Sizing and supply
FortiGate models are sized on inspected throughput with security services enabled, not on
the marketing datasheet number — which is measured with most of them off. We size
against your actual internet bandwidth, user count, VPN tunnel count and whether SSL
inspection is in scope, then leave headroom for the licence term.
FortiGate 40F–200F classThroughput sizingHA pairsLicence terms
Deployment and cutover
Configuration built and tested before the cutover window, a documented rollback path, and
a change window agreed around your business rather than ours. We migrate rules deliberately
rather than importing a legacy ruleset wholesale, because a clean policy is the entire point
of replacing the box.
Pre-staged configRollback planOut-of-hours cutoverRule rationalisation
Policy, UTM and inspection
Application control, web filtering, intrusion prevention and antivirus profiles set to
what your business actually needs. SSL inspection deployed where the benefit justifies the
operational cost, and honestly declined where it does not — a half-configured
inspection setup breaks applications and teaches staff to route around security.
Application controlWeb filteringIPSSSL inspectionPolicy review
Monitoring, logging and reporting
FortiAnalyzer or equivalent logging so you can see what the firewall is doing rather than
assume it works. Firmware kept on a supported release, security advisories acted on, and a
readable monthly summary of blocked threats, top applications and policy hits.
FortiAnalyzerFirmware lifecycleAdvisory responseMonthly reporting
Taking over an existing FortiGate
We inherit estates deployed by other providers regularly. The first step is always a
configuration and policy review before anything changes: what is exposed, what firmware is
running, which rules are unused, whether admin access is restricted, and whether the licence
and support contract are current and in your name.
Config reviewExposure checkLicence ownershipUnused rule cleanup
Network segmentation
Flat networks are why one infected laptop becomes a company-wide incident. We separate
staff, guest Wi-Fi, servers, CCTV and IoT, and building systems into VLANs with policy
between them — then document it, so the segmentation survives the next office change.
VLAN designGuest isolationServer zoneIoT & CCTV separation