Skip to main content
lea768
New Member
June 18, 2021
Question

UTM Features

  • June 18, 2021
  • 1 reply
  • 2966 views

I am researching into FortiGate hardware as we are looking to replace Draytek routers for some small businesses we manage,  they are under 20 users the majority and will likely use FortiGate 30E and 60E or F for any companies likely to grow. There's 2 reasons behind the move improving security & replacing dated hardware.

 

The reason for the post is I am looking at the UTM features and trying to work out which I should be enabling for small businesses as standard.  These are my thoughts and queries around the UTM features, any input appreciated.

 

[ul]
  • IPS - Probably the best part as keeps tracking network for threats. Will be enabling.
  • Web Filtering - Whilst we offer this with our AV (Bitdefender) and would be easier to manage in the cloud. We will enable on guest VLANs for BYOD. For VLANs with company devices not enabled.
  • App Control - Torn if we need this or the benefits. Its good to monitor apps in use though. However we control apps that are installed and these businesses don't have any specific app lockdown requirements. What's peoples thoughts on this? Should I be looking into it further?
  • Antivirus - Is this an AV on the firewall that protects the network or is this only needed if our users are using FortiClient AV app on devices? 
  • Anti-Spam - Users are all on Microsoft 365 and have a Spam Filtering Service so not sure if this is required or does it provide another layer and worth having?
  • Industrial Database - This part I can see in a FortiGate device but not mentioned around UTM in Fortinet articles (that I can see). It sounds like it the part which keeps UTM real time up to date? I assumed if you buy UTM is does this anyway? Could anyone explain this please?
  • Security Rating - This looks beneficial to help understand how secure the network is and especially in the first few years transitioning to FortiNet products would be useful? [/ul]

    I am going to watch some of the Fortinet videos to help understand it better, but any help from the experts here would be greatly appreciated.

     

    TIA

    • 1 reply

      andrewbailey
      New Member
      June 18, 2021
      Hi Lea, Firstly, I would avoid the 30E completely. It doesn’t have enough memory for even a small number of users and will not support the 6.6 and 7.0 firmware releases. The 40F is a far better product and similarly price. Likewise I would stick to the 60F rather than the 60E (which are almost identically priced). The FortiAPs from the F series (231F etc) are pretty good too- and are managed and controlled from the Fortigate. I wouldn’t use the Fortigates with WiFi- the WiFi tends to be a little limited. Check carefully before you go for them. Likewise the FortiSwitches are controlled and managed from the Fortigate. The “single pane of glass” view for the FortiAPs and FortiSwitches is very useful and helpful. The documentation site is pretty good these days. You can find it here (if you hadn’t already):- [link]https://docs.fortinet.com/[/link] Some specific comments:- - IPS has options to block malicious web sites and connections to Botnet C&C servers. I would suggest it is essential for all traffic to/ from the internet. - Webfilter is very useful. You block by category and should restrict categories like “potentially liable”, “security risk” etc. Again I would apply to all traffic facing the internet. - App control is worth using. It does let you see apps being used- and again there may be some you want to block. For example some remote control apps etc. For app control to fully work ssl deep inspection is required. That can be tricky- effectively the Fortigate performs a “man in the middle” inspection so the Fortigate’s CA cert needs to be trusted by the device. Not always easy to do or get right. - Antivirus is useful and will scan all traffic. Again it can’t see a virus in an SSL/ HTTPS connection with deep inspection. But never the less well worth having. - Anti-spam doesn’t sound like it is needed in your scenario. - Industrial database is more aimed at operation technologies I think. Things like PLCs used in a factory, SCADA networks things like that. - Security rating is helpful- it does steer you towards good security practices. You haven’t mentioned DNS filter- again for me this is essential. Each DNS query is validated against a database and a a block ip is returned for blocked categories. I have used DreyTek devices a few times and they are decent routers. But the Fortigates are much more capable, faster and secure- when properly configured. The custom FortiNet network and content processors (or SOC chips for the models you are looking at) are very good. If you are managing a number of small businesses it might be worth looking at FortiManager (for easy and consistency of deployment) and FortiAnalyzer for detailed reporting and logging. Obviously those choices will depend on budgets and what service levels you are providing. Hope that helps a bit. Kind Regards, Andy.
      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!