It offers a proxy and a firewall.
IT Director with 501-1,000 employees
I don't need to have a cluster because it's stable, but rules are not intuitive and the admin UI needs improvement.
Pros and Cons
- "The product is so stable I don't need to have a cluster."
- "User experience for the administrator is basically not good as it needs to be more proficient."
What is most valuable?
How has it helped my organization?
It has a better processor than CheckPoint.
What needs improvement?
It's not intuitive, as the rules will be in the last place you look. You can look for a report for an hour, eventually getting a blank page. User experience for the administrator is basically not good as it needs to be more proficient.
For how long have I used the solution?
I've used it for two years.
Buyer's Guide
Fortinet FortiGate
September 2026
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,924 professionals have used our research since 2012.
What was my experience with deployment of the solution?
I have five ISPs, and it was hard to connect the LAN to the WAN. It did not go well and I had do to a roll-back.
What do I think about the stability of the solution?
The product is so stable I don't need to have a cluster.
How are customer service and support?
Customer Service:
I use a service given by the integrator and it's better than Fortigate’s. The integrator gives me a guarantee that they will immediately replace my machine if a problem occurs.
Technical Support:I use a service given by the integrator and it's better than Fortigate’s. The integrator gives me a guarantee that they will immediately replace my machine if a problem occurs.
Which solution did I use previously and why did I switch?
I used an open-source product name Squid.
How was the initial setup?
It's straightforward, and was transparent for the users.
What about the implementation team?
We did it in-house.
What was our ROI?
It costs $200,000 and is only a bit better than the open source solution, which was free.
What's my experience with pricing, setup cost, and licensing?
You don’t have to buy the Fortigate analyzer, as you can also get the reports using Fortinet.
What other advice do I have?
It's fine as a firewall and as a proxy. You need to configure the rules right or else it will be hard to keep up with the logs.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Consultant at Webernetz.net - Network Security Consulting
Cisco ASA vs. Fortinet FortiGate vs. Palo Alto vs. Juniper SSG
Pros and Cons
- "Palo Alto did a good job on the IPv6 interfaces and security policies."
- "However, two distinct security policies must be used and nothing of the IPv6 settings are configurable via the GUI."
Since IPv6 gets more and more important, I am using it by default on all my test firewalls, which of course support IPv6. However, when comparing the different functions and administration capabilities, they vary significantly.
Here comes my short evaluation of the IPv6 functions on the following four firewalls: Cisco ASA, Fortinet FortiGate, Juniper SSG, and Palo Alto.
Criteria
I was merely interested in the basic IPv6 usage and not in the typical firewall categories:
- Interface: IPv6 address and link-local address configurable?
- Router Advertisement and DHCPv6: Whether the firewalls support nothing (–), only RA (-), DHCPv6 relay (ο), stateless DHCPv6 (+), or stateful DHCPv6 (++). The existence of stateless DHCPv6 is vital for delivering the DNS server IPv6 addresses to the clients. (The “IPv6 Router Advertisement Options for DNS Configuration”, RFC 6106, is not supported by any of these devices.)
- Security Policy: Whether IPv4 and IPv6 addresses can be used in the same policy and whether address groups can have objects from both protocols.
- Administration: How easy are the IPv6 functions to manage? Only via the CLI (–), fifty-fifty (ο), GUI but complicated (+) , or fully via the GUI (++).
Results
These are the results. They range from — via ο to ++.
|
|
Cisco ASA
|
Fortinet FortiGate
|
Juniper ScreenOS
|
Palo Alto
|
|
Version
|
9.2(3)
|
5.2.2
|
6.3.0r18.0
|
6.1.3
|
|
Interface
|
++
|
+
|
++
|
++
|
|
RA, DHCPv6
|
-
|
++
|
+
|
0
|
|
Security Policy
|
++
|
-
|
-
|
++
|
| Administration | + | - | + | ++ |
Details
Cisco ASA
The Cisco ASA has no DHCPv6 instance running. That is: there is no way to run an IPv6-only network because clients won’t get the DNS server. The security policy is capable of both protocols. Everything is configurable via the GUI, which is not the best at all.
