Fortinet FortiGate-VM Room for Improvement
The product does not have a good graphical interface. Their patches and their upgrades are not always compatible with configuration. That means that often you find after you upgrade that there was something else you have to do to the rest of the infrastructure, whether it's a printer or a user or whatever. It doesn't appear to me that their upgrades are well tested. They usually do what they're supposed to do, however, they also usually do some other things that FortiGate doesn't seem to be aware of.
It doesn't maintain legacy capabilities very well.
The stability of the solution isn't ideal.
They don't seem capable of supporting their own product.
The solution needs a better user interface and more intelligent services like spam blocking and auto whitelisting, gray listing, blacklisting, et cetera. It just basically needs better user monitoring.View full review »
Manager Information Technology at a media company with 51-200 employees
In terms of what features should be improved with Fortinet, I feel it should give better reports. They provide some basic reports in the entry-level and middleware products but I would love this product if they gave more reports, including more MIS from the traffic because they capture everything in the UTM. They don't produce a team value report. They don't produce a usable report where the IT manager, IT head or CTO can analyze where the attack happened or figure out where the bridge is down, etc. The reports are basic. There are engines which make everything on the GUI. All the user can potentially access for the risky function in the Fortinet but it should be on the GUI, it should not be behind the command line. They could definitely provide the FortiAnalyzer with the basic UTM in a bundle pack.
People should not have to ask for another FortiAnalyzer. It's an entry-level product. I understand that FortiAnalyzer is an expert level product but the functionality should be available at the entry-level as well. Fortinet should think about the entry-level and give it managing capabilities. That's why I selected Sophos because, for a small or medium office, all the reports are available there.
Secondly, Sophos is cost-effective. It is comparatively much cheaper. Sophos is available for a much cheaper price than Fortinet. Also, they have some other functions like sandboxing and others. FortiGate should be more customer-friendly and budgeted better. If I am a buyer, I do not want multiple appliances to manage. It should be one box, one appliance. One mobile should do everything. Multiple products require IT to create a workaround. You have to buy two products and then there is actually another one with that, one plus one, and then there is multiple management, so the product is definitely cumbersome. The beauty of the product is implementation and maintenance without it.
I have my own team to maintain this product. We are very happy as a Sophos user, as we get whatever we want from the reporting point of view. There are no glitches. There is no one issue in particular. When I ask, or my team asks, how the network is working and why there is network latency there are reports about where the traffic is going and I do not have the input after moving or switching to Sophos. I can get the support regarding which IP is working where and which IPs are making traffic, and more.View full review »
Senior Security Engineer at a energy/utilities company with 1,001-5,000 employees
Their offering for MFA isn't the cleanest. They have a product called FortiAuthenticator. It's not a FortiGate but that is one of their MFA offerings. However, other products that I've used, like Duo, are better from a user experience standpoint. They are easier to configure.View full review »
Learn what your peers think about Fortinet FortiGate-VM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2021.
552,136 professionals have used our research since 2012.
Director at Treasure Technology
The stability could be improved. I find Cisco to be more stable than Fortigate, which is I major differentiator between the two.
I haven't really explored the cloud too much, as we deal mostly with an on-premises system. However, now with everyone working from home due to COVID-19, it's something I'm beginning to explore and something I think Fortigate needs to invest in and expand on. If they could do something that integrates the cloud effectively, maybe with a cloud provider like Azure, that would be helpful.
Fortigate could speed up its level of customer service in our region.View full review »
I think one thing we couldn't find in the software console was all of our logs. In the logs themselves, for example, we couldn't find if a user was accessing all of the VPN. We don't get to know or we don't have a report that shows on what date or for how long and from what time he user has logged on. We don't have that particular feature or that kind of visibility. That could be improved. Reporting, therefore, in general, could be improved.
The one thing that could be improved is the integration with the exchange. The gateway level controls can be enhanced a bit more. For example, it's still little here and there. You do get malicious attacks and suspicious emails like spam. It's not like Sophos where we got a lot of spam email, and yet, it's still relatively vulnerable. It can be upgraded, maybe with a fifth-generation firmware that it is ready for unknown threats.
