost, and licensing?
FortiGate is much cheaper than other OEMs such as Cisco, Palo Alto, and Check Point. I'll rate FortiGate's pricing a five out of ten since it is moderately priced.
What other advice do I have?
Currently, we are pushing all our clients to adopt the Fortinet cloud firewall instead of using the native solutions found on the different cloud environments they use, like Azure and Google, because they are not really effective.
FortiGate is a very good firewall that has a lot of features, and it's a firewall that gives the same stability as enterprise ones, and it gives you scalability in terms of deployment and operational management. I rate FortiGate NGFW a nine out of ten.