In this article:
Want us to find IT vendors for you?
Share your vendor requirements with one of our account managers, then we build a vetted shortlist and arrange introductory calls with each vendor.
Book a call

What is Fortinet, How it Works, and What it Does for IT Leaders

This guide covers what Fortinet is, how FortiGate and the wider portfolio fit together, which Fortinet products run from one console, how FortiGuard licensing works, and where Fortinet fits your environment and where it doesn't.

Author:
Date

What Is Fortinet?

Fortinet is a network security vendor. Its core product, FortiGate, runs firewalling, SD-WAN, VPN and routing on one operating system, FortiOS.

It sits in the next-generation firewall category. It is built around one idea: network and security functions belong on the same box, under the same policy.

In practice, Fortinet:

  • Sits at the edge of every site, data centre and cloud network you run
  • Inspects traffic on custom processors built to take work off the main CPU
  • Extends the firewall to switches, Wi-Fi and 5G extenders, so the LAN takes its configuration from the FortiGate
  • Manages fleets of firewalls from one console
  • Sells adjacent security products, from EDR to SIEM, that connect back to the firewall

It fits organisations with many sites, a mix of on-premises and cloud infrastructure, and a push to run fewer network vendors.

It's budget season; let's see how you do

Budget comes up in about 88% of the thousands of conversations we have with IT leaders. So we made a game about it. Play to find out what your year-end board meeting looks like.

Play game
IT budget season game

How Does Fortinet Work?

At a high level, Fortinet replaces a chain of separate appliances with one operating system on one box. The firewall, VPN concentrator, SD-WAN router and wireless controller become functions of the FortiGate, and the rest of the estate connects back to it.

1. FortiOS runs everything on the FortiGate

FortiOS holds one policy model for:

  • Firewall rules and NAT
  • SD-WAN path selection
  • VPN and zero trust network access
  • Routing and segmentation

Every function reads the same address objects, user identities and device tags. You write a rule once and it applies across all of them.

2. Custom processors carry the traffic load

FortiGate appliances contain two kinds of Fortinet-built chips. Network processors forward established sessions without touching the main CPU. Content processors accelerate inspection and encryption.

How much work those chips take on depends on how you configure inspection. That choice matters more than the model number, and the edge security section below explains why.

3. FortiGuard subscriptions feed the inspection engines

IPS signatures, URL categories, antivirus definitions and sandbox verdicts arrive from Fortinet's FortiGuard service. The engines ship with FortiOS, but most of them need a live subscription to stay useful.

The licence tier you buy decides which features switch on. It is the least visible line on a quote and the one that shapes the most behaviour.

4. FortiLink extends the firewall to the LAN

FortiSwitch, FortiAP and FortiExtender can run in a managed mode where the FortiGate acts as their controller. They take configuration and firmware from the firewall. You manage ports and SSIDs from the same interface as your firewall rules.

5. FortiManager and FortiAnalyzer run the estate

FortiManager pushes configuration to fleets of FortiGates. FortiAnalyzer collects their logs for reporting, correlation and retention.

Everything else in the portfolio connects through Fabric connectors, syslog and APIs. That is how FortiEDR, FortiSIEM and the rest exchange data with the core.

Result: the closer a product sits to FortiOS, the more of it you run from one place.

Fortinet Product Architecture: FortiGate, Secure LAN, Management, FortiSASE and Security Operations

Fortinet sells dozens of products under the same prefix. The names hide how differently they behave once deployed.

When I review a Fortinet quote, I ask one question of every line: does this run from the FortiGate, or does it need its own console? The five product groups below answer that question differently.

FortiGate next-generation firewall

What it does: Enforces firewall, IPS, application control, web filtering, SD-WAN and VPN policy at each site. It comes as a hardware appliance, a virtual machine or a cloud marketplace image.

