Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lea768
New Contributor

UTM Features

I am researching into FortiGate hardware as we are looking to replace Draytek routers for some small businesses we manage,  they are under 20 users the majority and will likely use FortiGate 30E and 60E or F for any companies likely to grow. There's 2 reasons behind the move improving security & replacing dated hardware.

 

The reason for the post is I am looking at the UTM features and trying to work out which I should be enabling for small businesses as standard.  These are my thoughts and queries around the UTM features, any input appreciated.

 

[ul]
  • IPS - Probably the best part as keeps tracking network for threats. Will be enabling.
  • Web Filtering - Whilst we offer this with our AV (Bitdefender) and would be easier to manage in the cloud. We will enable on guest VLANs for BYOD. For VLANs with company devices not enabled.
  • App Control - Torn if we need this or the benefits. Its good to monitor apps in use though. However we control apps that are installed and these businesses don't have any specific app lockdown requirements. What's peoples thoughts on this? Should I be looking into it further?
  • Antivirus - Is this an AV on the firewall that protects the network or is this only needed if our users are using FortiClient AV app on devices? 
  • Anti-Spam - Users are all on Microsoft 365 and have a Spam Filtering Service so not sure if this is required or does it provide another layer and worth having?
  • Industrial Database - This part I can see in a FortiGate device but not mentioned around UTM in Fortinet articles (that I can see). It sounds like it the part which keeps UTM real time up to date? I assumed if you buy UTM is does this anyway? Could anyone explain this please?
  • Security Rating - This looks beneficial to help understand how secure the network is and especially in the first few years transitioning to FortiNet products would be useful? [/ul]

    I am going to watch some of the Fortinet videos to help understand it better, but any help from the experts here would be greatly appreciated.

     

    TIA

  • 1 REPLY 1
    andrewbailey
    Contributor II

    Hi Lea, Firstly, I would avoid the 30E completely. It doesn’t have enough memory for even a small number of users and will not support the 6.6 and 7.0 firmware releases. The 40F is a far better product and similarly price. Likewise I would stick to the 60F rather than the 60E (which are almost identically priced). The FortiAPs from the F series (231F etc) are pretty good too- and are managed and controlled from the Fortigate. I wouldn’t use the Fortigates with WiFi- the WiFi tends to be a little limited. Check carefully before you go for them. Likewise the FortiSwitches are controlled and managed from the Fortigate. The “single pane of glass” view for the FortiAPs and FortiSwitches is very useful and helpful. The documentation site is pretty good these days. You can find it here (if you hadn’t already):- [link]https://docs.fortinet.com/[/link] Some specific comments:- - IPS has options to block malicious web sites and connections to Botnet C&C servers. I would suggest it is essential for all traffic to/ from the internet. - Webfilter is very useful. You block by category and should restrict categories like “potentially liable”, “security risk” etc. Again I would apply to all traffic facing the internet. - App control is worth using. It does let you see apps being used- and again there may be some you want to block. For example some remote control apps etc. For app control to fully work ssl deep inspection is required. That can be tricky- effectively the Fortigate performs a “man in the middle” inspection so the Fortigate’s CA cert needs to be trusted by the device. Not always easy to do or get right. - Antivirus is useful and will scan all traffic. Again it can’t see a virus in an SSL/ HTTPS connection with deep inspection. But never the less well worth having. - Anti-spam doesn’t sound like it is needed in your scenario. - Industrial database is more aimed at operation technologies I think. Things like PLCs used in a factory, SCADA networks things like that. - Security rating is helpful- it does steer you towards good security practices. You haven’t mentioned DNS filter- again for me this is essential. Each DNS query is validated against a database and a a block ip is returned for blocked categories. I have used DreyTek devices a few times and they are decent routers. But the Fortigates are much more capable, faster and secure- when properly configured. The custom FortiNet network and content processors (or SOC chips for the models you are looking at) are very good. If you are managing a number of small businesses it might be worth looking at FortiManager (for easy and consistency of deployment) and FortiAnalyzer for detailed reporting and logging. Obviously those choices will depend on budgets and what service levels you are providing. Hope that helps a bit. Kind Regards, Andy.
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors