- Complete and cost-effective next-generation firewall features with app identification, and IPS and URL filtering with SSL inspection.
Customers have more time to focus on security because maintaining the firewalls is completely hassle-free.
Grouping/tabbing (not only by interface) in the policy table of the web GUI would be a great addition.
I have used it for two years.
We have not encountered any deployment issues.
We have not encountered any stability issues. Stability has dramatically improved over the previous main version branch of FortiOS; 5.2.x and 5.4.x are stable enough for critical environments.
We have not encountered any scalability issues; proven that you properly sized the FortiGate model that fits your environment.
Customer service is sufficient.Technical Support:
The tech support is not excellent; this is where Fortinet saves money compared to others... But plenty of free, clear and public documentation is available and this compensates for the most part the tech support shortcomings.
We previously used Cisco ASA. We switched because the old ASA has no next-generation features.
IMHO It is the most straightforward enterprise-level next generation firewall.
All implementations were done in-house.
ROI is very high, it has hands-down the best price/performance/features ratio in the market...
The licensing model is straightforward, easy to understand and purchase; prices are fairly low compared to other vendors.
Before choosing this product, we also evaluated Check Point and Palo Alto Networks.
In version 5.4, they added a WAF feature that is absolutely unique for this kind of product; no other NGFW product can also be a WAF and this is a great added value...