Expertise in
Fortinet environments
We do not sell boxes. We design the segmentation, convert the rulebase, cut over one VLAN at a time, and keep the fabric running after it is live - from the FortiGate at the edge to FortiSASE for the people who no longer sit in the office.
Security Fabric -
one chain: firewall, switch, AP
This is Fortinet's method, and the reason the estate stops being three consoles from three vendors: the FortiGate configures the ports and the SSIDs and inspects what crosses between them, down one chain.
FortiGate
The next-generation firewall at the edge, and the thing that configures the rest of it. Segmentation stops being a line on a diagram and becomes a policy that a firewall enforces between VLANs.
FortiSwitch
Access switches that attach to the FortiGate over FortiLink, so ports, PoE and VLANs are configured where the policy already lives - with no separate switch controller and no management licence.
FortiAP
Access points that register to the FortiGate's own wireless controller over CAPWAP. One console for SSIDs and switch ports, one firmware plan, one place to look when a floor drops.
FortiSASE -
the office stopped being a place
The flagship of this page, and the one we are asked for most. Remote users stop terminating on a VPN concentrator that was sized for a quarter of them, and start terminating in a Fortinet-managed point of presence where the same inspection runs wherever the laptop was opened.
The VPN concentrator on the perimeter, the backhaul design that drags branch traffic to headquarters just to pass an inspection engine, and the per-site web filtering that only exists where somebody remembered to buy it. What it does not replace is worth saying plainly: the on-premises FortiGate is still the LAN edge, still the SD-WAN endpoint, and still what inspects traffic between segments inside a site.
The first decisions are commercial and expensive to undo: which PoPs, which tier, how many users - the minimum is 50, and each user registers three devices before a fourth consumes another licence. For an Israeli customer the trap is Tel Aviv. TLV-G2 is a public cloud location, so Advanced buys it as a security PoP and inspection happens in-country - but keeping log analytics in-country there requires Comprehensive.
Access gets narrower. A contractor who needed a VPN account, and therefore a route to an entire subnet, now gets one application - brokered per session with posture re-checked each time, so an out-of-date laptop is refused the next connection rather than trusted for the rest of the day. And for a small IT team, joiners and leavers are one place to look, with one log stream behind them.
The rest of
the stack
What gets added once the edge is in place, in the order most organisations actually reach for it.
FortiManager holds the policy for every FortiGate you run. FortiAnalyzer holds their logs.
- ADOMs keep each site or tenant in its own administrative scope
- Policy packages install one change across many FortiGates
- Every install is versioned - diff a revision, revert a device
- Indexed analytics for search, compressed archive for depth
One agent and one console for endpoint posture, with access granted per application instead of a full VPN tunnel.
- EMS issues each endpoint a certificate carrying its device UID
- Posture rules become tags the FortiGate reads over the Fabric connector
- The FortiGate is the trust broker: access proxy for web, TCP forwarding for RDP and SSH
- No ZTNA licence on the FortiGate - the access proxy is in FortiOS
A live inventory of what is actually connected, identified on sight and put on the VLAN it belongs on, at the port it plugged into.
- Agentless profiling from OUI, DHCP fingerprint and NetFlow
- Dynamic VLAN steering across a broad multi-vendor switch matrix
- Built-in RADIUS for 802.1X and MAB, or RADIUS proxy
- Guest and contractor portals with sponsor approval and expiry
Fake servers and planted credentials across the network, so an intruder's first wrong move raises an alert.
- Decoys for Windows, Linux, macOS, SCADA, IoT, VoIP and medical
- Tokens on real endpoints: cached credentials, SMB, RDP, SSH, ODBC
- A touch of a decoy is an alert, with no baselining period
- Campaign view traces lateral movement, mapped to MITRE ATT&CK
Email, browser and the collaboration apps around them - scanned for malicious files and links, blocked in the mail path and remediated automatically in the apps. Fortinet completed its acquisition of Perception Point in December 2024 and launched the suite in June 2025. SpotNet sells and operates it as an MSSP.
- Email, browser, Teams, SharePoint, OneDrive, Slack, Drive, Box, Salesforce
- Recursive unpacking and dynamic scanning, with a CPU-level sandbox layer
- 24x7 managed incident response included in every SKU
- API onboarding to Microsoft 365 and Google Workspace, no MX cutover
Migrating to
a full Fortinet estate
A converter moves the rules. It does not move the exceptions nobody documented, the VLAN that was never really segmented, or the service that only worked because the old firewall was permissive on a Tuesday. This is the sequence we run, and none of it happens in one night.
Survey and rule archaeology
Inventory every firewall, switch, controller, circuit and renewal date, pull the live configs, and find out which rules are actually hit. Most rulebases carry a decade of exceptions nobody will admit to owning.
Design and sizing
Fix the segmentation and VLAN plan, choose the FortiOS branch, and size the FortiGate on threat protection throughput with inspection actually enabled - not on the headline number, and not without the model's AP and switch limits.
Parallel build and conversion
Stand the FortiGate up beside the live firewall and convert the rulebase with FortiConverter, then resolve by hand what no converter can carry across: the vendor-specific objects and the rules that were only ever true on the old platform.
Staged cutover, VLAN by VLAN
Move one VLAN or one service at a time, with the old firewall still powered and a rollback designed before the window opens. Nothing goes across in one night.
LAN edge adoption
Bring the FortiSwitch estate under the FortiGate over FortiLink and register the FortiAPs to its wireless controller, so ports, SSIDs and policy finally sit in one config.
Central management and handover
Register the devices to FortiManager, import the per-box policies into policy packages in stages, point the logs at FortiAnalyzer, and hand over a documented estate rather than a set of passwords.
Fortinet
Security Day 2026