FortiGate
Next-generation firewall (NGFW) with layer-7 inspection, IPS, application control, web filtering, and SD-WAN in an enterprise appliance.
Service overview
FortiGate is ACT Tecnologia's next-generation firewall solution for environments that require the highest level of inspection, control, and visibility. It's the only tier in the line with real layer-7 inspection, with firewall, IPS, antivirus, application control, web filtering, and SD-WAN already present from the entry-level model, scaling in performance on higher models. ACT manages the FortiGate fleet centrally and securely, with VPN access, continuous monitoring, and response.
UTM security
Firewall, IPS, antivirus, anti-malware, application control, and web filtering integrated and correlated in a single appliance.
Application visibility
Traffic identification and control by application and user, with SSL/TLS inspection and identity-based policies.
Intelligent SD-WAN
Dynamic selection of the best link per application, with automatic failover and real-time quality measurement.
Next-generation security
Deep inspection: FortiGate's security stack inspects traffic across multiple layers, correlating threats and applying policies by user, application, and content, with logging and evidence for every event.
| Feature | Status | Description |
|---|---|---|
| Application firewall | Included | Policies by application, user, and service, not just by port |
| IPS | Included | Intrusion prevention with continuously updated signatures |
| Antivirus / anti-malware | Included | Traffic and attachment scanning at the edge |
| Application control | Included | Identification of thousands of applications with policy-based actions |
| Web filtering | Included | Blocking by category, reputation, and URL |
| SSL/TLS inspection | Included | Inspection of encrypted traffic in line with policy and privacy |
| Anti-bot / C&C | Included | Detection of communication with command-and-control servers |
| Advanced sandboxing | Optional | Analysis of suspicious files in an isolated environment (dedicated subscription) |
Feature availability and performance vary according to the appliance model and the contracted security subscriptions.
Network, SD-WAN, and VPN connectivity
Beyond security, FortiGate delivers advanced routing, SD-WAN, and enterprise-grade VPN, with hardware acceleration to keep performance up even with inspection active.
Network and SD-WAN
- Static and dynamic routing (BGP, OSPF)
- 802.1Q VLANs and segmentation by security zone
- SD-WAN with link selection by application and SLA
- Load balancing and failover across multiple carriers
- Traffic shaping and VoIP prioritization
Corporate VPN
- Interoperable site-to-site IPsec VPN
- SSL-VPN for remote user access
- Hub-and-spoke topology for networks behind CGNAT (requires a fixed IP at the hub)
- Integrated LDAP / Active Directory authentication
- Multi-factor authentication for remote access
One relevant operational note: FortiGate's SIP ALG can affect VoIP telephony (one-way audio, registration failure). ACT validates and adjusts this behavior during deployment.
Centralized fleet management
NOC operation: ACT manages the FortiGate fleet centrally and securely, with administrative access restricted to VPN, Zabbix-based monitoring, and operational automation; the client sees the health of security without operating the equipment.
Monitoring and visibility
- Zabbix-based collection: CPU, memory, sessions, tunnels, links
- Proactive alerts for link failure, VPN failure, and resource issues
- Availability, threat, and bandwidth usage dashboards
- Centralized security logs for auditing
Operation and automation
- Centralized management of multiple devices
- Configuration backup before every change
- Operation and collection automation via integration
- Critical changes made in an agreed maintenance window
One fleet, under single control.
ACT operates FortiGates over VPN in a hub-and-spoke model, with backup, versioning, and continuous monitoring. Every critical change is preceded by a backup and executed with an agreed window and evidence.
Log analysis and reporting · FortiAnalyzer
While FortiGate protects and inspects traffic, FortiAnalyzer answers "what happened, when, to whom, and why": logs from the entire fleet gathered in a single point, with event correlation and scheduled reports.
Consolidated visibility
Logs from the entire FortiGate fleet gathered in one place, with search, filters, and security and traffic dashboards.
Correlation and investigation
Events correlated across devices to speed up incident investigation and response.
Reporting and compliance
Scheduled executive and technical reports, with history retention for auditing and LGPD compliance.
Evidence when it matters.
In an audit or after an incident, the difference between "we think" and "we have the record" lies in log retention and organization. FortiAnalyzer preserves that history in a searchable way, and ACT keeps it ready to respond.
SOCaaS · Security operations as a service
An additional layer of security operations on top of the FortiGate fleet, with monitoring and response conducted by ACT.
Threat monitoring
Continuous tracking of security alerts and events generated by the FortiGate fleet.
Incident response
Triage and response led by the ACT team in the face of relevant security events.
SOCaaS scope and SLA are defined according to each client's commercial proposal.
Specifications
| Form factor | Desktop or rack enterprise appliance, sized by throughput |
| Acceleration | Hardware-accelerated processing to maintain performance with active inspection |
| Interfaces | Multiple Gigabit ports; SFP/10G depending on model |
| Subscriptions | Continuous IPS, antivirus, and web filtering updates (per license) |
| Monitoring | Zabbix integration, 24x7 alerts |
| ACT support | Support via ACT's central desk, with SLA per contract (managed models) |
The top layer ACT watches for you.
In managed models, ACT takes on end-to-end operation of FortiGate: security policy, inspection, VPN, SD-WAN, monitoring, and response. Security posture stays visible to decision-makers, with evidence and backup before every change.
Recommended use cases
Enterprise perimeter
- Consolidated UTM security
- Deep inspection and IPS
- Application and user visibility
Multi-site connectivity
- SD-WAN between branches
- IPsec and SSL VPN at scale
- Link selection by application
Compliance and auditing
- Web filtering and access control
- Centralized security logs
- 24x7 monitoring by ACT
Want to know if FortiGate solves what your operation needs?
Talk to ACT and understand, with clarity, how this solution fits your environment.
Talk to ACT