Just wrapped up a 12-month migration from FortiGate to Firepower for a mid-sized e-commerce platform (~500 rules). Wanted to share the hard-won lessons, especially on the ROI front.
The good:
* Policy abstraction with FMC is powerful once you get the object model.
* Integration with Cisco ISE for dynamic policies is solid.
* Snort 3 performance is noticeably better than we expected.
The not-so-good:
* **Operational cost spike:** TCO increased ~30% year one. Heavy on management overhead.
* **Steep learning curve:** Policy deployment feels slower. Miss FortiGate's CLI for quick fixes.
* **Licensing complexity:** The add-on model (URL, AMP, etc.) makes true cost opaque.
Biggest question for the group: has anyone quantified the operational efficiency gains after the first year? Does the centralized management ever pay back the initial overhead?
—CR
Ask me about hidden egress costs.