Fortinet FortiGate
The FortiGate is the only firewall with a stateful DHCPv6 server. Great. However, two distinct security policies must be used and nothing of the IPv6 settings are configurable via the GUI. WHAT???
Juniper SSG (ScreenOS)
ScreenOS is dead. However, most of the IPv6 functions are working quite good, except the protocol dependent security policies. Everything is accessible via the GUI, but sometimes on confusing positions.
Palo Alto
Palo Alto did a good job on the IPv6 interfaces and security policies. The GUI is quite intuitive and the policy accepts both protocols at the same time. Unluckily, there is no DHCPv6 server which makes it impossible to operate an IPv6-only client network behind a Palo Alto (without further servers).
Conclusion
It’s interesting to see the differences between those firewalls. While the Fortinet und Juniper firewalls support the whole SLAAC process incl. DNS servers, they have no single security policy for both protocols and are horrable to configure.
The Palo Alto is quite good to configure but lacks the DHCPv6 server. Same for the Cisco.
In summary, all firewalls position in the middle of my scale. From an IPv6-only view, I cannot say which one is the best. It depends….
Originally published on blog.webernetz.net
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiGate
September 2026
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,924 professionals have used our research since 2012.
Customer Support engineer at a healthcare company with 51-200 employees
It helps to come up with the requirements of proxy servers, but it does not have that much troubleshooting & network testing features.
Pros and Cons
- "It is value for money product as we’ve purchased it with Fortinet's three-year warranty package."
- "The FortiGate series does not have that much troubleshooting and network testing features in its GUI, hence we’ll definitely be looking for some add-on features in near future."
What is most valuable?
The key features of this product are:
- Network security
- UTM Features
- Configuration and ease of deployment.
- IP/User/Device Mac ID/Device Type based policy configuration
- Traffic shaping
- Load balancing
- Ease of VPN configurations
- Explicit proxy
- Link segregation
- Application signatures
- Network object based HTTPS/SSL inspection etc.
How has it helped my organization?
In many organizations it helps to come up with the requirements of proxy servers, defining network traffic and the amount of bandwidth for any network object or specified user(s). It has also provided us with security compatibility with other network devices such as IP cameras, the video conferencing system, VOIP phones. It also logs & reports on individual users network activities.
What needs improvement?
The FortiGate series does not have that much troubleshooting & network testing features in its GUI, hence we’ll definitely be looking for some add-on features in near future.
For how long have I used the solution?
I have been using this solution for the past year.
What was my experience with deployment of the solution?
No issues yet.
What do I think about the stability of the solution?
No issues yet.
What do I think about the scalability of the solution?
For massive logs & reports (over a month) we have to go for a separate logging & reporting device i.e. FortiAnalyzer/FortiCloud, as this is not available in Fortigate itself.
How are customer service and technical support?
Customer Service:
7/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
We started with FortiGate itself.
How was the initial setup?
This product has a setup wizard (FortiExplorer) for the initial configuration, while the physical connectivity is done via a USB cable which is very easy to use.
What about the implementation team?
We implemented the solution ourselves.
What was our ROI?
It is value for money product as we’ve purchased it with Fortinet's three-year warranty package.
Which other solutions did I evaluate?
We have evaluated Dell’s Sonicwall & Cyberoam.
What other advice do I have?
Analyze your needs first before implementing this product.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Test Engineer with 501-1,000 employees
The product has lived up to its expectations but the web interface needs to be improved.
Pros and Cons
- "The product has lived up to its expectation with no issues whatsoever."
- "The web interface could be made better."
What is most valuable?
- Anti-virus
- NAT
- VPN
How has it helped my organization?
It's the only security product in place that is responsible for guarding the network infrastructure deployed within the premises. The product has lived up to its expectation with no issues whatsoever.
What needs improvement?
The web interface could be made better.