Especially after this pandemic situation, it requires a little more enhancement. For an SME level organization, it's okay, but when it comes to corporate and banking enterprises it still requires a lot of enhancement. Comparing it to Palo Alto, for example, it's still very behind the curve.View full review »
It would be better if it could provide you with options before completely blocking anything through the web filter. If you are doing a deep SSL inspection on the site if it says it's expired, it doesn't give you the option to continue at your own risk. I can't say that it's bad, but SSL internally isn't really a requirement. However, its security features can help. Right now, we have people going out and spending on purchasing the SSL certificates for internal sites.View full review »
The licensing needs to be improved. We need longer licensing periods, especially for POCs and trials. It should be for six months. Right now, it's too short of a timeframe.
Overall as I say, the features-wise and performance-wise the VM and hardware versions are the same. The main difference is that the hardware-based option ins is more powerful compared to the VM version.
Their technical support is not helpful and I try to avoid using it.
Lead Cybersecurity Analyst at a consultancy with 5,001-10,000 employees
It's important that, over time, the solution just keeps up with additional features. There's nothing specific that comes to mind, however, it's important for Fortinet to stay as much on the edge as possible, as far as keeping up with what's out there.
The solution is fairly complex.View full review »
Solutions Architect at a computer software company with 5,001-10,000 employees
Compatibility and integration with other products or vendors such as Cisco SD-WAN products need improvement.
The multi-tenancy environment for multiple customers, to make it more secure, needs some improvement.
When you buy a bigger box, you should have the ability to slice and dice data. It should also have the ability to give customers either read and write or more privileged access to that environment. Specifically, to the environment that doesn't overflow into the other parts that have been sliced up.
I would like to see a type of portal for on-site deployment, where they can report into a cloud portal and have a high-level view of utilization. Basic indicators on the performance of the environment, including health status, should be displayed.View full review »
Engineering Manager at Primatel Communication Snd Bhd
To improve FortiGate-VM, Fortinet needs to harden it more. For example, if you are using Hyper-V, then you need guidelines for hardening FortiGate-VM that are specific to the Hyper-V environment. If it's VMware, there should be at least a guideline on how to harden the firewall.View full review »
The encryption detection could be improved. In my opinion, I think Sophos has better encryption detection than this solution.
The security of the solution could be better.
The interface needs to be updated and simplified.
The management could be more in-depth or clear.View full review »
IT Engineering Manager at Mission Critical Partners
They should keep us up to date about the latest version. That's the biggest thing. Currently, we have to go looking for the latest version. We should get notified about what's going on with the versions.
I would like to see easier dual-factor authentication.View full review »
Managing Director at a tech vendor with 11-50 employees
Customization needs improvement. A lot of people have very unique requirements that they ask for at times. Everybody wants to get more out of the solutions so that they have more with less. I would like a little more customization, especially now that everything is becoming a lot more flexible with cloud-based deployments. A little more flexibility in terms of the offering that we can do or the bundling of products would help acquire markets much faster or much better.View full review »
Chief Information Officer at LCC Group Inc
As we just began implementing the solution, I'm not sure if there are any features missing. We haven't come across any shortcomings in the product yet.
We purchased the product through a reseller, and we don't have any issues with them and therefore, so far, don't have any issues with the solution itself.
The product may not be as robust as Palo Alto. However, unless you are a big bank, you probably won't need it to be.View full review »
Founder & Managing Director at a tech services company with 1-10 employees
The solution could be improved by making deployment easier and dispensing with the reliance on FortiManager, as well as FortiAnalyzer to get any meaningful reporting out of it. If they could exclude both of those from the whole equation so that it bundles direct to the firewall, that would be a big improvement. It should be decoupled from the whole ecosystem, the security fabric side of it, and that would improve things. I get the feeling we have limited functionality if we just look at the data itself, and that's not cool when you're spending thousands of dollars on a product.
