- Complete and cost-effective next-generation firewall features with app identification, and IPS and URL filtering with SSL inspection.
Senior Security Consultant with 501-1,000 employees
They added a valuable WAF feature to the latest version.
Pros and Cons
- "ROI is very high, it has hands-down the best price/performance/features ratio in the market."
- "The tech support is not excellent; this is where Fortinet saves money compared to others... But plenty of free, clear and public documentation is available and this compensates for the most part the tech support shortcomings."
What is most valuable?
How has it helped my organization?
- Better manageability
- Straightforward deployments
- Streamlined and reliable upgrades
Customers have more time to focus on security because maintaining the firewalls is completely hassle-free.
What needs improvement?
Grouping/tabbing (not only by interface) in the policy table of the web GUI would be a great addition.
For how long have I used the solution?
I have used it for two years.
Buyer's Guide
Fortinet FortiGate
May 2026
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,244 professionals have used our research since 2012.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
What do I think about the stability of the solution?
We have not encountered any stability issues. Stability has dramatically improved over the previous main version branch of FortiOS; 5.2.x and 5.4.x are stable enough for critical environments.
What do I think about the scalability of the solution?
We have not encountered any scalability issues; proven that you properly sized the FortiGate model that fits your environment.
How are customer service and support?
Customer Service:
Customer service is sufficient.
Technical Support:The tech support is not excellent; this is where Fortinet saves money compared to others... But plenty of free, clear and public documentation is available and this compensates for the most part the tech support shortcomings.
Which solution did I use previously and why did I switch?
We previously used Cisco ASA. We switched because the old ASA has no next-generation features.
How was the initial setup?
IMHO It is the most straightforward enterprise-level next generation firewall.
What about the implementation team?
All implementations were done in-house.
What was our ROI?
ROI is very high, it has hands-down the best price/performance/features ratio in the market...
What's my experience with pricing, setup cost, and licensing?
The licensing model is straightforward, easy to understand and purchase; prices are fairly low compared to other vendors.
Which other solutions did I evaluate?
Before choosing this product, we also evaluated Check Point and Palo Alto Networks.
What other advice do I have?
In version 5.4, they added a WAF feature that is absolutely unique for this kind of product; no other NGFW product can also be a WAF and this is a great added value...
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Infrastructure Engineer at a tech company with 11-50 employees
FortiGate/FortiWiFi; FortiManager; FortiAnalyzer
Pros and Cons
- "Fortinet solutions are very easy to implement, proven, certified and tested."
- "They could improve vulnerability scanning."
What is most valuable?
FortiGate/FortiWifi:
- IPS
- Application control
- IPsec & SSL VPN
- Web filtering
- E-mail security
- Data leak prevention
- Wireless security and wireless controller
- Central antivirus (FortiClient)
- HW & SW token controller (FortiToken) etc.
- FortiManager
- Central management
- Administrative domains (can group devices according to geographical are, functionality, admins, etc.)
- FortiGuard management
- Logging and reporting
- Configuration version control and tracking
- Firmware management
- Scripting
- FortiAnalyzer
- Centralized security log analysis and forensics
- Centralized graphical reports
- Customized reports
- Scheduled reports
- Queries
- Content archiving/data mining
How has it helped my organization?
Routing and security policies, central management and all of the other features help us to improve network performance and implement organization policies.
What needs improvement?
They could improve vulnerability scanning.
For how long have I used the solution?
I have used it for three years.
What do I think about the stability of the solution?
We encountered a few stability issues; maybe one case per year.
What do I think about the scalability of the solution?
I did not encounter any scalability issues.
How are customer service and technical support?
Technical support is 10/10. They respond and offer solutions very fast.
Which solution did I use previously and why did I switch?
We previously used Cisco solutions. They are more expensive, have fewer features, are more difficult to use, and response and help from
technical support is not quick.
How was the initial setup?
For Fortinet solutions, the initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
They are very cheap compared to other vendors.
What other advice do I have?
Fortinet solutions are very easy to implement, proven, certified and tested.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Fortinet FortiGate
May 2026
Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,244 professionals have used our research since 2012.
ICT Manager at a aerospace/defense firm
Virtual domains are treated as separate firewall instances
Pros and Cons
- "You can create multiple Virtual Domains (VDOMs), which are treated as separate firewall instances."
- "The reporting you receive out of this appliance is excellent. You will not need an external management system."
- "The user interface is relatively easy. The devices are easy to deploy and figure out when you have experience with other security appliances."
- "The ROI is great, as these boxes are not that expensive compared to what they can do, their functionality, and the reporting you receive."
- "I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE."
- "There is one big configuration file with no separations for the unique VDOMs. Maybe they could separate individual VDOM configuration files with the root VDOM configuration file referencing the individual VDOM config files."
- "I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE."
How has it helped my organization?
There is no need to buy physical firewall hardware when you host multiple customers requiring individual secure access to their FW. You just create virtual domains (VDOMs).
What is most valuable?
You can create multiple Virtual Domains (VDOMs), which are treated as separate firewall instances. The reporting you receive out of this appliance is excellent. You will not need an external management system.
What needs improvement?
1. sFlow and NetFlow
I could not configure sFlow from the FortiGate graphical user interface. I realized that the sFlow configuration is available only from the CLI, and discovered that sFlow is not supported on virtual interfaces, such as VDOM links, IPsec, or GRE.
NetFlow is a network protocol developed by Cisco for collecting IP traffic information and monitoring network traffic. It is not supported on FortiGate for those who have a NetFlow analyzer/collector already setup in their network.
2. Policies
To control traffic in a firewall, you need to create and apply policies to the FW interfaces. By default, policies are sorted by FW interfaces and this makes FW interfaces an integral part of the policies. Zones provide the option to logically group multiple virtual and physical FortiGate firewall interfaces. Then, you apply security policies to those zones (logical groups of interfaces) to control traffic flow on those interfaces.
In a FortiGate unit with a lot of interfaces (including virtual interfaces), there is a high probability of having duplication of policies.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
These devices are very stable.
What do I think about the scalability of the solution?
They are easily scalable with multiple built-in interfaces. It supports a minimum of 10 VDOMs. VDOM supports all dynamic routing protocols like RIP, OSPF, BGP, and IS-IS. You do not need to reboot after enabling the VDOMs.
Area for improvement - there is one big configuration file with no separations for the unique VDOMs. Maybe they could separate individual VDOM configuration files with the root VDOM configuration file referencing the individual VDOM config files.
How are customer service and technical support?
Customer Service:
Customer service is great, an eight out 10.
Technical Support:
I will give technical support an eight out 10.
Which solution did I use previously and why did I switch?
We previously used different solutions as well. We did not switch, we have different requirements for different customers.
How was the initial setup?
The user interface is relatively easy. The devices are easy to deploy and figure out if you have experience with other security appliances.
What about the implementation team?
It was an in-house installation.
What was our ROI?
The ROI is great. These boxes are not that expensive compared to what they can do, their functionality, and the reporting you receive.
What's my experience with pricing, setup cost, and licensing?
Fortinet licensing is straightforward and less confusing compared to Cisco. Fortinet has one or two license types, and the VPN numbers are only limited by the hardware chassis make.
Which other solutions did I evaluate?
I already have experience with Cisco ASA, so it was simply a customer preference and well within the budget.
What other advice do I have?
Great appliances, and it is affordable.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Dëvóps Engineer at a tech company with 51-200 employees
Fortigate is only cheap if you don't value your time or product quality
I have had the displeasure of having to support SOHO Fortigate offerings (Fortigate/Fortiwifi). in almost any measure, I have found these products inferior to respective solutions from cisco and juniper (two examples i've had experience with).
I'll start with the most egregious and disturbing: the product is unstable. the VPN client is crash prone and the VPN daemon is crash prone. if you want to enjoy having to drive to the office when the roads are iced because the VPN daemon just gave up the ghost again, just to reboot a unit, by all means - choose Fortigate.
I'll continue with support - pretty much a joke, although being fair here, it is similar in other respective products. by the time a competent engineer reviews your case, you may have to wade through more than a month of back and forth with t1/t2 support who offer very little usable assistance.
