Fortinet
An enterprise network security platform managed on a single policy plane — from the firewall to the endpoint — through the Security Fabric architecture.
Fortinet solutions are a product family that unites network security, SD-WAN, SASE, endpoint and email security in a single architecture. Every product runs on a shared policy, identity and telemetry layer called the Security Fabric, and the FortiGate firewall sits at the center of that architecture. As a Fortinet authorized channel partner in Turkey, Sora Yazılım provides licensing, sizing, installation, migration and managed services.
Fortinet solutions bring together every security layer that stretches from the internet edge of the corporate network down to the end device within a single vendor architecture: FortiGate next-generation firewall, FortiSASE cloud-delivered access security, FortiClient and FortiEDR endpoint protection, FortiAP and FortiSwitch as the secure access layer, FortiAnalyzer for log and event analytics, FortiMail for email security, and FortiWeb for web application and API security. What these nine products have in common is the Security Fabric: the layer where devices recognize one another and share policy and telemetry. In practical terms, that means managing a single policy plane and a single event timeline instead of nine separate consoles.
On the question of scale, Fortinet's official corporate figures state the following: more than 1,000,000 customers, more than 17.2 million devices shipped as of June 30, 2026, and 1,448 global patents (Fortinet About Us, 2026). On the threat intelligence side, FortiGuard Labs processes and analyzes more than 100 billion events every day using artificial intelligence and machine learning systems (Fortinet, 2026). The Security Fabric ecosystem is not limited to Fortinet products alone; more than 500 third-party solutions can connect into the same visibility layer (Fortinet, 2026).
Threat data explains why this architecture is on the agenda today. According to Verizon's 2025 Data Breach Investigations Report, vulnerability exploitation reached 20% as an initial access vector, and within that figure the share of edge devices and VPNs climbed from 3% to 22% in a single year (Verizon DBIR, 2025). The same report notes that organizations were able to fully remediate only around 54% of their edge device vulnerabilities, and that doing so took a median of 32 days. ENISA's 2025 Threat Landscape report, which examined 4,875 incidents, measures vulnerability exploitation at 21.3% of initial access and phishing at 60% (ENISA Threat Landscape, 2025). In short, the device at the network edge is now both the primary line of defense and the primary target.
What exactly does the Fortinet Security Fabric solve?
The Security Fabric is the architectural framework that lets Fortinet products operate on a shared policy, identity and telemetry layer. The problem it solves is operational rather than technical: when a firewall, an endpoint agent, a wireless controller and a log server bought from different vendors cannot interpret one another's data, getting to the root cause of an incident means walking from console to console, matching timestamps by hand, and very often missing the incident altogether.
Fortinet defines the Security Fabric by three qualities: broad — covering the entire digital attack surface; integrated — products and third-party solutions visible from a single point; automated — detection and response that can be triggered without human intervention (Fortinet Security Fabric, 2026). On the central management side, in the wording of its official product page, FortiManager scales to manage 100,000 Fortinet devices (FortiGate, FortiSwitch, FortiAP, SD-WAN and FortiSASE) from a single point (Fortinet FortiManager, 2026).
Concretely, this is what it looks like: an indicator of compromise detected on an endpoint can trigger FortiGate to move the relevant user into a quarantine segment; FortiSwitch shuts the port down, and FortiAnalyzer gathers every step onto a single timeline. In a single-vendor environment that chain comes ready-made; in a multi-vendor environment it has to be written, tested and maintained separately on a SIEM or SOAR platform. This is where Fortinet's strongest argument for the enterprise buyer lies — less in technological superiority than in operational coherence and less integration debt.
There is a cost to this too: dependency on a single vendor. At Sora Yazılım we position the Security Fabric not as dogma but as a choice that can be justified. We also work with organizations that deliberately diversify to a different vendor at layers such as endpoint or email; if you would like to compare the alternatives, you can review our complete solution portfolio.
Which Fortinet product fits which need?
