A use case for Fortinet FortiGate includes connecting nine to ten different sites to the main Fortinet FortiGate firewall and diversifying the traffic with two-way traffic. It functions as a load balancer to balance loads between different sites.
FortiGate Next-Generation Firewall (ARM64/Graviton)
Fortinet Inc.External reviews
External reviews are not included in the AWS star rating for the product.
Works very well for Indian market because of the economic value, scalability, and different sizing options
What is our primary use case?
How has it helped my organization?
The main benefits of Fortinet FortiGate, especially in India, are its economic value, scalability, and different sizing options. When compared to Cisco or Juniper, upgrading to a higher class involves a substantial cost increase, whereas with Fortinet FortiGate, the next class is only marginally higher.
What is most valuable?
The best feature of Fortinet FortiGate is SD-WAN. It ensures continuous connectivity by taking over during link failures, preventing any downtime for the company. One of my clients faced many problems with the primary internet provider and requested multi-path functionality. We implemented the SD-WAN facility and added another three-link WAN link, converting the normal port into SD-WAN and assigning weightage. When there is no response from the primary connection after a certain number of milliseconds, it switches to the secondary and then to the tertiary connection. The impact on network performance with the SD-WAN is very good, provided it is sized properly based on throughput. It is necessary to calculate how much data is transferring daily or per minute, then size the firewall accordingly and select a particular model.
The Fortinet FortiGate solution offers ease of use, not requiring highly skilled workers. General users with two or three experienced team members can read the manual and implement the needed configurations.
Hardware-assisted DDoS protection in Fortinet FortiGate is very easy to implement with single-click options, though care must be taken not to burden bandwidth. Certain ACL units should be used, applying rules only to interesting or exposed traffic.
What needs improvement?
Some features in Fortinet FortiGate need improvement as we discover when calling support that certain actions must be done from the command line. Not all features are available in the web UI. Features such as enabling multiple MPLS circuits can only be accomplished through the command line, so these need to be made available in the web UI.
Fortinet needs to improve customer support and documentation.
For how long have I used the solution?
I have been working with Fortinet FortiGate for more than 15 years.
What do I think about the stability of the solution?
Fortinet FortiGate is very stable, but the person procuring the firewall needs to ensure it is sized properly. If the sizing is not proper, it will create many problems.
What do I think about the scalability of the solution?
The scalability of Fortinet FortiGate is very good. It has improved significantly compared to five years ago when it was not as scalable.
How are customer service and support?
When we encounter struggles, they perform actions from the backend, taking control and resolving issues. This becomes a black box for us because we do not know what actions they took.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup of Fortinet FortiGate is straightforward and easy. HA is the deployment model we always recommend.
What was our ROI?
While we have not calculated it specifically, we found the ROI to be good, approximately 97% to 98%.
What other advice do I have?
I utilize the Fortinet FortiGate hardware and have never tried the VM version, working only with normal VPN configuration, user configuration, normal routing, and multiple WAN links. While we are using the dynamic segmentation feature, we have not tested it thoroughly enough to analyze its benefits.
People generally go with the recommendations of high-level architects. For core networks, they typically suggest Cisco or Juniper. In India, the market follows whatever the chief architect suggests without quantifying whether it is worth it.
My advice for others considering Fortinet FortiGate implementation is to focus on its ease of use.
Based on my experience, I would rate this solution an eight out of ten.
A stable solution with an intuitive interface and quick customer service
What is our primary use case?
We are IT MSPs, and we provide solutions for clients based on their requirements and expectations.
We are a Fortinet FortiGate partner, reselling products such as FortiGate 100F, 60F, and 70F. We are currently exploring newer versions including 70G, 90G, and 120G. I have also worked with Fortinet FortiGate F200. The UI is similar across all these firewalls, with differences mainly in capacity limitations.
What is most valuable?
The best features of Fortinet FortiGate include its easy configuration and user interface.
Its firmware is very stable, which is a significant advantage. I have experienced many challenges while configuring Sophos during firmware upgradation, where changes occur and certain features stop working, requiring reconfiguration. However, Fortinet FortiGate has a very stable Linux-based operating system that is easy to use.
What needs improvement?
One drawback of Fortinet FortiGate is that they provide two types of models: one with a hard disk and another without. The model without a hard disk has very low ROM where you can store very few logs, after which you need to upload it to the cloud or purchase a firewall with SSD. That's the only drawback.
