We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Security
  2. Fortinet FortiGate Dubai
Fortinet FortiGate, Dubai and the UAE

FortiGate deployment and management in Dubai: sized properly, configured properly, and actually maintained.

FortiGate is the most widely deployed firewall in the UAE mid-market and most of the ones we inherit are doing a fraction of what was paid for. Threat protection licensed but not enabled, an expired subscription nobody noticed, firmware three years behind, and a rule base that has grown to four hundred entries where six are actually used. We deploy FortiGate from scratch, take over existing units, and run them properly afterwards, which is the part that determines whether the box was worth buying.

Book a FortiGate health checkSee what we deliver
Fortinet FortiGate firewall deployment for UAE businesses
  • Sized on dataNot on the sales sheet
  • 5 minP1 remote response
  • ManagedFirmware and policy lifecycle
  • FreeExisting FortiGate health check
What we deliver on FortiGate

Eight scopes, from sizing through to the part everyone skips.

Buying and racking a FortiGate is the easy part and it is where a lot of UAE deployments stop. These are the eight scopes that decide whether the appliance is protecting anything two years later.

Sizing against your actual traffic

FortiGate datasheet throughput figures are measured with inspection largely disabled. Turn on SSL inspection, IPS and application control and real throughput drops substantially, which is why undersized units are the single most common cause of "the new firewall made everything slow". We size against your measured traffic profile, your inspection requirements and three-year growth, not against the headline number.

Deployment and migration

Design, staging and configuration before anything touches production, then a planned cutover in a window with a rollback position. Migrations from an existing firewall are rebuilt rather than blindly converted, because importing a decade of accumulated rules recreates every problem you were trying to leave behind.

Policy design that stays understandable

A rule base built on named objects, groups and a documented structure, so the person looking at it in three years can tell what each rule is for and whether it is still needed. Rule review on a cycle to remove what has gone stale. Most inherited FortiGates have hundreds of rules and no documentation, which makes every change risky.

Turning on what you already paid for

The UTM and threat protection bundle is where the licence cost sits, and it is routinely licensed and left disabled or in monitor mode. We enable IPS, antivirus, web filtering, application control and DNS filtering deliberately, tuned to avoid the false positives that cause someone to switch them off again a fortnight later.

SSL inspection done without breaking things

Without SSL inspection most threat protection sees very little, since almost all traffic is encrypted. Doing it badly breaks banking portals, certificate-pinned applications and mobile apps. We deploy it with a properly distributed CA certificate and a maintained exemption list, in stages, so it works rather than being abandoned after the first week of complaints.

Remote access and site-to-site VPN

SSL VPN or IPsec for remote users with multi-factor authentication enforced, and site-to-site tunnels between offices, warehouses and cloud. Remote access is a frequent entry point when it is left on defaults with no MFA, and it is one of the first things we check on any inherited unit.

Firmware and subscription lifecycle

Firmware kept on a supported branch with upgrades tested and scheduled rather than deferred indefinitely, and subscription renewals tracked so nothing lapses silently. An expired UTM subscription leaves a firewall that still passes traffic and no longer protects anything, and nobody notices because nothing visibly breaks.

Logging, monitoring and evidence

Logs retained somewhere other than the appliance itself, alerting into our NOC, and reporting that a non-technical reader can act on. For clients with a compliance obligation, firewall configuration and change records feed straight into the evidence pack an assessor or a bank will ask for.

The sizing trap

Why the new firewall made everything slower.

This is the most common complaint we hear about FortiGate in the UAE, and it is almost never a fault in the product. It is an arithmetic problem introduced at the point of sale.

  • Datasheet throughput is measured with inspection largely off. The headline figure on the quote is firewall throughput, which is the least demanding measurement. Once IPS, antivirus and application control are running, real throughput is a fraction of it, and with SSL inspection enabled it falls considerably further.
  • So the unit sized against the headline number is adequate on day one, when nothing is turned on, and inadequate the moment somebody enables the protection you bought it for. The rational response by whoever is being shouted at is to turn the inspection back off, which is how you end up with an expensive router.
  • The fix at purchase is to size against the throughput figure for the inspection profile you actually intend to run, with headroom for three years of growth, and to buy the model above if the calculation is marginal. The gap in cost between adjacent models is far smaller than the cost of replacing one early.
  • If you already have an undersized unit, there are options short of replacement: selective SSL inspection with a well-maintained exemption list, offloading some inspection, or tuning profiles by traffic type. We would rather do that than sell you hardware you do not need.
Ask for a sizing review
Why clients move FortiGate management to us

Four reasons the appliance is not the hard part.

We fix what the reseller sale leaves behind

The common pattern in this market is a hardware sale with a basic configuration, an invoice, and no ongoing relationship. Two years later the firmware is old, the subscription has lapsed, the rule base has been added to by three different people and threat protection was never turned on. Almost every FortiGate we take over shows at least three of those four.

We size on measurement, not on the datasheet

Undersizing is the most expensive mistake in a firewall purchase because the fix is a new appliance. We measure current throughput and connection counts, model what inspection will cost you in performance, and recommend a model with headroom. Sometimes that means recommending a smaller unit than you were quoted.

Vendor-neutral about whether FortiGate is right

We also deploy Sophos and work with other platforms, so we have no reason to push FortiGate where it does not fit. It is an excellent choice for most UAE mid-market environments and there are cases where something else suits better. We would rather say so than sell you the box we happen to be quoting.

The lifecycle is contracted, not remembered

Firmware currency, subscription renewal dates, rule review and configuration backup are scheduled items in the service rather than things someone means to get around to. That is the entire difference between a firewall that protects you in year three and one that is decorative.

Where FortiGate fits well

Six UAE environments we deploy it into.

Multi-site businesses

Head office plus branches or warehouses, with site-to-site VPN and centrally managed policy. FortiGate is strong here and the management overhead stays reasonable as sites are added.

Manufacturing and industrial

Segmenting the plant floor from the office network, with controlled and monitored paths between them. Internal segmentation is where FortiGate earns its keep in these environments.

Retail with multiple branches

POS traffic separated from guest wireless and back office, consistent policy across stores, and card-data segmentation where PCI DSS scope applies.

Clinics and healthcare

Clinical systems isolated from general traffic, remote access for practitioners with MFA, and logging that supports the evidence a health authority may ask for.

Regulated financial firms

Documented rule base, change control, log retention and configuration evidence, all of which a DFSA or FSRA review will look at rather than taking on trust.

Education and training providers

Content filtering with age-appropriate policy, separation of student and staff networks, and capacity for dense wireless usage at peak times.

Ownership models compared

Four ways UAE businesses end up running a FortiGate.

