Editor’s note: This is a summary of our testing of this product, for a full rundown of how it fared in our testing across 10 UTM categories, please see our full coverage.
Fortinet’s FortiGate 3600A is in the midrange of Fortinet’s broad UTM firewall product line, which starts at SOHO devices and moves its way up to a carrier-sized chassis. Fortinet’s strength lies in its hardware-acceleration technology. While many other firewall vendors are jumping to designs that maximize the use of off-the-shelf components, Fortinet continues to develop custom silicon both in the network processor and content analysis parts of its products. Not every product has the same level of acceleration technology, but the 3600A is certainly a winner when it comes to high-speed virus scanning.
The challenge Fortinet has had, and continues to have in the version of the product we evaluated, is its ability to bring the FortiGate 3600A to the level where it can compete successfully in the enterprise. However, we found the FortiGate 3600A’s simplistic management interface unsuitable for enterprise configuration tasks.
Still, underneath this SMB-style GUI, Fortinet has planted a very complete command-line interface that activates a much more complete feature set. In our initial evaluation of the product using the GUI, we found eight significant flaws, ranging from missed viruses to poor e-mail behavior when viruses were caught to insufficient IPS logging information. After working with Fortinet’s technical support, all of these flaws were resolved — but we had to use the CLI for those fixes.
In a carrier environment where configuration using a CLI is expected, the FortiGate product line would be perfectly acceptable. But in an enterprise, having a complete global management system and device GUI are not just expected, but are required. This is especially true in the UTM environment, where managing the IPS requires substantially more policy controls than are available in the FortiGate 3600A, even using the command line.
The FortiGate 3600A does have the raw speed you need. It even has most of the features you might be looking for. What Fortinet needs to do, though, is improve the management and configuration of the product so that it is ready to be deployed in an enterprise environment.