For how long have I used the solution?
I have been working with Fortinet FortiGate for the last 4 to 5 years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
Fortinet FortiGate is highly scalable because it is easy to allocate resources. It is very flexible, especially when using a VM base, as you can easily increase any configuration you want to upgrade. Scalability is now a common feature in all firewalls.
How are customer service and support?
I have had positive experiences with both Sophos and Fortinet as service providers. When we face any issues with firmware or other things, we can directly approach them for assistance.
As a solution provider, when I encounter problems, I connect directly with Fortinet support, and they provide solutions within a very short time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have been working with Fortinet FortiGate, WatchGuard, Sophos, and SonicWall. I'm not as comfortable with SonicWall because of their UI and limitations.
I prefer Fortinet above all other options. When it comes to configuration, I am confident in my ability to handle various tasks, including creating policies such as firewall rules, web policies, and application policies. Additionally, I can configure VPNs and implement load balancing, among other tasks. Overall, I feel much more comfortable working with Fortinet.
Fortinet has made significant improvements by integrating AI with firewalls for threat analysis and prevention. In the past 2-3 years, they have launched FortiSASE and SIEM, and they also provide SOC services. Both Palo Alto and Fortinet FortiGate are excellent. While Fortinet FortiGate comes at higher prices, the functionality and support justify the cost. They promptly resolve firmware issues and inform all support providers about configuration changes.
How was the initial setup?
The initial setup of Fortinet FortiGate is straightforward. It involves step-by-step configuration, setting up rules, configuring network interfaces, WAN, LAN, and creating basic rules.
Most of our clients are using on-premises firewalls. If they have a private cloud, they typically establish a site-to-site tunnel. However, in general, they rely heavily on on-premises firewalls.
What was our ROI?
Fortinet FortiGate is a premium product. From a cybersecurity perspective, the ROI typically comes within 1.5 to 2 years. When investing in cybersecurity with Fortinet FortiGate 200, which costs more than $10,000, companies that are growing directly can expect ROI within 1.5 to 3 years. This calculation considers future planning and monthly security spending, including license upgrades every 3 years. This refers to new procurement only, as license upgradation is a separate consideration.
What's my experience with pricing, setup cost, and licensing?
If you are looking for a quality product, it will come at a higher price. Expecting them to be significantly cheaper is unrealistic. In terms of pricing, it is a bit costly. However, the functionality and support offered are worth it.
What other advice do I have?
Regarding SD-WAN capabilities with Fortinet FortiGate, I have configured and merged WAN lines. There are two options: round-robin and session-based, and I typically prefer the session-based connection. With Fortinet Unified SASE, for multiple locations, we configure site-to-site tunnels where all data transmits directly to the Central Office.
I would rate Fortinet FortiGate a nine out of ten because AI is still in development and constantly evolving. Nothing is perfect, which is why I chose that rating. There is definitely room for improvement.
Cost-efficient, straightforward to use, and easy to deploy
What is our primary use case?
The use case for Fortinet FortiGate primarily refers to firewall functionality.
What is most valuable?
The best features of Fortinet FortiGate include the simple user interface. The GUI is in English with intuitive navigation. It is very easy to find solutions, meaning it is simple to locate what we need and which settings we need to modify through the GUI.
We have integrated FortiGate SD-WAN. It's working pretty well.
What needs improvement?
Areas that have room for improvement in Fortinet FortiGate include support and GUI enhancement. While the GUI is already simple, further improvements would greatly benefit them.
For how long have I used the solution?
I have been working with Fortinet FortiGate for one year in this organization.
What do I think about the stability of the solution?
I would rate the stability of Fortinet FortiGate as eight out of ten, as it has proven to be reliable.
What do I think about the scalability of the solution?
Fortinet FortiGate is scalable. We primarily deal with small and medium businesses, and for our clients in this segment, it works effectively.
How are customer service and support?
The technical support that Fortinet provides is not satisfactory. When we call Fortinet technical support, it takes too much time to connect with them. The process is complicated, requiring us to hold for many minutes, and when we visit clients, we are not satisfied with their technical support.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We work with five firewall vendors, including Fortinet, Cisco, Palo Alto, SonicWall, and Sophos. We have specialists for their products.
We first recommend Fortinet FortiGate or Palo Alto. If a customer cannot afford Palo Alto, we recommend Fortinet FortiGate. If they cannot afford Fortinet FortiGate, we recommend Sophos or SonicWall.
