Home  /  Blog  /  Fortinet

FortiGate licences explained: UTM, ATP and Enterprise

The appliance is a one-off purchase. The subscription is not — and what happens when it lapses surprises people.

Buying a FortiGate is two purchases, not one: the hardware, and a subscription that keeps the security services fed with current threat data. The second one is where most of the confusion — and most of the unpleasant surprises — live.

What works without any subscription

An unlicensed FortiGate is not a paperweight. It still performs:

  • Stateful firewalling and NAT
  • VLAN routing and segmentation
  • IPsec and SSL VPN
  • SD-WAN link steering and failover
  • Traffic logging and basic reporting

For a very simple site this is genuinely enough. What you do not get is anything that depends on knowing about threats discovered since the firmware shipped.

What the subscription adds

The paid services are the ones that need continuous updates from Fortinet:

  • Antivirus — inspecting files in transit against current signatures
  • IPS (intrusion prevention) — detecting exploitation attempts against known vulnerabilities
  • Web filtering — category-based blocking, which needs a constantly updated site database
  • Application control — recognising applications by behaviour rather than port
  • DNS filtering — blocking malicious domains before a connection is made
  • Sandboxing (ATP tier) — detonating unknown files in isolation before delivery

UTP, ATP and Enterprise

Fortinet packages these into bundles. Names change between generations, but the structure holds:

UTP (Unified Threat Protection) — antivirus, IPS, web filtering, application control, DNS filtering. This is the standard bundle and covers what most small and mid-sized businesses actually need.

ATP (Advanced Threat Protection) — a narrower bundle centred on antivirus, IPS and sandboxing, without the full web filtering set. Suits organisations whose main concern is malware rather than controlling browsing.

Enterprise — UTP plus additional services such as CASB and industrial protocol protection. Relevant where those specific requirements exist; otherwise you are paying for shelfware.

What happens when it expires

This is the part that catches people out. When the subscription lapses, the features do not switch off with an alarm. They keep running — on the last signature set they received.

So the dashboard still shows antivirus as enabled. Traffic is still being inspected. It is being inspected against threat data that is now months old, which for this purpose is close to worthless.

We have audited appliances where the subscription had been dead for over a year and nobody in the business knew. There was no outage to trigger a call. That is exactly why it goes unnoticed.

How to avoid the trap

  • Know your expiry date. It is on the appliance dashboard and on your Fortinet support portal account. Write it somewhere that is not one person's calendar.
  • Set the appliance to alert. FortiGate can raise a notification as the subscription approaches expiry. It is off by default in many deployments.
  • Do not buy a longer term than the appliance's useful life. A five-year bundle on hardware you will replace in three is money left behind.
  • Match the bundle to what you enable. If you have never turned on web filtering and never will, ATP may be the honest choice over UTP.

For clients we support, we track these dates ourselves and raise the renewal before anything stops updating — because a lapsed subscription produces no symptom until the day it matters.

Need help with this?

Ask us about fortinet firewall installation, or request a free assessment directly.

Fortinet firewall installation
Blog

More articles

Fortinet

Choosing a FortiGate model: 40F, 60F, 90G or 100F?

The model number goes up and so does the price. But which one does your office actually need?

Fortinet

SSL inspection on FortiGate: why it matters and how to deploy it

If you are not inspecting encrypted traffic, you are inspecting almost nothing. Here is what it takes to do it properly.

Fortinet

End internet outages: dual WAN with FortiGate SD-WAN

A second line only helps if the switchover is automatic and fast. Otherwise it is an expensive standby nobody remembers to use.