Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hippo
New Contributor

Replacing Sophos UTM

Hello everyone,
We need to replace our Sophos UTM and were thinking of doing so with Fortinet systems.
Since we use quite a few Sophos UTM services, I'm wondering which Forti system I can use to map which services, or whether it's even possible to map all services.

Here are the “services” I need to provide:

 

Network Protection

  • Firewall
  • IPS
  • VPN: IPSec / SSL
  • Reporting

 

Email Protection

  • Email reception
  • Virus protection
  • Email encryption
  • Spam protection (Quarantine , daily SPAM-report)

 

Web Protection

  • Web-Proxy
  • Virus protection
  • HTTPS-Scanning
  • Webserver Protection
  • WAF (Web Application Firewall) for On-Premise Exchange OWA access

 

General

  • Active-Passive Cluster
  • AD synchronization
  • Reporting

Is it possible to deploy all services with Fortinet?

1 Solution
AEK
SuperUser
SuperUser

Hello Hippo

Since I don't have experience with Sophos UTM, I'll comment following my experience with Sophos XGS, which is more modern than Sophos UTM.

Yes all mentioned features are available in FortiGate, and in general talking FGT is better than Sophos XGS. However I must say the following:

  • Sophos' WAF that is embedded in the Sophos XGS is more powerful and has more features than FortiGate's WAF
  • Same for Antispam
  • For all the rest I find FortiGate is better

So for basic WAF and Antispam you can use FortiGate, and for medium efficiency and more features you can use Sophos' WAF and Antispam, but for enterprise level WAF and Antispam you definitely need dedicated WAF and Antispam in addition to your NGFW.

Fortinet's enterprise level WAF and mail gateway products are FortiWeb and FortiMail.

On the other hand FortiGate embedded reporting is basic, so if you are looking for advanced and more sophisticated reporting then you additionally need FortiAnalyzer, which is the reporting product for all Fortinet products.

AEK

View solution in original post

AEK
3 REPLIES 3
kaman
Staff
Staff

Hi Hippo,

Yes, all of the services can be deployed within Fortinet.

Regards,
Aman

Hippo
New Contributor

Hi Aman,

in Sophos UTM, I was able to map all services within a single system.
How many products do you think I need with Fortinet?
Which products do I need for a secure yet affordable environment?

AEK
SuperUser
SuperUser

Hello Hippo

Since I don't have experience with Sophos UTM, I'll comment following my experience with Sophos XGS, which is more modern than Sophos UTM.

Yes all mentioned features are available in FortiGate, and in general talking FGT is better than Sophos XGS. However I must say the following:

  • Sophos' WAF that is embedded in the Sophos XGS is more powerful and has more features than FortiGate's WAF
  • Same for Antispam
  • For all the rest I find FortiGate is better

So for basic WAF and Antispam you can use FortiGate, and for medium efficiency and more features you can use Sophos' WAF and Antispam, but for enterprise level WAF and Antispam you definitely need dedicated WAF and Antispam in addition to your NGFW.

Fortinet's enterprise level WAF and mail gateway products are FortiWeb and FortiMail.

On the other hand FortiGate embedded reporting is basic, so if you are looking for advanced and more sophisticated reporting then you additionally need FortiAnalyzer, which is the reporting product for all Fortinet products.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors