FortiGate Virtual Firewall

VIRTUAL NGFW FOR PRIVATE, PUBLIC AND HYBRID CLOUD

FortiGate Virtual Firewall in Dubai, UAE

FortiGate Virtual Firewall is the FortiGate-VM family of software-based next-generation firewalls designed to place FortiOS security and networking controls inside virtualised and cloud infrastructure. It is relevant when an organisation needs firewall policy, application control, intrusion prevention, VPN, segmentation and secure connectivity around workloads that no longer sit only behind a physical perimeter. The important buying decision is not simply whether to choose a virtual firewall, but which VM entitlement, service bundle, cloud or hypervisor deployment model, management approach and high-availability design match the workload.

What to have ready for a useful quote

Share the target platform, expected inspected traffic, preferred license model, required security services, number of instances, interfaces, availability design and management requirements.

Performance, cloud instance cost, license entitlement and supported features can vary by FortiOS release, model, bundle and platform.

Deployment
Private cloud, public cloud and hybrid environments
Licensing
BYOL, subscription, marketplace and FortiFlex options
Sizing
1 to unlimited vCPU classes depending on entitlement
Key check
Cloud or hypervisor limits can be lower than FortiGate limits

Direct answer: what is FortiGate Virtual Firewall?

FortiGate Virtual Firewall is a software deployment of Fortinet FortiGate, generally referred to as FortiGate-VM, that runs on supported hypervisors and cloud platforms. It is mainly used to secure virtual networks, cloud workloads, north-south internet traffic, east-west application traffic, hybrid connectivity and segmented environments while retaining the FortiOS policy and security framework. It is worth considering for organisations that need FortiGate controls without placing a physical appliance at the protected virtual edge. Before proceeding, buyers should confirm the exact FortiGate-VM size, vCPU allowance, cloud instance or hypervisor resources, license and FortiGuard bundle, number of interfaces, routing design, high-availability pattern, management platform and target FortiOS release.

What it does in a virtual network

A FortiGate-VM instance inserts FortiOS security enforcement into a software-defined network path. Depending on the design and licensed services, it can enforce stateful firewall policies, control applications, inspect traffic for threats, terminate VPN connections, participate in dynamic routing, support segmentation and contribute to SD-WAN or hybrid connectivity designs. The virtual form factor is useful because the firewall can be placed where the workloads live instead of forcing every traffic flow back through an on-premises hardware appliance.

The VM still depends on the surrounding infrastructure. Virtual network interfaces, cloud route tables, security groups, load balancers, instance types, hypervisor switches and orchestration choices determine how traffic reaches the firewall. A good design therefore treats FortiGate-VM as one component in the traffic path rather than as an isolated software image.

Who should consider it

FortiGate Virtual Firewall can fit enterprises, cloud-first organisations, managed service environments, software teams, data-centre operators and businesses that already use FortiGate hardware and want a related policy model in cloud or virtual infrastructure. It can also suit organisations replacing a legacy virtual firewall, building a disaster-recovery environment, protecting hosted applications, creating secure cloud hubs or separating application tiers.

It may be a poor fit when the buyer actually needs physical switching ports, local hardware acceleration characteristics, integrated appliance functions or a branch device that must continue operating independently of a virtualisation platform. In such cases, a physical FortiGate or a mixed design may be more appropriate. FourTeck can compare the operational requirement before the bill of materials is fixed.

Business challenges a virtual FortiGate can help address

Cloud traffic visibility

Virtual networks can create traffic paths that bypass a traditional perimeter. FortiGate-VM can be placed in cloud or virtual routing paths so selected flows are subject to policy and inspection.

Consistent policy models

Organisations already operating FortiOS can extend familiar policy concepts into software-defined environments, reducing the need to operate completely unrelated firewall platforms for every location.

Segmentation around workloads

Application tiers, shared services, tenant zones and sensitive workloads often need controlled paths between them. Virtual firewalls can enforce boundaries within the data centre or cloud design.

