In short
FortiGate installation is the work of configuring a Fortinet firewall’s interfaces, VLANs, security policies, VPNs, SSL inspection, high availability (HA) and firmware to fit a company’s network. It is needed at every scale, from single-office SMEs to multi-branch companies. CybUp reviews the existing network, builds the rule base from scratch or migrates it from the old device, tests it and hands over a fully documented configuration.
How is a FortiGate installed and configured?
A FortiGate installation works through four layers: first the network is inventoried, then interfaces and VLANs are defined, then security policies are written, and finally security profiles are switched on and everything is tested. The order matters. Racking the unit and running the wizard until “the internet works” takes ten minutes, but at that point all you have is a single rule letting everything on the inside out to anywhere.
We start by writing down which device sits on which network, which server is reached from outside and which applications use which ports. Take a 45-person accountancy practice on a single floor: a file server, the database behind the accounting package, IP phones, two printers, a CCTV recorder and guest Wi-Fi. That picture yields at least five separate network segments, and how much each one may reach the others is decided pair by pair.
Most of the FortiGate configuration work is turning those decisions into policy. On the physical side, the VLAN trunks to the switches have to be right, and we handle that in the same project as Cisco switch configuration. For offices in Istanbul we install on-site; elsewhere in Türkiye, once your local staff have racked the unit, we finish the configuration remotely.
How should FortiGate firewall policies and VLANs be designed?
A good FortiGate policy set is written on the principle of “deny by default, open only what is needed”. FortiOS already ends with an implicit deny rule; the real problem is the broad “all → all” rules added during installation that never get tightened afterwards. We give address and service objects meaningful names and add a comment and logging to every rule. Whoever reads a rule six months later should be able to tell why it is there.
VLAN segmentation decides how far the damage spreads when a device is compromised. The CCTV recorder has no reason to reach the accounting server, and guest Wi-Fi should never see the internal network. In a typical office we separate these segments:
- Staff computers (the user network)
- Servers and storage
- IP phones (a dedicated voice VLAN with priority)
- IoT devices such as cameras, door access controllers and printers
- Guest network (internet only)
- Management network (management interfaces of switches, access points and the FortiGate)
Should you enable SSL inspection on a FortiGate?
It comes down to how much protection you want and how much management overhead you will accept for it, and for most companies a two-stage approach makes sense. FortiOS offers two main methods. Certificate inspection looks only at the information in the TLS handshake; it is enough for web filtering and needs nothing on the client. Deep inspection decrypts the traffic, scans the content and re-encrypts it with a certificate signed by the FortiGate (Fortinet: SSL/TLS deep inspection).
If you switch on deep inspection, the FortiGate’s CA certificate has to be installed on every computer, otherwise users see a certificate warning on every site. In an Active Directory environment we push it out through Group Policy and leave phones and guest devices out of scope. According to Fortinet’s own documentation, the finance and banking, health and personal privacy categories are exempt from inspection by default. Banking apps, update servers and software that uses certificate pinning usually need further exemptions too.
Then there is the human side. Decrypting traffic means you may end up handling employees’ personal data, which brings in KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698). Before deep inspection goes live, we recommend covering it in the company’s information security policy and in the privacy notice given to staff; the details are on our KVKK technical measures page.
“Organizations that have performed a risk assessment and determined that HTTPS inspection is a requirement should ensure their HTTPS inspection products are performing correct transport layer security (TLS) certificate validation.”
When do you need a FortiGate HA setup?
You need high availability (HA) if a firewall failure would leave the whole company without internet and cut off from its branches. With FGCP, FortiGate’s HA protocol, two units form a cluster: one carries the traffic, while the other stands by with its configuration and session information kept in sync. If the power fails or a monitored interface loses its link, the standby unit takes over.
The units in a cluster must be the same model with the same firmware and the same hardware configuration, and they must be registered to the same FortiCare account (Fortinet: FGCP). We run two separate heartbeat links directly between the units and spread the internet and internal connections symmetrically across both. One point worth knowing before you buy: on some small and mid-range models (the 40F to 100F families), an HA pair sold for the purpose can have its FortiGuard subscription tied to a single virtual serial number (Fortinet: single FortiGuard licence for an A-P HA cluster), which keeps licensing simpler.
Which FortiGate model do you need for your number of users?
The right model depends less on headcount than on which security features you will switch on and how fast your internet line is. The headline “firewall throughput” figure on a datasheet measures rule checking only. The “threat protection” figure, measured with IPS, antivirus and application control enabled, and the SSL inspection performance are far closer to real life.
The points to look at are your internet line speed and how it will grow, the number of concurrent remote access users, the number of branch tunnels, how much traffic will go through deep inspection, and whether you need HA. One more warning: from FortiOS 7.4.4, models with 2 GB of RAM (the 40F, 60F, 60E, 80E and 90E series and their variants) no longer support proxy-related features such as ZTNA, proxy-based inspection and WAF (Fortinet release note). If you need those features, choose the model with that in mind.