And final insult to injury - aggressive and clueless resellers. Fortigate tries to distance themselves from customers via resellers (as if support filtering wasn't enough). getting the wrong product or wrong configuration is very common, especially with unneeded packages.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Everyone writes basing on his own experience.
In this specific case (and I hope that it does not disturb you) would divide your review in two parts.
I agree with your complains regarding support.
My impression is that Fortinet prefers to delegate a big part of the problems to its reseller channel.
From then on, it is a simple matter of luck to find a company that is competent and able to help or not (I have found more often the second kind).
As you pointed out, it is not a different scenario from the one you have with other vendors, but it did NOT constitute a justification.
I do not use SOHO appliances (or not as often as you) so maybe they are not good as you noticed.
Again, probably the SOHO market, based on low prices - low quality is full of products that are not worth our time, not only the Fortinet's one.
Said so, I disagree from you about the Fortigate family of products to be not good as a whole. Their medium/high level appliances are so good (and so rich in features) that is really hard to find something like it on the market.
We are talking about UTM devices, able to replace what other vendors do with a lot of different pieces. They are not hard to configure (of course, it is not something for "newbies") and reliable.
I keep up networks with thousands of geographically dispersed users with no issue at all, and using only FortiGate appliances.
So, let me add (based on my experience, this time): support is not good. The high-end appliances from the FortiGate family are really good.
IT NETWORK ENGINEER at a energy/utilities company with 501-1,000 employees
The most valuable features for us are VPN, WebFilter, and Firewall.
Pros and Cons
- "It's features are highly customizable."
- "I'd like to see an improvement in the Bandwidth Management and Traffic limit control. Also, the licenses are expensive, turning off some users."
What is most valuable?
The most valuable features for us are
- VPN
- WebFilter
- Firewall
How has it helped my organization?
It's features are highly customizable. This means that when our different business groups have different needs, the implementations can be customized to meet the demands of those groups and needs.
What needs improvement?
I'd like to see an improvement in the Bandwidth Management and Traffic limit control.
Also, the licenses are expensive, turning off some users.
For how long have I used the solution?
We've used all units for five years, except the FortiGate 200D which has been in use for one year. Alongside FortiGate, we also have FortiAnalyzer 1000B and the FortiManager 200D.
What was my experience with deployment of the solution?
There have been no issues with the deployment.
What do I think about the stability of the solution?
There have been no stability issues.
What do I think about the scalability of the solution?
It has not been a problem to scale it.
How are customer service and technical support?
Customer Service:
Customer service is very good.
Technical Support:Technical support is very good.
Which solution did I use previously and why did I switch?
I depend on different products from different vendors depending on the required function.
How was the initial setup?
The initial setup is simple in the CLI or Web GUI.
What about the implementation team?
An in-house network engineer implemented it using the best practice recommendations from the vendor.
What's my experience with pricing, setup cost, and licensing?
The appliances and licenses are expensive, and I know some people use other vendors because of this.
What other advice do I have?
You should know the customization you want from the beginning, and plan your requirements appropriately.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
How would the improvements within bandwidth management impact your User Experience/productivity?
Network Engineer at a tech services company with 501-1,000 employees
I could achieve the same results with a software firewall. This one comes in a nice hardware package. Using the CLI should be documented better.
Pros and Cons
- "I never encountered any stability issues; it is a very stable product."
- "Sometimes it's super hard to figure out what's wrong with a FortiGate VPN unless you know the commands on the CLI to see the flow and how to interpret it."
What is most valuable?
- Flexibility
- Flow tracking
- B2B VPN
How has it helped my organization?
It's good for what it is. I could achieve the same results with a pfSense firewall. This one just comes in a nice hardware package.
What needs improvement?
Better documentation about usage of the CLI. I learned most of what I know in diagnostic functionality through saving SSH sessions with the customer support staff while in WebEx sessions.
I have tried looking up the manuals. They are OK in some respects, but I feel exhaustive documentation about the CLI "with examples" should be there, and I feel it's not.
I'm saying, hey lets consolidate some of the primary real world scenarios like:
Section A: - Troubeshooting B2B VPN peering with a business partner or client when initially setting up the VPN tunnel.
Inevitably, there are always quirks and nuances between the fortigate vendor versus peering with a Palo Alto or an ASA firewall or even a Juniper SSG.
Imagine providing all steps, command line syntax, and GUI (if available) and how to take steps to debug the flow and see what's failing.
Sometimes it's super hard to figure out what's wrong with a fortigate VPN unless you know the commands on the CLI to see the flow and how to interpret it.
If they had all the methods / syntax and the "how's and why's" for a scenario; even possibly an instructional video showing how via the CLI and gui alongside the documentation. It would be like the pearly gates had opened and I had gone to heaven.
For how long have I used the solution?
I have used it for three years.
What do I think about the stability of the solution?
I never encountered any stability issues. It is a very stable product.
What do I think about the scalability of the solution?
Scalability's not been an issue for my org. We only utilize it for certain applications.
How are customer service and technical support?
Technical support is excellent, although it can be a bit difficult to understand the tech. As with most support staff from almost all vendors now, the support comes from somewhere across the pond.
Which solution did I use previously and why did I switch?
On the site where the FortiGate is stationed, it's never been changed out.
How was the initial setup?
Initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Buy the support package! Upgrades, advice about upgrade paths, and troubleshooting help is paramount. There have been some times where, without it, I'd have been dead in the water.
Which other solutions did I evaluate?
This was an in-place firewall when I integrated the site to my org.
What other advice do I have?
Figure out what features you want, and what policies you want. Look up how to do it in advance, and create an implementation plan.
Plan for policies, routing, NATting, etc. Create a step-by-step process in advance, possibly create the environment in a DEV sandbox, test it, then implement.
It has a good feature set. However, sometimes you are forced to solicit technical support to get it working.
Also, I find the web interfaces sometimes do not display things properly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Andrew S. Baker (ASB)Cybersecurity & IT Operations Professional (VirtualCxO) at a tech services company with 1-10 employees
Top 20Consultant
Great review. I was going to disagree with you about the CLI documentation, but I found that the examples are really missing for the common use cases, as you stated, so I had to agree.
The cookbook is getting better, but it's not yet comprehensive enough. Very good platform.
I also wish there were elements that you could rename without having to reload an entire config, but I am happy that you can easily search/replace a config and then replace it.
-ASB
Security Analyst at a tech services company with 10,001+ employees
The UTM (application control) features have solved many issues that other firewall providers cannot, such as Google suite blocking and allowing.
Pros and Cons
- "The UTM (application control) features have been very important, because they have solved many issues that other firewall providers have not developed as Fortinet has."
- "They could improve performance with all the UTM features working. Sometimes, we have seen that when you enable the antivirus sensor, customers report slow web browsing."
What is most valuable?
The UTM (application control) features have been very important, because they have solved many issues that other firewall providers have not developed as Fortinet has.
A clear example of this feature advantages is blocking and allowing the Google suite. For example, without UTM, we would not have been able to execute some customer requirements like this one:
A customer asked us that some host on their LAN is going to be assigned to be a POS workstation. They needed that workstation to have permissions to some applications and some URLs, and they needed to block users from opening sites like YouTube, Google+, and Google Drive, but they needed to get in to some POS URLs hosted in the Google cloud. We were working with rules allowing some specified URLs, but it didn’t work because the subnetting IP address the customer needed to be allowed, sometimes matched the YouTube service. Google support engineers told us they rotate their IP addressing subnets to be more secure and they do not always attach an IP address to a domain name. So, sometimes the customer’s workstations were able to open YouTube sites too.
The way we could block YouTube and allow the customer POS URLs sites, was by configuring an application control sensor, where we were able to block some categories like this:

Another requirement was to allow some specified applications, so we configured the next sensor structure:


Another customer reported to us they had issues working with Gmail attachment files; they could not do it. Executing some packet captures and with the Fortinet TAC help, we found they were using the latest Chrome versions that use the QUIC Google protocol, which is not supported by Fortinet because it is not a valid protocol. We proceeded to block the QUIC protocol using an application control sensor.
