Just finished a two-year slog with Meraki MX firewalls. The "set and forget" promise felt more like "pay and forget" – forget about real logging, forget about granular policy, forget about controlling your own destiny without a credit card. So we jumped ship to FortiGate, specifically the 600E series.
The control is, as advertised, phenomenal. Policy-based NGFW features that actually work, a CLI that doesn't feel like an afterthought, and a TCO that doesn't induce a panic attack. But my god, the UI. It's like they handed the GUI project to a different engineering team every six months for the last decade and told them never to speak to each other.
* Want to see all policies affecting a specific subnet? Good luck. The "Where Used" search is anemic compared to Meraki's visual dependency map.
* The dashboard is a chaotic mess of widgets begging to be "customized," yet half of them show data you'll never need.
* Simple tasks like creating an address object feel like navigating a maze where every door is labeled "Network," "Policy & Objects," and "Security Profiles," with zero intuition about which one holds the right form.
I'm not mourning the Meraki dashboard, which was a glossy brochure hiding how little you could actually do. But Fortinet seems to have taken the opposite extreme: unimaginable power buried under layers of inconsistent menus and bizarre organizational logic. It feels like the UI was designed by someone who has never had to troubleshoot a misbehaving policy at 3 AM.
Has anyone else made this switch and found a sane way to navigate this? Are we just destined to live in the CLI, or are there hidden workflows that make the FortiGate GUI tolerable for day-to-day management beyond initial setup?
Question everything.
At my last shop we ran both Meraki MX and FortiGate side-by-side across ~15 sites, so I've felt this exact pain. We were a 400-person SaaS shop with a hybrid cloud stack.
* **Total Cost of Ownership:** FortiGate wins on hardware cost. A comparable FortiGate 600E was about 40% less upfront than the Meraki MX we quoted. But factor in labor. FortiGate's UI complexity means your first few configs will take 3-4x longer than on Meraki. You're trading subscription fees for engineering time.
* **Operational Clarity:** Meraki's UI wins for visibility. Finding a policy path is intuitive. On FortiGate, even with the Security Fabric topology view, tracing policies for a subnet often meant manual CLI checks (`diagnose firewall iprope`). The dashboard data is overwhelming; we ended up building our own Grafana dashboards from FortiAnalyzer logs.
* **Deployment & Change Speed:** Meraki is faster for greenfield or simple changes. Pushing a new site live took an hour. With FortiGate, that same site took a half-day for initial base config (zones, policies, security profiles). However, bulk changes via FortiManager's CLI templates later were more powerful.
* **Where It Breaks:** FortiGate's UI consistency is the real limitation. Settings are scattered across menus ("Network" vs "Policy & Objects"). Creating a simple VIP can require steps in three different sections. Meraki's limitation is the black box. You hit a bug or need a detailed packet trace, and you're stuck waiting on support with no CLI to self-serve.
For a centralized team that can absorb the learning curve and needs deep control, I'd stick with FortiGate. If you have a lean team or distributed sites managed by generalists, the operational simplicity of Meraki is worth the premium. Tell us your team's size and how often you change firewall rules.