What Is a FortiGate Firewall & How Does It Work?
NetworkingOctober 6, 2026·Dhanush Vr

What Is a FortiGate Firewall & How Does It Work?

FortiGate firewall appliance | Empeller Systems

A FortiGate firewall is Fortinet’s network security platform used to control and inspect traffic moving between networks.

It can work as a traditional firewall, but FortiGate also provides next-generation firewall (NGFW) capabilities such as intrusion prevention, application control, web filtering, VPN, SSL inspection and Secure SD-WAN.

For a business, FortiGate may sit between the internet and the internal network, between different network segments, or at branch and data-centre locations. FortiGate is available as physical appliances as well as virtual and cloud-based deployments.

The important part for buyers is choosing the right FortiGate model and security services for the actual network.

Key Takeaways

  • FortiGate is Fortinet’s firewall and NGFW platform.
  • It controls traffic entering, leaving or moving between networks.
  • Firewall policies determine what traffic is allowed or blocked.
  • Security profiles can inspect permitted traffic for threats and unwanted activity.
  • FortiGate supports capabilities such as IPS, application control, web filtering, VPN and Secure SD-WAN.
  • FortiGuard services provide threat intelligence and subscription-based security capabilities.
  • Firewall sizing should consider bandwidth, inspection, sessions, VPNs, interfaces and future growth—not only user count.

What Is a FortiGate Firewall?

FortiGate is Fortinet’s family of next-generation firewalls.

A traditional firewall primarily controls network connections according to rules such as:

  • source;
  • destination;
  • IP address;
  • port; and
  • protocol.

A next-generation firewall goes further.

Depending on its configuration and security services, FortiGate can also identify applications, inspect traffic for threats, control website access, detect intrusion attempts and inspect encrypted traffic.

This allows the firewall to make decisions based on more than simply where traffic is coming from and which port it uses.

In a simple office network, the layout might look like:

Internet → FortiGate → Business Network

In larger environments, FortiGate can also protect:

  • branch offices;
  • data centres;
  • network segments;
  • servers;
  • remote users;
  • cloud environments; and
  • connections between multiple business locations.

Fortinet also offers virtual FortiGate deployments for supported private, public and hybrid cloud environments.

How Does a FortiGate Firewall Work?

The exact traffic flow depends on how the network and policies are configured, but a simplified process looks like this.

1. Traffic Reaches the FortiGate

Network traffic passes through FortiGate according to the network design.

This could be traffic:

  • entering from the internet;
  • leaving the company network;
  • travelling between network segments;
  • moving between offices; or
  • using a VPN connection.

2. FortiGate Checks the Traffic

FortiGate evaluates information about the connection against its configured firewall policies.

Depending on the configuration, this can include the source, destination, service, application, user or other traffic information.

3. Firewall Policies Are Applied

Administrators create policies that determine how different traffic should be handled.

A policy can allow or deny traffic and can also apply additional security inspection.

For example, a business might allow employees to access normal web services while applying web filtering, antivirus, application control and intrusion prevention to that traffic.

4. Security Profiles Inspect Allowed Traffic

Where configured, FortiGate can apply security profiles and FortiGuard services such as:

  • antivirus;
  • intrusion prevention (IPS);
  • application control;
  • web filtering;
  • DNS filtering; and
  • other threat-protection functions.

Encrypted traffic can also be inspected where SSL/TLS inspection is appropriately configured.

5. FortiGate Takes Action

Based on the firewall policy and security inspection, traffic may be:

  • allowed;
  • blocked;
  • monitored;
  • logged; or
  • handled according to another configured action.

6. Traffic and Security Events Can Be Logged

Logging gives administrators visibility into network activity and security events.

This information can help with:

  • troubleshooting;
  • security monitoring;
  • investigating incidents;
  • understanding network use; and
  • improving firewall policies.

The exact logging and reporting setup depends on the FortiGate environment and management tools being used.

What Can a FortiGate Firewall Help Protect Against?

When properly configured with the appropriate security services, FortiGate can help detect or block threats such as:

  • malicious network traffic;
  • malware;
  • known exploits;
  • intrusion attempts;
  • access to malicious websites;
  • unauthorised applications;
  • unwanted network access; and
  • some threats hidden within encrypted traffic.

However, a firewall should never be treated as the entire cybersecurity strategy.

Businesses should also consider:

  • endpoint security;
  • identity and access control;
  • multi-factor authentication;
  • software and firmware updates;
  • secure configuration;
  • backups;
  • monitoring; and
  • employee security awareness.

FortiGate protects an important part of the network, but no single security product can protect against every type of cyberattack.

Key FortiGate Features

Next-Generation Firewall (NGFW)

FortiGate combines standard firewall policies with deeper security inspection.

This allows organisations to create more detailed rules around applications, users, destinations and security requirements rather than relying only on ports and IP addresses.

Intrusion Prevention System (IPS)

IPS inspects network traffic for activity associated with known attacks and vulnerabilities.

When enabled and correctly configured, it can detect and block matching malicious traffic before it reaches protected systems.

Application Control

FortiGate Application Control can identify applications and allow administrators to create policies around them.

This is useful because modern applications do not always use one fixed network port.

A business may, for example, want to allow approved applications while monitoring or restricting applications that are unnecessary or create additional risk.

Web Filtering

Web filtering helps businesses control access to websites according to categories and security policies.

Depending on the FortiGuard service and configuration, it can help restrict access to malicious, phishing, inappropriate or unwanted websites.

VPN

FortiGate supports encrypted VPN connectivity for use cases such as:

  • connecting offices;
  • site-to-site communication; and
  • supported remote-access environments.

