Fortinet, a security-driven, all-in-one network

Firewall, switches, Wi-Fi, WAN, and web protection under one brand and one management console. When IT is one or two people, having one less system to maintain often matters more than the specs of any single product.

FORTINET — Security-Driven Networking
One firewall runs the whole company network
FortiGate does more than guard the perimeter - it can take over switches and access points directly. Four functions, one management console.
FortiGate next-generation firewall FortiWeb web and API protection FortiSwitch switches FortiAP access points (including Wi-Fi 7) FortiLink single-console management

What is Fortinet

Fortinet, Inc. is a security company founded in 2000 and headquartered in California, USA, listed on NASDAQ (ticker: FTNT). Its main difference from most pure security vendors is that it builds security and networking equipment into one system. Firewalls, switches, access points, and WAN connections all run on its own FortiOS. One management console, one set of logs. The vendor calls this architecture the Security Fabric.

According to the vendor's own website, it has more than 1 million customers worldwide and has shipped more than 17.2 million units cumulatively (as of 30 June 2026). The vendor also states that FortiGate is the most widely deployed network firewall in the world (source: vendor's public website information). Based on common deployment patterns in Taiwan, it typically suits organizations with 20 to 2,000 employees, as well as branch sites of larger enterprises.

This page spans two categories. To understand it from a requirements perspective, see Web & API Protection (WAF) and Enterprise Networking.

Security product line

From the network perimeter to web and API, email, and endpoints - one ecosystem, one set of log reports.

FortiGate next-generation firewall

The gatekeeper at the network's outbound edge. It identifies which application and which user is connecting, can inspect encrypted traffic, and has built-in intrusion prevention (IPS), antivirus, and URL filtering. Models range from branch to data center class, all running the same FortiOS.

Application identificationIPSVPN / ZTNA
FortiWeb web application firewall

A standard firewall cannot read attacks at the web application layer. FortiWeb covers this gap: OWASP Top 10, application-layer DDoS, malicious bots, and automated API discovery protection. Available in four forms: hardware 100F-4000F, virtual machine VM01-VM16, container VMC01-VMC08, and public cloud.

OWASP Top 10API protectionBot defense
FortiAppSec Cloud (formerly FortiWeb Cloud)

A cloud subscription version that requires no equipment to maintain. The vendor has consolidated cloud web protection, FortiGSLB global load balancing, and Advanced Bot Protection into a single platform; older contracts are listed as legacy contracts. Quotes should reference the current SKU names.

SubscriptionGlobal load balancing
FortiMail email security gateway

Blocks spam, phishing, and attachments carrying malware, and includes data loss prevention. Especially relevant for trading and manufacturing companies frequently targeted by BEC (business email compromise) fraud.

Phishing blockingBEC protection
FortiClient endpoint protection

Software installed on employee computers. Provides VPN, a zero-trust connection client, and endpoint antivirus, and lets the firewall check the computer's health status before deciding whether to allow it onto the network.

Endpoint antivirusZTNA connection
FortiManager/FortiAnalyzer

FortiManager lets you change settings, push policies, and update firmware for multiple devices from a single screen. FortiAnalyzer centralizes log collection and produces audit reports, the "log retention" tool most often required in regulatory checks.

Centralized managementAudit reports
FortiSASE cloud security

Moves security to the cloud so employees working off-site are protected by the same policies without connecting back to the office. Made up of a secure web gateway (SWG), zero-trust network access (ZTNA), cloud access security broker (CASB), and digital experience monitoring (DEM).

Remote workReplaces traditional VPN

Networking product line

Switches, wireless, mobile network failover, multi-link routing, and network access control can all sit under FortiGate.

FortiSwitch enterprise switches

The backbone of the internal wired network. The 100-200 series (8-48 ports) suits offices, 300-600 suits campuses, 1000-3000 (10/25/100GE) suits data centers, and there is a hardened Rugged line for industrial use. Supports 802.3bt PoE, powering IP phones, cameras, and access points directly.