Elastic infrastructure planning

The VM model provides multiple vCPU classes and consumption approaches. It can support growth, but scaling still requires planning for licenses, cloud resources, interfaces, routing and operational controls.

Capabilities buyers normally evaluate

Network security

Stateful firewalling, application-aware controls and FortiGuard-backed security services are available according to the FortiOS build and chosen service bundle.

Secure connectivity

FortiGate-VM can participate in VPN, routing and SD-WAN designs, making it useful for cloud-to-site, cloud-to-cloud and controlled internet access architectures.

Central operations

FortiManager can be used for centralised management and FortiAnalyzer can support log analytics where those platforms and licenses are included in the design.

Flexible consumption

Fortinet supports several VM licensing and consumption approaches, including annual subscriptions, perpetual entitlements in supported models, FortiFlex and public-cloud marketplace options.

FortiGate-VM fit matrix

RequirementSuitable whenConfirm before ordering
Public cloud edgeInternet, VPC/VNet and hybrid flows need FortiGate policy in a cloud environment.Cloud, region, instance type, routing, interface count, PAYG or BYOL and HA pattern.
Private cloud segmentationVirtual workloads require controlled east-west and north-south paths.Hypervisor release, virtual switch design, NIC mapping, throughput and storage.
Hybrid connectivityBranches, data centres and cloud networks need routed or VPN connectivity with shared policy objectives.Tunnel count, routing protocol, encryption load, resilience, IP plan and management.
Elastic or project-based usageConsumption may rise, fall or move between environments.Whether subscription, marketplace or FortiFlex economics and entitlement rules fit the project.
Large shared firewall serviceHigher vCPU classes and centralised operations are needed.Actual inspected throughput, session load, policies, VDOM requirement, logging and platform limits.

Current FortiGate-VM family information

The figures below are family-level planning references from current Fortinet material, not a substitute for sizing against your traffic profile.

VM classvCPU classPublished firewall throughputPlanning note
FortiGate-VM001 vCPUUp to 12 GbpsEntry virtual class; verify licensing and FortiOS support for the planned environment.
FortiGate-VM01 / VM01V1 vCPUUp to 12 GbpsSuitable for smaller workloads only after inspected traffic and session requirements are reviewed.
FortiGate-VM02 / VM02V2 vCPUUp to 15 GbpsCloud instance type and packet processing characteristics can materially affect real results.
FortiGate-VM04 / VM04V4 vCPUUp to 28 GbpsCommonly evaluated for mid-scale cloud hubs and virtual data-centre use cases.
FortiGate-VM08 / VM08V8 vCPUUp to 33 GbpsCheck encrypted inspection, session scale and HA overhead rather than relying on headline firewall throughput.
FortiGate-VM16 / VM16V16 vCPUUp to 36 GbpsRequires appropriate host or cloud compute capacity and a design that can deliver traffic to the VM efficiently.
FortiGate-VM32 / VM32V32 vCPUUp to 50 GbpsHigher scale does not remove the need to validate cloud NIC and instance throughput ceilings.
FortiGate-VMUL / VMULVUnlimited vCPU entitlement classConfiguration dependentUsed where larger or more flexible resource allocation is required; actual platform and release limits still apply.

Important: Fortinet publishes performance values as “up to” figures under defined test conditions. Real throughput changes with the FortiOS build, security profiles, traffic mix, packet size, SSL inspection, logging, VM resources and the underlying cloud or hypervisor. Current Fortinet material also identifies annual S-series entitlement classes from 1, 2, 4, 8, 16 and 32 vCPU through an unlimited-vCPU class, with storage support starting at 32 GB and extending to 2 TB in the published S-series table. Platform support and limits should be rechecked against the intended FortiOS release before purchase.