The short answer: FortiGate protects the network edge and internal segmentation, FortiSASE the user outside the office, FortiClient and FortiEDR the endpoint, FortiAP and FortiSwitch the access layer, FortiAnalyzer logs and audit evidence, FortiMail email, and FortiWeb web applications and APIs. The table below summarizes which concrete need each product within the Fortinet solution set answers, and the trigger that typically brings it onto the agenda in a project.
| Product | Need it addresses | When we typically discuss this product |
|---|---|---|
| FortiGate NGFW | Internet edge, internal segmentation, SD-WAN, IPsec/SSL VPN and IPS. FortiOS is identical across all models; policy can be carried from a small model to a large one. | A new building or branch opening, the existing firewall reaching end of support, moving MPLS egress onto an internet line. |
| FortiSASE | Cloud-based inspection of remote user and branch traffic. SWG, ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN and end-to-end DEM on a single platform. | Work outside the office becoming permanent, the VPN concentrator turning into a bottleneck, not wanting hardware in the branch. |
| FortiClient | EPP, ZTNA, SSE, CASB, DEM, sandbox, vulnerability management and USB device control in a single agent; central management with FortiClient EMS. | Moving to ZTNA, a wish to cut the number of agents on the endpoint, a compliance auditing requirement. |
| FortiEDR | Behavior-based detection on the endpoint, automated response and post-incident investigation; broad platform coverage including legacy operating systems. | Ransomware risk, legacy Windows versions on the production line, the SOC's demand for endpoint visibility. |
| FortiAP | Enterprise wireless access managed by FortiGate's built-in WLAN controller, the FortiEdge Cloud portal or FortiSASE; Wi-Fi 6, 6E and 7 models. | Campus Wi-Fi refresh, separating out the guest network, density and coverage complaints. |
| FortiSwitch | Access switches that become a logical extension of the FortiGate through the FortiLink protocol; PoE+ on every model, basic NAC at no extra cost. | Access layer refresh, automatic segmentation of IoT devices, the need for port-based policy. |
| FortiAnalyzer | Central log collection, correlation, forensic investigation and out-of-the-box compliance reports (PCI-DSS, HIPAA); Analyzer and Collector modes. | Bringing a second FortiGate into service, an audit/compliance obligation, a log retention requirement. |
| FortiMail | Email security in Gateway, Transparent and Server modes, or out of band through Microsoft/Google cloud email APIs without changing the MX record. | Microsoft 365's built-in filter falling short, targeted phishing, BEC (executive impersonation) cases. |
| FortiWeb | Web application and API security: OWASP Top 10, a second detection layer driven by machine learning, schema validation and client-side protection. | Publishing an externally facing application or API, PCI DSS 4.0 payment page script requirements. |
Three products come up together in almost every project: FortiGate, FortiAnalyzer and an endpoint agent. FortiGate enforces policy, FortiAnalyzer stores and reports what happens, and FortiClient or FortiEDR ties the endpoint into the same policy plane. Organizations that start with a single FortiGate almost invariably need central logging as soon as they bring a second device into service; sizing FortiAnalyzer in the first round is therefore both cheaper and less risky than migrating logs retroactively later on.
The verified capacity ranges that make sizing easier are as follows. The FortiAnalyzer hardware family scales from 100 GB to 8,300 GB of daily log ingestion and from 180 to 10,000 devices/VDOMs; an HA cluster of up to four nodes can be built (Fortinet FortiAnalyzer Data Sheet, 2026). FortiMail hardware models offer routing capacity of between 50,000 and 3.5 million messages per hour and manage between 20 and 2,000 protected email domains (Fortinet FortiMail Data Sheet, 2026). FortiWeb appliances operate at between 2.5 Gbps and 70 Gbps of throughput with sub-5-millisecond latency; the same capabilities can also be deployed as a virtual machine, a container and SaaS (Fortinet FortiWeb Data Sheet, 2025). At the access layer, the FortiLink protocol makes between 8 and 300 FortiSwitches manageable from a single point depending on the FortiGate model, and delivers basic NAC functions such as profiling connected devices, IoT segmentation and quarantine in the event of a breach at no extra cost (Fortinet FortiSwitch Secure Access Data Sheet, 2026).
On the cloud side, FortiSASE combines SWG, ZTNA, CASB, FWaaS, SSPM, secure browser, secure SD-WAN and end-to-end digital experience monitoring (DEM) on a single platform (Fortinet FortiSASE, 2026). On its product page Fortinet states that as of August 2026 the service is delivered through more than 200 PoPs (Fortinet FortiSASE, 2026); because the data sheet describes the same network as "hundreds of security PoPs" without giving a number, we report this figure as a Fortinet claim. The commitments confirmed directly in the data sheet are these: a latency-backed 99.999% SLA for security inspection and SOC 2 Type II certification against the AICPA Trust Services criteria (Fortinet FortiSASE Data Sheet, 2026). The web filtering engine sorts hundreds of millions of URLs into more than 90 categories and also analyzes TLS 1.3 traffic; application control recognizes more than 8,000 applications.
On the endpoint side, two products should not be confused with each other. FortiClient combines EPP, ZTNA, SSE, CASB, DEM, sandbox, vulnerability management and USB device control in a single agent (Fortinet FortiSASE Data Sheet, 2026); under the FortiTrust per-user license a single user can install FortiClient on at most three devices, and the EMS server requires a minimum of 6 virtual CPUs, 12 GB of RAM and 80 GB of disk (Fortinet FortiClient Data Sheet, 2025). FortiEDR, by contrast, is the detection and response layer: the agent uses 1-2% CPU, 200-350 MB of memory and 750 MB-1 GB of disk, and supports legacy operating systems from Windows XP SP2 through to Windows 11 and from Windows Server 2003 SP2 through to Server 2025 (Fortinet FortiEDR Data Sheet, 2025). That legacy system coverage is one of the most concrete reasons organizations choose Fortinet on production lines and medical device networks. According to Fortinet's own statement, in the fourth round of the MITRE Engenuity ATT&CK Evaluations (the Wizard Spider and Sandworm scenarios) FortiEDR blocked 100% of attacks and detected 97% of the 90 non-Linux steps (Fortinet, 2022).
On the wireless side, the FortiAP portfolio covers Wi-Fi 6, Wi-Fi 6E and Wi-Fi 7 models together; the Wi-Fi 7 flagships FAP-441K and FAP-443K offer four radios and four spatial streams, support the 6 GHz band, and come with 10 Gigabit Ethernet ports and 802.3bt PoE (Fortinet FortiAP Series Data Sheet, 2026). Access points run under one of three management models: FortiGate's integrated WLAN controller, the FortiEdge Cloud portal, or FortiSASE.
Which FortiGate model should I start with?
Model selection is not driven by user count but by the security profiles that will stay enabled. The determining metric is almost always Threat Protection throughput: the real capacity with firewall, IPS, application control and malware protection all switched on and logging active. The "firewall throughput" figure that stands out in brochures is measured with no security profile enabled at all, and it is unattainable in a production environment. Every value in the table below is taken from the relevant model's official Fortinet data sheet.