PoE powerIndustrial-grade models
FortiAP access points

Enterprise-grade (not consumer) Wi-Fi. Wi-Fi 7 models are already available (FAP-221K / 231K / 241K / 441K / 443K), alongside Wi-Fi 6E and Wi-Fi 6 series. FortiGate can act as the wireless controller directly, so wired and wireless share the same policy set.

Wi-Fi 7No separate controller needed
FortiExtender 4G / 5G failover

Turns a carrier's mobile network into another network line for the company. It switches over automatically if the main line fails, lets temporary sites or construction sites without fixed-line service get online right away, and can also serve as a backup link for SD-WAN.

FailoverTemporary sites
Secure SD-WAN

Built into FortiOS, with no separate equipment to buy. With multiple outbound lines, it automatically determines which one performs best, routes critical traffic such as video conferencing and ERP over the best-performing line, and switches over automatically if a line drops.

Multi-link routingSite-to-site connectivity
FortiNAC network access control

An access-control system for the network. When printers, cameras, IoT sensors, or legacy equipment connect, it first identifies what the device is, whether it should be allowed on, and which network segment it belongs to. Suits manufacturing plants, healthcare facilities, and schools.

IoT inventoryNetwork segmentation

The biggest selling point: FortiLink

Firewall, wireless controller, network management software, and NAC would normally mean four separate purchases. Instead, one FortiGate takes over FortiSwitch and FortiAP. That saves on equipment, and on annual licensing fees and learning costs as well.

The firewall doubles as the wireless controller
FortiGate (including the virtual-machine edition, FortiGate-VM) can manage FortiAP directly. Small and mid-sized sites no longer need to buy a separate wireless controller and controller license.
Zero-touch switch deployment
When FortiSwitch connects to FortiGate via FortiLink, FortiGate automatically discovers it, provisions it, and applies security policy. Replacing a switch does not mean rebuilding the configuration from scratch.
Built-in NAC at no extra license
FortiSwitch has network access control (NAC) built in, and the vendor states explicitly that no additional license is required. Device identification and segment assignment for wired ports can be handled directly from the firewall console.
One console, one log
Wired, wireless, and firewall policy are all configured from the same console, with logs centralized in one report. Troubleshooting does not mean cross-checking timelines across three systems, and maintenance means dealing with just one support window.
For a company with just one or two IT staff, the real cost is not the price of the equipment - it is having to learn and maintain several systems at once.
- GN-AI Networking and Security Team

Who this suits

The six situations below are where this architecture delivers the most value.

Multi-site, chain retail, and food service
Each site is small but there are many of them. SD-WAN is built into FortiGate, so there is no need to buy a separate WAN device for every site.
Manufacturing plants
Offices, production lines, and warehousing share the same network. Large numbers of cameras and sensors need FortiNAC for inventory and segmentation.
IT staff of one to two people
One brand, one console, one support window - the lowest operational burden and the smallest learning cost at handover.
Driven by security compliance
Government agencies and designated organizations covered by the Cyber Security Management Act. Or companies that must produce evidence of web protection and log retention for ISO 27001 or customer supply-chain audits.
Limited budget but full requirements
Wanting to cover firewall, switches, Wi-Fi, and internet access control in one go, without splitting the project across four vendors and four quotes.
Already have FortiGate and want to extend it
When switches or access points come up for replacement, that is the point to fold them into the same console. It is the most cost-effective time to do it.

If the site is a single large campus with very high wireless density in one location and a dedicated networking team, a campus-network-centric architecture is a better fit. For a side-by-side comparison, see Enterprise Networking and Web & API Protection (WAF).

Version management and security operations

Vendor firmware updates and security advisory tracking are both part of annual maintenance.

Perimeter network equipment faces the internet directly. Version management and security advisory tracking are at the core of operations. Once a device is live, whether someone keeps track of versions, follows vendor announcements, and schedules update windows matters as much as which brand you chose.