The appliance is identical in all four columns. What differs is whether anyone is looking after it, and that is what determines the security outcome.
Sized against measured traffic
Managed by us
Bought from a reseller, unmanagedRarely
Managed in-houseSometimes
Whoever set it up, occasionallyRarely
Threat protection actually enabled
Managed by us
Bought from a reseller, unmanagedOften not
Managed in-houseUsually
Whoever set it up, occasionallyOften not
SSL inspection deployed and working
Managed by us
Bought from a reseller, unmanagedRarely
Managed in-houseSometimes
Whoever set it up, occasionallyRarely
Firmware kept on a supported branch
Managed by us
Bought from a reseller, unmanaged
Managed in-houseDepends on workload
Whoever set it up, occasionally
Subscription renewal tracked
Managed by us
Bought from a reseller, unmanagedInvoice arrives, or does not
Managed in-house
Whoever set it up, occasionally
Rule base documented and reviewed
Managed by us
Bought from a reseller, unmanaged
Managed in-houseSometimes
Whoever set it up, occasionally
Configuration backed up off the box
Managed by us
Bought from a reseller, unmanagedRarely
Managed in-houseUsually
Whoever set it up, occasionallyRarely
MFA enforced on remote access
Managed by us
Bought from a reseller, unmanagedOften not
Managed in-houseUsually
Whoever set it up, occasionallyOften not
Logs retained off the appliance
Managed by us
Bought from a reseller, unmanaged
Managed in-houseSometimes
Whoever set it up, occasionally
24/7 response when it fails
Managed by us
Bought from a reseller, unmanagedBusiness hours at best
Managed in-houseDepends on staff
Whoever set it up, occasionallyBest effort
Evidence pack for audits
Managed by us
Bought from a reseller, unmanaged
Managed in-houseSometimes
Whoever set it up, occasionally
Feature
Managed by us
Bought from a reseller, unmanaged
Managed in-house
Whoever set it up, occasionally
Sized against measured traffic
RarelySometimesRarely
Threat protection actually enabled
Often notUsuallyOften not
SSL inspection deployed and working
RarelySometimesRarely
Firmware kept on a supported branch
Depends on workload
Subscription renewal tracked
Invoice arrives, or does not
Rule base documented and reviewed
Sometimes
Configuration backed up off the box
RarelyUsuallyRarely
MFA enforced on remote access
Often notUsuallyOften not
Logs retained off the appliance
Sometimes
24/7 response when it fails
Business hours at bestDepends on staffBest effort
Evidence pack for audits
Sometimes
Health check

Twelve things to check on the FortiGate you already own.

Every item here is something we have found on an inherited unit in the UAE, most of them repeatedly. You can check all twelve yourself, or we will do it free and send you the findings.

Is it actually protecting anything

  • Is the UTM or threat protection subscription current?
    An expired subscription still passes traffic and stops inspecting it. Nothing visibly breaks, which is why it goes unnoticed for months.
  • Are IPS, antivirus and web filtering enabled or just licensed?
    Licensed and disabled is the most common finding, and you are paying for it either way.
  • Are any profiles still in monitor mode from the deployment?
    Monitor mode logs the attack and lets it through. It is meant to be temporary.
  • Is SSL inspection on?
    Without it, inspection sees very little, because almost everything is encrypted.

Is it maintained

  • What firmware version is it running, and is that branch still supported?
    Check the release date. Three years behind is common and means unpatched vulnerabilities in the device protecting you.
  • When was the configuration last backed up, and where is that backup?
    A config backup stored only on the appliance is not a backup.
  • How many rules are in the policy, and who can explain them?
    If nobody can, every future change carries risk and nobody will clean it up.
  • Are logs going anywhere off the appliance?
    Local logging fills and rotates. After an incident you will want more history than the box holds.

The ways in

  • Is MFA enforced on SSL VPN and every remote access method?
    Remote access without MFA is the single highest-risk finding on this list.
  • Is the administrative interface reachable from the internet?
    It should not be. Check, because defaults and quick fixes leave it exposed more often than you would expect.
  • Are there admin accounts belonging to a previous provider?
    Extremely common after a provider change, and rarely removed.
  • Are default or shared admin credentials still in use?
    Named accounts per administrator, with logging. Shared credentials mean no accountability.
How a FortiGate engagement runs

Five steps, whether it is new or inherited.

A new deployment and a takeover of an existing unit follow the same shape. The difference is that a takeover starts with finding out what you actually have, which is rarely what the documentation says.
  1. 1

    Assessment and sizing

    Week 1

    Measured traffic profile, connection counts, what inspection you need, site topology, remote access requirements and growth plans. For an existing unit, a full configuration review against the twelve-point health check. Output is a written finding and a sizing recommendation.

  2. 2

    Design and staging

    Weeks 1 to 2

    Policy structure, object and group naming, segmentation plan, inspection profiles, VPN design, logging and retention. Configured and tested on the bench before anything is touched in production. Migrations are rebuilt rather than converted.

  3. 3

    Cutover

    One planned window

    Out of hours with a documented rollback position and a validation test plan. We stage inspection rather than enabling everything at once, because a cutover that also flips on SSL inspection produces complaints nobody can attribute.

  4. 4

    Tuning

    Weeks 2 to 4

    The phase that decides whether protection stays on. False positives found and resolved, exemption lists built for applications that legitimately break under inspection, and profiles moved from monitor to enforcement as each is proved.

  5. 5

    Managed lifecycle

    Ongoing

    Firmware currency, subscription renewal tracking, scheduled rule review, configuration backup off the appliance, log retention, monitoring into our NOC, and configuration evidence for any audit obligation.

“We had a FortiGate for four years and assumed we were covered. GR ran a free health check and found the threat protection subscription had expired fourteen months earlier, the firmware was from 2022, and there was still an admin account belonging to the company that installed it. None of that was visible to us because nothing had broken. That is the uncomfortable part.”
Finance Director
Finance leadership · Dubai distribution business
Lapsed protection restored, stale admin access removed
FortiGate FAQ

What UAE buyers ask about FortiGate.

It depends on measured throughput with inspection enabled, not on user count, and that distinction is where most sizing goes wrong. A hundred users doing light browsing and a hundred users moving large files to cloud storage are completely different loads. We measure your current traffic, model what SSL inspection and threat protection will cost in performance, add headroom for three years, and recommend from there. If the calculation lands close to a boundary we recommend the model above, because the price gap between adjacent models is far smaller than replacing an undersized unit two years early.

Both are strong and we deploy both, so we have no reason to steer you. FortiGate tends to suit multi-site environments, businesses that want internal segmentation, and anyone likely to grow into a wider Fortinet estate with switches and access points under one management plane. Sophos tends to suit organisations that value a simpler management experience and are already using Sophos endpoint protection, because the integration between the two is genuinely useful. The wrong way to choose is on datasheet throughput, since both are measured the same optimistic way. The right way is on how it will be managed and by whom.

Yes, and this is a large share of the FortiGate work we do. Takeover starts with a full configuration review because the documentation, if any exists, is rarely accurate. We check subscription status, firmware currency, whether protection is enabled or merely licensed, the state of the rule base, admin accounts including any belonging to the previous provider, remote access configuration, and whether the config has ever been backed up. You get the findings in writing with severity, and we can usually restore proper protection without replacing hardware.

The firewall keeps passing traffic and stops inspecting it. Signature updates cease, so IPS and antivirus are working from a database that ages every day, and depending on configuration some services stop functioning entirely. The dangerous part is that nothing visibly breaks: no outage, no alert to a user, no obvious symptom. We have found subscriptions expired for well over a year in businesses that believed they were protected throughout. This is precisely why renewal tracking belongs in a managed service rather than depending on somebody noticing an email.

If you want the threat protection you are paying for to see anything, largely yes, because the overwhelming majority of traffic is encrypted and without inspection your IPS and antivirus are examining an opaque tunnel. The reason many deployments skip it is that doing it badly breaks things: banking portals, certificate-pinned mobile applications, and some software update mechanisms fail in ways that are hard to diagnose. Done properly, with the CA certificate distributed to managed devices and a maintained exemption list for applications that legitimately cannot be inspected, it works well. It needs a staged rollout and a tuning period rather than being switched on during the cutover window.

Stay on a supported branch and apply maintenance releases on a planned schedule, typically quarterly, with an out-of-band update if a serious vulnerability is published. Firewall firmware vulnerabilities are actively exploited and a firewall is by definition internet-facing, so being years behind is a genuine exposure rather than a housekeeping matter. That said, we do not chase the newest release: major version jumps get tested and scheduled rather than applied immediately, because a firmware upgrade that breaks a VPN at 9am is its own kind of incident. The discipline is planned currency, not maximum currency.