| Model | Class | IPv4 Firewall throughput (1518 / 512 / 64 byte UDP) | Threat Protection throughput | Typical positioning |
|---|---|---|---|---|
| FortiGate 40F | Entry level | 5 / 5 / 5 Gbps | 600 Mbps | Micro office, checkout/POS point, small single-line branch |
| FortiGate 60F | Entry level | 10 / 10 / 6 Gbps | 700 Mbps | Classic branch; the most widespread entry model |
| FortiGate 70G | Entry level | 10 / 10 / 10 Gbps | 1.3 Gbps | Branch that will run with SSL inspection enabled (SSL inspection 1.4 Gbps) |
| FortiGate 80F | Entry level | 10 / 10 / 7 Gbps | 900 Mbps | Branch that needs PoE (96 W budget on the PoE model) |
| FortiGate 90G | Entry level | 28 / 28 / 27.9 Gbps | 2.2 Gbps | Branch requiring high IPsec (25 Gbps) in a desktop form factor |
| FortiGate 100F | Entry level | 20 / 18 / 10 Gbps | 1 Gbps | Small head office, deployment that needs rack mounting (data sheet 2023; successor 120G) |
| FortiGate 120G | Entry level | 39 / 39 / 28 Gbps | 2.8 Gbps | Large branch or small head office; IPsec 35 Gbps |
| FortiGate 200F | Mid-range | 27 / 27 / 11 Gbps | 3 Gbps | Mid-sized head office, need for 10GE uplink (data sheet 2023; successor 200G) |
| FortiGate 400F | Mid-range | 79.5 / 78.5 / 70 Gbps | 9 Gbps | Campus egress, head office with heavy SSL inspection |
| FortiGate 600F | Mid-range | 139 / 137.5 / 70 Gbps | 10.5 Gbps | Campus core, environment requiring 25GE SFP28 ULL |
| FortiGate 900G | Mid-range | 164 / 163 / 153 Gbps | 30 Gbps | Large campus; 28 million concurrent sessions |
| FortiGate 1000F | Mid-range | 198 / 196 / 134 Gbps | 13 Gbps | Data center edge requiring 100GE uplink (2RU) |
| FortiGate 1100E | Mid-range | 80 / 80 / 45 Gbps | 7.11 Gbps | Deployments extending an existing E-series fleet |
| FortiGate 1800F | High end | 198 / 197 / 140 Gbps | 15 Gbps | Data center; 4x 100GE QSFP28 |
| FortiGate 2600F | High end | 198 / 196 / 140 Gbps | 25 Gbps | Data center; 24 million sessions (40 million with Hyperscale) |
| FortiGate 3700F | High end | 589 / 589 / 420 Gbps | 75 Gbps | 400GE QSFP-DD and low latency (1.45 µs on ULL ports) |
| FortiGate 4400F | High end | 1.15 / 1.14 / 0.50 Tbps | 75 Gbps | Hyperscale; 210 million sessions (700 million with the license) |
| FortiGate 7081F | High end | 1.89 / 1.88 / 1.129 Tbps | 312 Gbps (with 6 FPMs) | 8-slot chassis (12U), carrier and hyperscale scale |
Keep four points in mind when reading the table. First, Fortinet publishes all performance figures as "up to" values and states explicitly that they may vary with system configuration. Second, IPsec VPN measurements use AES256-SHA256 encryption at a 512 byte packet size, while IPS, NGFW and Threat Protection measurements are taken with logging enabled on Enterprise Mix traffic (Fortinet Product Matrix, 2026). Third, firewall throughput is always given as the 1518 / 512 / 64 byte triplet; there is no single "throughput" figure, and small-packet performance (the 64 byte column) is decisive for voice and real-time traffic. Fourth, the 100F and 200F rows in the table rest on Fortinet's 2023-dated data sheets; a current English data sheet for these two models is no longer published and they have been succeeded by the 120G and the 200G respectively. For organizations that already have these devices in their fleet the values remain valid, but for new deployments we evaluate the successor models.
In practice we use the following approach: take the bandwidth of your existing internet line, add a three-year growth allowance, and if SSL inspection is going to be enabled, compare that figure against the Threat Protection column. For a classic single-line branch the FortiGate 60F is still the most common starting point; for mid-sized head offices moving to symmetric lines above 1 Gbps that want to keep SSL inspection permanently enabled, the FortiGate 400F represents a clear step up. In scenarios where no physical appliance is wanted, we evaluate FortiGate-VM (seven license tiers from VM-01S through to VM-ULS with unlimited vCPU, available on the AWS, Azure, GCP, OCI, Alibaba Cloud and IBM Cloud marketplaces) and the fully as-a-service FortiGate CNF (AWS and Azure) as alternatives.
Where does Fortinet really stand in analyst reports and independent tests?