The technology is just not there yet in terms of UX and true integration. We have had endless woes with our Analyzer services and the Manager seems rather rudimentary on its own. We believe that the actual Fortigate should have all this disparate functionality baked-in.
Head of IT at a mining and metals company with 10,001+ employees
Right now, we are totally satisfied with this solution. There are several units worldwide. We have only one unit at our Kolkata location, and we are satisfied as of now in terms of its capabilities.
Price-wise, it could be slightly better, however, if you compared it to other makes and models of equal category, it is generally cheaper.
Team leader technical support at a manufacturing company with 201-500 employees
It would be useful to have integration with different reporting tools. This is something we are sorely missing. It would be a plus to have reporting integrations.
It would be good to have more integration with the identity suites, such as Office 365 and Azure Active Directory, of different providers that we use. Integrations are already available, but it would be nice to have some more advanced options.View full review »
There are certain GUI features that should be present but are not, although these we can address through the command-line interface. We have to make use of this to create certain policies or change the interface layer. These configuration restrictions should be addressed.
Moreover, the reporting should be upgraded, as there are only a small number of reports available. We also encounter issues on the logging pages. GUI does not allow for live logging and the command-line interface must be used in its stead. The need to rely on CLI should be done away with entirely.
While we consider the solution to be user-friendly, certain improvements should be made in this respect.View full review »
IT Specialist at a tech services company with 51-200 employees
The key activation is very complicated at times. For example, when you use it for different customers, due to the fact that they are linked with one customer or another, you need an account. Sometimes the customer doesn't have the account, or they confuse the key. It derails the process a bit. It would be ideal if they could simplify or streamline the process.
The internal logs could be easier to manage. When you handle debugging sometimes you have some trouble seeing the whole of a packet that crossed the firewall. Luckily, I have a lot of expertise and therefore can work within these shortcomings. However, it would be easier if there was more visibility.
I have had a data issue with physical devices that could improve.View full review »
There's this command in the email of service policy that you add for the email of service policy. It's hard to do in reality. It could be made easier.
The block, the clarity, the quarantine command, is not very user-friendly. You would have to do everything through the command line and I would have preferred if it wasn't a CLI.View full review »
Principal & CTO at Constructure Technologies at a construction company with 11-50 employees
In the next releases, it would be nice to see central cloud management.
They have an on-premises solution that you can deploy for fleet management or for multiple site management, but it seems like a cloud solution would be a little bit easier.View full review »
Network Administrator at Furnmart
We have had some issues with connecting to the VPN from home after firmware updates, which could be an area for improvement.View full review »
The scalability of the solution needs to be improved.
The price model is not transparent by any means and should be made more clear. What's included in the packages is often not very obvious.View full review »
The reporting is not as good as it is with other firewalls and it should be improved. There should be a customized report, for example.
The dashboard seems to change quickly from version to version, and they should follow the lead of vendors like Palo Alto, Juniper, and Cisco, and always keep it the same.
The bandwidth limitations should be increased.View full review »
Consultant at a comms service provider with 11-50 employees
There should be more options to use lower-end models in a high availability configuration.
They should continue to improve the traffic shaping; they should add some AI to the traffic shaping. They should also consider learning from other organizations as opposed to just internally. They should follow patterns instead of everyone having to recognize patterns and make adjustments on their own. Instead, they should add some form of intelligence to guide administrators in best practices with traffic shaping. I think this will become very important as we move more toward a SaaS-type world.
IT Director at a retailer with 1,001-5,000 employees
The technical support is not very responsive and is an area that needs to be improved.View full review »
Junior Network Engineer at a tech services company with 11-50 employees
We've had issues with integration. It hasn't gone well.
We have had some stability issues.
There are some instances where configurations can get complex.View full review »
Manager-Information Technology at a tech services company with 1-10 employees
There isn't anything in terms of features that we find are lacking. We don't see any places on the solution that don't cater to our requirements.
