A FortiGate installation UK project usually goes wrong before the appliance is even racked. The common failure points are not the firewall itself, but poor model sizing, mismatched licences, unclear WAN design, and rushed cutover planning. If you are buying for a branch, head office, warehouse, school, or multi-site estate, the right result comes from getting the commercial and technical details aligned early.
That matters because FortiGate is rarely a simple swap for a domestic router. In most business environments it sits at the edge of a wider stack – switches, wireless, VLANs, VPNs, voice traffic, remote users, web filtering, and sometimes SD-WAN or site-to-site failover. Buy too small and you create a bottleneck. Buy too large and you tie up budget that could have covered switches, optics, access points, or a support term that the deployment actually needs.
FortiGate installation UK buyers need more than a box
For experienced IT teams, the hardware is only one line item. A proper FortiGate installation in the UK market usually means checking appliance throughput against real traffic, not headline marketing figures. Firewall throughput, threat protection throughput, SSL inspection impact, concurrent sessions, and VPN performance can all tell a different story depending on the feature set you intend to enable.
A small office with one internet circuit and a handful of VLANs may be well served by an entry model. A busy site running cloud apps, VoIP, guest wireless, endpoint telemetry, and remote access can push much harder on inspection and session handling than the user count suggests. That is why procurement by model family alone is risky. A FortiGate 40F, 60F, 80F, 100F or larger unit may all look viable on paper until SSL inspection, IPsec tunnels, or UTM services are added into the picture.
Commercially, this is where buyers often overspend in the wrong place. A discounted firewall chassis can still become the expensive option if it lacks the right subscription bundle, support cover, or expansion path. A sharper purchase is one that matches throughput, ports, and licence term to the deployment window and refresh cycle.
Choosing the right FortiGate model
The correct model depends on traffic profile, not just site size. For larger offices and growing organisations, the FortiGate 100F Firewall is frequently considered due to its higher throughput and greater scalability. A retail branch with card terminals, CCTV uplinks, staff Wi-Fi and a backup WAN can have different demands from an office with the same headcount. Likewise, a school or healthcare site may need stronger content filtering and segmentation than a general SME environment.
Port density is one of the first practical checks. Some buyers assume they will uplink the firewall to a managed switch and let the switching estate do the rest. That is often sensible, but only if the interface layout fits the network design. If you need separate WAN circuits, DMZ separation, HA planning, or dedicated interfaces for voice and guest traffic, count those requirements before you place the order.
Then look at the licensed feature set. If the project includes IPS, application control, antivirus, DNS filtering, web filtering or FortiGuard security services, size for those enabled services. Raw firewall figures are not enough. This is where many rushed FortiGate installation UK purchases fall short – the appliance is technically online, but performance drops once the intended security stack is actually switched on.
Common FortiGate Models for Business Deployments
For many small and medium-sized businesses, the FortiGate 60F Firewall remains a popular choice. It offers a strong balance of security, VPN performance and value, making it suitable for branch offices, retail locations and growing SME environments.
The licensing and support question
FortiGate deployments are often judged on appliance price first, but licensing determines a large part of operational value. Different licence bundles suit different risk profiles. A branch firewall used mainly for routing and VPN may not need the same package as an internet-facing head office handling remote users and heavier web traffic inspection.
Support cover matters as well. Buyers looking to understand support options in more detail can also explore our Fortinet Firewall Maintenance Contract Guide. If the site can tolerate downtime, your buying decision may be different from a business where every lost hour hits sales, operations, or customer access. For MSPs and procurement teams, this becomes a total cost question rather than a checkout price question. Hardware, licences, renewals, replacement handling, and model longevity all need to line up.
It is also worth checking whether you are standardising across multiple sites. Buying one off-spec unit because it is discounted can create support friction later. Standard builds are easier to deploy, easier to document, and easier to replace under pressure.
Network design decisions before installation
A successful FortiGate installation starts with a clear topology. That means defining WAN links, LAN segments, VLANs, DHCP scopes, NAT requirements, VPN peers, and any dependencies on existing switches or wireless controllers. If those decisions are left until install day, the cutover window gets longer and the risk climbs fast.