Problems it replaces:

  • A separate firewall, VPN concentrator and branch router at each site
  • Branch designs that backhaul internet traffic over MPLS to a central breakout
  • Standalone IPS appliances

When you need it: A firewall refresh, a branch circuit renewal, or a move to local internet breakout at remote sites.

Key capabilities:

  • One policy across firewall, SD-WAN and remote access
  • Hardware acceleration on appliance models
  • The same FortiOS across hardware, virtual and cloud deployments

Where you manage it: On the FortiGate itself, or through FortiManager across a fleet.

Secure LAN edge: FortiSwitch, FortiAP and FortiExtender

What it does: Provides switching, Wi-Fi and 5G or LTE WAN connectivity that the FortiGate controls in managed mode.

Problems it replaces:

  • A separate wireless controller
  • Switch configuration managed box by box
  • Different policy models for wired, wireless and firewall traffic

When you need it: When switches or access points are nearing end of support, or when a new site needs LAN and firewall live on the same day.

Key capabilities:

  • Port, VLAN and SSID configuration from the FortiGate
  • Firmware delivered through the FortiGate
  • One view of firewall, switch and access point status

Where you manage it: From the FortiGate, while in managed mode. A switch converted to standalone mode gets its own web interface back.

Management and analytics: FortiManager and FortiAnalyzer

What it does: FortiManager centralises configuration, policy and firmware across many FortiGates. FortiAnalyzer stores and correlates their logs and produces reports.

Problems it replaces:

  • Logging into each firewall to change a rule
  • Logs spread across devices with no single retention policy
  • Manual compliance reporting

When you need it: Once you run enough FortiGates that change control and log retention stop working device by device.

Key capabilities:

  • Policy packages pushed to groups of firewalls
  • Central firmware scheduling
  • Log retention, reporting and event correlation
  • Log forwarding to third-party SIEMs over syslog or CEF

Where you manage it: This is the console. Both products run as appliances, virtual machines or cloud services.

FortiSASE

What it does: Delivers secure web gateway, ZTNA and CASB from the cloud, for users outside the office and for small sites.

Problems it replaces:

  • Backhauling remote user traffic to a head-office FortiGate
  • VPN as the only remote access path

When you need it: When your remote workforce is large enough that head-office VPN becomes the bottleneck, or when small sites don't justify firewall hardware.

Key capabilities:

  • Cloud-hosted ZTNA, CASB and web security
  • The FortiClient agent, shared with on-premises ZTNA
  • Starter kits that tie in existing FortiGates

Where you manage it: Its own cloud console.

Security operations: FortiEDR, FortiSIEM, FortiSOAR and FortiNDR

What it does: Covers endpoint detection and response, security event correlation, automated response playbooks and network detection and response.

Problems it replaces:

  • Signature-only endpoint antivirus
  • Manual log review across disconnected tools
  • Alert triage done by hand

When you need it: A SOC build-out, an EDR renewal, or an insurer or auditor asking you to prove detection and response capability.

Key capabilities:

  • Endpoint protection and response through the FortiClient agent (FortiEDR)
  • Log correlation across Fortinet and third-party sources (FortiSIEM)
  • Playbook-driven response (FortiSOAR)
  • Network traffic analysis (FortiNDR)

Where you manage it: Each product's own console.

Fortinet also sells FortiMail, FortiWeb, FortiSandbox and FortiAuthenticator. FortiManager can manage parts of their configuration and FortiAnalyzer collects their logs, but each keeps its own console and policy model.

Origin tells you little about integration depth. FortiADC arrived with Fortinet's purchase of Coyote Point, and it attaches to the core exactly as the in-house FortiMail does.

If you already run a dedicated email security layer, you will operate a second console whichever vendor you choose.