I would like to see VNX security and WildFire. Those features I would like to see on the solution in the future in order to be able to evaluate it further.View full review »
Network Security Engineer at a tech company with 201-500 employees
The graphical user interface should be enhanced. While the antivirus profile can be implemented very easily with the graphic user interface, there are many important features that cannot be undertaken without the CLI command like signature, such as extending a database. One cannot do a graphical user interface for this and CLI command must be employed instead.
All hidden features related to CLI should appear as a graphical user interface.
It needs an Application Inspection. The threat landscape is very high. Anyone can exploit the flow-based policies. It is always better to have intern-based policies.View full review »
Information Technology Manager and ISMS Auditor at a consultancy with 51-200 employees
There should be a bit more automation.
There could be more integration capabilities.
Technical support could be better.
The solution needs more features surrounding event log management.View full review »
The price of FortiGate-VM is high and should be more competitive.
In the next release, we would like to see full integration with VMware NSX virtualized networks.View full review »
Network Engineer at a maritime company with 201-500 employees
When new versions are deployed they tend to be a little buggy, so they should be more fully tested before release.View full review »
Cyber Security Engineer at a tech vendor with 1-10 employees
Pricing should be more competitive, it's expensive.
In the next release, I would like to see integration capability with SIEM tools, such as QRadar, and LogRhythm.View full review »
Manager, Infrastructure Support at a construction company with 10,001+ employees
I don't see any specific features that are missing from the solution right now.
The user interface needs to be improved.View full review »
Systems Engineer at a tech services company with 501-1,000 employees
The user interface could be improved, but as a firewall, it's the best product we have.View full review »
Data reporting could be improved and also in terms of performance, some improvement should be made on VM, it should be more optimized. Scalability of the solution could also be improved.
For an additional feature, Fortinet should add more SD-WAN with caching as a special functionality. It should be integrated with Fortinet.
CISO at a religious institution with 501-1,000 employees
Integration could be better. Whatever devices I'm using with FortiGate are all compatible. The access points and switches are also FortiGate, so I can easily integrate them. But it would be better if we could embed other devices as well. There are compatibility issues with other brands, and we need that. We can only integrate universal brands with FortiGate. The initial setup could also be easier.View full review »
Director Of Technology at a tech services company with 1,001-5,000 employees
More monitoring should be included with Fortinet FortiGate-VM, in my opinion.
It has a monitoring tool, but it could be improved.View full review »
Creative Head/Director at a marketing services firm with 1-10 employees
The solution should provide more useful GUI features. This would prevent us from having to resort to CLI or certain basic commands.
There should be an IPsec failover.View full review »
The technical support could be improved. I'd like to see the security platform upgraded.View full review »
Web filtering is a feature that needs some improvement. There should be some additional features to allow active users to change their own passwords.
Additionally, the secure web gateway and the inspection feature need more security improvement in the next release.View full review »
We have encountered certain issues with the bandwidth in respect of the security layer.View full review »
Assistant Housekeeping Manager at a hospitality company with 10,001+ employees
The performance could be better. Some features need to have quality control when the switch is working. The dedicated bandwidth for some users is not reliable.View full review »
Project manager at a comms service provider with 10,001+ employees
It is a very good product, and it is good at standing by itself. It can maybe have a little bit of integration with other products, but it is not that important for most use cases.
The interface of the solution could be improved. Right now, it's not the best.
In some areas of the solution, it works slowly.View full review »
It is difficult to size the VM in terms of machine resources, and for this reason, clients prefer the appliance.View full review »
Project Coordinator at a marketing services firm with 201-500 employees
We are experiencing a failed login issue. There should also be improvements in functionalities we store to enhance our services.View full review »
Fortinet could improve the availability and delivery of its products. It takes four to six weeks for every purchase to arrive.View full review »
Owner at a financial services firm with 1-10 employees
It should have the SD-WAN feature. This would increase the number of features that are available in the box.View full review »
Learn what your peers think about Fortinet FortiGate-VM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2021.
552,136 professionals have used our research since 2012.