Try our new research platform with insights from 80,000+ expert users
PeerSpot user
CEO with 51-200 employees
Vendor
I've been using it for 6 years. I like the security profiles and vulnerability assessment.

What is most valuable?

  • Load Sharing
  • VDOM
  • Security Profiles
  • Vulnerability Assessment

For how long have I used the solution?

6 Years

What was my experience with deployment of the solution?

Yes, bugs.

What do I think about the stability of the solution?

No.

Buyer's Guide
Fortinet FortiGate
August 2025
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.

How are customer service and support?

Poor.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
it_user275226 - PeerSpot reviewer
IT Director with 501-1,000 employees
Vendor
I don't need to have a cluster because it's stable, but rules are not intuitive and the admin UI needs improvement.

What is most valuable?

It offers a proxy and a firewall.

How has it helped my organization?

It has a better processor than CheckPoint.

What needs improvement?

It's not intuitive, as the rules will be in the last place you look. You can look for a report for an hour, eventually getting a blank page. User experience for the administrator is basically not good as it needs to be more proficient.

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

I have five ISPs, and it was hard to connect the LAN to the WAN. It did not go well and I had do to a roll-back.

What do I think about the stability of the solution?

The product is so stable I don't need to have a cluster.

How are customer service and technical support?

Customer Service:

I use a service given by the integrator and it's better than Fortigate’s. The integrator gives me a guarantee that they will immediately replace my machine if a problem occurs.

Technical Support:

I use a service given by the integrator and it's better than Fortigate’s. The integrator gives me a guarantee that they will immediately replace my machine if a problem occurs.

Which solution did I use previously and why did I switch?

I used an open-source product name Squid.

How was the initial setup?

It's straightforward, and was transparent for the users.

What about the implementation team?

We did it in-house.

What was our ROI?

It costs $200,000 and is only a bit better than the open source solution, which was free.

What's my experience with pricing, setup cost, and licensing?

You don’t have to buy the Fortigate analyzer, as you can also get the reports using Fortinet.

What other advice do I have?

It's fine as a firewall and as a proxy. You need to configure the rules right or else it will be hard to keep up with the logs.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Andrew S. Baker (ASB) - PeerSpot reviewer
Andrew S. Baker (ASB)Cybersecurity & IT Operations Professional (VirtualCxO) at BrainWave Consulting Company, LLC
Consultant

The v5.6 GUI is much improved, IMO. Very happy to see the changes there. Some things are still a little hard to find, but not as many.

See all 5 comments
Buyer's Guide
Fortinet FortiGate
August 2025
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.
PeerSpot user
Security Consultant at Webernetz.net - Network Security Consulting
Consultant
Cisco ASA vs. Fortinet FortiGate vs. Palo Alto vs. Juniper SSG

Since IPv6 gets more and more important, I am using it by default on all my test firewalls, which of course support IPv6. However, when comparing the different functions and administration capabilities, they vary significantly.

Here comes my short evaluation of the IPv6 functions on the following four firewalls: Cisco ASA, Fortinet FortiGate, Juniper SSG, and Palo Alto.

Criteria

I was merely interested in the basic IPv6 usage and not in the typical firewall categories:

  • Interface: IPv6 address and link-local address configurable?
  • Router Advertisement and DHCPv6: Whether the firewalls support nothing (–), only RA (-), DHCPv6 relay (ο), stateless DHCPv6 (+), or stateful DHCPv6 (++). The existence of stateless DHCPv6 is vital for delivering the DNS server IPv6 addresses to the clients. (The “IPv6 Router Advertisement Options for DNS Configuration”, RFC 6106, is not supported by any of these devices.)
  • Security Policy: Whether IPv4 and IPv6 addresses can be used in the same policy and whether address groups can have objects from both protocols.
  • Administration: How easy are the IPv6 functions to manage? Only via the CLI (–), fifty-fifty (ο), GUI but complicated (+) , or fully via the GUI (++).

Results

These are the results. They range from — via ο to ++.


Cisco ASA
Fortinet FortiGate
 Juniper ScreenOS
Palo Alto
Version
9.2(3)
5.2.2
6.3.0r18.0
6.1.3
Interface
++
+
++
++
RA, DHCPv6
-
++
+
0
Security Policy
++
-
-
++
Administration + - + ++

Details

Cisco ASA

The Cisco ASA has no DHCPv6 instance running. That is: there is no way to run an IPv6-only network because clients won’t get the DNS server. The security policy is capable of both protocols. Everything is configurable via the GUI, which is not the best at all.

Fortinet FortiGate

The FortiGate is the only firewall with a stateful DHCPv6 server. Great. However, two distinct security policies must be used and nothing of the IPv6 settings are configurable via the GUI. WHAT???

