Choosing a FortiGate model: 40F, 60F, 90G or 100F?
The model number goes up and so does the price. But which one does your office actually need?
Taking over an existing FortiGate is a routine part of our work. The faults are remarkably consistent — which is encouraging, because it means they are all checkable in an afternoon.
The most common finding by a wide margin. Antivirus and IPS are enabled, the dashboard looks healthy, and the policy is using certificate inspection rather than deep inspection. Encrypted traffic — which is to say nearly all traffic — passes through unscanned.
Check: open each policy and look at the SSL/SSH Inspection profile. If it says certificate-inspection, content scanning is not happening on HTTPS.
During commissioning someone creates an allow-all rule to get things working, intending to tighten it later. Later does not arrive. Because policies evaluate top to bottom, everything below it is decoration.
Check: review the policy list in order. Any rule with source all, destination all and service ALL near the top makes the rest of the ruleset irrelevant.
A next-generation firewall protecting a network where the servers, the workstations, the guest Wi-Fi, the cameras and the production machinery all share one subnet. The firewall inspects traffic crossing the perimeter and sees nothing that moves internally — which is how ransomware actually spreads.
Check: count your VLANs. If the answer is one, that is the finding.
HTTPS management reachable from the internet, sometimes on the default port, occasionally with a default or shared password. Sometimes it was opened temporarily for a remote engineer and never closed.
Check: look at each interface's administrative access settings, and any virtual IP or policy that publishes the management port. Management should be reachable from the internal network or over VPN, and nowhere else.
Firmware updates are deferred because the appliance is working and nobody wants to risk an outage. Two years pass. The device is now missing fixes for vulnerabilities that are publicly documented and actively exploited.
Check: compare the running version against the recommended release for your model. Plan updates in a window with a configuration backup taken first — but plan them.
Logs written to local memory only, which means they survive until the next reboot and hold a few hours of history. When you need to establish what happened last Tuesday, there is nothing to look at.
Check: confirm where logs are sent — FortiAnalyzer, a syslog collector, or somewhere off the appliance. Also confirm NTP is configured; timestamps that disagree between devices make correlation impossible.
The security services keep running on the last signatures they received, so nothing visibly breaks. We have found appliances more than a year past expiry in businesses that believed they were fully protected.
Check: the licence status page on the dashboard. Then put the date somewhere that survives an employee leaving.
We audit existing FortiGate deployments regardless of who installed them, and report what we find in writing with findings ranked by risk. Where the configuration is sound we say so — that is a legitimate outcome and it happens.
There is no obligation to have us do the remediation. You can hand the report to whoever currently supports you.
Ask us about fortinet firewall installation, or request a free assessment directly.
The model number goes up and so does the price. But which one does your office actually need?
The appliance is a one-off purchase. The subscription is not — and what happens when it lapses surprises people.
If you are not inspecting encrypted traffic, you are inspecting almost nothing. Here is what it takes to do it properly.