Fortinet is a clear Leader in the firewall category; in categories such as SASE, SSE and SIEM its position sits at Challenger level and shifts from year to year. The phrase "a Gartner Leader in every category", frequently seen in marketing material, is not accurate. Knowing the distinction is necessary if the purchasing decision is to rest on solid ground.
| Report | Year | Fortinet's position |
|---|---|---|
| Gartner Magic Quadrant for Hybrid Mesh Firewall | 2025 | Leader — positioned highest on the Ability to Execute axis |
| Forrester Wave: Enterprise Firewall Solutions | Q4 2024 | Leader — the highest possible score (5/5) in 10 criteria |
| Gartner Magic Quadrant for SD-WAN | 2024 | Leader — fifth consecutive year; the only Leader positioned highest in Ability to Execute (fourth year) |
| Gartner Magic Quadrant for SASE Platforms | 2025 → 2026 | Leader in 2025; listed as Challenger for 2026 on Fortinet's own MQ page |
| Gartner Magic Quadrant for Security Service Edge (SSE) | 2025 | Challenger — not a Leader |
| Gartner Magic Quadrant for SIEM | 2025 | Challenger |
| Gartner Magic Quadrant for Email Security | 2025 | Challenger |
Here is how to read the table: within the Fortinet solution set the network security backbone — FortiGate and SD-WAN — sits in the analysts' top tier, while the cloud-native access security side is still maturing. Gartner has also stopped publishing the classic "Network Firewalls" Magic Quadrant and replaced it with the Hybrid Mesh Firewall MQ; the phrase "Network Firewalls MQ Leader" therefore points to a category that, as of 2026, no longer exists. Alongside its Leadership in the Hybrid Mesh Firewall MQ, Fortinet states that it appears in a total of 12 Gartner Magic Quadrant reports (Fortinet, 2025).
On the independent testing side, the most current and most instructive data comes from CyberRatings.org's 2025 Q4 Enterprise Firewall test, run together with NSS Labs. Security effectiveness across the seven enterprise firewalls tested ranged from 46.37% to 99.59%; the devices were put through 3,326 exploits, 11,311 malware samples, 5,752 evasion techniques spread across 53 categories, 6,481 false-positive samples and 55 performance tests (CyberRatings.org, 2025). In the first round the FortiGate-200G came up short against Layer 4 TCP evasion techniques: security effectiveness measured 79.24%, exploit evasion resistance 60%, and the product received a "Caution" rating. Fortinet released an updated IPS package within days; on retest, evasion resistance rose to 100% and overall security effectiveness to 99.24%, and the rating was raised to "Recommended" (CyberRatings.org, 2025).
These two results have to be read together. On its own, the first round makes FortiGate look poor; on its own, the second makes it look flawless. The real takeaway is this: an NGFW's security effectiveness depends directly on how current its IPS and signature package is; a device whose subscription has not been renewed, or that is not receiving signature updates, will not deliver the performance it shows on paper. In the same test round the Palo Alto Networks PA-1410 scored 46.37% effectiveness and 0% evasion resistance on the first measurement and rose to 96.07% with an up-to-date PAN-OS release (CyberRatings.org, 2025) — in other words, the issue is not vendor-specific but a matter of lifecycle management. On customer satisfaction, Fortinet was named a Gartner Peer Insights Customers' Choice in the SD-WAN category for the sixth consecutive time; as of March 2025 it reported a score of 4.9 out of 5 across 414 reviews and a 97% willingness-to-recommend rate (Fortinet, 2025).
Why does FortiASIC hardware acceleration make a difference?
Fortinet's hardware acceleration means handing security operations over to purpose-built processors instead of general-purpose CPUs; the practical result is more inspected traffic for the same budget. That is decisive in an era when TLS inspection is no longer optional. CyberRatings reports that more than 95% of global web traffic is encrypted and that some products suffer a marked drop in performance while inspecting encrypted traffic (CyberRatings.org, 2025).
Two processor families stand out in the architecture. The NP7 network processor offloads sessions from the CPU to deliver "fastpath" acceleration; each NP7 supports a maximum data rate of 200 Gbps across two 100 Gigabit interfaces, and a single NP7 can carry up to 12 million concurrent sessions (Fortinet Document Library, 2026). On FortiGates with a Hyperscale license, the NP7 additionally takes session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection off the CPU.
The CP9 content processor, for its part, delivers more than 10 Gbps of pattern-matching acceleration in flow-based inspection — that is, in IPS and application control (Fortinet Document Library, 2026). The same processor's VPN bulk data engine runs DES/3DES and AES-128/192/256 together with MD5/SHA-1/SHA-256/384/512 operations, and its key exchange processor handles public key operations of generally up to 4096 bits (up to 8K with CRT for RSA) and ECC P-256 support for NSA Suite B, all in hardware. Current FortiGate devices use the CP10, CP9, CP9Lite and CP9XLite content processors; CP4, CP5, CP6 and CP8 belong to earlier generations (Fortinet Document Library, 2026).
From a purchasing standpoint this means: two devices showing the same firewall Gbps figure can behave completely differently once SSL inspection is enabled. That is why in comparisons we do not look only at the firewall row but explicitly show the customer the SSL Inspection and Threat Protection rows as well. We also put in writing the risk that buying a model on an older ASIC generation today means running into a capacity wall three years from now.
How should the FortiOS version and license timeline be planned?
The FortiOS version decision outlives the hardware choice and should be made according to the support calendar. For a standard FortiOS major or interim release, Fortinet provides 36 months of engineering support from the GA date, followed by 18 months of "Must Fix" support. For Long-Term Supported (LTS) releases that period stretches to a total of 72 months including an 18-month Urgent Fix phase, and LTS access is possible only with a FortiCare Elite contract (Fortinet Community, 2026).
The current calendar was extended by one year with bulletin CSB-260330-1 published in March 2026: end of engineering support for FortiOS v7.4 became May 11, 2027 and end of full support November 11, 2028; for v7.6, end of engineering support is July 25, 2028 and end of full support January 25, 2030 (Fortinet Community, 2026). For a five-year usage plan on a device bought today, the v7.6 line offers markedly safer ground than v7.4; for fleets remaining on v7.4, the upgrade window needs to be put on the calendar now.
Fortinet announced FortiOS 8.0 on March 10, 2026. The release brings FortiView for detecting shadow-AI usage, AI-aware application control, Model Context Protocol visibility, OCR-supported data loss prevention and quantum-safe cryptography controls with Post-Quantum Cryptography certificates (Fortinet, 2026). We do not rush the move to a new major release in production environments; we recommend a configuration backup and a pilot device first, followed by a phased rollout. On the licensing side it also matters to keep FortiCare and FortiGuard separate: FortiCare covers hardware warranty, technical support and RMA service, while FortiGuard covers threat intelligence subscriptions such as IPS signatures, the malware database, web filtering and application control. As the CyberRatings test showed, without the latter a device's security effectiveness falls off quickly.
How does Fortinet meet KVKK, PCI DSS and enterprise audit requirements?
Fortinet solutions directly satisfy a significant share of the controls requested under the heading of "technical measures" in audits; compliance, however, is a process rather than a product, and it is completed by producing evidence. The Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) defines the firewall and gateway as the priority measure and the first line of defense in protecting information technology systems containing personal data against unauthorized access threats arriving over the internet (KVKK, January 2018).
The summary table of technical measures in the same guide lists network security, firewalls, intrusion detection and prevention systems, log records, access logs and penetration testing as separate items. In practice FortiGate covers the first three items, FortiAnalyzer covers the log records and access logs items, and regular firmware and signature management covers the vulnerability management side. The guide also requires that regular log records be kept of all user transaction activity and that regular vulnerability scanning and penetration testing be carried out — in other words, installing the device is not enough on its own; operational discipline is audited as well.
On the PCI DSS v4.0 side the terminology has changed: Network Security Controls (NSC) is used in place of "firewall", and Requirement 1 is titled "Install and Maintain Network Security Controls". Clause 1.2.7 requires NSC configurations to be reviewed at least once every six months; 1.3.1 and 1.3.2 require traffic entering and leaving the cardholder data environment to be restricted to what is necessary and all other traffic to be explicitly denied; 1.4.1 requires NSCs to be placed between trusted and untrusted networks; and 11.4.5 requires penetration testing at least every 12 months and after every segmentation change wherever segmentation is used (PCI Security Standards Council, PCI DSS v4.0). For clauses 6.4.3 and 11.6.1 concerning payment page scripts, FortiWeb's client-side protection module targets those requirements directly (Fortinet FortiWeb Data Sheet, 2025).
The gap we encounter most often in audit preparation is not the device itself but evidence production. FortiAnalyzer's ready-made PCI-DSS and HIPAA compliance reports, together with the FortiGuard IOC service's forensic data feed of 500,000 IOCs per day, make the evidence that can be presented to an auditor genuinely producible (Fortinet FortiAnalyzer Data Sheet, 2026). In organizations supervised by the BDDK (Turkey's banking regulator), log integrity and retention period are a separate design decision; for that reason we size the Analyzer and Collector modes, the disk capacity and the archive policy specifically for each project. We calculate the retention period not as a product feature but as an outcome of capacity planning.
As a Fortinet authorized channel partner, Sora Yazılım runs the project in four stages: mapping out the existing topology and traffic profile, sizing and quotation based on official data sheets, a phased cutover that keeps downtime to a minimum, and then continuous operation. During the migration stage, part of a Cisco ASA, Palo Alto or Check Point configuration can be transferred with Fortinet's conversion tool; the remaining custom rules are rewritten by hand by our engineers and tested in a pilot environment. We design the automation, monitoring, backup and change management side together with our DevOps and infrastructure services.
For a Fortinet architecture and model selection that matches your organization's traffic profile, branch count, endpoint inventory and compliance obligations, get in touch with Sora Yazılım. Once you share your existing device inventory, line capacities and license expiry dates, we prepare a data-sheet-based sizing report, a migration plan and a formal quotation. Because pricing varies with the model, the license bundle and the contract term, the quotation is always produced specifically for the project.
- A single policy plane across a nine-product Fortinet portfolio
- Model sizing based on official data sheets
- Fortinet NSE certified engineering team
- Logging design focused on KVKK, PCI DSS and audit evidence
- Migration, license tracking and managed service
Sora Yazılım is a Fortinet authorized channel partner. Our NSE certified engineers take on architectural design, data-sheet-based sizing, installation, migration and managed service; we track the FortiCare and FortiGuard renewal calendar on your organization's behalf.
Other brands you may consider in the same category
Trend Micro
Trend Micro unifies endpoint, server, network, email and mobile protection products in a single console through the Vision One XDR platform.
Product detailsCybersecurityBitdefender
Bitdefender GravityZone is an EPP, EDR and XDR platform that protects endpoints, servers, virtualization, email, containers and cloud workloads from a single agent and a single console. Sora Yazılım provides licensing, deployment, migration and managed service support in Turkey.
Product detailsNetwork InfrastructureRuijie / Reyee
Ruijie Networks delivers cloud-managed networking — switching, Wi-Fi and gateways — that scales from SMB to enterprise campus and is centrally operated through Ruijie Cloud. Reyee is the SMB-focused sub-brand.
Product detailsProducts we deliver under this brand
Use the side menu to navigate products quickly, or click a card to open the detail page.
FortiGate NGFW
A 20-model NGFW family: from the 40F to the 7081F, a single FortiOS policy, built-in SD-WAN and ZTNA.
The FortiGate NGFW family offers 20 models from the 40F to the 7081F, FortiOS, NP7/CP9 hardware acceleration and built-in SD-WAN and ZTNA. Sora Yazılım provides sizing, licensing, installation and managed services.
Product detailsFortiSASE
Cloud SASE with a single policy for remote workers and branches: SWG, ZTNA, CASB, FWaaS.
Cloud-based Fortinet SASE service that protects remote workers and branch users under one policy: SWG, ZTNA, CASB and FWaaS in a single console, FortiClient as a single agent, and a hybrid architecture built with FortiGate.
Product detailsFortiClient (Unified Endpoint Agent)
VPN, ZTNA, endpoint protection, vulnerability scanning and Security Fabric telemetry in one enterprise agent.
FortiClient is the Fortinet client that brings remote access VPN, ZTNA-based application access, endpoint protection, vulnerability scanning and device compliance checking together in a single enterprise agent, managed centrally through EMS.
Product detailsFortiEDR / FortiXDR
Behavioral detection, real-time blocking and automated incident response at the endpoint.
An EDR/XDR solution that combines pre-infection NGAV with post-infection behavioral blocking in a single lightweight agent, delivers automated incident response and rollback, covers legacy operating systems and integrates with the Fortinet Security Fabric.
Product detailsFortiAP (Wi-Fi 6/6E/7)
Enterprise Wi-Fi access points managed from FortiGate, with no separate controller hardware.
Indoor, outdoor and ruggedized access points supporting Wi-Fi 6, 6E and Wi-Fi 7; managed by the FortiGate integrated controller, FortiEdge Cloud or FortiSASE, and forming the campus access layer together with FortiSwitch.
Product detailsFortiSwitch
Enterprise PoE access switch family managed from FortiGate via FortiLink.
Enterprise switch family managed from FortiGate via FortiLink; the Secure Access series offers up to 48 access ports in a 1 RU chassis, PoE+ and 802.3bt power, segmentation, and basic NAC at no extra cost.
Product detailsFortiAnalyzer
Central logging, compliance reporting and SOC automation for the Security Fabric.
Central logging and security analytics platform that gathers logs from FortiGate and Security Fabric components into a single data lake, produces correlation and compliance reporting, and offers playbook automation through built-in SIEM/SOAR.
Product detailsFortiMail
Multi-layered enterprise email security gateway against spam, phishing, BEC and data leakage.
Fortinet email security gateway that inspects inbound and outbound mail against spam, phishing, BEC and malicious attachments while providing DLP, encryption and archiving. Available as hardware, virtual machine, cloud or API mode.
Product detailsFortiWeb (WAF)
The Fortinet WAF that protects web applications and APIs with two-layer, machine learning-driven inspection.
Fortinet WAF providing two-layer, machine learning-driven protection against OWASP Top 10, bot and API attacks; scales from 100 Mbps to 70 Gbps on hardware and is also deployed as a virtual machine, container and SaaS.
Product details
How we deliver projects for this brand
- 01
Discovery and architectural design
We map out the existing topology, branch count, line capacities, application profile and compliance obligations, then propose a target design in line with the Fortinet reference architecture.
- 02
Sizing and quotation
We select the model based on the Threat Protection and SSL Inspection values in the official Fortinet data sheets; we settle the license bundle and term and present a formal, project-specific quotation.
- 03
Installation and phased cutover
We run a phased cutover inside the maintenance window with a configuration backup, pilot installation, policy conversion and a rollback plan; we document every step with test records.
- 04
Continuous operation
We keep up periodic health reporting, FortiGuard signature and firmware lifecycle management, log and audit evidence production, and license renewal tracking.
Common questions about this brand
What is Fortinet and which components make up the product family?
Is Fortinet really a Gartner Leader in every category?
Which metric should I use to choose a FortiGate model?
What is the difference between FortiCare and FortiGuard?
Which FortiOS version should I choose?
Is FortiAnalyzer essential, or is FortiGate's own logging enough?
Is there a free version of FortiClient?
For remote workers, FortiGate VPN or FortiSASE?
How is a migration from another brand to Fortinet carried out?
How do you supply Fortinet products in Turkey and how is pricing determined?
Fortinet licensing and deployment
Get in touch for packaged offerings including licenses, deployment, training and ongoing support.