Juniper SSG (ScreenOS)

ScreenOS is dead. However, most of the IPv6 functions are working quite good, except the protocol dependent security policies. Everything is accessible via the GUI, but sometimes on confusing positions.

Palo Alto

Palo Alto did a good job on the IPv6 interfaces and security policies. The GUI is quite intuitive and the policy accepts both protocols at the same time. Unluckily, there is no DHCPv6 server which makes it impossible to operate an IPv6-only client network behind a Palo Alto (without further servers).

Conclusion

It’s interesting to see the differences between those firewalls. While the Fortinet und Juniper firewalls support the whole SLAAC process incl. DNS servers, they have no single security policy for both protocols and are horrable to configure.

The Palo Alto is quite good to configure but lacks the DHCPv6 server. Same for the Cisco.

In summary, all firewalls position in the middle of my scale. From an IPv6-only view, I cannot say which one is the best. It depends….

Originally published on blog.webernetz.net

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user245154 - PeerSpot reviewer
Customer Support engineer at a healthcare company with 51-200 employees
Vendor
It helps to come up with the requirements of proxy servers, but it does not have that much troubleshooting & network testing features.

What is most valuable?

The key features of this product are:

  • Network security
  • UTM Features
  • Configuration and ease of deployment.
  • IP/User/Device Mac ID/Device Type based policy configuration
  • Traffic shaping
  • Load balancing
  • Ease of VPN configurations
  • Explicit proxy
  • Link segregation
  • Application signatures
  • Network object based HTTPS/SSL inspection etc.

How has it helped my organization?

In many organizations it helps to come up with the requirements of proxy servers, defining network traffic and the amount of bandwidth for any network object or specified user(s). It has also provided us with security compatibility with other network devices such as IP cameras, the video conferencing system, VOIP phones. It also logs & reports on individual users network activities.

What needs improvement?

The FortiGate series does not have that much troubleshooting & network testing features in its GUI, hence we’ll definitely be looking for some add-on features in near future.

For how long have I used the solution?

I have been using this solution for the past year.

What was my experience with deployment of the solution?

No issues yet.

What do I think about the stability of the solution?

No issues yet.

What do I think about the scalability of the solution?

For massive logs & reports (over a month) we have to go for a separate logging & reporting device i.e. FortiAnalyzer/FortiCloud, as this is not available in Fortigate itself.

How are customer service and technical support?

Customer Service:

7/10.

Technical Support:

8/10.

Which solution did I use previously and why did I switch?

We started with FortiGate itself.

How was the initial setup?

This product has a setup wizard (FortiExplorer) for the initial configuration, while the physical connectivity is done via a USB cable which is very easy to use.

What about the implementation team?

We implemented the solution ourselves.

What was our ROI?

It is value for money product as we’ve purchased it with Fortinet's three-year warranty package.

Which other solutions did I evaluate?

We have evaluated Dell’s Sonicwall & Cyberoam.

What other advice do I have?

Analyze your needs first before implementing this product.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user241746 - PeerSpot reviewer
Software Test Engineer with 501-1,000 employees
Vendor
The product has lived up to its expectations but the web interface needs to be improved.

What is most valuable?

  • Anti-virus
  • NAT
  • VPN

How has it helped my organization?

It's the only security product in place that is responsible for guarding the network infrastructure deployed within the premises. The product has lived up to its expectation with no issues whatsoever.

What needs improvement?

The web interface could be made better.

For how long have I used the solution?

I've used it for eight years.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

How are customer service and technical support?

We have managed to maintain the device without getting in touch with technical support. Credit can be given to the documentation provided.

Which solution did I use previously and why did I switch?

This was the first security device that was deployed.

How was the initial setup?

Setup was straightforward and the documentation was very clear which meant that there were no issues during the initial setup.

What about the implementation team?

We had a vendor assist us who had decent knowledge about the product.

Which other solutions did I evaluate?

We also looked at pfSense.

What other advice do I have?

The product has reached its end of life.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user241101 - PeerSpot reviewer
Network Administrator at a real estate/law firm with 51-200 employees
Vendor
It offers unlimited VPN licensing but it needs a real-time log viewer in the GUI.

What is most valuable?

The unlimited VPN licensing. All of our remote locations (1000+) used IPSec VPN and SSL to connect to the cluster.

How has it helped my organization?

We went from being terrified about our firewalls screwing up to completely forgetting we had firewalls. I slept better and so did my manager.

What needs improvement?

A real-time log viewer in the GUI with the capability to filter traffic displayed. Cisco ASA's have this and it's fantastic.

For how long have I used the solution?

I used it for four years. We had two devices that were clustered together in a high availability pair as the front end of an country wide, high visibility solution.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

Customer service was decent with Fortinet - they were helpful and got the product to our doorstep quickly.

