The typical next-generation firewall use case is to restrict access to the users by using a firewall.
Senior solution architect at a comms service provider with 51-200 employees
Flexible to use and easy to set up
Pros and Cons
- "It is very flexible to use."
- "It is stable, but its stability can be improved."
What is our primary use case?
What is most valuable?
It is very flexible to use.
What needs improvement?
It is stable, but its stability can be improved.
For how long have I used the solution?
I have been using this solution for maybe four or five years.
Buyer's Guide
Fortinet FortiGate
November 2024
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
What do I think about the stability of the solution?
Its stability is just okay. It should be better.
What do I think about the scalability of the solution?
The scalability of the device is limited.
How are customer service and support?
Technical support is okay. They could be more knowledgeable and faster.
Which solution did I use previously and why did I switch?
I was using Sophos. We switched because it was very unstable in terms of both software and hardware. I found a lot of vulnerabilities. Even though they provide a lot of features for a minimum cost, these features don't do what they are supposed to do.
How was the initial setup?
The initial setup was easy. The deployment duration depends on the situation. I have done the installation in one to three days.
What about the implementation team?
I installed it myself. You just need one technical guy to maintain and manage the firewall. It is a small product for 200 to 500 users.
What's my experience with pricing, setup cost, and licensing?
It has a competitive price.
What other advice do I have?
I would recommend this solution. We plan to continue using it. Even though it has a few stability issues, its price is competitive.
I would rate Fortinet FortiGate an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
President at simnet
Detailed analytics that integrates with SIEM products and has good support
Pros and Cons
- "The most valuable feature of this solution is the analytics."
- "Quality control on their firmware versions needs improvement. When they introduce new firmware, there tend to be bugs."
What is our primary use case?
Typically, we use Fortinet FortiGate with edge devices for businesses.
We also use them to integrate with a SIEM product and we use it for detailed analytics.
What is most valuable?
The most valuable feature of this solution is the analytics.
What needs improvement?
Quality control on their firmware versions needs improvement. When they introduce new firmware, there tend to be bugs.
I would like the licensing price to be better. It would be nice if it were less than 25 percent of the hardware costs.
For how long have I used the solution?
I have been using this solution for fifteen years. We are an MSSP.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
With respect to scalability, it's good.
We have 15 people using this solution in our organization.
How are customer service and technical support?
We contact technical support almost daily. They have good support.
How was the initial setup?
The initial setup was not straightforward but not too complex. It's a bit of both.
What's my experience with pricing, setup cost, and licensing?
For our organization, the licensing costs are approximately $7,000 per year.
Which other solutions did I evaluate?
Before choosing the Fortinet FortiGate, I evaluated other solutions.
What other advice do I have?
I would rate Fortinet FortiGate a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Fortinet FortiGate
November 2024
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Solution Architect at Brillbean Ventures Pvt ltd
Good security, performance, and traffic inspection
Pros and Cons
- "The most valuable feature is the VDOM, which allows the customer to have multiple firewalls in a single campus."
- "Improvement is needed in the Web Filter quotas to restrict users with allocated quotas."
What is our primary use case?
I have deployed FortiGate with multiple organizations such as universities, government institutions, healthcare, and ISP providers. I have worked with FortiGate models 30-500 series and I have deployed the 3200D model for one of the broadband service providers located in India, Namely Sikka Broadband.
How has it helped my organization?
I have installed the FortiGate 500 and 400D to replace a Sophos firewall in a main corporate office. This implementation provided improved network performance.
This solution made it easier to connect all of the branches together via an IPsec VPN and remote users with SSL VPN.
What is most valuable?
The most valuable feature is the VDOM, which allows the customer to have multiple firewalls in a single campus.
Using the FortiGate security solution provides comprehensive visibility and advanced layer 7 security, including threat protection, intrusion prevention, web filtering, and application control. They face a major complexity hurdle managing these point products with no integration and lack of visibility.
Thie solution provides a high-performance inspection of clear-text and encrypted traffic.
The FortiOS Operating system is robust, and the WAN load-balancing very much transparent.
What needs improvement?
Improvement is needed in the Web Filter quotas to restrict users with allocated quotas.
It would be an improvement to add a feature for active users to change/reset their own passwords.
Fortinet renewal prices for all models are too high, so they should offer discounts for customers on renewal.
For how long have I used the solution?
I have been using this solution for almost seven years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Engineer at Concentus
An intuitive user interface for our SOHO edge protection solution
Pros and Cons
- "This solution has solid UTM features combined with a nice GUI."
- "The Web-filter in this solution is not very good."
What is our primary use case?
We use this solution for edge protection in SOHO and K-12 environments.
How has it helped my organization?
FortiOS has a very good, intuitive GUI.
What is most valuable?
This solution has solid UTM features combined with a nice GUI.
What needs improvement?
The Web-filter in this solution is not very good. Perhaps because Fortinet does not want to compete with its own dedicated solution.
For how long have I used the solution?
