Sora Yazılım
English
Custom software solutions from Türkiye

FortiGuard UTP, ATP and Enterprise Bundles: Which License Fits Whom?

FortiGuard license bundles deliver the threat-intelligence services of a FortiGate firewall in three tiers: Advanced Threat Protection (ATP) is the baseline against network- and file-based threats, Unified Threat Protection (UTP) adds web and DNS security, and Enterprise Protection is the broadest bundle, covering SaaS, data, IoT and attack-surface monitoring. All three ship with FortiCare Premium support.

What Is a FortiGuard Bundle and How Does It Differ from FortiCare?

FortiGuard is the umbrella name for the subscription services fed by FortiGuard Labs, Fortinet's threat research unit: IPS signatures, antivirus, web and DNS filtering, application control and more. FortiCare is the hardware warranty, RMA and technical support contract. A bundle combines both layers in a single part number.

When you buy a FortiGate you actually get two separate things: the appliance (or virtual machine) and the subscriptions that keep it current. The device works without subscriptions; stateful firewalling, routing, VPN and VLANs stay available. But because IPS signatures, the antivirus database and web categories stop updating, within a few weeks the appliance becomes blind not only to new attacks but to well-known ones as well. Our article on the differences between FortiCare and FortiGuard renewals shows which line of a contract covers what.

Fortinet sells these services individually (a la carte) and also groups them into three ready-made bundles, currently marketed as "FortiGuard AI-Powered Security Bundles": Advanced Threat Protection (ATP), Unified Threat Protection (UTP) and Enterprise Protection. According to Fortinet's official bundle page and the FortiGate subscriptions ordering guide, the bundles are cumulative: UTP contains all of ATP, and Enterprise Protection contains all of UTP (Fortinet, FortiGuard Security Bundles). What the three have in common is that each ships with FortiCare Premium by default and can be upgraded to FortiCare Elite; we compare the support tiers in FortiCare Premium vs. Elite support levels.

How the services are activated on the appliance and attached to security profiles is a separate topic; the full licensing model is covered in our FortiGate licensing and FortiGuard subscriptions guide. This article focuses on one question: which bundle is right for which organization?

What Does the Advanced Threat Protection (ATP) Bundle Include?

Advanced Threat Protection (ATP) is the entry bundle that combines FortiGuard IPS, Anti-Malware Protection (antivirus, cloud-based sandbox, virus outbreak protection and content disarm) and Application Control with FortiCare Premium support. URL filtering, DNS filtering and video filtering are not part of this bundle.

In Fortinet's own words, ATP is the "first line of defense" against network- and file-based threats. The IPS service blocks known attack signatures and protocol anomalies; Anti-Malware Protection pairs the antivirus engine with a cloud sandbox that detonates unknown files to catch zero-day threats; Application Control identifies thousands of applications regardless of port or protocol and ties them to policy. For locations where users do not browse the internet, or where web traffic is inspected by another layer, this trio can be enough.

In our field experience ATP makes sense in three typical positions. First, a data-center or internal segmentation firewall: there is no use for web-category filtering between server VLANs, but IPS and file scanning are critical. Second, branch appliances where web security is handled by a cloud layer such as FortiSASE or by the head office; buying UTP there means paying for the same service twice. Third, DMZ firewalls that only publish servers. Outside these scenarios, in an office where employees browse the internet through the FortiGate, the web and DNS layer that ATP leaves out is usually the most attacked surface.

One detail deserves attention: some components of Anti-Malware Protection, such as Content Disarm and Reconstruct (CDR), are not available on every model. The subscription-table footnote in Fortinet's datasheet states that CDR is not available on the 40F series with FortiOS 7.4.4 and later; for an entry-level model such as the FortiGate 40F, the list of services the bundle actually delivers must be read together with that footnote.

What Does the Unified Threat Protection (UTP) Bundle Add?

Unified Threat Protection (UTP) adds URL Filtering, DNS Filtering, Video Filtering and anti-botnet/command-and-control (C2) blocking to everything in ATP. It is the default starting point for any office whose users reach the internet directly through the FortiGate, and the bundle we recommend most often in our SMB projects.

The difference between ATP and UTP can be summed up in one word: "web". Phishing pages, malicious download links, ransomware talking to its command server and data exfiltration through DNS tunnels all pass through the web and DNS layer. According to Fortinet's service description, the DNS Filtering service provides full visibility into DNS traffic, blocks high-risk domains and protects against DNS-based threats such as DNS tunneling, DNS spoofing, dynamic DNS and domain generation algorithms (DGAs). URL Filtering ties websites to policy by category (gambling, adult, file sharing, proxies and so on); Video Filtering adds channel- and category-level control on platforms such as YouTube.

There is a practical reason we treat UTP as the default at SMB scale: web filtering is not only a security control but also a user-behavior and compliance tool. Enforcing the corporate internet policy, category-based reporting and logging access to suspicious domains produce a large share of the evidence auditors ask for. How these services attach to security profiles on the appliance is explained step by step in FortiGate UTM and security profiles.

