There is no need to buy physical firewall hardware when you host multiple customers requiring individual secure access to their FW. You just create virtual domains (VDOMs).
ICT Manager at a aerospace/defense firm
Virtual domains are treated as separate firewall instances
Pros and Cons
- "You can create multiple Virtual Domains (VDOMs), which are treated as separate firewall instances."
- "The reporting you receive out of this appliance is excellent. You will not need an external management system."
- "The user interface is relatively easy. The devices are easy to deploy and figure out when you have experience with other security appliances."
- "I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE."
- "There is one big configuration file with no separations for the unique VDOMs. Maybe they could separate individual VDOM configuration files with the root VDOM configuration file referencing the individual VDOM config files."
How has it helped my organization?
What is most valuable?
You can create multiple Virtual Domains (VDOMs), which are treated as separate firewall instances. The reporting you receive out of this appliance is excellent. You will not need an external management system.
What needs improvement?
1. sFlow and NetFlow
I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE.
NetFlow is a network protocol developed by Cisco for collecting IP traffic information and monitoring network traffic. It is not supported on FortiGate for those who have a NetFlow analyzer/collector already setup in their network.
2. Policies
To control traffic in a firewall, you need to create and apply policies to the FW interfaces. By default, policies are sorted by FW interfaces and this makes FW interfaces an integral part of the policies. Zones provide the option to logically group multiple virtual and physical FortiGate firewall interfaces. Then, you apply security policies to those zones (logical groups of interfaces) to control traffic flow on those interfaces.
In a FortiGate unit with a lot of interfaces (including virtual interfaces), there is a high probability of having duplication of policies.
For how long have I used the solution?
Three to five years.
Buyer's Guide
Fortinet FortiGate
July 2025

Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
861,524 professionals have used our research since 2012.
What do I think about the stability of the solution?
These devices are very stable.
What do I think about the scalability of the solution?
They are easily scalable with multiple built-in interfaces. It supports a minimum of 10 VDOMs. VDOM supports all dynamic routing protocols like RIP, OSPF, BGP, and IS-IS. You do not need to reboot after enabling the VDOMs.
Area for improvement - there is one big configuration file with no separations for the unique VDOMs. Maybe they could separate individual VDOM configuration files with the root VDOM configuration file referencing the individual VDOM config files.
How are customer service and support?
Customer Service:
Customer service is great, an eight out 10.
Technical Support:
I will give technical support an eight out 10.
Which solution did I use previously and why did I switch?
We previously used different solutions as well. We did not switch, we have different requirements for different customers.
How was the initial setup?
The user interface is relatively easy. The devices are easy to deploy and figure out if you have experience with other security appliances.
What about the implementation team?
It was an in-house installation.
What was our ROI?
The ROI is great. These boxes are not that expensive compared to what they can do, their functionality, and the reporting you receive.
What's my experience with pricing, setup cost, and licensing?
Fortinet licensing is straightforward and less confusing compared to Cisco. Fortinet has one or two license types, and the VPN numbers are only limited by the hardware chassis make.
Which other solutions did I evaluate?
I already have experience with Cisco ASA, so it was simply a customer preference and well within the budget.
What other advice do I have?
Great appliances, and it is affordable.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Dëvóps Engineer at a tech company with 51-200 employees
Fortigate is only cheap if you don't value your time or product quality
I have had the displeasure of having to support SOHO Fortigate offerings (Fortigate/Fortiwifi). in almost any measure, I have found these products inferior to respective solutions from cisco and juniper (two examples i've had experience with).
I'll start with the most egregious and disturbing: the product is unstable. the VPN client is crash prone and the VPN daemon is crash prone. if you want to enjoy having to drive to the office when the roads are iced because the VPN daemon just gave up the ghost again, just to reboot a unit, by all means - choose Fortigate.
I'll continue with support - pretty much a joke, although being fair here, it is similar in other respective products. by the time a competent engineer reviews your case, you may have to wade through more than a month of back and forth with t1/t2 support who offer very little usable assistance.
And final insult to injury - aggressive and clueless resellers. Fortigate tries to distance themselves from customers via resellers (as if support filtering wasn't enough). getting the wrong product or wrong configuration is very common, especially with unneeded packages.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Everyone writes basing on his own experience.
In this specific case (and I hope that it does not disturb you) would divide your review in two parts.
I agree with your complains regarding support.
My impression is that Fortinet prefers to delegate a big part of the problems to its reseller channel.
From then on, it is a simple matter of luck to find a company that is competent and able to help or not (I have found more often the second kind).
As you pointed out, it is not a different scenario from the one you have with other vendors, but it did NOT constitute a justification.
I do not use SOHO appliances (or not as often as you) so maybe they are not good as you noticed.
Again, probably the SOHO market, based on low prices - low quality is full of products that are not worth our time, not only the Fortinet's one.
Said so, I disagree from you about the Fortigate family of products to be not good as a whole. Their medium/high level appliances are so good (and so rich in features) that is really hard to find something like it on the market.
We are talking about UTM devices, able to replace what other vendors do with a lot of different pieces. They are not hard to configure (of course, it is not something for "newbies") and reliable.
I keep up networks with thousands of geographically dispersed users with no issue at all, and using only FortiGate appliances.
So, let me add (based on my experience, this time): support is not good. The high-end appliances from the FortiGate family are really good.
Buyer's Guide
Fortinet FortiGate
July 2025

Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
861,524 professionals have used our research since 2012.
IT NETWORK ENGINEER at a energy/utilities company with 501-1,000 employees
The most valuable features for us are VPN, WebFilter, and Firewall.
What is most valuable?
The most valuable features for us are
- VPN
- WebFilter
- Firewall
How has it helped my organization?
It's features are highly customizable. This means that when our different business groups have different needs, the implementations can be customized to meet the demands of those groups and needs.
What needs improvement?
I'd like to see an improvement in the Bandwidth Management and Traffic limit control.
Also, the licenses are expensive, turning off some users.
For how long have I used the solution?
We've used all units for five years, except the FortiGate 200D which has been in use for one year. Alongside FortiGate, we also have FortiAnalyzer 1000B and the FortiManager 200D.
What was my experience with deployment of the solution?
There have been no issues with the deployment.
What do I think about the stability of the solution?
There have been no stability issues.
What do I think about the scalability of the solution?
It has not been a problem to scale it.
How are customer service and technical support?
Customer Service:
Customer service is very good.
Technical Support:Technical support is very good.
Which solution did I use previously and why did I switch?
I depend on different products from different vendors depending on the required function.
How was the initial setup?
The initial setup is simple in the CLI or Web GUI.
What about the implementation team?
An in-house network engineer implemented it using the best practice recommendations from the vendor.
What's my experience with pricing, setup cost, and licensing?
The appliances and licenses are expensive, and I know some people use other vendors because of this.
What other advice do I have?
You should know the customization you want from the beginning, and plan your requirements appropriately.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Engineer at a tech services company with 501-1,000 employees
I could achieve the same results with a software firewall. This one comes in a nice hardware package. Using the CLI should be documented better.
What is most valuable?
- Flexibility
- Flow tracking
- B2B VPN
How has it helped my organization?
It's good for what it is. I could achieve the same results with a pfSense firewall. This one just comes in a nice hardware package.
What needs improvement?
Better documentation about usage of the CLI. I learned most of what I know in diagnostic functionality through saving SSH sessions with the customer support staff while in WebEx sessions.
I have tried looking up the manuals. They are OK in some respects, but I feel exhaustive documentation about the CLI "with examples" should be there, and I feel it's not.
I'm saying, hey lets consolidate some of the primary real world scenarios like:
Section A: - Troubeshooting B2B VPN peering with a business partner or client when initially setting up the VPN tunnel.
Inevitably, there are always quirks and nuances between the fortigate vendor versus peering with a Palo Alto or an ASA firewall or even a Juniper SSG.
Imagine providing all steps, command line syntax, and GUI (if available) and how to take steps to debug the flow and see what's failing.
Sometimes it's super hard to figure out what's wrong with a fortigate VPN unless you know the commands on the CLI to see the flow and how to interpret it.
If they had all the methods / syntax and the "how's and why's" for a scenario; even possibly an instructional video showing how via the CLI and gui alongside the documentation. It would be like the pearly gates had opened and I had gone to heaven.
For how long have I used the solution?
I have used it for three years.
What do I think about the stability of the solution?
I never encountered any stability issues. It is a very stable product.
What do I think about the scalability of the solution?
Scalability's not been an issue for my org. We only utilize it for certain applications.
How are customer service and technical support?
Technical support is excellent, although it can be a bit difficult to understand the tech. As with most support staff from almost all vendors now, the support comes from somewhere across the pond.
Which solution did I use previously and why did I switch?
On the site where the FortiGate is stationed, it's never been changed out.
How was the initial setup?
Initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Buy the support package! Upgrades, advice about upgrade paths, and troubleshooting help is paramount. There have been some times where, without it, I'd have been dead in the water.
Which other solutions did I evaluate?
This was an in-place firewall when I integrated the site to my org.
What other advice do I have?
Figure out what features you want, and what policies you want. Look up how to do it in advance, and create an implementation plan.
Plan for policies, routing, NATting, etc. Create a step-by-step process in advance, possibly create the environment in a DEV sandbox, test it, then implement.
It has a good feature set. However, sometimes you are forced to solicit technical support to get it working.