For how long have I used the solution?
I've used it for eight years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
How are customer service and technical support?
We have managed to maintain the device without getting in touch with technical support. Credit can be given to the documentation provided.
Which solution did I use previously and why did I switch?
This was the first security device that was deployed.
How was the initial setup?
Setup was straightforward and the documentation was very clear which meant that there were no issues during the initial setup.
What about the implementation team?
We had a vendor assist us who had decent knowledge about the product.
Which other solutions did I evaluate?
We also looked at pfSense.
What other advice do I have?
The product has reached its end of life.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at a real estate/law firm with 51-200 employees
It offers unlimited VPN licensing but it needs a real-time log viewer in the GUI.
Pros and Cons
- "We went from being terrified about our firewalls screwing up to completely forgetting we had firewalls."
- "Technical Support: This is where Fortinet stumbles. The support is farmed out overseas to techs that are not very knowledgeable about the Fortinet products."
What is most valuable?
The unlimited VPN licensing. All of our remote locations (1000+) used IPSec VPN and SSL to connect to the cluster.
How has it helped my organization?
We went from being terrified about our firewalls screwing up to completely forgetting we had firewalls. I slept better and so did my manager.
What needs improvement?
A real-time log viewer in the GUI with the capability to filter traffic displayed. Cisco ASA's have this and it's fantastic.
For how long have I used the solution?
I used it for four years. We had two devices that were clustered together in a high availability pair as the front end of an country wide, high visibility solution.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
Customer service was decent with Fortinet - they were helpful and got the product to our doorstep quickly.
Technical Support:This is where Fortinet stumbles. The support is farmed out overseas to techs that are not very knowledgeable about the Fortinet products. The response time for a critical priority one issue was over four hours and they only responded because we threatened legal action for them violating our support contract.
Which solution did I use previously and why did I switch?
They used to have Juniper products, which are terrible. The enterprise class firewalls do not support any sort of packetflow gathering such as netflow, and the devices didn't even support Juniper's proprietary jflow. Their SRX series routers, meant for home office use, had more features and capabilities.
How was the initial setup?
It was very straightforward and we encountered very little problems. Fail-over occurred within a second with zero outages or anyone actually taking notice. Firmware updates were easy to apply in a live environment if required, and the GUI was very easy to understand.
What about the implementation team?
I deployed it - I'm FCNSA certified.
What was our ROI?
If we used a similar solution that required a "per seat" license per VPN, we would have literally spent over 100x what the solution cost us.
What's my experience with pricing, setup cost, and licensing?
We implemented the clustered firewalls for around $30,000, and each office had another Fortigate device at a cost of around $1,000.
Which other solutions did I evaluate?
Cisco was evaluated but we didn't want to pay for the VPN licensing.
What other advice do I have?
It's an absolutely fantastic product. Just get your support contract clarified, and confirm the response times.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Security Engineer with 501-1,000 employees
It's excellent and we strongly recommend it, but WAN link load balancing needs improving.
Pros and Cons
- "Our experience of using Fortigate is excellent and we strongly recommend it."
- "We faced some technical issues on the Fortinet side."
What is most valuable?
I am using different features of this product but the most valuable are -
- SSL VPN
- Web filter
- Explicit proxy
- IPS
- Application control
- Routing
How has it helped my organization?
I replaced my core router with a Fortigate appliance and it is performing inter-VLAN routing. I removed manual proxies and used transparent proxy using Fortigate security profiles, and implemented traffic shaping, web filter, application control, IPS and anti-virus. All the servers are protected by Fortigate security profiles.
What needs improvement?
- WAN link load balancing
- Reports
- Anti-virus.
For how long have I used the solution?
I have been using this solution since 2013.
What was my experience with deployment of the solution?
We faced some technical issues on the Fortinet side.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
6/10.
Technical Support:6/10.
Which solution did I use previously and why did I switch?
I didn't use any other solution prior to Fortinet.
How was the initial setup?
It was complex because there was a huge network with VLANs configured and routing protocols enabled.
