A FortiGate managed service can reduce the operational load of running a next-generation firewall, but only when the service scope matches the environment. Buying a capable Fortinet appliance is one part of the decision. Keeping policies current, reviewing alerts, applying firmware safely and responding to incidents is the work that determines whether the firewall is delivering value.
For IT teams with limited security coverage, multi-site estates or compliance pressure, managed firewall support can be a practical route to better control. For teams that already have skilled network and security engineers on call, a lighter support arrangement may be the more cost-effective choice. The right answer depends on who owns the risk after the appliance is installed.
What a FortiGate managed service should cover
The phrase “managed service” is used broadly. One provider may offer a monthly health check and helpdesk access; another may operate the firewall around the clock. Before comparing prices, establish exactly which activities are included and which remain with your internal team.
A meaningful service normally starts with onboarding. The provider should document the appliance model, FortiOS version, serial number, WAN configuration, VPNs, VLANs, security policies, administrators, logging destination and current subscriptions. This baseline matters. Without it, later changes become harder to audit and an incident response team may lose time identifying how traffic is meant to flow.
Day-to-day management commonly includes configuration backups, firmware planning, policy changes, VPN administration, log review and device health monitoring. The better services also tune IPS, web filtering, application control and antivirus profiles to reduce false positives without weakening protection. A firewall that blocks legitimate cloud applications or business-critical suppliers will soon be bypassed by frustrated users.
There is a clear distinction between monitoring and response. A provider may notify you that a WAN interface is down, but will they investigate the circuit, fail traffic over to a secondary connection, contact the carrier or alter routing? Ask for the escalation path in writing. “24/7 monitoring” is not the same as “24/7 remediation”.
FortiGate managed service scope: questions that affect cost
Service pricing should reflect the appliance estate, traffic profile and operational responsibility, rather than a single headline monthly figure. A small FortiGate protecting one office with standard policies is not comparable with a high-availability pair supporting several branches, SD-WAN, remote-access VPNs and inspection of encrypted traffic.
When evaluating a FortiGate managed service, ask these practical questions:
- Are configuration changes included, and how many change requests are permitted each month?
- Is security event monitoring continuous, during business hours, or only reviewed in periodic reports?
- What are the response and resolution targets for critical incidents?
- Does the provider manage firmware upgrades, including rollback planning and maintenance windows?
- Are reporting, compliance evidence and policy reviews included or separately charged?
- Who owns Fortinet licensing, renewals and the relationship with support?
These details prevent a familiar procurement problem: a low initial service fee followed by charges for routine changes, urgent support, reporting or out-of-hours work. For a buyer comparing managed options, the useful figure is the total annual operating cost, including subscriptions, hardware support, implementation and expected change activity.
Licensing, support and hardware are separate decisions
FortiGate appliances rely on more than their physical ports and throughput figures. Security capabilities such as IPS, antivirus, web filtering, application control and sandbox-related services can depend on active FortiGuard subscriptions. Vendor support coverage also has its own term and entitlement rules. A managed provider can administer these elements, but the contract should state whether licences are supplied, renewed by the customer or billed as a pass-through cost.
Check that the proposed appliance is sized for the security services you intend to enable. Firewall throughput alone can be misleading. Threat protection, SSL inspection, IPsec VPN performance, concurrent sessions and interface requirements all affect real-world sizing. A unit that appears economical on paper can become a bottleneck once encrypted traffic inspection and remote users are added.
Availability also deserves attention. A single appliance may be appropriate for a low-risk site, particularly where internet downtime has limited commercial impact. For a headquarters, warehouse, call centre or site hosting critical applications, a high-availability pair and dual WAN design may be justified. Managed service cannot remove the risk of a single hardware failure if there is no replacement unit or failover design.
For replacement and expansion projects, confirm the exact model, power supply region, rack accessories, interface modules and support eligibility before ordering. New, surplus and used enterprise hardware can offer substantial budget savings, but compatibility and warranty terms should be checked against the deployment plan. Green Code UK supplies branded network and security hardware for buyers who need to compare models, specifications and available stock without treating every requirement as a bespoke project.
Keep ownership and access clear
Outsourcing firewall operations should not mean surrendering visibility. Your organisation should retain access to configuration backups, event logs, reporting and administrative records. It should also be able to regain operational control if the service relationship changes. This is not a sign of distrust. It is sound continuity planning.
Agree who can approve policy changes and how emergency changes are handled. A service desk should not be able to open inbound access to a sensitive system on the strength of an informal request. Use named approvers, ticket records and a defined emergency process. The same discipline applies to administrator accounts, multi-factor authentication and privileged access reviews.
Logging is another point that needs a firm decision. Local logs may be enough for a straightforward branch deployment, whereas centralised logging and longer retention can be necessary for investigations, governance or regulated workloads. The provider should explain what data is retained, where it is stored, how long it remains available and whether you can export it.
The operational value comes from policy quality
A managed FortiGate is most useful when it improves the quality of security decisions, not merely the speed at which tickets are closed. Over time, policies should become easier to understand: unused rules removed, broad source-and-destination access narrowed, temporary exceptions expired and shadowed rules identified. Monthly reports that only list blocked attacks may look reassuring but do not prove that exposure is reducing.
Ask for reporting that connects activity to action. Useful reports show high-risk events, top applications, VPN usage, denied traffic trends, ageing firmware, interface health, policy changes and open recommendations. For a smaller business, a concise monthly review may be enough. Larger environments may need service reviews tied to incident patterns, audit controls and planned network changes.
There are trade-offs. Aggressive inspection can improve detection while increasing latency and demanding more appliance performance. Frequent firmware updates can address known issues but require testing around critical applications. Centralised control can standardise policy across sites, while site-specific requirements still need local knowledge. A good provider explains these choices plainly rather than applying a one-size-fits-all template.
Build the contract around real incidents
The best test of a managed firewall proposal is not the dashboard. It is what happens when a remote access VPN fails before the working day, a newly discovered vulnerability requires urgent mitigation, or an employee clicks a malicious link that triggers suspicious outbound traffic.
Define severity levels using your business impact, not generic labels. Set contact methods, response commitments, decision authority, communications cadence and post-incident reporting requirements. If the provider is expected to make containment changes without waiting for approval, document the limits of that authority in advance. Fast action is valuable, but so is knowing what action will be taken.
A properly scoped service gives IT teams more time for projects, users and infrastructure planning while keeping firewall operations accountable. Start with the applications, sites and risks that the FortiGate must protect, then select the appliance, licences and management level that can support that requirement. The most economical arrangement is rarely the cheapest monthly quote – it is the one that gives you clear ownership, predictable support and a firewall policy that remains useful long after installation.