ScenarioFortinet productWhere you manage itConsole
Replacing branch firewalls and routersFortiGate with SD-WANFortiGate or FortiManagerCore
Refreshing switches and Wi-FiFortiSwitch, FortiAPFrom the FortiGate, in managed modeCore
Running firewalls across many sitesFortiManager, FortiAnalyzerCentral consoleCore console
Protecting plant and field sitesRugged FortiGate and FortiSwitch, plus OT SecurityFrom the FortiGateCore
Securing remote and small-site usersFortiSASEFortiSASE cloud consoleSeparate
Securing emailFortiMailFortiMail consoleSeparate
Protecting web applicationsFortiWebFortiWeb consoleSeparate
Endpoint detection and responseFortiEDR through FortiClientFortiClient EMS and FortiEDR consolesSeparate
Centralising security logs and detectionFortiSIEMFortiSIEM consoleSeparate

The lowest-risk sequence starts with FortiGate. Add FortiSwitch and FortiAP at the next LAN refresh, and bring in FortiManager and FortiAnalyzer as the fleet grows. Evaluate the security operations products against specialists, on their own merits.

Not sure which Fortinet products your quote needs?

Answer five questions about your environment and we'll show you which Fortinet products apply, which run from one console, and which vendors offer comparable alternatives.

Start the five-question check

What Fortinet Offers IT Leaders

Fortinet covers a lot of ground. For IT leaders, the offer is easiest to judge through four lenses:

  • Network security at the edge
  • Secure networking beyond the firewall
  • Security operations and consolidation
  • Licensing and cost control

Network Security at the Edge

Every site you add is another perimeter you are accountable for. Fortinet's answer is one box per site that handles every edge job.

1. One operating system for firewall, SD-WAN and remote access

FortiOS runs every edge function under one policy model, so a new branch needs one device and one rule set. Firewall rules, SD-WAN steering and VPN access share the same objects.

That cuts the number of places a rule can drift out of step. It also means one firmware upgrade touches every edge function at once, so we test upgrades as full-site changes.

2. Custom silicon, and the inspection choices that decide whether you get it

Fortinet's processors earn their keep on flow-based inspection. Sessions that match policies with proxy-based security profiles are never handed to the network processors, so the CPU processes them.

A few other conditions send traffic back to the CPU:

None of these settings is unusual in production. Check your inspection mode and monitoring settings before you trust any throughput figure.

3. How to read Fortinet performance figures

Fortinet lists the FortiGate 60F at 10 Gbps of firewall throughput with 1518-byte packets. The same entry lists 700 Mbps of threat protection throughput.

Same box, same document. The second figure is about 7% of the first.

Each number measures something different:

  • Firewall throughput: stateful forwarding of UDP packets at a fixed size
  • NGFW throughput: firewall, IPS and application control on an enterprise traffic mix
  • Threat protection throughput: NGFW plus malware protection, with logging enabled

When a reseller quotes one number, ask which of the three it is. In my experience, threat protection is the figure to plan against, because it is closest to what a fully licensed firewall does all day.

Virtual FortiGates use software acceleration in place of Fortinet's chips. Their performance depends on vCPU count, NIC and hypervisor settings, so size them by testing against your own traffic.

Secure Networking Beyond the Firewall

The branch, the LAN and the remote user used to be three projects with three vendors. Fortinet treats them as extensions of the same firewall.

1. Switches and access points that run from the firewall

In managed mode, the FortiGate configures FortiSwitch ports, VLANs and FortiAP SSIDs from the same interface as firewall policy. With automatic firmware updates enabled, it also upgrades managed switches, following a compatibility list that Fortinet maintains.

This is where consolidation pays off most clearly. You get one firmware path, one set of objects, and one place to look when a user can't connect.

2. Branch SD-WAN and remote users

SD-WAN is a FortiOS feature, so every FortiGate can steer traffic across broadband, 5G and MPLS links without a separate router. Our guide to how Fortinet compares with Cisco, Palo Alto and HPE Aruba for SD-WAN covers that decision in depth.

For users outside the office, FortiSASE delivers web security, CASB and ZTNA from the cloud. Check SASE starter kit eligibility against your own quote, because Fortinet's ordering documents list different minimum FortiGate models.