What about the implementation team?
We implement this through a vendor. I would rate their level of experience 8/10.
What was our ROI?
I would only say that Fortinet provides business and security returns at a cost substantially lower than the benefits derived.
Which other solutions did I evaluate?
We evaluated Sophos and Barracuda alongside Fortigate.
What other advice do I have?
Our experience of using Fortigate is excellent and we strongly recommend it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior NetOps Engineer at a tech services company with 51-200 employees
Security has been increased but the licensing fees could be lower.
Pros and Cons
- "The product is easy to implement, easy to manage, and easy to develop and grow."
- "I'm happy with the product, however the licensing fees could be lower."
What is most valuable?
- GUI
- Flexibility
- Easy to configure
- UTM
How has it helped my organization?
- Option to control application = increased productivity
- Data leak prevention = increased security
- Anti-virus & IPS = increased security
What needs improvement?
I'm happy with the product, however the licensing fees could be lower.
For how long have I used the solution?
I've used it for six years.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
There is a specific way of deploying a Fortigate product, and the scalability is related to the new unit deployment so there are no problems here. If you need more power/space, you just have to add a new box.
How are customer service and technical support?
Customer Service:
It's very good, I've never had any problems with customer service.
Technical Support:It's very good, I've never had any problems with technical support.
Which solution did I use previously and why did I switch?
I was using Cisco ASA, and I switched due to a lack of features (e.g. poor SSL VPN support).
How was the initial setup?
It's a very simple setup as everything is well documented online and via the Fortigate channel on YouTube. Also, I posses a large amount of knowledge gained during the years that has helped me to deploy all my solutions. Even from the the beginning, it was easy as Fortigate has a great GUI and good online help,
What about the implementation team?
We did an in-house implementation, with no third party involvement.
What was our ROI?
The product is deployed as part of, and an add-on to, the MPLS solution for the majority of my customers. There is no ROI as this is not the major expectation, as the ROI is coming from the whole solution, not just this product.
What's my experience with pricing, setup cost, and licensing?
All the costs are for the annual licenses. The cost of the original deployment fell below £5,000, and licenses are priced at around £3,000.
Which other solutions did I evaluate?
We considered Cisco, however we decided to go with Fortigate as it provides a good set of the features for the price paid,
What other advice do I have?
Enjoy it. The product is easy to implement, easy to manage, and easy to develop and grow.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IP Senior Engineer at a comms service provider with 501-1,000 employees
It offers stability, scalability and plenty of security features. Enjoy fast and effective troubleshooting as everything is organized in a very understandable way.
Pros and Cons
- "Throughout the last six years we have been using Fortigate firewalls, and the experience we gained is only positive."
- "Its web interface needs to be more stable, and more functional, through the variety of browsers."
What is most valuable?
- High Availability clustering
- SNAT/DNAT
- Policies section view
- Virtual Domains
- Logging and Reporting
- IPS
How has it helped my organization?
It has made our daily operations easier, as well as adding security, and stability to them. Adding or removing security policies is simplified through its web interface, or CLI. Additionally, troubleshooting is fast and effective, as everything is organized in a very understandable way.
What needs improvement?
Its web interface needs to be more stable, and more functional, through the variety of browsers. Additionally a nice add-on would be a “diagnostic sniffer” capability in the web interface.
For how long have I used the solution?
I've used it for six years.
What was my experience with deployment of the solution?
With different browsers, the web interface crashes. On newer versions of Fortios the problem has been minimized.
What do I think about the stability of the solution?
Not at all, it is as stable as it should be.
What do I think about the scalability of the solution?
I believe that it is a little complex adding new firewalls in an existing cluster.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:9/10.
Which solution did I use previously and why did I switch?
We are using different firewall solutions, in parallel with the Fortigate ones.
How was the initial setup?
It was straightforward. Taking control of the device for first time is easy, and the cookbook manual is very helpful.
What about the implementation team?
A vendor team offered five day training but the implementation was in-house.
