Expertise in
Fortinet environments
We design the segmentation, convert the rulebase, cut over one VLAN at a time, and keep the fabric running after it is live - from the FortiGate at the edge to FortiSASE for staff working outside the office.
Security Fabric -
one chain: firewall, switch, AP
This is Fortinet's method: the FortiGate configures the ports and the SSIDs and inspects what crosses between them, from a single console.
FortiGate
The next-generation firewall at the edge, and the device that configures the rest of the LAN edge. It enforces the segmentation plan as policy between VLANs.
FortiSwitch
Access switches that attach to the FortiGate over FortiLink, so ports, PoE and VLANs are configured where the policy already lives - with no separate switch controller and no management licence.
FortiAP
Access points that register to the FortiGate's own wireless controller over CAPWAP. SSIDs, switch ports and firmware are all managed from the same console.
FortiSASE -
security that follows the user
The most requested of these services. Remote users connect through a Fortinet-managed point of presence, where the same inspection runs wherever the laptop is opened.
The VPN concentrator on the perimeter, the backhaul design that drags branch traffic to headquarters just to pass an inspection engine, and the per-site web filtering deployed only at sites where it was bought. The on-premises FortiGate stays in place: it is the LAN edge, the SD-WAN endpoint, and what inspects traffic between segments inside a site.
The first decisions are commercial and expensive to undo: which PoPs, which tier, how many users - the minimum is 50, and each user registers three devices before a fourth consumes another licence. For an Israeli customer, the Tel Aviv location needs attention. TLV-G2 is a public cloud location, so Advanced buys it as a security PoP and inspection happens in-country - but keeping log analytics in-country there requires Comprehensive.
Access gets narrower. A contractor who needed a VPN account, and therefore a route to an entire subnet, now gets one application - brokered per session with posture re-checked each time, so an out-of-date laptop is refused the next connection. And for a small IT team, joiners and leavers are one place to look, with one log stream behind them.
The rest of
the stack
What gets added once the edge is in place, in the order most organisations actually reach for it.
FortiManager holds the policy for every FortiGate you run. FortiAnalyzer holds their logs.
- ADOMs keep each site or tenant in its own administrative scope
- Policy packages install one change across many FortiGates
- Every install is versioned - diff a revision, revert a device
- Indexed analytics for search, compressed archive for depth
One agent and one console for endpoint posture, with access granted per application.
- EMS issues each endpoint a certificate carrying its device UID
- Posture rules become tags the FortiGate reads over the Fabric connector
- The FortiGate is the trust broker: access proxy for web, TCP forwarding for RDP and SSH
- No ZTNA licence on the FortiGate - the access proxy is in FortiOS
A live inventory of what is actually connected, identified on sight and put on the VLAN it belongs on, at the port it plugged into.
- Agentless profiling from OUI, DHCP fingerprint and NetFlow
- Dynamic VLAN steering across a broad multi-vendor switch matrix
- Built-in RADIUS for 802.1X and MAB, or RADIUS proxy
- Guest and contractor portals with sponsor approval and expiry
Fake servers and planted credentials across the network, so an intruder's first wrong move raises an alert.
- Decoys for Windows, Linux, macOS, SCADA, IoT, VoIP and medical
- Tokens on real endpoints: cached credentials, SMB, RDP, SSH, ODBC
- A touch of a decoy is an alert, with no baselining period
- Campaign view traces lateral movement, mapped to MITRE ATT&CK
Email, browser and the collaboration apps around them - scanned for malicious files and links, blocked in the mail path and remediated automatically in the apps. Fortinet completed its acquisition of Perception Point in December 2024 and launched the suite in June 2025. SpotNet sells and operates it as an MSSP.
- Email, browser, Teams, SharePoint, OneDrive, Slack, Drive, Box, Salesforce
- Recursive unpacking and dynamic scanning, with a CPU-level sandbox layer
- 24x7 managed incident response included in every SKU
- API onboarding to Microsoft 365 and Google Workspace, no MX cutover
Migrating to
a full Fortinet estate
A converter moves the rules. Undocumented exceptions, a VLAN that was never actually segmented and a service that depended on the old firewall's settings are resolved by hand. This is the sequence we run, and it is staged over several steps.
Survey and rule archaeology
Inventory every firewall, switch, controller, circuit and renewal date, pull the live configs, and find out which rules are actually hit. Most rulebases carry a decade of exceptions with no recorded owner.
Design and sizing
Fix the segmentation and VLAN plan, choose the FortiOS branch, and size the FortiGate on threat protection throughput with inspection enabled, in line with the model's AP and switch limits.
Parallel build and conversion
Stand the FortiGate up beside the live firewall and convert the rulebase with FortiConverter, then resolve by hand what no converter can carry across: the vendor-specific objects and the rules that were only ever true on the old platform.
Staged cutover, VLAN by VLAN
Move one VLAN or one service at a time, with the old firewall still powered and a rollback designed before the window opens.
LAN edge adoption
Bring the FortiSwitch estate under the FortiGate over FortiLink and register the FortiAPs to its wireless controller, so ports, SSIDs and policy finally sit in one config.
Central management and handover
Register the devices to FortiManager, import the per-box policies into policy packages in stages, point the logs at FortiAnalyzer, and hand over the estate with its documentation.
Fortinet
Security Day 2026