If FortiSASE is up against other vendors, our SASE platform comparison covers the field.

3. OT and industrial sites

Fortinet sells ruggedised FortiGate and FortiSwitch models for plants, substations and field sites. FortiOS inspects industrial protocols such as Modbus and lets you segment plant networks away from the office network.

ICS and SCADA signatures now come from a separate OT Security service. The licensing section below explains why that matters at renewal, and our guide to ICS and SCADA security covers the wider controls.

Security Operations and Consolidation

Tool sprawl costs you twice: once in licences, and again in the hours your team spends switching between consoles. Fortinet reduces that cost a lot at the core, and much less at the edges of the portfolio.

1. One console for the network core

FortiManager and FortiAnalyzer cover FortiGate, FortiSwitch, FortiAP and FortiExtender as a single system. Configuration, firmware and logs for the whole network edge live in one place.

For a lean network team running dozens of sites, this is the strongest operational case Fortinet makes.

2. Where Fortinet adds a second console

Everything beyond the core keeps its own console. FortiSIEM, FortiSOAR, FortiEDR and FortiCNAPP exchange data with the firewall through connectors, syslog and APIs.

Those integrations work. They are also the same kind of integration a competent third-party tool would use, so buy these products on their own merits.

Weigh FortiSIEM against other SIEM platforms, and FortiCNAPP against the options in our CNAPP comparison.

FortiEDR is moving closer to the core. Fortinet has integrated the FortiEDR agent into FortiClient, so EMS can deploy both from one installer. Detection still runs on FortiEDR's own backend, which you integrate with EMS as a separate system.

3. Upgrades move the whole estate together

The tight coupling that makes the core easy to manage also ties its upgrades together. Fortinet has published fixes for cases where managed FortiSwitches went offline after a FortiGate upgrade. The switches stayed offline until someone corrected an LLDP setting on the firewall.

Plan every firewall upgrade as a network change. We stage upgrades on one site's firewall, switches and access points before touching the rest.

Licensing and Cost Control

The licence decides what your firewall actually does. Two identical FortiGates can behave very differently depending on the FortiGuard tier behind them.

1. What FortiGuard bundles switch on

FortiGuard services come in three nested bundles: ATP sits inside UTP, which sits inside Enterprise. Firewall, VPN, SD-WAN, application control and inline CASB come with a FortiCare support contract alone.

CapabilitySupport onlyATPUTPEnterprise
Firewall, VPN, SD-WANIncludedIncludedIncludedIncluded
Application control, inline CASBIncludedIncludedIncludedIncluded
IPS, antivirus, cloud sandboxNoIncludedIncludedIncluded
URL, DNS and video filteringNoNoIncludedIncluded
DLPNoNoNoIncluded
AI-based inline malware preventionNoNoNoIncluded
OT SecurityÀ la carteÀ la carteÀ la carteÀ la carte

I have not found list pricing for FortiGate hardware or FortiGuard subscriptions on Fortinet's site. Pricing comes through partners, which makes the bundle tier the cost lever you can check yourself.

2. The December 2024 bundle change

On 11 December 2024, Fortinet restructured the Enterprise bundle. DLP and AI-based inline malware prevention moved in, and two older services merged into one called Attack Surface Security.

OT Security moved out of every bundle. Fortinet's stated reason was "low utilization among bundle buyers."

That creates a quiet renewal trap. If your last quote carried OT signatures inside Enterprise, a like-for-like renewal no longer includes them, so add OT Security as its own line.

3. FortiFlex, FortiCare and the hardware lifecycle

FortiFlex is Fortinet's points-based licensing programme. It covers FortiGate-VM, many hardware FortiGates and several other Fortinet products.

Points are deducted daily. Unused points are forfeited 90 days after the programme expires, so put the expiry date in the renewal calendar the day you sign.