Appliance choice and bundle choice must be considered together. Web filtering combined with SSL inspection raises CPU load noticeably, so the model decision should be based on the "Threat Protection" throughput in the datasheet rather than raw firewall throughput. For matching models to capacity, our firewall selection guide for SMBs is the starting point.

Who Is the Enterprise Protection Bundle For?

Enterprise Protection adds Inline CASB (SaaS application security), Data Loss Prevention (DLP), IoT Detection with vulnerability correlation, Attack Surface Security (monitoring and risk scoring) and AI-based inline malware prevention on top of UTP. It is designed for SaaS-heavy, regulated organizations or those running many IoT/OT devices.

Fortinet describes Enterprise Protection as built for the "entire attack surface": network, web, files, SaaS, data and devices. The difference here is less about depth of protection than about breadth. Inline CASB makes visible which tenant is being accessed in SaaS applications such as Microsoft 365 or Google Workspace, whether personal accounts touch corporate data, and where shadow IT is in use. The DLP service catches patterns such as national ID numbers, card numbers or fingerprinted documents inside traffic. IoT Detection identifies cameras, printers, medical devices and industrial controllers on the network and correlates them with known vulnerabilities. Attack Surface Security compares your appliance configuration with best practices and produces a security score with remediation advice. Fortinet's bundle paper lists CASB for SaaS application security, DLP, IoT detection with vulnerability correlation, attack surface monitoring and risk scoring, and AI-based inline malware prevention as what Enterprise Protection adds on top of UTP (Fortinet, Enterprise Protection Bundle).

A component Fortinet highlights in the bundle description is AI-based inline malware prevention: it aims to block unknown files, including zero-day and AI-driven threats, inline and in real time. Compared with the cloud sandbox approach in ATP and UTP, the verdict is delivered in the flow, before the file reaches the user.

In our projects we bring Enterprise Protection to the table for three profiles: finance and healthcare organizations that must show DLP evidence; hospitals and manufacturing sites with medical-device or OT networks; and companies whose users do most of their work in SaaS and want to manage shadow-IT risk. For an SMB outside these profiles, Enterprise Protection usually means budgeting for services that will never be switched on. How the bundle tier affects total cost, alongside term and model, is discussed in the factors that determine FortiGate pricing.

Comparison Table of the Three Bundles

The FortiGuard bundle comparison rests on a single principle: each higher bundle contains everything in the one below it. ATP starts with four service groups, UTP adds the web-security layer, and Enterprise Protection completes the list with SaaS, data, IoT and attack-surface services. The table below summarizes the distribution shown on Fortinet's official bundle page.

ServiceATPUTPEnterprise Protection
FortiCare Premium (24x7 support, RMA)YesYesYes
FortiGuard IPSYesYesYes
Anti-Malware Protection (antivirus, cloud sandbox, virus outbreak protection)YesYesYes
Application ControlYesYesYes
URL FilteringYesYes
DNS FilteringYesYes
Video FilteringYesYes
Anti-botnet and C2 communication blockingYesYes
Inline CASB (SaaS application security)Yes
Data Loss Prevention (DLP)Yes
IoT Detection and vulnerability correlationYes
Attack Surface Security (monitoring, risk scoring)Yes
AI-based inline malware preventionYes
Upgrade to FortiCare EliteOptionalOptionalOptional

The service names in the table follow Fortinet's current naming. Fortinet periodically renames services and adjusts bundle contents, so rely on the current ordering guide before placing an order (Fortinet, FortiGate Subscriptions and FortiGuard Bundles Ordering Guide). Some UTP order lines also list an Antispam service in their name; confirm the contents per model and period in the current guide. Separate SD-WAN and SASE service bundles also exist; this article covers only the security bundles.

Which Bundle Fits Whom? Scenario-Based Selection

Bundle selection follows the appliance's position in the network: if user internet traffic flows through the FortiGate, start with UTP; if the appliance serves as an internal segmentation or DMZ firewall, ATP; if SaaS, data or IoT visibility is mandatory, Enterprise Protection. Where budget or technical limits apply, individual (a la carte) services are the alternative.

ScenarioRecommended bundleRationale
Office with 10–100 users, internet breakout through the FortiGateUTPURL/DNS filtering and sandbox close the most attacked surface
Data-center or internal segmentation firewallATPNo use for web-category filtering between servers; IPS and file scanning are critical
Branch appliance; web security in FortiSASE or at head officeATPAvoids paying for the same service on two layers
Microsoft 365 / SaaS-heavy organization with shadow-IT concernsEnterprise ProtectionInline CASB and DLP visibility
Hospital or manufacturing site with medical-device or OT networkEnterprise ProtectionIoT Detection and vulnerability correlation
Regulated financial institution expected to show DLP evidenceEnterprise ProtectionDLP plus Attack Surface Security scoring
Only one service is needed (e.g. IPS alone)A la carte serviceSubscribe to what is needed instead of a bundle

The table is a starting point; what settles the decision is the existing network topology, endpoint protection and any SASE or email-security layers already in place. If an EDR with its own sandbox already runs on endpoints, the firewall sandbox is valuable as a second control layer but is not a decision driver on its own. Likewise, if the DLP requirement is met on the email side, the DLP component of Enterprise Protection offers a second gate at the network edge; whether that deserves budget is decided by the organization's risk profile.

6 Points to Check Before Choosing a Bundle

When choosing a FortiGuard bundle, the service list alone is not enough: appliance model, FortiOS release, contract term, performance impact, renewal calendar and the balance between bundle and individual services mean the same bundle can produce different results in two organizations.

  1. Model limits. Some services do not run on entry-level models. Fortinet's datasheet footnote states that Content Disarm and Reconstruct, Video Filtering and Inline CASB are not available on the 40F series with FortiOS 7.4.4 and later. Buying Enterprise Protection for a 40F means Inline CASB cannot actually be used; check such footnotes against the model data on our FortiGate product pages before ordering.
  2. FortiOS release. New services require a specific FortiOS release. If your appliance stays on an older release you will see the service in the license but cannot enable it in profiles. Verify the release-to-service mapping in Fortinet's release notes.
  3. Contract term. Bundles are sold in 1-, 3- and 5-year terms; the 12/36/60 suffixes in Fortinet part numbers denote these terms. In multi-appliance environments, aligning end dates to a single calendar simplifies renewal management.
  4. Performance impact. Each additional service, especially combined with SSL inspection, calls for sizing based on the datasheet's "Threat Protection" throughput rather than raw firewall throughput. The DLP and CASB services in Enterprise Protection add further load.
  5. Renewal calendar. When the subscription expires the appliance keeps running but stops receiving updates; the consequences are described in what happens when a FortiGate license expires. Planning the renewal before expiry avoids both the protection gap and the reactivation effort.
  6. Bundle or individual service? Fortinet also offers services a la carte. If only IPS or only web filtering is needed, a single subscription makes sense; once more than two or three services are required, the bundle approach simplifies both management and contracts. For a firm comparison, put quotes for both options side by side.

Carrying these six points into the renewal period usually moves the decision away from the "just extend the same bundle" reflex toward a fresh assessment of what the network needs today. The renewal process as a whole is covered in our comprehensive FortiGate license renewal guide.

Frequently Asked Questions

What is the difference between FortiGuard UTP and ATP?

UTP adds URL Filtering, DNS Filtering, Video Filtering and anti-botnet/C2 blocking to everything in ATP (IPS, Anti-Malware Protection, Application Control, FortiCare Premium). The difference is the web and DNS layer; UTP suits offices whose users browse through the FortiGate, while ATP is usually enough for internal segmentation and DMZ appliances.

Does an SMB need the Enterprise Protection bundle?

For most SMBs, UTP is sufficient. Enterprise Protection makes sense for organizations that will actually use Inline CASB, DLP, IoT Detection and Attack Surface Security: SaaS-heavy, regulated, or running many IoT/OT devices. Rather than budgeting for unused services, it is healthier to upgrade when the need arises.

Does a FortiGate work without a FortiGuard bundle?

Yes, the appliance keeps working with core functions such as stateful firewalling, routing, VPN and VLANs. However, IPS signatures, the antivirus database and web categories are no longer updated, and the device soon becomes blind to current threats. We do not recommend running a FortiGate without subscriptions in production.

Is FortiCare support included in the bundles?

Yes. According to Fortinet, all three bundles, ATP, UTP and Enterprise Protection, ship with FortiCare Premium by default, covering 24x7 web, chat and phone support plus hardware replacement. Organizations that want faster response and a designated support team can upgrade the bundle to FortiCare Elite.

Can I upgrade the bundle in the middle of the contract term?

Upgrading is possible, but the path depends on the model, the remaining term and the distributor process; in most cases a new subscription aligned with the remaining term or an upgrade part number is used. We confirm the exact method and term alignment at the quotation stage; do not assume an upgrade path without reading the contract.

Which terms are FortiGuard bundles sold in?

Bundles are offered in 1-, 3- and 5-year terms; the 12, 36 and 60 suffixes in Fortinet part numbers indicate the term in months. Multi-year contracts reduce renewal frequency; in multi-appliance environments, aligning all end dates to the same period simplifies management.

Which bundle does Sora Yazılım recommend?

We have no single standard recommendation; we review the network topology, user count, existing endpoint and email security and compliance requirements, then recommend a bundle per model. In our field experience, UTP for user offices, ATP for internal segmentation and Enterprise Protection for organizations that require SaaS/IoT visibility are the most frequent outcomes.

Conclusion

The difference between FortiGuard bundles is not a "good, better, best" ladder but a matter of scope that changes with the appliance's role in the network. ATP is the right choice at internal segmentation and DMZ points where web filtering has no use; UTP in offices where users browse the internet; Enterprise Protection in organizations where SaaS, data, IoT and attack-surface visibility is mandatory. Model limits, FortiOS release and contract term are the other three variables shaping the decision.

At Sora Yazılım we treat the bundle decision as a separate line item in FortiGate projects: we review the existing topology and other security layers, recommend individual services instead of a bundle where appropriate, and align contract terms to a single calendar. If you would like to assess which bundle fits your organization, get in touch with us; in a free discovery call we review your current setup and prepare a project-specific quote.

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support