Technical Support:

This is where Fortinet stumbles. The support is farmed out overseas to techs that are not very knowledgeable about the Fortinet products. The response time for a critical priority one issue was over four hours and they only responded because we threatened legal action for them violating our support contract.

Which solution did I use previously and why did I switch?

They used to have Juniper products, which are terrible. The enterprise class firewalls do not support any sort of packetflow gathering such as netflow, and the devices didn't even support Juniper's proprietary jflow. Their SRX series routers, meant for home office use, had more features and capabilities.

How was the initial setup?

It was very straightforward and we encountered very little problems. Fail-over occurred within a second with zero outages or anyone actually taking notice. Firmware updates were easy to apply in a live environment if required, and the GUI was very easy to understand.

What about the implementation team?

I deployed it - I'm FCNSA certified.

What was our ROI?

If we used a similar solution that required a "per seat" license per VPN, we would have literally spent over 100x what the solution cost us.

What's my experience with pricing, setup cost, and licensing?

We implemented the clustered firewalls for around $30,000, and each office had another Fortigate device at a cost of around $1,000.

Which other solutions did I evaluate?

Cisco was evaluated but we didn't want to pay for the VPN licensing.

What other advice do I have?

It's an absolutely fantastic product. Just get your support contract clarified, and confirm the response times.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user236523 - PeerSpot reviewer
Senior Information Security Engineer with 501-1,000 employees
Vendor
It's excellent and we strongly recommend it, but WAN link load balancing needs improving.

What is most valuable?

I am using different features of this product but the most valuable are -

  • SSL VPN
  • Web filter
  • Explicit proxy
  • IPS
  • Application control
  • Routing

How has it helped my organization?

I replaced my core router with a Fortigate appliance and it is performing inter-VLAN routing. I removed manual proxies and used transparent proxy using Fortigate security profiles, and implemented traffic shaping, web filter, application control, IPS and anti-virus. All the servers are protected by Fortigate security profiles.

What needs improvement?

  • WAN link load balancing
  • Reports
  • Anti-virus.

For how long have I used the solution?

I have been using this solution since 2013.

What was my experience with deployment of the solution?

We faced some technical issues on the Fortinet side.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

6/10.

Technical Support:

6/10.

Which solution did I use previously and why did I switch?

I didn't use any other solution prior to Fortinet.

How was the initial setup?

It was complex because there was a huge network with VLANs configured and routing protocols enabled.

What about the implementation team?

We implement this through a vendor. I would rate their level of experience 8/10.

What was our ROI?

I would only say that Fortinet provides business and security returns at a cost substantially lower than the benefits derived.

Which other solutions did I evaluate?

We evaluated Sophos and Barracuda alongside Fortigate.

What other advice do I have?

Our experience of using Fortigate is excellent and we strongly recommend it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user236517 - PeerSpot reviewer
Senior NetOps Engineer at a tech services company with 51-200 employees
Consultant
Security has been increased but the licensing fees could be lower.

What is most valuable?

  • GUI
  • Flexibility
  • Easy to configure
  • UTM

How has it helped my organization?

  • Option to control application = increased productivity
  • Data leak prevention = increased security
  • Anti-virus & IPS = increased security

What needs improvement?

I'm happy with the product, however the licensing fees could be lower.

For how long have I used the solution?

I've used it for six years.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

There is a specific way of deploying a Fortigate product, and the scalability is related to the new unit deployment so there are no problems here. If you need more power/space, you just have to add a new box.

How are customer service and technical support?

Customer Service:

It's very good, I've never had any problems with customer service.

Technical Support:

It's very good, I've never had any problems with technical support.

Which solution did I use previously and why did I switch?

I was using Cisco ASA, and I switched due to a lack of features (e.g. poor SSL VPN support).

How was the initial setup?

It's a very simple setup as everything is well documented online and via the Fortigate channel on YouTube. Also, I posses a large amount of knowledge gained during the years that has helped me to deploy all my solutions. Even from the the beginning, it was easy as Fortigate has a great GUI and good online help,

What about the implementation team?

We did an in-house implementation, with no third party involvement.

What was our ROI?

The product is deployed as part of, and an add-on to, the MPLS solution for the majority of my customers. There is no ROI as this is not the major expectation, as the ROI is coming from the whole solution, not just this product.

What's my experience with pricing, setup cost, and licensing?

All the costs are for the annual licenses. The cost of the original deployment fell below £5,000, and licenses are priced at around £3,000.

Which other solutions did I evaluate?

We considered Cisco, however we decided to go with Fortigate as it provides a good set of the features for the price paid,

What other advice do I have?

Enjoy it. The product is easy to implement, easy to manage, and easy to develop and grow.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros sharing their opinions.