FortiCare support comes in three tiers:

  • Essentials: web tickets and next-business-day response, for the smallest FortiGate models only
  • Premium: 24×7 support with one-hour response on critical issues, and the level bundled with hardware
  • Elite: 15-minute response targets and single-touch handling

Fortinet gives at least 90 days' notice before a model reaches end of order. Hardware support generally ends about 60 months after that date, so plan refreshes from the end-of-order date.

See Which Fortinet Products Best Suit Your Needs

Answer the questionnaire below. We'll show you which Fortinet products your environment actually needs, which of them run from one console, and which FortiGuard tier your requirements call for.

Is Fortinet Right for Your Environment?

Fortinet fits estates that want network and security on the same box. The benefit is strongest at the core, where FortiGate, FortiSwitch, FortiAP and the management pair run as one system.

That benefit weakens with every product that brings its own console. Past the core, you are comparing individual products, and the Fortinet name on the invoice adds little.

Fortinet is a strong fit if:

  • FortiGate is already your firewall and your switches or Wi-Fi are nearing end of support
  • Branch circuit contracts are up for renewal and you want SD-WAN on the firewall
  • You run many sites with a small network team
  • Your plant or field sites need segmentation on hardened hardware
  • You want one vendor accountable for firewall, LAN and remote access

Evaluate carefully or consider alternatives if:

Leaving Fortinet is easier for data than for policy. FortiOS exports configuration in its own format or in YAML. FortiAnalyzer forwards logs to any syslog or CEF target.

Firewall policy is the part that stays behind. I found no Fortinet tool that converts FortiGate policy into another vendor's format, so budget for a rebuild.

Our guide to switching vendors without losing control covers how to sequence that move.

Also read: What is Zscaler, How it Works, and What it Does for IT Leaders, What are the Best MDR and XDR Providers for Security Teams in 2026

Comparing Fortinet with Palo Alto, Cisco or Check Point?

See how Fortinet stacks up before you shortlist. Browse pre-vetted firewall and network security vendors on TechnologyMatch. It's private and free, and no one contacts you until you choose.

Find security vendors

FAQ

What is Fortinet?

Fortinet is a network security vendor built around FortiGate, a firewall that runs security, SD-WAN, VPN and routing on one operating system, FortiOS. Its other products, including FortiSwitch, FortiAP, FortiManager, FortiAnalyzer, FortiEDR and FortiSIEM, either extend FortiGate or connect to it.

What is the Fortinet Security Fabric?

The Security Fabric is Fortinet's name for how its products share configuration, telemetry and policy. Integration depth varies by product. FortiSwitch and FortiAP run as part of FortiGate in managed mode, while FortiSIEM and FortiEDR keep their own consoles and connect through connectors, syslog and APIs.

What is the difference between FortiGuard UTP and Enterprise?

UTP adds web, DNS and video filtering to ATP's IPS, antivirus and sandbox services. Enterprise adds DLP and AI-based inline malware prevention on top of UTP.

Is OT Security included in the FortiGuard Enterprise bundle?

No. Fortinet removed OT Security from all FortiGuard bundles on 11 December 2024. It is now sold à la carte, so renewals based on older Enterprise quotes need it added as a separate line.

Does FortiGate hardware acceleration work with proxy-based inspection?

No. FortiGate never hands sessions that match proxy-based security profiles to its network processors. The CPU processes them, so appliance throughput figures don't apply to that traffic.

Can I size a FortiGate-VM from an appliance datasheet?

No. Virtual FortiGates use software acceleration in place of Fortinet's processors. Their performance depends on vCPU count, NIC and hypervisor settings, so test with your own traffic and inspection profile.

Do FortiSwitch and FortiAP need a FortiGate?

In managed mode, yes. They run as one system with the FortiGate and take their configuration and firmware through it. FortiSwitch can also run standalone with its own web interface.

How long does Fortinet support FortiGate hardware?

Fortinet generally ends hardware support about 60 months after a model's end-of-order date. It gives at least 90 days' notice before end of order.