A product team that does not want to run a firewall
A company whose production workloads run on Azure does not want to patch a separate firewall; with CNF, software infrastructure maintenance disappears.
A software-as-a-service firewall for AWS and Azure; protects VPCs/VNets, availability zones and accounts across a region with a single shared policy.
FortiGate CNF (Cloud-Native Firewall) is Fortinet's software-as-a-service firewall offering for AWS and Azure. It eliminates the need to configure, provision and maintain firewall software infrastructure; a single instance can protect multiple VPCs or VNets, availability zones and accounts within a region using one shared policy. Fortinet does not publish fixed throughput or session capacity figures for this service.
FortiGate CNF (Cloud-Native Firewall) is, in Fortinet's own words, a software-as-a-service offering that simplifies cloud network security while delivering availability and scalability; it removes the need to configure, provision and maintain firewall software infrastructure (FortiGate CNF Administration Guide 25.3.a, 2025). The service is in production support on both AWS and Azure — the widely repeated claim that "the AWS side is in beta" is not correct.
FortiGate CNF is for organizations that run workloads in the cloud but do not want to operate the firewall itself as an infrastructure component. Instances are hosted on AWS or Azure infrastructure in the same region as the workload they protect; for organizations with data residency and KVKK (Turkey's data protection law) requirements, keeping traffic inside the region is a decisive criterion. The real architectural gain, though, lies in policy scope: a single instance can protect multiple VPCs, availability zones and AWS accounts within a region with one shared policy, and on the Azure side the same construct applies to virtual networks and Azure accounts. In a landing zone with dozens of accounts, this means managing one policy set instead of operating a separate firewall per account. In return, scope is limited to AWS and Azure; if GCP, OCI or a private cloud is in play, FortiGate-VM is what you need.
The timeline also corrects a common misconception: Fortinet made the Cloud-Native Firewall service generally available on AWS first, on November 28, 2022, through AWS Marketplace (Fortinet Newsroom, 2022); Azure support was added later.
| Criterion | FortiGate CNF | FortiGate-VM |
|---|---|---|
| Delivery model | SaaS — Fortinet operates it | Cloud instance — you operate it |
| Environment | AWS and Azure | AWS, Azure, GCP, OCI, Alibaba, IBM Cloud, VMware, Hyper-V, KVM, Nutanix, OpenShift |
| Capacity | Not published; the service scales | S-series license + vCPU (VM-01S → VM-ULS) |
| Software maintenance | No firewall software infrastructure maintenance | FortiOS upgrades are yours |
| Policy scope | One shared policy for many VPCs/VNets, AZs and accounts in a region | Policy per instance and per VDOM |
| Management | CNF portal and REST API; AWS Firewall Manager integration | FortiOS interface, CLI, FortiManager |
The decision rule is this: if you want to hand off the operational burden and run a single policy across a region, choose FortiGate CNF; if you need full control of FortiOS, VDOM separation, or a platform outside AWS and Azure, choose FortiGate-VM. The two models are not mutually exclusive — in a multi-cloud architecture they are used side by side, and both are part of the same FortiGate product family.
The official documentation lists FortiGuard Labs-backed IPS profiles, DNS filtering, geo-IP blocking, known-bad IP address filtering and geo-fencing. In this model, keeping signature and reputation data current is entirely on the service side, and that is exactly where the difference shows: according to FortiGuard Labs' 2026 Global Threat Landscape Report, the time to exploitation on critical advisories has fallen to 24-48 hours and global exploitation attempts rose 25.49% year over year (Fortinet, 2026). The management plane is the CNF portal and the REST API; on the AWS side, Firewall Manager integration handles rolling the deployment out across the organization. The claim that it is "configured only from the Azure portal" does not match current documentation.
Fortinet does not publish throughput, concurrent session or new sessions per second figures for FortiGate CNF. The reason is not incomplete documentation but the delivery model: the service scales as SaaS and is not positioned around a fixed capacity limit. In practice, policy planning takes the place of capacity planning. If a regulation or a tender specification demands a measured Gbps figure, hardware is required: the FortiGate 400F delivers 79.5 Gbps of IPv4 firewall and 9 Gbps of Threat Protection throughput, while the FortiGate 1000F delivers 198 Gbps of IPv4 firewall and 13 Gbps of Threat Protection throughput. The choice is not a performance race but a question of where responsibility sits.
As a Fortinet authorized channel partner, Sora Yazılım handles the rollout of FortiGate CNF in your AWS and Azure environments, the migration of existing policies to the shared CNF policy, the design of IPS profiles along with DNS filtering and geo-fencing rules to match your corporate policy, and the managed service. We clarify region selection, log flow and data residency in scope of KVKK (Turkey's data protection law) at the start of the project. Reach us through our contact page for a quote.
A company whose production workloads run on Azure does not want to patch a separate firewall; with CNF, software infrastructure maintenance disappears.
In a region with dozens of AWS accounts and VPCs, all networks are protected by a single shared policy; Firewall Manager rolls the deployment out.
In an infrastructure where traffic multiplies seasonally, CNF is not positioned around a fixed capacity limit, so firewall sizing stops being a line item in the campaign plan.
Because instances are hosted in the same region as the workload, data residency scenarios become easier; access is restricted at the policy level with geo-IP blocking and geo-fencing.
Organizations running hardware in the data center and CNF in the cloud operate the two layers under separate responsibility models: hardware stays wherever measured throughput is required.
Organizations running production workloads on AWS and/or Azure that do not want to operate the firewall software layer themselves; multi-account cloud organizations and landing zone architectures; financial and public sector institutions with in-region data residency requirements.
Fanless desktop NGFW delivering 5 Gbps IPv4 firewall for micro offices of 5–10 users.
Details10-port desktop NGFW delivering 10 Gbps IPv4 firewall for small offices and branches of 10–30 users.
DetailsThe SP5 ASIC-based branch NGFW that replaces the 60F: 10 Gbps symmetric firewall, 1.4 million sessions, PoE and FortiWiFi variants.
DetailsDesktop branch firewall with eight PoE/+ ports and a 96 W budget that also powers the access layer.
DetailsSora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.