Wherever you end up buying the unit, we work out the requirements with you and explain the difference between two suitable models in terms of how you will actually use them. The review is free.
How are FortiGate licences, FortiGuard renewals and firmware upgrades managed?
The FortiGate hardware and the FortiGuard security subscriptions are two separate things. IPS signatures, the antivirus database and web filtering categories are updated for as long as the subscription runs; once it lapses, that protection stops working with current information. We record the renewal dates in the handover document and remind you before they expire.
For firmware the rule is simple: no skipping versions, follow Fortinet’s upgrade path and read the release notes. Release notes sometimes hide major changes. FortiOS 7.6.3, for example, removed SSL VPN tunnel mode in favour of IPsec VPN; the old settings are not carried across, so the migration has to be done by hand before upgrading (Fortinet 7.6.3 release note). If your remote staff connect over SSL VPN, we plan that move as part of VPN server setup.
How do you migrate from another firewall to FortiGate?
A migration starts by cleaning up the old rule base, not by copying it one-for-one. Fortinet’s FortiConverter tool can translate other vendors’ configurations into FortiGate format (FortiConverter), but it will also faithfully carry across the hundreds of unused rules that have built up over the years. We first use the logs to find out which rules actually see traffic, weed out the rest and rewrite what remains to fit the new VLAN and object structure.
Say your old firewall has 200 rules, three branch tunnels and an ERP port open to the internet. The new FortiGate is built in parallel first, the branch tunnels are matched with the far ends and test users try everything out. The cutover happens out of hours, and the old unit stays in the rack for a few days as the rollback plan. If a second internet line is being brought in as well, we set up FortiGate SD-WAN in the same cutover.
What you receive
- Network inventory, VLAN and IP plan
- Least-privilege security policies, each with a comment and logging
- IPS, web filtering, application control and SSL inspection profiles
- Site-to-site and remote access VPNs with MFA
- HA cluster build and failover test (where needed)
- Configuration backup, admin access restrictions and a firmware plan
- A handover document explaining every setting
How we work
- 1
Free review
We review your current network, the old firewall configuration and your internet lines, and set out requirements and risks in writing.
- 2
Design
We prepare the VLAN and IP plan, the policy matrix and the VPN and HA design, and put them to you for sign-off.
- 3
Preparation
We upgrade the FortiGate to the current recommended firmware and build the configuration before it touches the live network.
- 4
Cutover and testing
We go live out of hours and test user, server, branch and phone traffic one by one.
- 5
Handover and follow-up
We hand over the documentation, watch the logs with you over the first few days and make any fine adjustments needed.
Frequently asked questions
How long does a FortiGate installation take?
For a single office with up to 50 users, design and installation are usually done within a few working days. Branches, HA and migrating rules from an old device add time. We confirm the schedule in writing after the review.
Will the internet go down during the installation?
Only briefly. Because the new unit is prepared in advance, downtime is limited to a short window while cables are moved and tests are run, and we schedule that window out of hours.
How much does a FortiGate installation cost?
We give you a written quote once we have reviewed the scope, and the review is free. The main factors are the number of users and branches, HA, SSL inspection and whether you are migrating from an old device.
Can you install a FortiGate remotely?
Yes. For offices outside Istanbul, your local staff rack and cable the unit, and we set up initial access and finish the configuration remotely. In Istanbul we install on-site.
Our FortiGuard subscription has expired. Will the FortiGate keep working?
It keeps working as a router and firewall, but subscription-based protection such as IPS, antivirus and web filtering no longer runs on current data. We help you work out which subscriptions you really need for the way you use the device.
Can we upgrade our old FortiGate to a newer FortiOS version?
Yes, up to the highest FortiOS version the model supports. If the model is out of support or loses important features on newer releases, we say so plainly in writing and set out the replacement options.
Where are FortiGate logs stored?
In smaller setups, on the device itself or in Fortinet’s cloud logging service; in larger ones, on FortiAnalyzer or a syslog server. We set the retention period to match your company policy.
Do you provide support after installation?
Yes. We offer maintenance agreements covering firmware upgrades, rule changes and periodic configuration reviews. We can also bring the FortiGate into Zabbix monitoring with alerts for faults and capacity.
Sources and official documentation
- Fortinet: FortiOS 7.6 Administration Guide
- Fortinet: SSL/TLS deep inspection
- Fortinet: FGCP (HA)
- Fortinet: Single FortiGuard licence for an A-P HA cluster
- Fortinet: Proxy features on 2 GB RAM models
- Fortinet: SSL VPN tunnel mode removed in FortiOS 7.6.3
- Fortinet: FortiConverter
- CISA: HTTPS Interception Weakens TLS Security (TA17-075A)