What is our primary use case?
The firewall system we have implemented in my company serves as the gateway to access the internet. We have different VLANs set up on the firewall for various networks.
We enforce security measures based on policies. When it comes to security, we have web monitoring, application filtering, and MAC address filtering implemented on the firewall. We also utilize VPN and SD-WAN architecture. Everything is functioning well.
Additionally, we have two ISPs connected for load balancing. We send the logs, and audit logs to FortiCloud for analytics and statistics.
Moreover, we have an alerting system for FortiGate, which is also functioning properly. The firewall operates in question mode, using round-robin connections, and handles routing as well.
What is most valuable?
FortiGate is a very good product. It offers a wide range of features, and its availability is almost everywhere. The support, both local and international, is good. Also, they provide certification programs for the next-generation firewalls, which is beneficial.
The product speaks for itself and holds a strong position in the market. In our company, we highly recommend FortiGate to our colleagues and other IT professionals. Furthermore, it offers cost advantages compared to other products.
What needs improvement?
The improvement that I would like to see is in the licensing. The licensing process is a bit high.
Additionally, there have been several vulnerabilities in the firewall. It is hackable, some of the images are hackable. So, upgrading to the latest patch, but these improvements would be more profitable for companies like ours.
I would like to see improvements in license costs and the handling of vulnerabilities.
For how long have I used the solution?
I have been working with FortiGate NGFW for ten years. I currently use the FortiGate 101E model at a customer site.
What do I think about the stability of the solution?
I would rate the stability a nine out of ten. It provides a stable network, and I can connect to remote sites as well. I find it reliable because we use SD-WAN. There are no major issues, except when there is an Internet outage. But overall, no significant problems.
What do I think about the scalability of the solution?
The scalability is very good. I would rate the scalability of the solution a nine out of ten because I have encountered no issues so far with the product. The scalability is excellent, very good.
We have 150 users using this solution. Moreover, we have plans to increase the usage. Maybe next year, I plan to upgrade to a newer version of FortiGate, and we have a plan to increase our user count by ten percent by next year. So I'm considering a more powerful firewall for better performance. That's the plan.
How are customer service and support?
In terms of support, they are very responsive. If you reach out to them, they will contact you within 15 minutes. Managing FortiGate is easy and simple compared to other products. It's not too complex.
Even if we miss renewing our licenses, FortiGate provides a grace period of 90 days, which is exceptional. Most products only offer 30 days. That's the best part, in my opinion.
The support is excellent. I've had very positive experiences with FortiGate's support team. They are friendly and always available. Their support is available 24/7 via phone, email, or chat.
They even offer remote access if we need help with configuration or auditing logs. Their support is reliable both locally and internationally.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
The availability of product support and its manageability were important factors for me. I found it easy to manage, not too complex.
Additionally, the product is readily available in my country. Based on the information I found on the Internet, FortiGate seemed to meet my requirements.
How was the initial setup?
The initial setup is straightforward. The setup is pretty simple. However, it acts as an authentic gateway between my routers and the internal network. All the traffic goes through the firewall in cluster mode. If one firewall goes down, the other one takes over until we have time to replace the faulty one. We typically use the firewall for a period of five years before considering a replacement.
The device is connected to the server room on-premises. We configure it locally, but we utilize FortiCloud for logging and analytics. We manage the number of assets (FortiGate assets) we have, which is manageable through the cloud. That's all.
Which other solutions did I evaluate?
I have used Barracuda, Sophos, Palo Alto, and more.
What other advice do I have?
My advice would be to start by conducting a Proof of Concept (POC) and test FortiGate NGFW in your own environment. Go through all the necessary configurations and spend around one or two weeks to become familiar with the solution.
After that, you can proceed with the purchase. But if I were to advise someone instantly, I would simply say, go ahead and give it a try.
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.