Platform support and infrastructure dependencies

FortiGate-VM is designed for a broad set of virtualisation and cloud environments. Current Fortinet material lists private-cloud support that includes VMware ESXi, VMware NSX-T, Microsoft Hyper-V, KVM-based environments, Nutanix AHV and other supported platforms, while public-cloud availability covers major services such as Amazon Web Services, Microsoft Azure, Google Cloud, Oracle Cloud, Alibaba Cloud and IBM Cloud. This breadth is useful, but it should not be read as permission to deploy any FortiOS image on any platform version. Fortinet explicitly notes that support varies by model and FortiOS build, and the exact combination should be confirmed from the relevant deployment guide and release notes.

Interface counts are a common design trap

Fortinet documentation states that FortiGate can consume up to 24 network interfaces from FortiGate version 6.4.0 onward, but the actual number attachable to a VM can be lower because the cloud instance or virtualisation platform imposes its own network-interface limits. A design that needs separate interfaces for management, internet, internal zones, DMZs, transit networks, clusters and service networks should therefore be validated against the chosen instance type before the license is purchased.

Licensing and consumption choices

FortiGate-VM is not sold through one universal licensing method. Fortinet documentation currently describes perpetual licensing for supported normal and V-series VM models, annual subscription licensing for S-series entitlements and FortiFlex for qualified use cases. Public cloud marketplaces can also provide on-demand deployments, while BYOL allows a separately acquired entitlement to be attached to a supported cloud image.

The practical choice depends on procurement preference, duration, expected utilisation, service bundle and the cloud commercial model. A long-running production firewall may be evaluated differently from a temporary project, disaster-recovery instance or variable MSP workload. FourTeck can help map the commercial approach to the expected lifecycle rather than selecting a license only from the headline purchase price.

Security bundles are not interchangeable

FortiGuard services are delivered through different bundles and individual services. The current FortiGate VM data sheet shows Enterprise, UTP and ATP bundle groupings, and states that FortiGate VM obtained through cloud marketplaces comes with the UTP bundle. Microsoft Marketplace separately notes that its PAYG offer includes the UTM bundle and that higher bundles require BYOL in that offer.

This is why a quotation request should state the required inspection services instead of only saying “FortiGate VM license.” IPS, malware protection, web and DNS controls, data security functions and other services may depend on the chosen bundle and current Fortinet packaging. Bundle names and inclusions can evolve, so the current ordering guide should be checked at quotation time.

A practical purchase and deployment journey

01

Define traffic paths

Document what must pass through the firewall: internet ingress and egress, inter-VNet or inter-VPC traffic, application tiers, branches, remote access, shared services and management paths.

02

Size the workload

Estimate normal and peak inspected throughput, sessions, encryption load, policy count, interfaces, growth and availability. Choose the VM class from these inputs, not from employee count alone.

03

Choose entitlement

Select BYOL, subscription, supported marketplace consumption or FortiFlex as appropriate, then match the security bundle and support term to the operational requirement.

04

Validate platform

Confirm the cloud region or hypervisor release, instance type, NIC limits, acceleration options, storage, routing and supported FortiOS image before implementation.

05

Deploy and test

Build routing, policies, security profiles, logging and HA as required, then test failover, application paths, inspected throughput and operational monitoring before production cutover.

Capability focus: performance depends on the whole virtual stack

A virtual firewall cannot process more traffic than the underlying compute and networking path can deliver to it. Published FortiGate-VM firewall-throughput figures are useful for comparing VM classes, but a real cloud or virtualised deployment adds several constraints. The host CPU generation, vCPU scheduling, network-interface bandwidth, packet-per-second limits, virtual switching, storage latency, security inspection profile and encryption workload all influence observed performance. Public clouds can also enforce bandwidth ceilings at the instance level even when the FortiGate license itself permits more resources.

For this reason, sizing should use the most demanding traffic profile that matters to the business. If most sessions will be encrypted and require deep inspection, use an inspected-throughput target rather than raw firewall throughput. If the firewall will concentrate many site-to-site tunnels, include the expected encrypted traffic and tunnel scale. If it will run as a central transit firewall, include east-west flows that may not appear in internet bandwidth figures. FourTeck can help turn these inputs into a shortlist that can then be validated in the target platform.

Capability focus: consistent policy without assuming identical infrastructure

One attraction of FortiGate-VM is that the FortiOS operating model extends across virtual and physical FortiGate deployments. Teams can work with familiar objects, policies, security profiles, routing concepts and operational tooling while placing enforcement in different environments. This can reduce unnecessary variation in security operations, especially for organisations that already use FortiGate appliances at branches or data centres and want related controls in cloud networks.

Consistency does not mean every design should be identical. A public cloud may use route tables, load balancers, cloud-native logging and autoscaling constructs that do not exist in an on-premises ESXi environment. A KVM deployment may use different acceleration and interface considerations from Azure or AWS. The strongest architecture keeps the security policy objectives consistent while respecting the native routing, resilience and automation patterns of each platform. Centralised management through FortiManager and logging or analytics through FortiAnalyzer can be considered where the operating model and licensing support them.

Capability focus: licensing flexibility needs governance

FortiGate-VM offers more consumption flexibility than a fixed hardware purchase, but that flexibility needs governance. BYOL can give procurement direct control over an entitlement and service bundle. Marketplace PAYG can be convenient when cloud consumption is charged to a project account and the instance may not run continuously. Annual subscription licensing can suit predictable operating periods. FortiFlex can support qualified organisations that need a points-based method for creating and changing entitlements across supported solutions.

The operational team should know which model was chosen and who owns renewal, entitlement assignment and cost tracking. Cloud compute, storage and network charges are normally separate from the FortiGate license charge. Microsoft Marketplace, for example, publishes FortiGate PAYG software rates by vCPU and explicitly states that cloud infrastructure charges are additional. Before deployment, confirm whether the intended service bundle is supported by the chosen procurement route, how the license is activated, whether the design needs extra VDOM entitlements, and how support will be maintained for the required term.

Where FortiGate Virtual Firewall can fit

Cloud application perimeter

Control selected traffic entering and leaving application networks, with routing and inspection designed around the cloud architecture rather than a physical campus edge.

Secure transit hub

Place FortiGate-VM in a hub or transit design that connects multiple networks, accounts, subscriptions or sites, subject to the native cloud routing and scaling model.

Virtual data-centre segmentation

Separate production, development, shared services, DMZ and sensitive zones on supported hypervisors while keeping policy close to virtual workloads.

Hybrid WAN and VPN

Connect cloud environments to branches, data centres or partner networks using supported routing and VPN functions, with resilience designed around the business requirement.

Disaster recovery

Use a virtual firewall in a secondary environment so recovery traffic can be controlled under a defined policy. Licensing, dormant capacity and failover procedures should be planned before an incident.

Hosted security service

Service providers and larger IT teams may use virtual firewall instances as part of a shared or repeatable service design, with tenant separation, entitlement and automation requirements confirmed first.

Integration and operational considerations

Successful FortiGate-VM deployment depends on the surrounding network architecture. In public cloud, the firewall may need explicit route-table changes, load-balancing constructs, gateway integration or transit services so traffic traverses the inspection path. In a private cloud, virtual switches, port groups, VLANs, overlay networking and hypervisor NIC mappings determine the same outcome. In both cases, management access should be separated and controlled appropriately, and the operational team should know how to recover access if a policy or route change creates an outage.

Logging also needs a deliberate destination. Local storage may be useful for limited troubleshooting, but larger environments normally need central retention and analysis. FortiAnalyzer can be part of that design, while cloud-native logging may also be used for infrastructure events and security operations. Time synchronisation, DNS, certificate management, backup strategy and administrator authentication are basic dependencies that are easy to overlook during a fast deployment.