For single-site businesses, routing may be straightforward, but even then there are choices to make. Will the FortiGate run simple edge security, or will it become the main inter-VLAN policy point? Are you using static routes, OSPF, or BGP? Will voice traffic require QoS handling? Are there legacy subnets that cannot be renumbered yet? These details affect the build template and the appliance selection.
For multi-site estates, SD-WAN and VPN design deserve extra attention. Link balancing, failover, branch breakout, and cloud application routing can all improve performance, but they need proper policy design. A cheaper appliance can stop looking cheap if it forces compromises on tunnel count, throughput, or future branch growth.
Physical installation is the easy part
Racking the unit, patching WAN and LAN interfaces, applying power, and performing the initial console or web setup is usually the shortest stage of the job. The real work is validation. That includes firmware planning, admin access control, backup configuration, logging destination, certificate handling, and policy testing across live business applications.
Firmware should never be treated as an afterthought. Some environments prioritise stability on a tested release, while others need features only available in a newer branch. There is no single answer here. It depends on the application mix, support policy, and how much change control your business requires.
High availability is another decision that should be made before purchasing, not after delivery. If the site needs resilience, plan for a matched pair, heartbeat connectivity, and the rack space and power budget to support it. Buying one unit now and hoping to mirror it later can create stock and lifecycle problems if the model becomes constrained or revised.
Common FortiGate installation UK mistakes
The first mistake is sizing by user count alone. Fifty users can produce light traffic or very demanding encrypted traffic. The second is ignoring SSL inspection overhead. The third is underestimating how many ports, VLANs, or VPNs the final design will need once the site is fully live.
Another frequent issue is incomplete information during procurement. Buyers know they need a FortiGate, but not whether they also need subscriptions, rack rails, console access, compatible optics, replacement power supplies, or additional support coverage. That creates delays and repeat orders. In a time-sensitive rollout, that is avoidable cost.
There is also the used versus current-stock question. Refurbished or used enterprise hardware can be a strong buy for labs, test environments, non-critical roles, or budget-led refresh cycles. But for production security at the edge, the answer depends on support eligibility, firmware path, licence compatibility, and how much operational risk the business is prepared to carry. Cheap hardware is only a good deal if it fits the support model.
Buying for value without buying blind
The smart buy is not always the newest or the highest-spec firewall. It is the model that meets your traffic profile, security requirements, support expectations, and refresh budget without forcing compromises six months later. That means comparing exact part numbers, checking licence terms, and being realistic about what the site will need once growth, cloud usage, and remote access are factored in.
For trade buyers, resellers, and internal IT teams, speed matters as much as specification. Stock availability, warranty terms, return handling, and access to related infrastructure parts can make the difference between a clean rollout and a delayed one. If you are sourcing firewalls alongside switches, SFP modules, servers or wireless equipment, buying from a supplier with broad enterprise inventory can remove a lot of friction from the project. Green Code UK serves that kind of requirement well, especially where cost control and model availability matter.
FortiGate is a strong platform when the deployment is planned properly. Start with the traffic, the features, and the support model – not just the appliance price – and the installation will be far easier to live with once the network is carrying real business load.
FAQ
Q1: What should I plan before a FortiGate installation?
A: Review traffic requirements, WAN design, VPN needs, licensing, security services and support requirements before deployment.
Q2: How do I choose the right FortiGate model?
A: Base your choice on throughput needs, enabled security features, VPN usage, port requirements and future growth plans.
Q3: Why is licensing important in a FortiGate deployment?
A: Licensing enables security services such as IPS, antivirus, web filtering and application control.
Q4: Should I use new or refurbished FortiGate hardware?
A: New hardware suits production environments, while refurbished units can work well for labs, testing and budget-conscious projects.
Q5: What are common FortiGate installation mistakes?
A: Common mistakes include undersizing the appliance, overlooking SSL inspection impact, ignoring licensing requirements and poor network planning.