VPN requirements should be considered during firewall sizing because encryption and the number of tunnels or users can affect the required capacity.

Secure SD-WAN

Fortinet integrates Secure SD-WAN with the FortiGate platform.

This allows organisations to combine WAN connectivity and security on the same platform and can be useful for businesses with:

  • multiple branches;
  • more than one internet connection;
  • MPLS and internet connectivity;
  • failover requirements; or
  • application-aware WAN routing.

For a UAE company with offices in Dubai and Abu Dhabi, for example, FortiGate can form part of a design that securely connects the locations while managing WAN traffic and failover.

SSL/TLS Inspection

A large amount of internet traffic is encrypted.

SSL/TLS inspection allows supported FortiGate configurations to decrypt and inspect appropriate encrypted traffic according to company policy, then re-encrypt it before forwarding.

This can help detect threats that would otherwise be hidden inside encrypted sessions.

However, SSL inspection requires additional processing.

This is important when sizing a FortiGate because a firewall that appears powerful enough based only on basic firewall throughput may perform very differently once security inspection is enabled.

FortiGate Hardware and FortiGuard: What’s the Difference?

This is an important distinction for first-time buyers.

FortiGate

FortiGate is the firewall platform.

It may be a physical appliance or a supported virtual/cloud deployment. It handles network traffic and applies the configured firewall and security policies.

FortiGuard

FortiGuard Security Services provide threat intelligence and subscription-based security capabilities used by FortiGate and other Fortinet products.

Depending on the package, these services can support areas such as:

  • intrusion prevention;
  • malware protection;
  • web filtering;
  • DNS security;
  • application security; and
  • other threat-protection capabilities.

So when comparing FortiGate quotations, do not look only at the appliance.

Check:

FortiGate model + FortiGuard package + licence term + support

Two quotations for the same FortiGate model may not include the same security services.

Where Is FortiGate Used?

FortiGate can be deployed across many different environments.

Small Offices

A smaller FortiGate appliance may provide firewall, VPN and security services for an office network.

Branch Offices

FortiGate can combine network security with SD-WAN and VPN connectivity for branches connected to headquarters or other locations.

Multi-Site Businesses

Businesses with several locations can deploy FortiGate across different sites and use centralised management tools such as FortiManager where appropriate.

Data Centres and Larger Networks

Higher-capacity FortiGate platforms can protect networks with much greater bandwidth, session counts, interfaces and security-inspection requirements.

Virtual and Cloud Environments

Fortinet also provides FortiGate virtual appliances for supported virtualised and cloud infrastructure.

Which FortiGate Firewall Do You Need?

Choosing the right FortiGate is not simply about counting employees.

Before selecting a model, consider:

  • number of users and devices;
  • internet/WAN bandwidth;
  • NGFW throughput;
  • threat-protection throughput;
  • IPS requirements;
  • SSL/TLS inspection;
  • concurrent sessions;
  • VPN users and tunnels;
  • number and speed of interfaces;
  • high-availability requirements;
  • number of locations; and
  • expected network growth.

The enabled security services matter because deeper inspection requires processing capacity.

For more detailed sizing advice, see our Next-Generation Firewall Buyer’s Guide.

FortiGate Models to Consider

Empeller Systems offers FortiGate firewalls in the UAE across different performance levels.

Some examples include:

FortiGate ModelTypical Starting Point
FortiGate 40FSmaller offices and branch environments
FortiGate 60F / 70FSmall businesses and branches requiring additional capacity
FortiGate 120GGrowing and mid-sized network environments
FortiGate 200GHigher-capacity business and distributed networks
FortiGate 600FMore demanding enterprise environments
FortiGate 900GHigh-performance enterprise requirements

These are general starting points, not fixed recommendations.

For example, two businesses may each have 100 employees but need completely different firewalls.

One may have a 500 Mbps internet connection with light cloud use.

The other may have multi-gigabit connectivity, SSL inspection, several VPN tunnels and large file transfers.

User count is the same. Firewall workload is not.

Why Firewall Throughput Is Not Enough

One of the most common mistakes when comparing firewalls is looking only at the largest throughput number on the datasheet.

Consider the FortiGate 120G.

Empeller’s current listing gives figures including:

  • Firewall throughput: up to 39 Gbps depending on packet size
  • IPS throughput: 5.3 Gbps
  • NGFW throughput: 3.1 Gbps
  • Threat-protection throughput: 2.8 Gbps

The numbers are different because security inspection adds work for the firewall.

This is why buyers should compare the performance figure that matches how they intend to use the device.

If IPS, application control, web filtering, SSL inspection and other security services will be enabled, basic firewall throughput alone does not tell you whether the appliance is correctly sized.

Benefits of FortiGate for Businesses

A properly sized and configured FortiGate can bring several network functions together on one platform.

Depending on the deployment, benefits can include:

  • firewall and NGFW security;
  • application visibility;
  • intrusion prevention;
  • secure VPN connectivity;
  • web filtering;
  • Secure SD-WAN;
  • encrypted traffic inspection;
  • network segmentation; and
  • centralised management for larger deployments.

The value comes from choosing the correct combination of appliance, security services and configuration for the network.

FortiGate vs Other Firewalls

FortiGate is one of several business firewall platforms.

Other vendors may differ in:

  • security architecture;
  • application visibility;
  • management;
  • SD-WAN;
  • performance;
  • licensing;
  • ecosystem integration; and
  • total cost.

For example, Fortinet and Palo Alto Networks both provide NGFW platforms but take somewhat different approaches to networking, application visibility and management.

Read our Fortinet vs Palo Alto firewall comparison for a more detailed comparison.