FortiGate deployment and management in Dubai: sized properly, configured properly, and actually maintained.
FortiGate is the most widely deployed firewall in the UAE mid-market and most of the ones we inherit are doing a fraction of what was paid for. Threat protection licensed but not enabled, an expired subscription nobody noticed, firmware three years behind, and a rule base that has grown to four hundred entries where six are actually used. We deploy FortiGate from scratch, take over existing units, and run them properly afterwards, which is the part that determines whether the box was worth buying.

- Sized on dataNot on the sales sheet
- 5 minP1 remote response
- ManagedFirmware and policy lifecycle
- FreeExisting FortiGate health check
Eight scopes, from sizing through to the part everyone skips.
Sizing against your actual traffic
FortiGate datasheet throughput figures are measured with inspection largely disabled. Turn on SSL inspection, IPS and application control and real throughput drops substantially, which is why undersized units are the single most common cause of "the new firewall made everything slow". We size against your measured traffic profile, your inspection requirements and three-year growth, not against the headline number.
Deployment and migration
Design, staging and configuration before anything touches production, then a planned cutover in a window with a rollback position. Migrations from an existing firewall are rebuilt rather than blindly converted, because importing a decade of accumulated rules recreates every problem you were trying to leave behind.
Policy design that stays understandable
A rule base built on named objects, groups and a documented structure, so the person looking at it in three years can tell what each rule is for and whether it is still needed. Rule review on a cycle to remove what has gone stale. Most inherited FortiGates have hundreds of rules and no documentation, which makes every change risky.
Turning on what you already paid for
The UTM and threat protection bundle is where the licence cost sits, and it is routinely licensed and left disabled or in monitor mode. We enable IPS, antivirus, web filtering, application control and DNS filtering deliberately, tuned to avoid the false positives that cause someone to switch them off again a fortnight later.
SSL inspection done without breaking things
Without SSL inspection most threat protection sees very little, since almost all traffic is encrypted. Doing it badly breaks banking portals, certificate-pinned applications and mobile apps. We deploy it with a properly distributed CA certificate and a maintained exemption list, in stages, so it works rather than being abandoned after the first week of complaints.
Remote access and site-to-site VPN
SSL VPN or IPsec for remote users with multi-factor authentication enforced, and site-to-site tunnels between offices, warehouses and cloud. Remote access is a frequent entry point when it is left on defaults with no MFA, and it is one of the first things we check on any inherited unit.
Firmware and subscription lifecycle
Firmware kept on a supported branch with upgrades tested and scheduled rather than deferred indefinitely, and subscription renewals tracked so nothing lapses silently. An expired UTM subscription leaves a firewall that still passes traffic and no longer protects anything, and nobody notices because nothing visibly breaks.
Logging, monitoring and evidence
Logs retained somewhere other than the appliance itself, alerting into our NOC, and reporting that a non-technical reader can act on. For clients with a compliance obligation, firewall configuration and change records feed straight into the evidence pack an assessor or a bank will ask for.
Why the new firewall made everything slower.
This is the most common complaint we hear about FortiGate in the UAE, and it is almost never a fault in the product. It is an arithmetic problem introduced at the point of sale.
- Datasheet throughput is measured with inspection largely off. The headline figure on the quote is firewall throughput, which is the least demanding measurement. Once IPS, antivirus and application control are running, real throughput is a fraction of it, and with SSL inspection enabled it falls considerably further.
- So the unit sized against the headline number is adequate on day one, when nothing is turned on, and inadequate the moment somebody enables the protection you bought it for. The rational response by whoever is being shouted at is to turn the inspection back off, which is how you end up with an expensive router.
- The fix at purchase is to size against the throughput figure for the inspection profile you actually intend to run, with headroom for three years of growth, and to buy the model above if the calculation is marginal. The gap in cost between adjacent models is far smaller than the cost of replacing one early.
- If you already have an undersized unit, there are options short of replacement: selective SSL inspection with a well-maintained exemption list, offloading some inspection, or tuning profiles by traffic type. We would rather do that than sell you hardware you do not need.
Four reasons the appliance is not the hard part.
We fix what the reseller sale leaves behind
The common pattern in this market is a hardware sale with a basic configuration, an invoice, and no ongoing relationship. Two years later the firmware is old, the subscription has lapsed, the rule base has been added to by three different people and threat protection was never turned on. Almost every FortiGate we take over shows at least three of those four.
We size on measurement, not on the datasheet
Undersizing is the most expensive mistake in a firewall purchase because the fix is a new appliance. We measure current throughput and connection counts, model what inspection will cost you in performance, and recommend a model with headroom. Sometimes that means recommending a smaller unit than you were quoted.
Vendor-neutral about whether FortiGate is right
We also deploy Sophos and work with other platforms, so we have no reason to push FortiGate where it does not fit. It is an excellent choice for most UAE mid-market environments and there are cases where something else suits better. We would rather say so than sell you the box we happen to be quoting.
The lifecycle is contracted, not remembered
Firmware currency, subscription renewal dates, rule review and configuration backup are scheduled items in the service rather than things someone means to get around to. That is the entire difference between a firewall that protects you in year three and one that is decorative.
Six UAE environments we deploy it into.
Multi-site businesses
Head office plus branches or warehouses, with site-to-site VPN and centrally managed policy. FortiGate is strong here and the management overhead stays reasonable as sites are added.
Manufacturing and industrial
Segmenting the plant floor from the office network, with controlled and monitored paths between them. Internal segmentation is where FortiGate earns its keep in these environments.
Retail with multiple branches
POS traffic separated from guest wireless and back office, consistent policy across stores, and card-data segmentation where PCI DSS scope applies.
Clinics and healthcare
Clinical systems isolated from general traffic, remote access for practitioners with MFA, and logging that supports the evidence a health authority may ask for.
Regulated financial firms
Documented rule base, change control, log retention and configuration evidence, all of which a DFSA or FSRA review will look at rather than taking on trust.
Education and training providers
Content filtering with age-appropriate policy, separation of student and staff networks, and capacity for dense wireless usage at peak times.
Four ways UAE businesses end up running a FortiGate.
| Feature | Managed by us | Bought from a reseller, unmanaged | Managed in-house | Whoever set it up, occasionally |
|---|---|---|---|---|
Sized against measured traffic | Rarely | Sometimes | Rarely | |
Threat protection actually enabled | Often not | Usually | Often not | |
SSL inspection deployed and working | Rarely | Sometimes | Rarely | |
Firmware kept on a supported branch | Depends on workload | |||
Subscription renewal tracked | Invoice arrives, or does not | |||
Rule base documented and reviewed | Sometimes | |||
Configuration backed up off the box | Rarely | Usually | Rarely | |
MFA enforced on remote access | Often not | Usually | Often not | |
Logs retained off the appliance | Sometimes | |||
24/7 response when it fails | Business hours at best | Depends on staff | Best effort | |
Evidence pack for audits | Sometimes |
Twelve things to check on the FortiGate you already own.
Is it actually protecting anything
- Is the UTM or threat protection subscription current?An expired subscription still passes traffic and stops inspecting it. Nothing visibly breaks, which is why it goes unnoticed for months.
- Are IPS, antivirus and web filtering enabled or just licensed?Licensed and disabled is the most common finding, and you are paying for it either way.
- Are any profiles still in monitor mode from the deployment?Monitor mode logs the attack and lets it through. It is meant to be temporary.
- Is SSL inspection on?Without it, inspection sees very little, because almost everything is encrypted.
Is it maintained
- What firmware version is it running, and is that branch still supported?Check the release date. Three years behind is common and means unpatched vulnerabilities in the device protecting you.
- When was the configuration last backed up, and where is that backup?A config backup stored only on the appliance is not a backup.
- How many rules are in the policy, and who can explain them?If nobody can, every future change carries risk and nobody will clean it up.
- Are logs going anywhere off the appliance?Local logging fills and rotates. After an incident you will want more history than the box holds.
The ways in
- Is MFA enforced on SSL VPN and every remote access method?Remote access without MFA is the single highest-risk finding on this list.
- Is the administrative interface reachable from the internet?It should not be. Check, because defaults and quick fixes leave it exposed more often than you would expect.
- Are there admin accounts belonging to a previous provider?Extremely common after a provider change, and rarely removed.
- Are default or shared admin credentials still in use?Named accounts per administrator, with logging. Shared credentials mean no accountability.
Five steps, whether it is new or inherited.
- 1
Assessment and sizing
Week 1
Measured traffic profile, connection counts, what inspection you need, site topology, remote access requirements and growth plans. For an existing unit, a full configuration review against the twelve-point health check. Output is a written finding and a sizing recommendation.
- 2
Design and staging
Weeks 1 to 2
Policy structure, object and group naming, segmentation plan, inspection profiles, VPN design, logging and retention. Configured and tested on the bench before anything is touched in production. Migrations are rebuilt rather than converted.
- 3
Cutover
One planned window
Out of hours with a documented rollback position and a validation test plan. We stage inspection rather than enabling everything at once, because a cutover that also flips on SSL inspection produces complaints nobody can attribute.
- 4
Tuning
Weeks 2 to 4
The phase that decides whether protection stays on. False positives found and resolved, exemption lists built for applications that legitimately break under inspection, and profiles moved from monitor to enforcement as each is proved.
- 5
Managed lifecycle
Ongoing
Firmware currency, subscription renewal tracking, scheduled rule review, configuration backup off the appliance, log retention, monitoring into our NOC, and configuration evidence for any audit obligation.
“We had a FortiGate for four years and assumed we were covered. GR ran a free health check and found the threat protection subscription had expired fourteen months earlier, the firmware was from 2022, and there was still an admin account belonging to the company that installed it. None of that was visible to us because nothing had broken. That is the uncomfortable part.”
What UAE buyers ask about FortiGate.
What clients usually scope alongside FortiGate.
Sophos firewall Dubai
The other platform we deploy, for buyers weighing the two or already running Sophos endpoint protection.
SOC as a service Dubai
Firewall logs are only useful if someone watches them. Monitoring, triage and response around the clock.
Network monitoring and NOC Dubai
Availability and performance monitoring across the whole network, not just the perimeter device.
Find out whether the firewall you own is actually protecting you.
We check subscription status, firmware currency, whether threat protection is enabled or only licensed, the state of the rule base, remote access configuration, and whether any previous provider still holds admin access. You get the findings in writing at no cost, whether or not you engage us.
Related Services
Explore more solutions that work great with this service
Sophos vs Fortinet
Independent comparison from a partner in both
Sophos Firewall Dubai
Authorised Sophos XGS partner UAE
SOC-as-a-Service
24/7 SOC on Microsoft Sentinel
Network Monitoring NOC
24/7 NOC monitoring with named engineers
Endpoint Security
Defender for Endpoint and Intune managed
Managed Security Services
MSS on Microsoft Defender XDR and Sentinel
IT AMC Dubai
Annual maintenance contracts for IT infrastructure