Also, I find the web interfaces sometimes do not display things properly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Andrew S. Baker (ASB)Cybersecurity & IT Operations Professional (VirtualCxO) at BrainWave Consulting Company, LLC
Consultant
Great review. I was going to disagree with you about the CLI documentation, but I found that the examples are really missing for the common use cases, as you stated, so I had to agree.
The cookbook is getting better, but it's not yet comprehensive enough. Very good platform.
I also wish there were elements that you could rename without having to reload an entire config, but I am happy that you can easily search/replace a config and then replace it.
-ASB
Security Analyst at a tech services company with 10,001+ employees
The UTM (application control) features have solved many issues that other firewall providers cannot, such as Google suite blocking and allowing.
What is most valuable?
The UTM (application control) features have been very important, because they have solved many issues that other firewall providers have not developed as Fortinet has.
A clear example of this feature advantages is blocking and allowing the Google suite. For example, without UTM, we would not have been able to execute some customer requirements like this one:
A customer asked us that some host on their LAN is going to be assigned to be a POS workstation. They needed that workstation to have permissions to some applications and some URLs, and they needed to block users from opening sites like YouTube, Google+, and Google Drive, but they needed to get in to some POS URLs hosted in the Google cloud. We were working with rules allowing some specified URLs, but it didn’t work because the subnetting IP address the customer needed to be allowed, sometimes matched the YouTube service. Google support engineers told us they rotate their IP addressing subnets to be more secure and they do not always attach an IP address to a domain name. So, sometimes the customer’s workstations were able to open YouTube sites too.
The way we could block YouTube and allow the customer POS URLs sites, was by configuring an application control sensor, where we were able to block some categories like this:
Another requirement was to allow some specified applications, so we configured the next sensor structure:
Another customer reported to us they had issues working with Gmail attachment files; they could not do it. Executing some packet captures and with the Fortinet TAC help, we found they were using the latest Chrome versions that use the QUIC Google protocol, which is not supported by Fortinet because it is not a valid protocol. We proceeded to block the QUIC protocol using an application control sensor.
After this blocking action, the customer was able to work without any issue.
How has it helped my organization?
It can block applications in level 7.
Even though other companies have latest-generation firewalls, FortiGate’s database is bigger.
What needs improvement?
They could improve performance with all the UTM features working.
Sometimes, we have seen that when you enable the antivirus sensor, customers report slow web browsing. We know this is normal, but we would like to know if it is possible to make feel the customer their web browsing is fast with not as much delay. The antivirus sensor analyzes all the protocols and packets we specified, and this is an important performance affectation. In my personal point of view, I don’t think it is a serious issue, but we receive many reports from users who browse the web with antivirus sensors applied to their firewall policies.
For how long have I used the solution?
I have been using it for seven years.
It is working in route mode, with all UTM licences active; it has FSSO configured to give permission to the users. It is configured to provide VPN SSL service.
What do I think about the stability of the solution?
I have encountered stability issues only when we enable all the UTM features.
What do I think about the scalability of the solution?
I have not encountered any scalability issues.
How are customer service and technical support?
Technical support is 9/10.
Which solution did I use previously and why did I switch?
We have been using FortiGate solutions for eight years. We have been upgrading when solutions in the family become unsupported.
How was the initial setup?
The initial setup is easy; no issues with doing it.
Which other solutions did I evaluate?
My company did not evaluate other options. They decided to purchase FortiGate directly.
What other advice do I have?
Work a lot with all of the UTM features because they can be very helpful right now with configuring firewall policies. The policies became very whole.
Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a Fortinet provider for Mexico.
IT Manager at a tech vendor with 501-1,000 employees
We were able to prevent the use of torrent applications. They need to improve the alert and event logs.
What is most valuable?
With the application and web filters, we were able to block social network websites and any other websites that could lead staff being less productive. We were able to stop use of VPN applications on the school’s network. We were able to prevent the use of torrent applications.
How has it helped my organization?
It was used in a school network, so it kind of helped in preventing staff and students from getting carried away with their browsing.
What needs improvement?
I feel they need to work on the alert and event logs. We were not able to get anything much out of it when we were facing issues. Not sure if it was a configuration issue; we were, in fact, not able to see any system-related logs.
For how long have I used the solution?
I used it for two years. I had to replace it as the number of staff increased to beyond its limit.
What do I think about the stability of the solution?
We did have an issue with it hanging occasionally. But then later, we figured out that it was handling traffic beyond its limit.
How are customer service and technical support?
Technical support is average.
Which solution did I use previously and why did I switch?
This was the first device we used.
How was the initial setup?
It was installed by the IT solution provider while setting up the school.
What other advice do I have?
It is a good device for a medium-sized company. But if you have over 150 staff/devices, I wouldn’t advise using this.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant Information Technology at a tech company with 51-200 employees
Delivers what it promises when it comes to performance, stability and security functions.
What is most valuable?