When comparing security policies, Palo Alto is superior to Fortinet FortiGate, but Fortinet FortiGate is adequate. For businesses with higher requirements, we recommend Palo Alto due to its advanced security features, while for small and medium businesses, we suggest firewalls based on their specific requirements.
How was the initial setup?
Deployment of Fortinet FortiGate is straightforward. If the customer requires, we can configure it from our end and deploy it directly.
Our clients are small and medium-sized businesses. They can't afford the cloud. They take the device and install it on-premises.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiGate is cost-efficient. Palo Alto is expensive, but Fortinet FortiGate is not.
What other advice do I have?
I would recommend Fortinet FortiGate because the GUI is understandable for English speakers, and the configuration is straightforward.
I would rate Fortinet FortiGate an eight out of ten.
Cost-effective and flexible with good integration capabilities
What is our primary use case?
We have configured it in our data center.
What is most valuable?
The best feature of Fortinet FortiGate is the IPS or IDS implementation. I appreciate most the agility or the flexibility to create hashes to block incoming threats, and I can integrate with third-party threat intelligence with our FortiGate.
SD-WAN is another beneficial feature of Fortinet FortiGate. It offers flexibility in terms of adding multiple network connectivity and building your own network. It's the replacement for traditional VPN solutions. With SD-WAN, I can connect my remote office quickly and add additional or multiple network connectivity to provide redundancy on my network. This is the simple part of that.
The effectiveness of Fortinet unified SASE in providing consistent security policies across multiple locations is very good. In FortiSASE, they have integration with FortiGate. As a network security individual in a company, you can provide a single view of policy, monitor them, audit them, or in one screen, you can see the activity of your users, the behavior of your users, and in contrast, you can see the possibility of tracing the users whenever they have some threats.
What needs improvement?
Whenever I perform a firmware upgrade or any upgrade on a VM, there are instances where the routing gets lost in the configuration itself on the running VM.
They have recently acquired a CNAP solution which should be integrated into FortiGate boxes natively for protection at any application layer. Since Fortinet FortiGate has Layer 7 protection, they should integrate that as soon as they can for threat detection and network detection. At the moment, if you don't integrate any third-party solution with a simple Fortinet FortiGate box, the box would not function as expected for superb protection. Compared to others, Palo Alto has more integration.
I'm waiting for Fortinet FortiGate to be more mature in terms of integrating AI. They already have AI automation in the configuration, but that's just the configuration. They need to address AI in threat intelligence and how they integrate with threat intelligence sources to protect customers using their Fortinet FortiGate boxes or Fortinet FortiGate VM instances.
For how long have I used the solution?
I have been working with Fortinet FortiGate for more than six years.
What do I think about the stability of the solution?
Whenever I perform a firmware upgrade or any upgrade on a VM FortiGate, there are instances where the routing gets lost in the configuration itself on the running VM. Whenever we do any upgrade or patch, we ensure we have a latest backup, and then validate every single configuration whenever we finish the upgrade or deploy the patch. This ensures there are no concerns in terms of connectivity or services that get impacted after the upgrade.
What do I think about the scalability of the solution?
This is not a criticism of FortiGate; it reflects my experience deploying several FortiGate instances across different public clouds such as AWS, OCI, Azure, and GCP. My main concern with FortiGate in OCI is its lack of support for features like auto-scaling. When you need additional CPU or bandwidth, it doesn't automatically provision those resources. Currently, in OCI, if you want to scale your FortiGate deployment, you have to shut down the instance and rebuild the virtual machine to accommodate increased capacity. For instance, when you purchase a VM instance, it may come with only four CPUs and a limited bandwidth of four Mbps. In scenarios where you need to scale up quickly, this can be a significant drawback compared to what can be achieved with Azure, AWS, and GCP.
However, I've deployed FortiGate on physical appliances in data centers in the past without any issues, as long as proper planning is done regarding the capacity of your firewall requirements. For example, if you need ten gigabits per second throughput, you should change the module and connect a ten-gig interface to the switch. The key lies in anticipating your design from the ground up, taking into account the growth in the number of users and the increase in the services you provide to your customers. This is my primary concern.
How are customer service and support?
Their support is very good. They respond quickly through their hotline number with an active subscription.
