Expertise in
Fortinet environments

We design the segmentation, convert the rulebase, cut over one VLAN at a time, and keep the fabric running after it is live - from the FortiGate at the edge to FortiSASE for staff working outside the office.

Start with FortiSASE

Security Fabric -
one chain: firewall, switch, AP

This is Fortinet's method: the FortiGate configures the ports and the SSIDs and inspects what crosses between them, from a single console.

FortiGate

The next-generation firewall at the edge, and the device that configures the rest of the LAN edge. It enforces the segmentation plan as policy between VLANs.

FortiSwitch

Access switches that attach to the FortiGate over FortiLink, so ports, PoE and VLANs are configured where the policy already lives - with no separate switch controller and no management licence.

FortiAP

Access points that register to the FortiGate's own wireless controller over CAPWAP. SSIDs, switch ports and firmware are all managed from the same console.

FortiSASE -
security that follows the user

The most requested of these services. Remote users connect through a Fortinet-managed point of presence, where the same inspection runs wherever the laptop is opened.

Remote user Branch Contractor FortiSASE inspected in the cloud SaaS Internet Private apps
Every path crosses one inspection point, and traffic that fails inspection is blocked there.

The VPN concentrator on the perimeter, the backhaul design that drags branch traffic to headquarters just to pass an inspection engine, and the per-site web filtering deployed only at sites where it was bought. The on-premises FortiGate stays in place: it is the LAN edge, the SD-WAN endpoint, and what inspects traffic between segments inside a site.

The first decisions are commercial and expensive to undo: which PoPs, which tier, how many users - the minimum is 50, and each user registers three devices before a fourth consumes another licence. For an Israeli customer, the Tel Aviv location needs attention. TLV-G2 is a public cloud location, so Advanced buys it as a security PoP and inspection happens in-country - but keeping log analytics in-country there requires Comprehensive.

Access gets narrower. A contractor who needed a VPN account, and therefore a route to an entire subnet, now gets one application - brokered per session with posture re-checked each time, so an out-of-date laptop is refused the next connection. And for a small IT team, joiners and leavers are one place to look, with one log stream behind them.

The rest of
the stack

What gets added once the edge is in place, in the order most organisations actually reach for it.

FortiManager & FortiAnalyzer

FortiManager holds the policy for every FortiGate you run. FortiAnalyzer holds their logs.

  • ADOMs keep each site or tenant in its own administrative scope
  • Policy packages install one change across many FortiGates
  • Every install is versioned - diff a revision, revert a device
  • Indexed analytics for search, compressed archive for depth

Migrating to
a full Fortinet estate

A converter moves the rules. Undocumented exceptions, a VLAN that was never actually segmented and a service that depended on the old firewall's settings are resolved by hand. This is the sequence we run, and it is staged over several steps.

Survey and rule archaeology

Inventory every firewall, switch, controller, circuit and renewal date, pull the live configs, and find out which rules are actually hit. Most rulebases carry a decade of exceptions with no recorded owner.

Design and sizing

Fix the segmentation and VLAN plan, choose the FortiOS branch, and size the FortiGate on threat protection throughput with inspection enabled, in line with the model's AP and switch limits.

Parallel build and conversion

Stand the FortiGate up beside the live firewall and convert the rulebase with FortiConverter, then resolve by hand what no converter can carry across: the vendor-specific objects and the rules that were only ever true on the old platform.

Staged cutover, VLAN by VLAN

Move one VLAN or one service at a time, with the old firewall still powered and a rollback designed before the window opens.

LAN edge adoption

Bring the FortiSwitch estate under the FortiGate over FortiLink and register the FortiAPs to its wireless controller, so ports, SSIDs and policy finally sit in one config.

Central management and handover

Register the devices to FortiManager, import the per-box policies into policy packages in stages, point the logs at FortiAnalyzer, and hand over the estate with its documentation.

Fortinet
Security Day 2026

The SpotNet team at their stand at Fortinet Security Day Israel

Send us the details

A few lines about your organisation, the infrastructure you have and what is not working are enough. The message reaches the engineering team directly.