Most networks are not insecure because somebody bought the wrong firewall. They are insecure because the firewall, the switches, the wireless and the VPN came from four vendors, log to three places, and nobody owns the seam between them.
Fortinet's argument is that those pieces should be one system. Ours is that the system still needs somebody to run it.
Where Fortinet actually earns its place
The branch office nobody has looked at since it opened
A FortiGate at each site, managed centrally, means the small office with no IT presence gets the same policy as headquarters — and you find out about a problem there before the people working in it call you.
SD-WAN, when the MPLS bill stops making sense
Fortinet builds SD-WAN into the firewall rather than selling it as a separate appliance. For multi-site organizations that means link failover, application steering and cost control without another box and another license at every location.
Wireless and switching that inherit the firewall's policy
FortiAP and FortiSwitch are managed from the FortiGate itself. A device that misbehaves on wireless is subject to the same rules as one on the wired network, without maintaining two policy sets that quietly drift apart.
Regulated environments that must show their working
FortiAnalyzer produces the reporting that CMMC, NIST 800-171 and HIPAA conversations eventually demand. Logs that exist only on the device are not evidence.
What we actually do with it
Buying Fortinet is straightforward. Configuring it so it does what you assumed it did is where engagements go wrong.
- Design and sizing — throughput with inspection enabled, not the datasheet number that assumes everything is switched off.
- Migration — moving from an incumbent firewall without a weekend outage, and without silently carrying over rules nobody understands.
- Managed firewall — patching, firmware, rule review and change control as an ongoing service rather than a project that ended.
- Monitoring — FortiGate telemetry into our 24/7 Security Operations Center, so an alert reaches a person.
- Rule hygiene — the any-any rule somebody added in 2021 for a migration that finished in 2021.
Honest trade-offs
Fortinet is not the right answer everywhere, and pretending otherwise wastes everyone's time.
It rewards consolidation. The value comes from running the fabric — firewall, switching, wireless, analytics. One FortiGate alongside four other vendors is just a firewall, and you can buy a good firewall from anyone.
The interface has depth. That is a strength once configured and a liability if it is left to someone who touches it twice a year. This is precisely why most of our Fortinet clients take it managed.
Licensing needs planning. Bundles differ substantially in what inspection they permit. Sizing on price alone is how organizations end up disabling the features they paid for because throughput collapsed.
Common questions
We already have a firewall. Is it worth changing?
Usually not on its own. It becomes worth it when the firewall is out of support, when you are adding sites, or when you are maintaining separate wireless and switching management that could collapse into one.
Can you manage a Fortinet estate we already own?
Yes. We take over existing deployments regularly. The first step is a rule and firmware review — that alone tends to surface a few things worth knowing.
Do you resell, or just manage?
Both. We are a Fortinet partner and can supply hardware and licensing, but we will also manage kit you bought elsewhere.
How does this fit with the rest of our stack?
Fortinet handles the network edge. Backup and recovery is typically Acronis, endpoints are covered by managed detection and response, and identity sits with Microsoft 365. The point of a single provider is that the seams between those are somebody's job — ours.