I would rate the support from Fortinet FortiGate as a nine out of ten. Sometimes if I don't escalate to our account manager, it will take the next business day for the interaction.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Cisco ASA firewall but didn't find it to be as straightforward as Fortinet FortiGate.
How was the initial setup?
The initial setup for Fortinet FortiGate is very straightforward. As long as you have the foundation of networking and understand the east-west and north-south firewall terminology, it's quick and easy.
The deployment would take a maximum of 30 minutes for edge layer protection and end-user protection. After that, you can enrich or enhance the policy, IPS, IDS tweaking, the built-in DDoS or UDP flooding integration.
What about the implementation team?
I performed the deployment of Fortinet FortiGate myself, and it was very easy.
What was our ROI?
I appreciate how Fortinet FortiGate, particularly in Saudi Arabia, is not as expensive compared to other competitors. The investment value is good, and technically, the value invested is worthwhile. It's a very useful tool to mitigate and protect your enterprise. I cannot speak to the financial analysis as I'm not involved in finance.
What's my experience with pricing, setup cost, and licensing?
It is cheaper and more competitive compared to other options. For example, when comparing Palo Alto products to others, Palo Alto tends to be more expensive. If you compare Cisco's platform, including Cisco Meraki, with Fortinet products, you'll notice that Cisco's offerings are generally higher priced than Fortinet's firewall solutions.
Which other solutions did I evaluate?
Before working with Fortinet FortiGate, I evaluated other firewalls such as the open-source firewall pfSense. pfSense is suitable only for small startup companies that need more financial consideration. However, in the long run, it's difficult to maintain and support without a subscription.
I also evaluated Sophos UTM, which was acquired by Sophos from Vyatta Networks, which began as open source but was later locked down for commercial purposes.
The biggest benefit of Fortinet FortiGate among other firewalls is the community. Many adopters and companies globally are already using FortiGates. Everyone in the community is sharing, and their support is very good.
What other advice do I have?
I can recommend Fortinet FortiGate. It's a very stable next-generation firewall where the majority of the firewall features and services are in one box.
My total rating for Fortinet FortiGate is nine out of ten because there are still some missing pieces that need to be integrated with the box itself.
Powerful and offers many security features in a single box
What is our primary use case?
The main use case for Fortinet FortiGate is as a perimeter firewall between the internet and the LAN to protect the networks from the internet.
We are using Fortinet FortiGate in the education industry.
What is most valuable?
One of the best features of Fortinet FortiGate is that it's a very powerful equipment that gives many security features in a single box with good performance, and the user interface is friendly to use and configure. The performance is good compared to other vendors that I have used, and the price is competitive.
I am utilizing Fortinet FortiGate's SD-WAN, and my experience in integrating the SD-WAN capabilities with Fortinet FortiGate in my network has been good. It was easy to integrate the SD-WAN capabilities with Fortinet FortiGate, and from my experience and background, it was easier with Fortinet FortiGate compared to other vendors. The monitoring after installing the SD-WAN is also easier. It is easy to see how it behaves and how the traffic goes through the different links. It's improving our performance with SD-WAN.
What needs improvement?
If you want to conduct some statistics or generate a report to understand the status of your configuration or filtering, you need FortiGate Analyzer for long-term data retention. FortiGate can only retain logs for 24 hours or 7 days. I'm not sure if it holds them for a longer period, such as for a month. It will be useful for assessing our strategy and monitoring our environment without investing in FortiGate Analyzer. It would be beneficial if Fortinet could enhance the FortiGate by providing more statistical and monitoring views for a longer timeframe, rather than requiring access to FortiGate Analyzer. Without Fortinet Analyzer, currently, I cannot see past events.
For how long have I used the solution?
I have had more than 10 years of experience with Fortinet FortiGate.
What do I think about the stability of the solution?
Fortinet FortiGate is very stable, and I have never seen a Fortinet FortiGate get stuck because of performance or memory issues. They have good hardware and ASICs, and I have not experienced any performance issues with all the features I have implemented in it.
What do I think about the scalability of the solution?
Fortinet FortiGate scales effectively, and even though I can't recall a specific use case regarding scalability, I am sure it is very scalable.
How are customer service and support?
Their support is very good. I would rate them a nine out of ten. When I open a case or provide feedback, they are very responsive. If I don’t get the answer I need, I can call them directly, which also deserves a nine.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and easy.