Three years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Network Analyst at Aloo Telecom
A stable product that allows us to offer several services in a single box
Pros and Cons
- "We have been able to offer several services to customers in a single box."
- "I use the FortiGate 60D model and realized the 300Mbps bandwidth limitation. Because it is a product that offers many services, I think it could have greater bandwidth capacity."
What is our primary use case?
Our primary use case for this solution is the provision of services to our customers, the end users.
How has it helped my organization?
This solution has improved our organization a lot. We have been able to offer several services to customers in a single box.
What is most valuable?
The firewall is a valuable feature because it offers more security for end customers. The HA function is fantastic, as the link switching time is almost imperceptible. It also offers dedicated IP, all in one box.
What needs improvement?
I use the FortiGate 60D model and realized the 300Mbps bandwidth limitation. Because it is a product that offers many services, I think it could have greater bandwidth capacity.
For how long have I used the solution?
Trial/evaluations only.
What do I think about the stability of the solution?
My impression of the stability is very good. It is very difficult to have to replace the equipment due to lack of resources.
What do I think about the scalability of the solution?
I found this product to be good for scalability. It offers several features, among them I can mention Application Control, Antispam, QoS and others.
How are customer service and technical support?
I found the technical support team to be careful and committed to delivering what we needed.
Which solution did I use previously and why did I switch?
Prior to using the FortiGate solution, I used the MikroTik RB1100AHx2e. I found that the FortiGate 60D offered more security.
How was the initial setup?
The setup was straightforward and easy, and the equipment has a good command line interface.
What about the implementation team?
We were given all the support that we needed for implementation. The vendors were fantastic.
What was our ROI?
The return is inevitable when you have equipment that offers stability and quality in services.
What's my experience with pricing, setup cost, and licensing?
Before choosing a piece of equipment you have to take into account the cost-benefit offered by each one. Sometimes it is not worth paying a very cheap price to have a minimum level of security.
Which other solutions did I evaluate?
Our evaluation of the MikroTik RB1100AHx2e revealed that it lacks antivirus software and has no lock for botnet control centers.
What other advice do I have?
There is a VOIP feature that by default is enabled on the Fortigate 60D. This greatly increases the CPU usage, which causes bad behavior in the equipment. This feature should be disabled and if necessary, the user can re-enable it.
The FortiGate 60D is a fantastic piece of equipment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT System Administrator at emirates hospital
Enables us to control our internet usage with the web filter for application features
Pros and Cons
- "The most important features with FortiGate are the web filter and application controls. We can control our internet usage and use the web filter for application purposes."
- "Some features of Fortinet FortiGate are actually fee enabled that are inconvenient for deploying in production. Other issues relate to isolation with Cisco products and your server."
What is our primary use case?
We use Fortinet FortiGate mainly for web filtering and site-to-site VPN connectivity. We establish filters based on the type of application for filtering purposes.
How has it helped my organization?
With Fortinet FortiGate I can do over forty enlaces. We give all of the log-based runtime support to every user and the web traffic coming in. Also, we can enlace all of the security projects from our two servers with the other forty enlaces.
What is most valuable?
The most important features with FortiGate are the web filter and application controls. We can control our internet usage and use the web filter for application purposes. All branch FortiGate devices are integrated with FortiAnalyzer and easy to download and monitor the logs from all other locations. It's easy to change the configurations using CMD-SSH. FSSO is also another good feature.
What needs improvement?
It is mainly our own application of FortiGate that we need to improve. If you compare FortiGate to any other products, all of the other products have more signatures. I couldn't find that many signatures available in the application.
Some features of Fortinet FortiGate are actually fee enabled that are inconvenient for deploying in production. Other issues relate to isolation with Cisco products and your server.
Fortinet should make it so that we are not able to use analytics from Cisco at the same time that FortiGate is installed. We are not able to do real-time network monitoring.
For the next release, FortiGate should be improved to support these issues. For the setup, you need to prepare a lot for that before engaging the deployment.
I learned a lot about FortiGate from books. That should be important in preparation. Fortinet should implement these changes, then we would be able to do more.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
Stability is good. The only issue is that in the VPN, I have seen many times that there is no stability in the VPN configuration and VPN connectivity. That is our only issue.
What do I think about the scalability of the solution?
If we implement Fortinet to Fortinet connections, then the solution works fine and there are no issues. If we connect with any other vendor like Cisco, Palo Alto, or these kinds of devices, I can see sometimes that the connectivity issue is there.
From IIS, the I/O packet works and connectivity is ideal. Connectivity is fine, but the title clock unnecessarily comes in and sometimes it doesn't reach the destination.
We use Fortinet FortiGate in twenty to twenty-five locations at the time, although we are basically focused on healthcare industry requirements.
For the deployment and maintenance, we have two people we are using right now. Regarding maintenance and deployment, we employ experts in network and security support.
We don't have any plans to increase usage of Fortinet FortiGate. We only use it in 25 locations.
How are customer service and technical support?
We have evaluated Fortinet FortiGate's technical support and it is good.
