Skip to content
Notifications
Clear all

Migrated from Fortinet to Cato Networks - 6 month report on a 200-user shop

1 Posts
1 Users
0 Reactions
5 Views
(@adrianm)
Trusted Member
Joined: 1 week ago
Posts: 50
Topic starter   [#3302]

Hello everyone, and thanks for having this community. I've learned a lot from lurking here. I wanted to share our team's experience after migrating from a Fortinet FortiGate setup to Cato Networks about six months ago. We're a ~200 user company with two offices and a growing number of remote staff.

The initial driver was simplifying our SD-WAN and security stack, which had become a bit of a patchwork. With Fortinet, we were managing separate firewalls, VPN concentrators, and a web filter. The move to Cato felt like a major shift in philosophy: instead of managing boxes, we're now managing a cloud service. The onboarding process was surprisingly smooth. Cato's SASE client deployment was far less painful than our old IPSec VPN client, especially for our less technical staff.

After six months, the biggest wins are in operational overhead and visibility. Having a single pane of glass for firewall, SD-WAN, and threat prevention across all our sites and remote users is a game-changer. I no longer have to log into separate systems to trace an issue. The policy management is very intuitive—being able to apply a security policy to a user or application that follows them, regardless of location, is something we just couldn't do effectively before.

It's not all perfect, of course. The transition required rethinking some of our network assumptions. For instance, advanced routing scenarios that were handled on the FortiGate now need to be approached differently within Cato's architecture. Also, while the Cato client is reliable, we had a small learning curve for some of our power users who were accustomed to the granular control of the Fortinet VPN client. The cost model is also different; it's OpEx vs. CapEx, which was a plus for us, but requires a different kind of budgeting.

Overall, we're very happy with the decision. The reduction in alert noise and the consolidated management have freed up a lot of my time for other projects. For teams steeped in traditional firewall CLI, it's a different world, but the trade-off in simplicity and unified security has been worth it for us. I'm curious to hear if others have had similar (or different!) journeys.


still learning


   
Quote