I am researching into FortiGate hardware as we are looking to replace Draytek routers for some small businesses we manage, they are under 20 users the majority and will likely use FortiGate 30E and 60E or F for any companies likely to grow. There's 2 reasons behind the move improving security & replacing dated hardware.
The reason for the post is I am looking at the UTM features and trying to work out which I should be enabling for small businesses as standard. These are my thoughts and queries around the UTM features, any input appreciated.
[ul]
IPS - Probably the best part as keeps tracking network for threats. Will be enabling.Web Filtering - Whilst we offer this with our AV (Bitdefender) and would be easier to manage in the cloud. We will enable on guest VLANs for BYOD. For VLANs with company devices not enabled.App Control - Torn if we need this or the benefits. Its good to monitor apps in use though. However we control apps that are installed and these businesses don't have any specific app lockdown requirements. What's peoples thoughts on this? Should I be looking into it further?Antivirus - Is this an AV on the firewall that protects the network or is this only needed if our users are using FortiClient AV app on devices? Anti-Spam - Users are all on Microsoft 365 and have a Spam Filtering Service so not sure if this is required or does it provide another layer and worth having?Industrial Database - This part I can see in a FortiGate device but not mentioned around UTM in Fortinet articles (that I can see). It sounds like it the part which keeps UTM real time up to date? I assumed if you buy UTM is does this anyway? Could anyone explain this please?Security Rating - This looks beneficial to help understand how secure the network is and especially in the first few years transitioning to FortiNet products would be useful? [/ul]I am going to watch some of the Fortinet videos to help understand it better, but any help from the experts here would be greatly appreciated.
TIA