Yes, and where a client is already on FortiGate it is often the sensible path. Managing switches and access points through the same FortiGate management plane gives you consistent policy, unified visibility and simpler troubleshooting, since a device can be traced from the access port to the internet in one place. It is not automatically the right answer: if you already run good switching from another vendor, replacing working hardware for consolidation alone rarely pays back. We look at what you have before recommending it.

We quote after the assessment rather than publishing a figure, because the work varies with the environment. The drivers are how many appliances and sites, whether switching and access points are in scope, complexity of the rule base and segmentation, whether you need 24/7 or business-hours cover, and whether there is a compliance obligation requiring evidence and change records. Management is usually taken as part of a wider IT AMC or managed services agreement rather than standalone, which works out better value. The health check on an existing FortiGate costs nothing and you get the findings whether or not you proceed.

Both, and you can take either. We can procure at distributor channel pricing, which is usually better than retail, or you can buy the hardware wherever you like and we simply deploy and manage it. We deliberately do not tie management to buying the box from us, because that arrangement gives a provider a reason to recommend hardware you do not need. If you already have a suitable FortiGate, the honest recommendation is to keep it and have it configured properly, and that is what we will say.

P1 remote response is 5 minutes, 24/7, including public holidays. A total firewall failure is a P1 by definition since it takes the site offline. On-site attendance follows our published bands: within 2 hours in Band 1, 3 hours in Band 2 covering most of Dubai, and longer for the northern emirates, all measured rather than estimated. For clients where an outage is genuinely intolerable we deploy an HA pair so a hardware failure fails over rather than becoming an outage, and that is a conversation worth having at purchase, because retrofitting HA means buying a second unit later at full price.

Yes. Firewall configuration is a substantial component of PCI DSS and appears in most other frameworks including DESC ISR, NESA and ISO 27001. What assessors want is not just that a firewall exists but that the rule base is documented and justified, that changes go through control with records, that reviews happen on a stated cadence with evidence, that logs are retained for a defined period, and that segmentation genuinely isolates whatever is in scope. We build the configuration to satisfy that and produce the evidence continuously, so an assessment is an export rather than a scramble.

Yes, and it usually should be, though carefully rather than aggressively. We analyse hit counts to find rules that have not matched traffic in months, identify shadowed rules that can never be reached because an earlier rule catches the traffic, consolidate overlapping entries, and replace unnamed IP addresses with named objects so the intent is readable. The rule we follow is that nothing gets removed without evidence and a rollback position, because deleting a rule that is used once a quarter by the finance team during closing is the kind of cleanup that gets remembered. Done properly, most inherited rule bases reduce substantially and become maintainable.
Related security services

What clients usually scope alongside FortiGate.

Sophos firewall Dubai

The other platform we deploy, for buyers weighing the two or already running Sophos endpoint protection.

Learn more

SOC as a service Dubai

Firewall logs are only useful if someone watches them. Monitoring, triage and response around the clock.

Learn more

Network monitoring and NOC Dubai

Availability and performance monitoring across the whole network, not just the perimeter device.

Learn more
Free FortiGate health check

Find out whether the firewall you own is actually protecting you.

We check subscription status, firmware currency, whether threat protection is enabled or only licensed, the state of the rule base, remote access configuration, and whether any previous provider still holds admin access. You get the findings in writing at no cost, whether or not you engage us.

Book a free FortiGate health checkCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Sophos vs Fortinet

Independent comparison from a partner in both

Learn more

Sophos Firewall Dubai

Authorised Sophos XGS partner UAE

Learn more

SOC-as-a-Service

24/7 SOC on Microsoft Sentinel

Learn more

Network Monitoring NOC

24/7 NOC monitoring with named engineers

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

Managed Security Services

MSS on Microsoft Defender XDR and Sentinel

Learn more

IT AMC Dubai

Annual maintenance contracts for IT infrastructure

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business Manager
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy