Back to Blog
Fortinet · Networking Sep 2026 7 min read

Fortinet FortiGate: 13 Questions Engineers and Buyers Ask Most

David Chen, Senior Network Engineer
BlackHawk Data Team
FortiCare vs FortiGuard, which bundle to buy, what expires when, the SSL-VPN deprecation, FortiLink, sizing traps in the datasheet, and how to plan renewals.

FortiGate is the platform we are asked about more than any other, and the questions cluster tightly. Below are the thirteen that come up in nearly every engagement, answered the way we would answer them on a design call.

Disclosure: BlackHawk Data is a Fortinet Platinum Partner holding the EPSP, ETSP and OT Security specializations. Bundle contents and version support change; verify specifics against the current Fortinet ordering guide before you buy.

1. What is the difference between FortiCare and FortiGuard?

FortiCare is support. FortiGuard is security content. They are separate purchases and you generally need both.

FortiCare covers TAC access, firmware entitlement and hardware RMA, with response times and proactive services improving at higher tiers. FortiGuard is the subscription feeding the security engines — IPS signatures, antivirus, web filtering, application control, anti-spam, sandboxing and others.

A FortiGate with FortiCare but no FortiGuard is a supported firewall with stale threat intelligence. A FortiGate with FortiGuard but no FortiCare has current signatures and no path to a replacement when the power supply dies.

2. Which bundle should I buy?

Fortinet packages FortiGuard services into tiers that ascend in coverage — a unified threat protection tier covering the core engines, an advanced tier adding sandboxing and advanced threat protection, and enterprise tiers layering on further services including OT security. The broadest bundles add orchestration and higher FortiCare tiers.

The decision rule we use:

  • Core/UTP tier — branch and small-site firewalls where the FortiGate is doing standard perimeter work.
  • Advanced/ATP tier — anywhere you need sandboxing, which in practice means any site handling email or user web browsing.
  • Enterprise tier — the internet edge, data center, and anywhere OT security services are required.

Do not buy one tier estate-wide out of administrative convenience. The access-layer branch device and the internet edge have different jobs.

3. What actually happens when a licence expires?

The FortiGate keeps forwarding traffic. It does not brick. What stops is the updating.

Specifically: signature updates cease, so IPS and antivirus protect against yesterday's threats indefinitely; cloud-dependent services such as web filtering, sandboxing and application-control categorization fail or fall back; firmware entitlement ends with FortiCare; and RMA coverage lapses.

This is a meaningful architectural difference from subscription-locked platforms where hardware stops functioning without an active licence. It is also a trap — an expired FortiGate looks perfectly healthy on a dashboard while its protection quietly ages.

4. Which FortiOS version should I run?

Run the branch your hardware supports and your features require, not the newest number. Fortinet maintains parallel branches with different maturity profiles: an established branch carrying the widest deployment base, and a newer branch required for recently released hardware and features.

The operating rule: the newest release is for new hardware and new features, not for production estates that are working. Check the supported-platforms matrix before planning any upgrade, since model support is dropped at branch boundaries and that discovery belongs in planning rather than in a maintenance window.

5. Is SSL-VPN going away?

Yes — plan around it. Fortinet has signalled the deprecation of SSL-VPN, with IPsec (IKEv2 with FortiClient) and ZTNA as the recommended replacements.

For any new remote-access design in 2026, do not build on SSL-VPN. For existing deployments, treat migration as a scheduled project rather than an emergency: inventory who uses it and for what, pilot IPsec or ZTNA with a representative group, then migrate by cohort. ZTNA is the better destination where the requirement is application access rather than full network access, because it grants per-application entitlement instead of a network position.

6. What is FortiLink, and do I still need a wireless controller?

FortiLink is the management protocol that lets a FortiGate manage FortiSwitch and FortiAP directly, making them logical extensions of the firewall rather than separately managed platforms.

The practical consequence: no separate wireless controller and no separate switch management platform. Ports, VLANs, SSIDs and the security policy that applies to them are configured in one place, and the security policy follows the client rather than stopping at the firewall.

It is a genuine cost and complexity reduction for branch and mid-size campus. At large campus scale — many hundreds of access points — the design deserves review rather than an assumption that the model extends linearly.

7. How do I size a FortiGate correctly?

The datasheet is where sizing goes wrong, because the headline number is not the number that applies to you.

Firewall throughput is measured with large packets and no inspection. Threat protection throughput — the figure with IPS, antivirus and application control enabled — is the one that matches production, and it is frequently a fraction of the headline.

Size against: threat protection throughput with the inspection you will actually run; concurrent and new sessions per second for your user count; SSL/TLS inspection throughput separately, because it is expensive and usually the real ceiling; VPN tunnel counts; and headroom for three to five years of growth. Sizing to today's peak guarantees a conversation about replacement in year two.

8. What is the Security Fabric and do I need it?

The Security Fabric is the integration layer across Fortinet products — FortiGate, FortiSwitch, FortiAP, FortiClient, FortiAnalyzer, FortiManager and the rest — providing a topology view, shared telemetry, a security rating against configuration benchmarks, and automation stitches that trigger actions across products.

You do not need it for a single firewall. It becomes valuable when you have three or more Fortinet product types, and the automation stitches — quarantine an endpoint when the sandbox convicts a file, for example — are where the operational return actually sits.

9. Active-passive or active-active HA?

Active-passive for almost everyone. It is simpler, session synchronization is well understood, and failover is predictable. The passive unit is not wasted; it is the thing that lets you patch without a maintenance outage.

Active-active is worth it when you genuinely need aggregate throughput beyond one unit and your traffic profile distributes well. It adds complexity to session handling and troubleshooting that most environments do not need to take on.

10. Do I need FortiManager and FortiAnalyzer?

FortiManager earns its place at roughly ten or more FortiGates, or fewer if they must stay configuration-consistent. Below that, direct management is usually fine.

FortiAnalyzer is a different calculation: it is log retention, reporting and forensics. If you have a compliance retention requirement or any expectation of investigating an incident after the fact, you need it or an equivalent SIEM destination. A firewall's local log buffer is not an investigation tool.

11. Is Fortinet appropriate for OT networks?

Yes, and it is one of the platform's stronger positions. FortiGate can inspect industrial protocols — Modbus, DNP3, EtherNet/IP, IEC 61850 and others — at the function level, which is what allows a rule permitting read operations from a monitoring segment while denying write. That distinction cannot be enforced by port-based filtering, because both ride the same port.

Combined with ruggedized hardware for cabinet and substation environments and the OT-specific FortiGuard services, it is a credible enforcement point at an IEC 62443 conduit. See our OT segmentation guide for how that fits the wider architecture.

12. How does FortiGate SD-WAN compare to cloud-delivered alternatives?

FortiGate SD-WAN is strongest where branch-to-branch and branch-to-datacenter traffic dominates, where ASIC acceleration gives you throughput per dollar that is hard to match, and where you want routing, security and switching in one box.

Cloud-delivered alternatives are strongest for globally distributed, cloud-first estates where a private backbone between regions matters more than local throughput. Increasingly the answer is both — FortiGates at the edge for segmentation and local breakout, tunnelled into a global fabric for transit. We covered the trade-off in detail in Fortinet SD-WAN vs. Cloudflare Magic WAN.

13. Should I co-terminate or stagger renewals?

Co-terminate if your priority is administrative simplicity; stagger if your priority is cash-flow smoothing and negotiating leverage.

Fortinet's licensing is modular enough to support either, which is a real commercial advantage over all-or-nothing subscription models. Two things to do regardless: keep a register of every expiry date with an owner and a reminder at ninety days, and re-examine service-by-service at each renewal rather than repeating last term's order. Estates routinely carry services nobody has used in years.


If you want an independent read on a FortiGate estate — version exposure, licence posture, rule hygiene and sizing headroom — that is what our architecture review covers. Practice detail is at /solutions/fortinet.