The duration depends on the size of the installation and the features you want to implement. It can take anywhere from one day to several days. In our case, we had to install it across all our campuses. We have 12 campuses with FortiGate devices installed at the central location. The main setup took about two to three days at the main site. After that, I prepared the templates for the other sites, which took about half a day to install once they were ready. Overall, if you are trained and familiar with the FortiGate environment, it can be quite straightforward. If you're not familiar, it may take some time to read and prepare everything; however, it’s not particularly difficult.
What about the implementation team?
Typically, we have a variety of roles in our environment, so I deal with multiple tasks. We need someone who understands the network, so I also function as a network engineer. It requires knowledge of both networking and security, hence network security.
What was our ROI?
It reduces the cost of operations by automating many tasks that I would do manually. It also helps to be proactive by detecting things and proposing features to improve the security posture. In that regard, I have seen a return on investment because it reduces the cost of operations. It saves about 20% of time per month.
What's my experience with pricing, setup cost, and licensing?
The pricing is comprehensive and clear. You can easily understand what you are purchasing, including which features correspond to each license and maintenance contract. Overall, the information is straightforward. Additionally, compared to other vendors, their prices are competitive.
What other advice do I have?
I have not yet tested or installed Fortinet unified SASE, but from what I read and my knowledge, it is something that may be good to integrate with existing systems. However, I cannot confirm its effectiveness as I haven't tested it yet. I do not utilize Fortinet FortiGate's data center solution at the moment.
I didn't work with all the FortiGate equipment. Based on the equipment I worked with, I would rate it an eight out of ten. It's very good.
A robust and customizable firewall with constant updates
What is our primary use case?
We use Fortinet FortiGate for gateway security, specifically for VPN access, security control, and filtering of traffic. For net monitoring, it has the capability to put the network traffic over to the analyzer. We use FortiAnalyzer to look at the traffic and to see what's happening, what's hitting our gateway, and what our users are doing. We use filtering rules on top of that.
What is most valuable?
Fortinet FortiGate is pretty robust. The updates and firmware releases are pretty timely. They have a good product revision and review system, so they are constantly reviewing their configuration and the different mechanisms that are used on Fortinet FortiGate. They review that periodically and provide new definitions and updates. We have quarterly fixes, updates, and releases, and there are constant new CVEs coming out. They are always keeping ahead of the threat monitoring system that notifies us of the latest landscape, what's new in the phishing landscape, botnets, rootkits, and all of those different malicious tools that are out there. We appreciate the filtering capabilities as well.
It integrates well with the SD-WAN capabilities. It works easily, and the transition was quite simple with literally no downtime.
It is very customizable. We have multiple different subnets going into that FortiGate controller. We have used various models and various designs. We can diversify the number of links coming in either the WAN gateways or the local LANs. We can separate various subnets across the LAN segment. It's quite diverse.
What needs improvement?
We haven't tapped into most of the functionalities that Fortinet FortiGate offers because we're using it just for gateway security. One of the things that I would prefer is a more expansive use of their analyzer. They could do more work on FortiAnalyzer in terms of the data and the information coming from it. I'm not sure if it is because the team managing our analyzer isn't giving us all the information that's required. It could be something based on our own usage of the platform. As we continue to use the appliance, we may learn more about the utility and functionalities that are offered.
For how long have I used the solution?
I have been using Fortinet FortiGate for about seven years.
What do I think about the stability of the solution?
Fortinet FortiGate is pretty stable, especially the enterprise version.
The reliability of Fortinet FortiGate is through the roof. We're experiencing 99.999% availability consistently. Fortinet FortiGate only goes offline for maintenance. I have seen it running for two years nonstop without doing a reboot. They're pretty stable and energy-efficient, and I make a lot of headroom for growth, specifying my units at least 40% greater than what I need. They are working within the requirements of their provision, and usually, the published specifications for the units are within the range of their operational usage.
What do I think about the scalability of the solution?
Scalability is all based on our design. Based on our network design, we can select or pick a product from the product listing that can scale with the growth potential of the organization within a specific time period. We tend to do our planning within time spans, such as the next 10 years, 5 years, or whatever the growth prospect is for that period. We put the units in place that can grow along with that growth development timeline.
How are customer service and support?
I would rate Fortinet's support a solid eight because I'm hard on my support. They're responsive to a greater extent. There are lots of things that I want to get done that aren't done on time. However, the local support that we use for Fortinet FortiGate is pretty technically competent and capable of managing the unit and delivering the functionality we need from the device.
How would you rate customer service and support?
Positive
How was the initial setup?
We outsource the management and configuration of Fortinet FortiGate to a third-party SOC center in Ireland. We don't do that ourselves, but we do manage it and go out to the third party to tell them what we want. They will recommend different methodologies, capabilities, or new features that we can implement, such as SD-WAN, and go ahead with it. We don't manage and do the configuration ourselves. My team's role is pretty much just to operate and utilize the service.
They handle the initial setup in the background. I just give them the requirements, and the engineers respond.
What about the implementation team?
We interacted with two engineers, but I'm not sure what the backend team is like.
What was our ROI?
It's very hard to measure return on investment with security because security is so dynamic. Based on our plan, the ROI has been pretty good. Whatever we expected and planned for, as far as usage goes, I can extend and push my Fortinet FortiGate up to maybe three or four quarters past its end of life. It has performed as expected in that concern, giving us good ROI for what we planned.
What's my experience with pricing, setup cost, and licensing?
It was pretty affordable. We did go a little bit above MSRP, but the service pack that was included was quite worth the additional costs.
It is competitively priced compared to other major players in the market. It is significantly cheaper than Check Point, which is a primary competitor. Additionally, its pricing is comparable to that of Cisco's ASA and a few other vendors.
Besides the pricing, we chose Fortinet FortiGate because of the service providers that are here locally and the support for the unit and the product.
What other advice do I have?
I would rate Fortinet FortiGate a nine out of ten.
Ransomware protection enhances security across multiple locations
What is our primary use case?
We are using it for security purposes. We have deployed it across multiple locations where we are already using it.
What is most valuable?
The security features are valuable, particularly the ransomware attack protection features. Fortinet FortiGate provides excellent security against ransomware attacks.
What needs improvement?
It contains every feature that is required. The things we require are already sorted out, so there isn't any scope for improvement as far as our requirements go. However, its price can be better.
For how long have I used the solution?
We have been using it for more than one and a half months.
What do I think about the stability of the solution?
It's stable. I would rate it an eight out of ten for stability.
What do I think about the scalability of the solution?
It's scalable. I would rate it a nine out of ten for scalability.
I am handling all the operations. We have multiple staff members at multiple locations.
How are customer service and support?
Coming from a technical background, there hasn't been any requirement to speak with customer care representatives. The manual provided covers everything comprehensively.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with Sophos, Fortinet FortiGate, and SonicWall.
How was the initial setup?
We purchased it through our vendor. Our company doesn't prefer to make purchases through online shopping platforms such as Amazon and Flipkart.
What was our ROI?
We have seen a return on investment of more than 20%.
What's my experience with pricing, setup cost, and licensing?
It is somewhat expensive compared to other solutions such as Sophos.
What other advice do I have?
I would recommend it to others. I would rate Fortinet FortiGate a nine out of ten. There isn't a need to compare it with anyone else because Fortinet FortiGate is at the top of the market.
A user-friendly firewall with good security features
What is our primary use case?
I was involved in deciding on Fortinet FortiGate, but I am not the one who's using it on a day-to-day basis.
We want to make sure that our on-prem servers are protected. We basically use VPN to configure that on Fortinet FortiGate, so that is the major purpose, and that part is working well.
How has it helped my organization?
We have not had any incidents where our servers got compromised. It's all good.
For security, it has all the required features, such as the web filter and DNS filter. Also, for accessing the network, we have various rules.
What is most valuable?
Our IT staff says that some of the security features are better than Sophos's.
Its usability is good. We can easily navigate the system, and we have a very good user experience. It's easier to understand the software compared to Sophos, which I feel is a little more technical and could be difficult for a first-time user.
What needs improvement?
I want some additional features. For example, I want something to ensure that when we are using Google email or Microsoft email, or Google Workspace, emails can only be accessed on designated machines given to our employees. I would like them to access data from designated machines, not from any machine. It should work for designated mobiles and laptops. I don't know if Fortinet provides something like that out of the box.
For how long have I used the solution?
We have just installed Fortinet FortiGate, and it has been two months since our installation.
What do I think about the stability of the solution?
Fortinet FortiGate is stable.
What do I think about the scalability of the solution?
Fortinet FortiGate is scalable.
How are customer service and support?
