Fortinet Fortigate
July 15, 2016

Fortinet Fortigate

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with Fortinet FortiGate

Firewalls were deployed at HQ, remote offices, and used as our primary gateway, UTM/NGFW for 2 production datacenters. Only firewall, UTM modules, and basic routing were used, no dynamic routing, wireless, vpn client or endpoint protection software.
  • Very fast and effective at overall UTM functionality
  • Best management UI I've seen across comparable vendors
  • Overall value, lower cost than competitors with similar features.
  • Support is downright horrid. Level 1 support will ask you (or even do it themselves) to *reboot* appliances. In a production datacenter. Level 2 will only do very basic support and will generally refuse bugs exist, in an overwhelming flood of proof.
  • Reliability isn't quite up to par. Although it's still a stable device, there are nuances you don't see in simpler deprecated devices like an ASA. But this comes with the territory of UTM/NGFW appliances.
  • Reduced overall operating cost year after year
  • Longer support windows means more overnight outages
Features and manageability are always better in Fortigate. Like everything else, the logic is different, do not try to apply old knowledge to a new implementation or it'll be unmanageable.
Unless there's a killer feature in another brand you must have, there's no situation I can think of that I would suggest another UTM.

Fortinet FortiGate Implementation

Prepare for terrible support, hour long hold time for Level 1, and next-day call backs for Level 2.
Yes - Each location was an acquisition, so each installation required translation and implementation of firewall rules.
Each office generally followed this process
1. Discovery and documentation
2. Reporting and logging
3. Sizing and purchasing
4. Configuration
5. Testing
6. Installation
7. Reporting, logging, and verification
Change management was a big part of the implementation and was well-handled
  • Translation of older firewall logic, ASA and SonicWall were among the worst and messiest.
  • Post-installation support, schedule an extra large window and hope you can get someone on the phone.