How was the initial setup?
The initial setup is straightforward. The normal VLAN interface configuration with the LAN configuration is fine. There is no problem with that.
Our deployment took a maximum of half an hour to forty-five minutes. It only took this much time for the entire configuration including the LAN and policy configuration.
What about the implementation team?
We did not use an integrator or consultant. Our security engineers completed the configuration.
What other advice do I have?
In terms of rating, Fortinet FortiGate will come in with an eight out of ten. We are satisfied with the product overall.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at HAMMOND LUMBER COMPANY
Their proxy-based inspection is responsive and secure
Pros and Cons
- "The CLI and GUI do a good job of putting a lot at your fingertips."
- "Their proxy-based inspection is responsive and secure."
- "It could use more templates for third-party site-to-site VPN setups other than FortiGate and Cisco."
What is our primary use case?
We use Fortinet FortiGate as our firewall and Layer 3 switch. Together, they connect all our locations for internal and external access with an MPLS as the primary connection and a backup VPN over a secondary DSL/Cable ISP.
How has it helped my organization?
Fortinet FortiGate has improved our routing and made us more secure. Using OSPF tables with an MPLS VPN, along with the combined security of the firewalls, has made a huge difference in our organization.
What is most valuable?
- The ability to customize UTM features and add or remove features as we like.
- Availability of different locations as options.
- The VPN features are easy to deal with.
- The CLI and GUI do a good job of putting a lot at your fingertips.
What needs improvement?
It could use more templates for third-party site-to-site VPN setups other than FortiGate and Cisco.
For how long have I used the solution?
Three to five years.
What other advice do I have?
Their proxy-based inspection is responsive and secure.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Owner at a tech services company
I am able to save hours of planning and implementation time because the documentation is so helpful
Pros and Cons
- "Their reliability and their policy of pre-shipping replacements when a unit has failed."
What is most valuable?
- The prompt and knowledgeable support behind them.
- Their reliability and their policy of pre-shipping replacements when a unit has failed.
- The simplicity and clarity of their user interface and documentation.
- Their 'cookbooks' that walk you through the most common installation scenarios.
How has it helped my organization?
I am a one-man show, so there is not much that can be done to improve the way that I function. However, these products provide best-in-class security at reasonable prices.
One of the most helpful features is their VPN, the client could not be any simpler to set up and use.
What needs improvement?
I can't think of too much which they can improve upon. I just have not come across any situation where they have fallen short of expectations.
For how long have I used the solution?
I am a consultant who supports these units for my clients who use them. I have had over 10 years of experience with Fortinet products.
What do I think about the stability of the solution?
The products are extremely stable. I have only had one instance where a unit did not function as expected, and Fortinet replaced the unit, despite the fact that it was still operational.
What do I think about the scalability of the solution?
Scalability is the one area where there is room for some improvement. Currently, customers need to purchase more powerful units as their network traffic and requirements grow. Fortinet will occasionally offer trade-in credits in such situations, but this is not always the case. Their product line allows customers to scale from SoHo through enterprise-level requirements, which is what I like about them so much.
How are customer service and technical support?
Their tech support is outstanding.
Which solution did I use previously and why did I switch?
I have sold and supported other solutions in the past. Fortinet is not always the least-cost solution available, but from a value standpoint, I find them hard to beat.
How was the initial setup?
Initial setup complexity will vary with the complexity of the installation. It is relatively straightforward and simple to set up basic configurations. More complex requirements entail reading through a lot of documentation in order to complete the firewall configuration because of the myriad of features and options that are available in their O/S. The 'cookbooks' are a big help in these instances.
What's my experience with pricing, setup cost, and licensing?
Pricing and licensing have to be taken in context with value. Fortinet is usually not the least expensive alternative when considering an upfront investment, but if you take into account the support costs over several years, they are often as cost-effective as the 'cheaper' solutions.
Which other solutions did I evaluate?
In this particular instance, Fortinet was evaluated against an equivalent solution sourced from D-Link. I also evaluated a solution from Xirrus (now Riverbed) which promised better signal strength. However, when I ran the various WiFi planning tools from each supplier, the coverage differences did not merit the more expensive Xirrus solution.
What other advice do I have?
Anyone evaluating this product should consult the documentation available and plan out their solution before making a decision. From personal experience, I find that I am able to save hours of planning and implementation time because Fortinet's documentation is so helpful.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Popular Comparisons
Netgate pfSense
OPNsense
Cisco Secure Firewall
Sophos XG
Palo Alto Networks NG Firewalls
Azure Firewall
Check Point NGFW
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
Untangle NG Firewall
Fortinet FortiGate-VM
SonicWall NSa
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Looking Into Implementing a Web Security Solution.
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- We're trying to choose between Fortinet or Checkpoint UTM firewalls. Can you help?
- What Is The Biggest Difference Between Fortinet FortiGate and Meraki MX Firewalls?
- What Is The Biggest Difference Between Fortinet FortiGate and WatchGuard XTM?
Good performance.