We are going through the vendor for technical support. If we have any issues, we raise a ticket, and they respond immediately.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we were using another firewall device, Sophos. Compared to that, Fortinet FortiGate provides more features and better security. Fortinet FortiGate supports WAN migration. Fortinet FortiGate is also better in terms of speed. In the dashboard, we can get all the stats reports and logs.
How was the initial setup?
Deployment is not very difficult because they have their migration tool.
What about the implementation team?
We are facing some challenges. We are working with a third-party vendor, not FortiGate directly, for the installation and other things. The problem is that their knowledge is very limited. We are facing some challenges. With Sophos, we could enable multi-factor authentication for VPN users. FortiGate also allows that, as per our initial analysis. The people we are working with are not able to configure MFA. They are having some technical issues. Fortinet needs to ensure that its partners are well-trained.
Only two people were involved in the deployment process. The vendor side had their own technician, and we had one person here.
What's my experience with pricing, setup cost, and licensing?
Cost-wise, there is not much difference from Sophos, but feature-wise, we get more features.
Which other solutions did I evaluate?
We did some comparisons between Fortinet FortiGate and Sophos. We went with Fortinet FortiGate because of the security features and easy-to-understand console.
What other advice do I have?
I would rate Fortinet FortiGate an eight out of ten.
Integrates seamlessly with the team for quick threat remediation and cost benefits
What is our primary use case?
We use Fortinet FortiGate to help protect and secure mission-critical data. There are policies and rules that we apply, and there is an intrusion prevention system that notifies if there are critical vulnerabilities on some clients.
What is most valuable?
I assess the security services provided by Fortinet FortiGate, such as URL filtering and DNS filtering, as quite good; they are quite effective. Fortinet FortiGate is rather sustainable; it's a good, stable product that gets faster and uses less power with new versions.
It helps us remediate threats more quickly because we have specialists who can work with it rather effectively. When there is an alert on the Fortinet FortiGate, they work together with our FortiAnalyzer and can quickly remediate the incidents.
What needs improvement?
They should do a better job in testing when they put out a new release because when a new software version is released, it is not always stable or does not always have all the previous features working correctly. They should do more testing or launch a new version later when they have tested it more thoroughly.
They already did a good job in their GUI, but they can make more features available in the GUI that are still only accessible through the command line.
For how long have I used the solution?
My proper experience is only two or three years, but in the company, they have been using it for over 10 years.
What do I think about the stability of the solution?
In terms of network and security convergence, they are there, but we are not currently using them because in the office itself, we have other brands of switches and access points. It's now not quite stable in the demo lab environment; we are now on the latest version, but in the production environment, we are not. Production is always on a lower version.
What do I think about the scalability of the solution?
It is scalable.
How are customer service and support?
I would give Fortinet's technical support an eight out of 10; they are responsive and helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Sophos before Fortinet FortiGate.
How was the initial setup?
If you first implement Fortinet FortiGate to get it up and running, it takes just a couple of minutes, but to get all the policies configured correctly, it takes a couple of days.
What about the implementation team?
For my company, Exclusive Networks, the whole company had three or four engineers involved.
What was our ROI?
We have seen a return on investment from using Fortinet FortiGate for integration with the SOC team. The automation part is giving us a cost benefit and speed; we can react faster.
What's my experience with pricing, setup cost, and licensing?
The price-to-performance ratio from using Fortinet FortiGate is very good; I would give it a nine out of 10. It has helped save on costs due to reduced power consumption.
Which other solutions did I evaluate?
Performance is the reason I switched from Sophos to Fortinet FortiGate. It has good value for money, ease of use, and a higher security level, with better security solutions. It's more expensive, but it offers a really good total cost of ownership and is still considerably cheaper than Palo Alto.
What other advice do I have?
I would suggest to anyone considering purchasing Fortinet FortiGate's data center firewall to get training to understand very thoroughly how FortiOS works, and if you have several Fortinet FortiGates, to go for a FortiManager with the necessary training.
The users who work with Fortinet FortiGate are only the IT people, around three or four. Locally, we have around 60 end-users for Fortinet FortiGate. The biggest lesson would be that Fortinet FortiGate provides a high level of security at a good total cost of ownership.
I would give Fortinet FortiGate an overall rating of nine.
Offers good SD-WAN capabilities and integrates easily with Fortinet devices
What is our primary use case?
