What is our primary use case?
Its primary use case is serving as a web security gateway.
What is most valuable?
One of its standout features is its exceptional user-friendliness. It seamlessly integrates with various security products, enhancing threat intelligence and improving indicators of compromise. In terms of security, it collaborates with leading security companies like Trend Micro, Forcepoint, FireEye, and others to bolster threat intelligence.
What needs improvement?
For IT administrators and managers, the reporting features are the main issues that should be addressed in order to improve the performance, security, and effective utilization of the product. As per the experience of my team and customers, this feature should be improved.
For how long have I used the solution?
We have been using it for two years.
What do I think about the stability of the solution?
It is a reliable product, but there have been instances where we encountered certain challenges. For example, during peak usage times, when the licenses are based on token users but the user sessions surge significantly, we faced issues. In such situations, when attempting troubleshooting, including running debug commands, we encountered a specific challenge with the firmware's stability. We discovered some bugs in that firmware version, leading to occasional crashes. Consequently, during peak hours, as we executed troubleshooting and debugging steps, our FortiProxy encountered issues and went into a critical state, requiring a restart from the backend, typically through Hyper V or the Hypervisor. Presently, the firmware is much more stable, and we continue to use it without major issues. I would rate it nine out of ten, as it has proven to be highly stable in its current state.
What do I think about the scalability of the solution?
While it has been deployed effectively in a virtual environment with an active topology, it faces challenges when user numbers increase significantly. In situations where there is a substantial user base, it might not meet the user's requirements and usability expectations.
How are customer service and support?
The support is available around the clock and it consists of highly knowledgeable and product-savvy individuals who are adept at assisting. They quickly grasp the nature of the issues presented to them and, within a few steps, are often able to identify both the root causes and potential solutions. This level of competence and responsiveness makes for excellent support, and I am thoroughly satisfied with the provided assistance.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup process is quite straightforward. When dealing with virtual machines or hardware appliances, you simply need to deploy the system and configure the necessary interfaces. It starts by configuring the incoming LAN interface and the outgoing interface and then proceeds to set up DNS, explicit proxy, and various proxy features, including vulnerability management. If you're using an extensive proxy setup, you also configure the IP for web proxy and analytic proxy. Following that, you establish policies and handle other network-related settings such as routing and switching. While the initial setup is straightforward, it can become more complex as you integrate additional features and services over time.
What about the implementation team?
It is a virtual machine specifically deployed within a Hyper-V environment. I have had the opportunity to deploy it in the banking sector, actively participating in operational activities, which included troubleshooting numerous cases.
What's my experience with pricing, setup cost, and licensing?
It offers a more cost-effective solution than alternatives like FortiMail, FortiGate, and various Barracuda devices.
Which other solutions did I evaluate?
Our organization works both as a user and deployer of this product. The primary reason our customers opt for FortiProxy is because it not only fulfills their web security requirements but also offers a rich set of features that many other products do not provide. It encompasses content filtering, threat intelligence, WAN optimization, VPN tunneling (including IPSec and SSL VPN tunneling), and functions as a firewall, including a web application firewall and gateway firewall. It even includes features for configuring Active Directory settings and integrates sandboxing capabilities. When a threat originates from outside sources, the system sends the file to a cloud sandbox for examination. If the file is deemed clean, it proceeds; otherwise, it halts and neutralizes the threat.
What other advice do I have?
Overall, I would rate it eight out of ten.
Which deployment model are you using for this solution?
On-premises