Security operations covered by annual maintenance

  • Version inventory and firmware update planning: regularly check the firmware version on each device, schedule update windows based on the vendor's recommended version, and keep a rollback plan.
  • Management interface closed to the internet: restrict the management interface to internal segments or specified source IPs, and disable outward-facing HTTP / HTTPS / SSH management services.
  • Vendor security advisory tracking: monitor the vendor's PSIRT advisories, check them against installed models and versions, and assess impact to decide whether to update early.
  • Configuration baseline backup and change log: keep configuration files before and after every change, so you can roll back quickly to the last known-good state if something goes wrong.
  • Subscription expiry reminders and renewal handling: FortiCare support and FortiGuard subscriptions must be renewed annually; we send reminders before expiry and handle the renewal.

* The annual maintenance contract provides business-hours support, including troubleshooting and periodic health checks; actual scope is as agreed in the contract.

Scope of services

The same engineering team handles everything from the requirements interview through to annual maintenance. For the full process, see Services.

1
Requirements interviews and architecture planning
Site survey, inventory of existing equipment and cabling, model selection based on bandwidth and user count, estimating switch port counts and PoE power budget, and planning a POC. A 3-5 year TCO estimate is also provided, including subscription renewal costs.
2
On-site build and installation
Rack mounting, cabling, access point site survey and installation, FortiLink deployment, firewall policy and VLAN configuration tuning, and cutover.
3
System migration
Rule and configuration migration when replacing existing firewalls, switches, and wireless equipment, network segment restructuring, and migration of virtual-machine versions.
4
Training and knowledge transfer
Training on the management console, guidance on day-to-day operating procedures, and delivery of network diagrams and configuration documentation, so your own IT staff can manage the system independently.
5
Annual maintenance contract
Business-hours support, troubleshooting, periodic health checks, vendor firmware updates and security advisory tracking, and vendor renewal handling.

On our role as supplier: We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance.

FAQ

The five questions we hear most before purchase.

Does a 30-person company need equipment at FortiGate's level?

Models range from branch to data center class. Sizing depends on outbound bandwidth, the number of concurrent users, and whether encrypted traffic needs to be inspected (this is the most performance-intensive feature). We give a model recommendation after assessment, to avoid under-spec or over-spec.

I already have switches and Wi-Fi from another brand. Do I have to replace everything?

No. FortiGate can be deployed on its own first as the perimeter firewall, alongside your existing equipment. The integration benefits of FortiLink usually show up once switches or access points reach their replacement cycle. Planning and maintaining a mixed-brand environment is also within scope.

What is the difference between FortiWeb and a cloud WAF?

FortiWeb sits in your own data center or cloud environment, so traffic does not need to route through an external node. It suits internal systems, B2B systems, and situations where data should not leave the country. A cloud WAF suits sites with heavy external traffic that need global nodes and CDN acceleration. The two can also run side by side. For guidance on choosing, see Web & API Protection (WAF).

Can these products run on a hyperconverged platform?

Yes. FortiGate-VM, FortiWeb-VM, and FortiManager-VM are all available as virtual machines and can run directly on a hyperconverged cluster. The same cluster can run business systems and virtual firewalls together. See Hyperconverged Infrastructure & VMware Alternatives for details.

After buying the hardware outright, do I still pay every year?

The hardware is a one-time purchase, but FortiCare support and FortiGuard security subscriptions need annual renewal. If a subscription lapses, the device still runs, but signatures and threat intelligence stop updating - protection effectively freezes at the date it lapsed. The initial quote includes a 3-5 year renewal cost estimate.

Want to start with an assessment of your current setup, model selection, and deployment scope?

Contact us See our services

Contact us about Fortinet deployment and maintenance

Leave your contact details and a description of your needs. An engineer will contact you to help assess the architecture plan, deployment approach, and annual maintenance scope.

Send an enquiry
LINE Ask us on LINE