I use Fortinet FortiGate for SD-WAN, specifically for branches, and for firewall purposes.
Fortinet FortiGate is sold to everyone, including banks, mining companies, and oil companies, as it's one of the most popular SD-WAN products that we sell. These are mainly medium-sized businesses or enterprise businesses because we only sell business-to-business, B2B, and we don't sell to normal clients, only businesses.
How has it helped my organization?
We usually do not have any problems. It's a very easy-to-use product. We also have a SOC or service operations center. They are certified in Fortinet FortiGate.
From the point of view of a reseller, Fortinet FortiGate improves our business because it is one of the products that we sell the most. We also use it on our backend because the devices have many slots and support substantial bandwidth.
What is most valuable?
The most valuable features of Fortinet FortiGate are its SD-WAN capabilities, such as dynamic routing, and other features, including security options such as antivirus, IPS, and IDS—all integrated into one device.
Another beneficial aspect of using Fortinet FortiGate is that if you have a LAN network, you can integrate it with FortiSwitch. You can manage everything from Fortinet FortiGate. It is easy to manage and integrate with other Fortinet devices.
What needs improvement?
Fortinet FortiGate is a very good device overall, though it can be improved in certain areas regarding the licenses, particularly the big one called unified threat management, which has many capabilities. The big license options have web filtering, IDS, and a lot of other things, but it's not like they are all good. That's the only thing I would change because the rest is very good.
For how long have I used the solution?
I have about 4 or 5 years of experience with Fortinet FortiGate.
What do I think about the stability of the solution?
I find Fortinet FortiGate to be quite stable, as I have never heard of any issues where they broke or malfunctioned; they are always working. I would rate the stability of Fortinet FortiGate a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability for Fortinet FortiGate as an eight out of ten
How are customer service and support?
We don't usually use that service. We only engage with Fortinet support when a device is broken and needs RMA, so I am not familiar with their operational teams.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We used to use Cisco firewalls and devices, which are also quite good. However, Cisco is more expensive, approximately twice their prices, but they are similar in functionality. With Fortinet, we are partner experts, which is a big advantage, whereas with Cisco, we are premium partners, which is not the biggest status, so if we are going to resell to our clients, we don't have the best discount or prices.
How was the initial setup?
I am not part of the initial setup or deployment process since I work in presales. The setup or deployment is quite easy, as you can do a one-touch deployment that automatically connects to the FortiManager cloud when you connect it to a broadband or dynamic IP, allowing you to start the configuration from that point.
We usually sell it for on-premises setups. It's on the cloud only when the client has virtual machines or their own service. Sometimes they have a service on the cloud like AWS, but it's more difficult to sell now because AWS has an e-commerce option where you can buy FortiGate directly. The only thing you need is someone to manage and configure.
What about the implementation team?
For deployments at one site, it usually requires only one person, and if we are talking about 1 to 50 sites, it still only takes one person because the same template is used for all sites.
In Argentina, we service about 100 locations. There are about 200 companies in Colombia and Brazil.
What was our ROI?
We service about 100 locations with Fortinet FortiGate in Argentina, but if we account for all the company's clients, it can be around 2,000 across Colombia and Brazil, since we have clients in all of these countries.
What's my experience with pricing, setup cost, and licensing?
Fortinet prices are around $600 for the small 40F model, and for licenses, the simplest option is about $300 for a year. They sell licenses that can last for 1, 2, 3, or 5 years.
Which other solutions did I evaluate?
Before using Fortinet, we evaluated other options such as Versa and Meraki, but Meraki is also from Cisco. Fortinet is better than Versa. One of the main differences between them is that we don't have many partners or distributors for Versa here in Argentina, making it difficult to sell something that you cannot pay for locally. It has been easier in the past to handle payments, but Versa doesn't have many providers or distributors in Latin America, making it a less viable option. Fortinet offers more products that are easier to integrate into our clients' networks, such as firewalls and access points, so that was one of the main reasons we didn't use Versa.
What other advice do I have?
My advice to other businesses or people considering using Fortinet FortiGate is that it is the starting product from Fortinet, and when you start using Fortinet FortiGate, you can then move on to the next products they offer, which are numerous.
We sell the 40F, 60F, 80F, 100F, and 200F models. There are the ones we sell readily from the bottom to the top. Sometimes, we sell bigger ones such as the 300 model.
Overall, I would rate Fortinet FortiGate around a nine out of ten.