Ran FortiSASE for our 50 devs & IT staff for half a year. Just ripped it out.
The pitch: unified security fabric, single pane of glass, blah blah. Reality for a small team?
* The "single pane" is a stained-glass window of complexity. Need to tweak a ZTNA rule? That's 3 different policy objects across 4 menus. Not "single."
* Agent fights. Constant. The FortiClient is a needy little beast. Conflicts with other endpoint tools, random drops, user complaints skyrocketed.
* Cost vs. actual need. We're mostly cloud. Paying for a full-blown SASE when we really just needed solid ZTNA and DNS filtering. Overkill tax is real.
If your "zero trust" journey is just starting, and your team is lean, this feels like buying a Formula 1 car to get groceries. Heavy, expensive, and you'll spend more time maintaining it than driving.
Switched to a combo of Cloudflare Zero Trust (Tunnels/Access) and plain old Terraform-managed NACLs. 80% less headache, 60% less cost. Fortinet's model is still firewall-thinking wrapped in cloud buzzwords.
Fight me.
FinOps practitioner at a 200-person SaaS shop, mostly AWS with a dash of GCP. We run Cloudflare Zero Trust for access and use Terraform for network controls. Evaluated FortiSASE about 18 months ago for a 60-person remote team, passed on it after a month of POC.
- Fit: FortiSASE is built for orgs that already have a Fortinet firewall stack and want to extend that same policy model to remote users. If you're not already married to the FortiGate ecosystem, you're paying for integration overhead you don't need. For a 50-person cloud-first team, it's overkill squared. Cloudflare Zero Trust is designed for cloud-native, by-cloud-native teams. No legacy baggage.
- Real pricing: FortiSASE quotes I saw for 50 users landed around $14-18/user/mo for the mid-tier with ZTNA and basic SWG. That's before you add the FortiClient license (another $4-6/user/mo if you want the telemetry that actually makes the "single pane" work). Cloudflare Zero Trust Access + Gateway runs $7-10/user/mo all-in, and the agent is free. The hidden cost with FortiSASE is the time you spend untangling policy objects -- I'd estimate 2-3 hours per week for a team of your size just to keep the rule base from becoming a knot.
- Deployment and integration: FortiSASE wants you to deploy their connector in your VPC, then configure tunnel endpoints, then sync policies across three separate object types (users, groups, rules). It's not hard, but it's not fast. Cloudflare Zero Trust is a DNS change and a lightweight agent deploy. The Tunnel part for private apps is a single docker container or binary. I had a proof of concept running in an afternoon. We were in production within two days.
- Where it breaks: FortiClient is a memory hog. On my team's MacBooks it would regularly spike to 400MB+ and cause kernel panics after updates. The policy sync lag is real -- I've seen changes take 10-15 minutes to propagate to the agent. And the ZTNA logging is a mess: you need to correlate events from three different dashboards to figure out why a user can't connect. Cloudflare's logs are a single query away.
- Where it wins: If you have a physical FortiGate at the office and need to extend the same IPS/AV inspection to remote users, FortiSASE is the only way to get that without a second vendor. Their SWG has better URL categorization than Cloudflare's Gateway (for now). But for a "mostly cloud" team, that's a niche advantage.
My pick: Cloudflare Zero Trust for any team under 100 people that's cloud-first and doesn't have a Fortinet firewall already. The cost saving alone is worth it, and the admin overhead is a fraction of what you've described. If you're forced to keep a FortiGate for compliance reasons, FortiSASE might make sense, but otherwise you're burning money and time.
What's your actual split between cloud and on-prem infrastructure? That's the one detail that could flip the recommendation.
Cloud costs are not destiny.