After this blocking action, the customer was able to work without any issue.
How has it helped my organization?
It can block applications in level 7.
Even though other companies have latest-generation firewalls, FortiGate’s database is bigger.
What needs improvement?
They could improve performance with all the UTM features working.
Sometimes, we have seen that when you enable the antivirus sensor, customers report slow web browsing. We know this is normal, but we would like to know if it is possible to make feel the customer their web browsing is fast with not as much delay. The antivirus sensor analyzes all the protocols and packets we specified, and this is an important performance affectation. In my personal point of view, I don’t think it is a serious issue, but we receive many reports from users who browse the web with antivirus sensors applied to their firewall policies.
For how long have I used the solution?
I have been using it for seven years.
It is working in route mode, with all UTM licences active; it has FSSO configured to give permission to the users. It is configured to provide VPN SSL service.
What do I think about the stability of the solution?
I have encountered stability issues only when we enable all the UTM features.
What do I think about the scalability of the solution?
I have not encountered any scalability issues.
How are customer service and technical support?
Technical support is 9/10.
Which solution did I use previously and why did I switch?
We have been using FortiGate solutions for eight years. We have been upgrading when solutions in the family become unsupported.
How was the initial setup?
The initial setup is easy; no issues with doing it.
Which other solutions did I evaluate?
My company did not evaluate other options. They decided to purchase FortiGate directly.
What other advice do I have?
Work a lot with all of the UTM features because they can be very helpful right now with configuring firewall policies. The policies became very whole.
Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a Fortinet provider for Mexico.
Hamza, I think you may find our product comparison between Checkpoint and Fortigate interesting:
www.itcentralstation.com/products/comparisons/check-point-utm-1_vs_fortinet-fortigate
IT Manager at a tech vendor with 501-1,000 employees
We were able to prevent the use of torrent applications. They need to improve the alert and event logs.
Pros and Cons
- "With the application and web filters, we were able to block social network websites and any other websites that could lead staff being less productive."
- "I feel they need to work on the alert and event logs."
What is most valuable?
With the application and web filters, we were able to block social network websites and any other websites that could lead staff being less productive. We were able to stop use of VPN applications on the school’s network. We were able to prevent the use of torrent applications.
How has it helped my organization?
It was used in a school network, so it kind of helped in preventing staff and students from getting carried away with their browsing.
What needs improvement?
I feel they need to work on the alert and event logs. We were not able to get anything much out of it when we were facing issues. Not sure if it was a configuration issue; we were, in fact, not able to see any system-related logs.
For how long have I used the solution?
I used it for two years. I had to replace it as the number of staff increased to beyond its limit.
What do I think about the stability of the solution?
We did have an issue with it hanging occasionally. But then later, we figured out that it was handling traffic beyond its limit.
How are customer service and technical support?
Technical support is average.
Which solution did I use previously and why did I switch?
This was the first device we used.
How was the initial setup?
It was installed by the IT solution provider while setting up the school.
What other advice do I have?
It is a good device for a medium-sized company. But if you have over 150 staff/devices, I wouldn’t advise using this.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Firewalls Secure Web Gateways (SWG) Intrusion Detection and Prevention Software (IDPS) Software Defined WAN (SD-WAN) Solutions WAN Edge ZTNA Unified Threat Management (UTM)Popular Comparisons
Netgate pfSense
Sophos Firewall
OPNsense
Darktrace
Cisco Secure Firewall
Cloudflare One
Cisco Umbrella
Prisma Access by Palo Alto Networks
Zscaler Internet Access
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cato SASE Cloud Platform
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Looking Into Implementing a Web Security Solution.
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- We're trying to choose between Fortinet or Checkpoint UTM firewalls. Can you help?
- What Is The Biggest Difference Between Fortinet FortiGate and Meraki MX Firewalls?














Hi Becky. I chose Fortigate mainly because it provides the capabilities to provide logical separate firewall instances to multiple customers. These logical firewall are know as VDOMs. I have the partitions the physical fw devices to multiple logical units thus saving costs.