The web content filtering and application control allow us to control which websites and online applications our users can access and those they cannot, thus preventing access to pornographic sites, online gaming sites, social media and many others during office hours.
The application control reinforces the blocks, preventing, for example, users from using specific applications to bypass the web content filter blocks. An example is a user running the UltraSurf proxy, attempting to access banned sites. With the application control function, FortiGate is able to prevent the operation of this application.
IPS - Intrusion Prevention System: It is the main component that detects and blocks hackers and malware attacks.
Other valuable features are SSL VPN and WAN link balancing.
How has it helped my organization?
It provides real security for business customers.
What needs improvement?
The reports provided by the equipment could be more detailed, and not so dependent on the FortiAnalyzer.
The FortiGate internal reports are good, but could have more details and options for viewing certain network data. For the client to get the richest reports, they need to buy the FortiAnalyzer appliance or hire FortiCloud service. These two aim to catch all of the FortiGate logs and turn them into friendly reports, many of which are not present in FortiGate itself.
For how long have I used the solution?
I have been installing and configuring this product for at least 10 years with different companies, including other models such as the Fortigate 60D and 80C.
What do I think about the stability of the solution?
The product has always been stable and performed quite well.
What do I think about the scalability of the solution?
I have not encounter any scalability issues.
How are customer service and technical support?
Technical support is very good. Fortinet professionals are well trained.
Which solution did I use previously and why did I switch?
For commercial UTM solutions, I have always worked with Fortinet; I had no reason to trust another third-party solution.
How was the initial setup?
It's simple: Just turn it on, access your Web console via the default IP address and then perform the settings.
What about the implementation team?
I installed and configured the 200D for one of my clients.
What's my experience with pricing, setup cost, and licensing?
The full license is UTM Bundle Full Guard. The license fee varies according to the Fortigate model; prices can be low or too high.
What other advice do I have?
If you need real and effective security for your network, do not hesitate to buy a Fortigate appliance. It is no wonder that it is the best according to Gartner, for several years running. It delivers what it promises and more when it comes to performance, stability and security functions.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Project Consultant at a tech consulting company
I can delegate more simple and routine tasks to other administrators and I don’t have to be the “Firewall” guy all the time, but the graphical interface always has room for improvement.
What is most valuable?
I enjoy the combination of an intuitive graphical interface and also a traditional shell command line environment for more advanced administration. The option to configure policies in a graphical environment is very easy to understand and also simple to teach someone else unfamiliar with the product.
How has it helped my organization?
It’s much easier to share administration tasks with more people. Due to the flexibility and ease of certain features, I can delegate more simple and routine tasks to other administrators and I don’t have to be the “Firewall” guy all the time.
What needs improvement?
I think the graphical interface always has room for improvement. I would like to see more attention put towards the logging functions as well.
For how long have I used the solution?
I worked with this solution daily for over 12 months.
What do I think about the stability of the solution?
I encountered several strange issues in v5.0 (and earlier) OS versions. Strange anomalies like random reloads, VPN instability and unexplained policy changes. However, all of these issues were resolved in v5.2.
How are customer service and technical support?
I always had great experiences with Fortinet. I worked with them several times to resolve configuration issues and process RMA’s on failed equipment, which was rare.
Which solution did I use previously and why did I switch?
I’ve personally used Cisco ASA and PIX architecture and after using Fortinet, I always prefer FortiGate products in terms of functionality and ease of use. I recommend these to clients looking for a firewall solution.
How was the initial setup?
Usually always simple and straight forward. I can get a client up and running with most standard policies and inbound/outbound control in a single day and make adjustments as needed. I can usually preconfigure Fortinet products and send them out for install.
What about the implementation team?
I always implemented via in-house. I think the most important advice is to always test new configurations in the lab especially, when upgrading firmware.
What was our ROI?
From my experience, FortiGate products are affordable and worth the investment.
What other advice do I have?
I think for almost any small to mid-size business this is a great solution. Fortigate should definitely be considered before choosing a more expensive and complicated product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2025
Popular Comparisons
Netgate pfSense
OPNsense
Sophos XG
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
Check Point NGFW
WatchGuard Firebox
Azure Firewall
SonicWall TZ
Cato SASE Cloud Platform
Cisco Catalyst SD-WAN
Juniper SRX Series Firewall
Sophos XGS
Fortinet FortiGate-VM
SonicWall NSa
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Looking Into Implementing a Web Security Solution.
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- We're trying to choose between Fortinet or Checkpoint UTM firewalls. Can you help?
- What Is The Biggest Difference Between Fortinet FortiGate and Meraki MX Firewalls?
Hi Becky. I chose Fortigate mainly because it provides the capabilities to provide logical separate firewall instances to multiple customers. These logical firewall are know as VDOMs. I have the partitions the physical fw devices to multiple logical units thus saving costs.