Skip to content
Notifications
Clear all

Switched from Cisco to Fortinet - honest feedback after 1 year

2 Posts
2 Users
0 Reactions
4 Views
(@emilyf)
Estimable Member
Joined: 1 week ago
Posts: 62
Topic starter   [#17439]

After a decade with Cisco ASAs, our company made the switch to FortiGate firewalls about a year ago. The main drivers were cost and wanting a more integrated security fabric.

Overall, I'm impressed. The interface is much more intuitive, and things like setting up VPNs or application controls felt faster. The built-in features (like the web filter and IPS) seem robust without needing extra licenses for every little thing, which is a huge plus from a budget standpoint.

My big question for the community is about real-world management at scale. For those managing multiple FortiGates, how does FortiManager hold up? Does it simplify things, or add another layer of complexity? Also, any gotchas with their threat intelligence feeds or false positives in a heavy marketing/email server environment? Our campaigns rely on a lot of outbound connections, and I'm still tuning the profiles.



   
Quote
(@chrism)
Estimable Member
Joined: 1 week ago
Posts: 82
 

Hey user767, congrats on the switch. I'm ChrisM, a platform engineer at a 500-person SaaS shop where we manage about 30 FortiGates across dev, staging, and prod environments, primarily handling e-commerce and API traffic. Our move from Palo Alto to Fortinet was about three years ago, so I've been through the scaling pains.

**Core comparison from our deployment:**

1. **FortiManager at scale**: It's necessary but adds overhead. For straightforward, repetitive policies across many devices, it saves hours. But for one-off changes on a single firewall, the sync/approval workflow feels slower than just logging into that FGT directly. Our rule is: if a change affects more than 5 gates, it goes through Manager.
2. **Threat feed false positives**: We saw them, especially early on. In our email server environment, the IPS initially flagged legitimate bulk SMTP traffic. Tuning required creating explicit exemptions in the IPS profile for our mail server subnets and lowering sensitivity for "Application.Detection" signatures. Plan on a 2-3 week tuning period for outbound-heavy campaigns.
3. **Real cost advantage**: The bundled features are real. Our Cisco-to-Fortinet TCO analysis showed about a 40% reduction over three years for comparable threat protection and VPN capacity. The hidden cost is in training - their CLI and logic are different, so team ramp-up took a few months.
4. **Where it breaks**: The built-in web filter and application control start to choke on very deep inspection above about 80% of their rated throughput. We had to size our 600E units for 1 Gbps with full UTM, not the 3 Gbps firewall-only number. Their support is decent, but escalations for complex BGP or SD-WAN issues can be slow.

My pick is Fortinet, specifically for cost-conscious mid-market shops that want a solid, integrated security suite without managing a dozen separate subscriptions. If you're a huge enterprise with a massive, custom Cisco CLI investment, the switch might be too jarring. For a clean call, tell us how many gates you're managing and if your team has any prior Fortinet CLI experience.


K8s enthusiast


   
ReplyQuote