Home About Partners Starlink Peplink Fortinet News Careers FAQ
Contact Us

Expertise in
Fortinet environments

We do not sell boxes. We design the segmentation, convert the rulebase, cut over one VLAN at a time, and keep the fabric running after it is live - from the FortiGate at the edge to FortiSASE for the people who no longer sit in the office.

Start with FortiSASE

Security Fabric -
one chain: firewall, switch, AP

This is Fortinet's method, and the reason the estate stops being three consoles from three vendors: the FortiGate configures the ports and the SSIDs and inspects what crosses between them, down one chain.

FortiGate

The next-generation firewall at the edge, and the thing that configures the rest of it. Segmentation stops being a line on a diagram and becomes a policy that a firewall enforces between VLANs.

FortiSwitch

Access switches that attach to the FortiGate over FortiLink, so ports, PoE and VLANs are configured where the policy already lives - with no separate switch controller and no management licence.

FortiAP

Access points that register to the FortiGate's own wireless controller over CAPWAP. One console for SSIDs and switch ports, one firmware plan, one place to look when a floor drops.

FortiSASE -
the office stopped being a place

The flagship of this page, and the one we are asked for most. Remote users stop terminating on a VPN concentrator that was sized for a quarter of them, and start terminating in a Fortinet-managed point of presence where the same inspection runs wherever the laptop was opened.

Remote user Branch Contractor FortiSASE inspected in the cloud SaaS Internet Private apps
Every path crosses one inspection point - and some of it does not come out the other side.

The VPN concentrator on the perimeter, the backhaul design that drags branch traffic to headquarters just to pass an inspection engine, and the per-site web filtering that only exists where somebody remembered to buy it. What it does not replace is worth saying plainly: the on-premises FortiGate is still the LAN edge, still the SD-WAN endpoint, and still what inspects traffic between segments inside a site.

The first decisions are commercial and expensive to undo: which PoPs, which tier, how many users - the minimum is 50, and each user registers three devices before a fourth consumes another licence. For an Israeli customer the trap is Tel Aviv. TLV-G2 is a public cloud location, so Advanced buys it as a security PoP and inspection happens in-country - but keeping log analytics in-country there requires Comprehensive.

Access gets narrower. A contractor who needed a VPN account, and therefore a route to an entire subnet, now gets one application - brokered per session with posture re-checked each time, so an out-of-date laptop is refused the next connection rather than trusted for the rest of the day. And for a small IT team, joiners and leavers are one place to look, with one log stream behind them.

The rest of
the stack

What gets added once the edge is in place, in the order most organisations actually reach for it.

FortiManager & FortiAnalyzer

FortiManager holds the policy for every FortiGate you run. FortiAnalyzer holds their logs.

  • ADOMs keep each site or tenant in its own administrative scope
  • Policy packages install one change across many FortiGates
  • Every install is versioned - diff a revision, revert a device
  • Indexed analytics for search, compressed archive for depth

Migrating to
a full Fortinet estate

A converter moves the rules. It does not move the exceptions nobody documented, the VLAN that was never really segmented, or the service that only worked because the old firewall was permissive on a Tuesday. This is the sequence we run, and none of it happens in one night.

Survey and rule archaeology

Inventory every firewall, switch, controller, circuit and renewal date, pull the live configs, and find out which rules are actually hit. Most rulebases carry a decade of exceptions nobody will admit to owning.

Design and sizing

Fix the segmentation and VLAN plan, choose the FortiOS branch, and size the FortiGate on threat protection throughput with inspection actually enabled - not on the headline number, and not without the model's AP and switch limits.

Parallel build and conversion

Stand the FortiGate up beside the live firewall and convert the rulebase with FortiConverter, then resolve by hand what no converter can carry across: the vendor-specific objects and the rules that were only ever true on the old platform.

Staged cutover, VLAN by VLAN

Move one VLAN or one service at a time, with the old firewall still powered and a rollback designed before the window opens. Nothing goes across in one night.

LAN edge adoption

Bring the FortiSwitch estate under the FortiGate over FortiLink and register the FortiAPs to its wireless controller, so ports, SSIDs and policy finally sit in one config.

Central management and handover

Register the devices to FortiManager, import the per-box policies into policy packages in stages, point the logs at FortiAnalyzer, and hand over a documented estate rather than a set of passwords.

Fortinet
Security Day 2026

The SpotNet team at their stand at Fortinet Security Day Israel

Send us the details

A few lines about the site, the circuits you have and what is not working are enough. The message reaches the engineering team directly.