Which other solutions did I evaluate?
We evaluated other solutions, but I was not responsible for taking the final decision.
What other advice do I have?
Throughout the last six years we have been using Fortigate firewalls, and the experience we gained is only positive. These devices are easy to manage, operate and troubleshoot any issues that might rise. The use of virtual domains has added more security presence by only having one physical device, and it’s easy to create them. Also, by enabling other security features on the VDoms, the physical performance will not be affected.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IP Core & Security Supervisor at a comms service provider
Web filtering is good but I can't allow traffic from outside to inside using a NAT pool.
Pros and Cons
- "Customer Service: They're good. Technical Support: They're very good."
- "I have an issue with NAT only, in that I can't allow traffic from outside to inside using a NAT pool."
What is most valuable?
- IPS
- Web filtering
How has it helped my organization?
We are making use of the VDOM feature to segregate the traffic, and apply policy to control that traffic.
What needs improvement?
This product can't show the NAT status or NAT logs.
For how long have I used the solution?
I've been using ForitGate for over two years alongside FortiManager 300D.
What was my experience with deployment of the solution?
I have an issue with NAT only, in that I can't allow traffic from outside to inside using a NAT pool.
What do I think about the stability of the solution?
There was a bug related to device stability with HA configuration. We face many attacks on the network which causes the CPU usage to become high and, with the older device, we started losing the heartbeat and control messages, causing HA split-brain and lag flapping.This issue has been fixed in the new release.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
They're good.
Technical Support:They're very good.
Which solution did I use previously and why did I switch?
No previous solution used.
How was the initial setup?
It was complex to setup.
What about the implementation team?
We used a vendor, ALU to help implement it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Infrastructure - Tech Specialist with 10,001+ employees
It has given me complete oversight of my network in a centralized fashion but certain features need improving.
Pros and Cons
- "Finally there is a UTM Fortinet. It has given me complete oversight of my network in a centralized fashion, so I know what is going on at all times."
What is most valuable?
- It's version of throughput is good
- It has a strong active cluster, as you can have between three and 32 units to a cluster
How has it helped my organization?
Finally there is a UTM Fortinet. It has given me complete oversight of my network in a centralized fashion, so I know what is going on at all times. It provides me with a solution that can automatically take control of situations when they arise, with the most intuitive interface. It stops you needing to be on the phone to tech support, or a local vendor, for days on end.
What needs improvement?
- Security
- LAN
- WAN
For how long have I used the solution?
I've used it for three years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:8/10.
Which solution did I use previously and why did I switch?
No previous solution was used.
How was the initial setup?
It was easy to set up.
What other advice do I have?
The most important factor is that you choose a firewall or UTM solution that fits your organizations security requirements. Begin by determining what business problem you are trying to solve, what technical controls you need to implement (Firewall, IPS, NAC, VPN, endpoint, mobility, web filtering, malware detection, etc.). Then, determine what hardware features you need such as (HA clustering, link aggregation or 10Gb, port sensity), and what kind of throughput, and how many concurrent connections.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Firewalls Secure Web Gateways (SWG) Intrusion Detection and Prevention Software (IDPS) Software Defined WAN (SD-WAN) Solutions WAN Edge ZTNA Unified Threat Management (UTM)Popular Comparisons
Cloudflare One
Cisco Secure Firewall
Darktrace
OPNsense
Netgate pfSense
Sophos Firewall
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Prisma Access by Palo Alto Networks
Cisco Umbrella
Zscaler Internet Access
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cato SASE Cloud Platform
Check Point Harmony SASE (formerly Perimeter 81)
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Looking Into Implementing a Web Security Solution.
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- We're trying to choose between Fortinet or Checkpoint UTM firewalls. Can you help?
- What Is The Biggest Difference Between Fortinet FortiGate and Meraki MX Firewalls?














The v5.6 GUI is much improved, IMO. Very happy to see the changes there. Some things are still a little hard to find, but not as many.