FortiGate is the appliance we deploy most, and the one we see misconfigured most. The two failures are consistent: an appliance chosen from the datasheet headline figure rather than from inspection throughput, and a licence that quietly expired so the security services stopped updating months before anyone noticed.
Both are avoidable. We size from measured traffic with inspection assumed on, and we track every licence expiry date on your behalf rather than leaving it to a reminder in someone's calendar.
We supply, install and support the full FortiGate range, plus FortiSwitch managed switching and FortiAP wireless — which, managed through the firewall itself, gives one console for the whole edge instead of three.
The range
FortiGate appliances we supply
From a desktop unit for a ten-person office to a data-centre class appliance. We supply, install and licence the full range.
FortiGate 50G / 51GDesktop appliance for small offices and branch sites.FortiGate 70GDesktop unit for offices needing more inspection headroom.FortiGate 90GMid-range desktop appliance for growing businesses.FortiGate 121GRack-mount unit with integrated switching ports.FortiGate 1000DRack appliance for larger networks and multi-site cores.FortiGate 1000FCurrent-generation 1U appliance for high-throughput sites.FortiGate 3000FData-centre class appliance for very high throughput.
Model selection
Which FortiGate suits your size?
Indicative groupings. The final decision comes from measurement, not from this table.
FortiGate 40F · 50G · 60F · 70G
Offices of roughly 10–50 users, branch connections and small businesses. Desktop form factor, quiet, simple to manage.
FortiGate is the centre of the family, but Fortinet's strength comes from the products talking to one another. Here is what we deploy and what each one actually does.
FortiGate
The firewall. Inspects traffic, applies policy, terminates VPN. It is also the management point for everything else.
FortiSwitch
Managed switching, administered through the FortiGate. Ports, VLANs and access policy from one screen.
FortiAP
Wireless access points. No separate controller to license or patch — the FortiGate does that job.
FortiAnalyzer
Log collection and reporting. This is usually what satisfies statutory log retention requirements.
FortiManager
Central management for multi-device estates. Push policy to dozens of branches from one console.
FortiClient
Endpoint agent. VPN connectivity, vulnerability scanning and reporting device posture back to the firewall.
FortiMail
E-mail security. Anti-phishing and attachment filtering, sitting in front of your mail platform.
FortiWeb
Web application firewall. Protects internet-facing applications at the application layer.
FortiAuthenticator
Authentication and multi-factor sign-in. Ties user identity to network policy.
FortiToken
Hardware or mobile tokens for multi-factor authentication. Ends relying on a password alone for VPN.
FortiSandbox
Detonates unknown files in isolation and watches their behaviour — for malware with no signature yet.
FortiExtender
Cellular backup connectivity. Keeps the site online when the fixed line drops.
You do not need all of them. For most businesses FortiGate + FortiSwitch + FortiAP covers it; add FortiAnalyzer where log retention is required.
Licensing
UTP, ATP or Enterprise?
You buy the appliance once and subscribe to the security services. That is the difference — and it is the part most often confused when comparing quotations.
Capability
No licence
UTP
ATP
Enterprise
Firewalling, NAT
✓
✓
✓
✓
VPN (site-to-site, SSL)
✓
✓
✓
✓
SD-WAN steering
✓
✓
✓
✓
Antivirus
—
✓
✓
✓
Intrusion prevention (IPS)
—
✓
✓
✓
Web filtering
—
✓
—
✓
Application control
—
✓
—
✓
DNS filtering
—
✓
—
✓
Sandboxing (unknown files)
—
—
✓
✓
CASB, OT protocols
—
—
—
✓
Bundle contents change between generations; we state the current official scope in writing when quoting. We will not recommend a bundle containing features you will never switch on — if you are not going to use web filtering, ATP may make more sense than UTP.
Our service
What installation includes
Not just racking the box.
Traffic assessment
We measure actual throughput, session counts and peak load before recommending a model.
Written recommendation
You receive the reasoning, not just a part number — including cheaper options where they are adequate.
Installation & migration
Deployment with a planned cutover window, and a documented rollback if anything is wrong.
Policy design
Rules built from what the business actually needs, not a permissive ruleset that gets tightened 'later'.
SSL inspection
Configured with the certificate distribution and exclusion list handled properly.
Segmentation
VLANs and inter-VLAN policy so a compromised workstation cannot reach the server network.
VPN & remote access
Site-to-site tunnels and client VPN with multi-factor authentication.
SD-WAN & dual WAN
Link monitoring and per-application steering so failover is genuinely seamless.
Licence management
Expiry dates tracked by us; renewal proposed before the services stop updating.
Legal Requirement
Law No. 5651 and log retention
Turkish law No. 5651 requires businesses that provide internet access to retain access records. Hotels, cafés, shopping centres, hospitals and workplaces offering guest Wi-Fi all fall within its scope.
In practice two things are needed: a record of who connected, when, and to what address, and the ability to show that record has not been altered. Accurate clocks matter too — a log whose timestamps do not line up carries no evidential weight.
FortiGate produces the record; for retention and reporting we normally add FortiAnalyzer. A separate captive portal and authentication step is set up for the guest network so records can be tied to a person.
During installation we also configure the retention period, access permissions and time synchronisation. Selling the box is not enough for this requirement.
Who Is Affected
Does this apply to you?
Hotels and guest houses offering Wi-Fi
Cafés, restaurants and shopping centres
Hospitals and clinics
Workplaces giving visitors internet access
Schools and training centres with student networks
Co-working spaces
If you are not sure, ask. We will assess whether you fall within scope and, if so, design the right setup.
A firewall is not a finished product on the day it is installed. Firmware needs updating on a considered schedule, policies drift as the business changes, and licences expire. We keep a record of your firmware level, your licence dates and your policy set, and we raise these with you rather than waiting to be asked.
You also get the configuration. Full backup of the appliance config, an interface and VLAN map, and the credentials — held by you, not just by us.
FAQ
Fortinet and FortiGate questions
Which FortiGate model do we need?
It depends on your internet bandwidth, user count, VPN requirement and — critically — whether SSL inspection will be enabled. Inspection can reduce usable throughput several-fold, so a model chosen from the headline firewall figure is often undersized in practice. We measure your traffic before recommending.
What does the licence actually cover?
The appliance includes basic firewalling. Content inspection features — antivirus, intrusion prevention, web filtering, application control, sandboxing — come through UTP or ATP subscription bundles. When the subscription lapses those features stop updating, which is where most surprises come from.
Can you take over a FortiGate someone else installed?
Yes. We audit the existing configuration, report what we find, and either correct it in place or rebuild the policy set. You get the documentation either way.
Do you support SD-WAN and dual internet lines?
Yes. FortiGate handles dual-WAN failover and application-aware SD-WAN natively. We configure link health checks and per-application steering so failover is genuinely transparent.
Do you work outside Ankara?
Yes. Appliances ship anywhere in Türkiye and most FortiGate work — configuration, policy design, licence management, troubleshooting — is done remotely. On-site attendance is standard in Ankara.
Do you support log retention requirements?
Yes. Turkish law (No. 5651) requires certain access logs to be retained. FortiAnalyzer or an equivalent collector covers this, and we configure retention and time synchronisation as part of the build.
Free site survey and quotation for FortiGate
Tell us how many users you have and which line you use — we will size the right model together.