Just finished my quarterly platform rotation, this time ditching the FortiGate 60F we’d been running for about 18 months in favor of a Meraki MX68. The trigger? My sales team’s constant nagging about “unclear” firewall denials slowing down demo environments.
The promised FortiGate logging depth always felt like a theoretical benefit. In practice, trying to trace why a specific SaaS tool was being blocked meant jumping between the Event Log, Security Log, and Traffic Log, each with its own quirks. The sheer volume is impressive, but correlating events feels like a manual archaeology project. Need to see if that blocked outbound call to an API was related to a policy change? Good luck.
Meraki’s logging is… different. It’s almost superficial by comparison, but that’s the point. The dashboard just tells you “Thing X was blocked by rule Y at this time” in a single, clean stream. For my use case—where I need to quickly unblock something for sales or confirm a security policy is working—it’s faster.
* **FortiGate:** Deeper forensic data, but requires you to know which log table to mine. The CLI is where the real detail lives, which is a non-starter for most of my team.
* **Meraki:** Integrated, simple timeline. The search is actually usable by a non-specialist. The trade-off is you lose packet-level details and some granular event codes.
So, “better” depends entirely on who’s looking. For a security analyst who needs the full packet capture? FortiGate, no contest. For a sales ops person managing a remote team who just needs to know what’s broken and how to fix it fast? Meraki’s approach is less daunting.
I’m already wondering what I’m missing, though. Anyone else made this jump and regretted the loss of depth, or found Meraki’s event logging sufficient for compliance/auditing?