Automation can improve repeatability but should be introduced with the same control as network changes. Cloud-init, templates, infrastructure-as-code and Fortinet tooling can help provision or configure instances, depending on platform and release. FortiFlex documentation also supports token injection methods for eligible entitlements. The exact approach should be tested in a non-production path before it becomes part of automated scaling or disaster recovery.

Questions to resolve before the quotation

What is the expected peak throughput after the required security inspection is enabled?
Which public cloud, hypervisor and exact version will host the VM?
How many network interfaces and security zones are required by the design?
Is the preferred commercial model BYOL, subscription, marketplace usage or FortiFlex?
Which FortiGuard services must be active from day one?
Will high availability be active-active, active-passive or based on a cloud-native architecture?
Is central management or central log analytics already available?
Does the project require migration from another firewall and translation of existing policies?

Procurement checklist for FortiGate-VM

✓ Exact FortiGate-VM entitlement class or shortlist
✓ Required number of production, test and DR instances
✓ Target cloud region or hypervisor version
✓ Peak inspected bandwidth and encrypted traffic
✓ vCPU, memory, storage and cloud instance type
✓ Security bundle and subscription term
✓ Number of interfaces, zones and routing domains
✓ VDOM requirement and any separate entitlement
✓ High-availability and failover design
✓ FortiManager, FortiAnalyzer or other management scope
✓ Installation, configuration and migration scope
✓ Support term, renewal ownership and documentation needs

How FourTeck can assist with selection and deployment planning

FourTeck can help turn a broad request for a “FortiGate virtual firewall” into a purchase-ready requirement. The process can cover workload sizing, virtual platform review, license-model comparison, FortiGuard bundle selection, network-interface requirements, high-availability scope and management dependencies. If a customer is moving from an existing firewall, the discussion can also include policy migration, routing conversion, VPN requirements, testing and cutover responsibilities.

For buyers who are still comparing physical and virtual options, FourTeck can help identify which traffic should remain on a hardware perimeter and which controls are better placed inside cloud or virtual networks. Explore FourTeck firewall products, review available security and deployment services, or see the broader Fortinet firewall guidance for Dubai before requesting the final bill of materials.

UAE availability guidance

Contact FourTeck to confirm current UAE availability for the required FortiGate-VM entitlement, FortiGuard bundle and support term. Virtual products can remove physical appliance logistics, but availability can still depend on license region, SKU, quantity, contract term, vendor processing and the cloud platform selected.

Delivery and project coordination can be discussed after the exact requirement is confirmed. Where implementation support is needed, include architecture review, deployment, configuration, migration and testing scope in the quotation instead of assuming those services are part of the software entitlement.

Dubai, Abu Dhabi, Sharjah and Ajman project coordination

Businesses planning FortiGate Virtual Firewall projects across Dubai, Abu Dhabi, Sharjah and Ajman can use one requirement review to define the virtual firewall entitlement, cloud or data-centre platform, security bundle, support term and implementation responsibilities. The same organisation may have different technical needs across sites: for example, a Dubai head office may connect to an Azure environment, a data-centre workload may run on VMware, and branch users may reach shared cloud applications through VPN or SD-WAN. FourTeck can help coordinate the security architecture and quotation around those actual traffic paths. Service scope, site activity, remote work, platform access and implementation timing should be agreed in advance. Contact the FourTeck firewall team with the deployment details for current options.

GCC Availability

For GCC projects, FortiGate-VM can be evaluated for organisations that need a consistent virtual firewall design across more than one cloud region, subsidiary or hosted environment. FourTeck can assist with requirement review, VM-size selection, licensing and subscription planning, quotation coordination, configuration scope, migration planning and renewal guidance for projects involving the United Arab Emirates and other GCC markets such as Saudi Arabia, Kuwait, Qatar, Bahrain and Oman. The exact commercial and technical path should be confirmed for each destination because product entitlement, marketplace availability, vendor lead time, cloud region support, implementation scope and service scheduling can vary. Buyers should share the destination country, required FortiGate-VM class, quantity of instances, security bundle, expected term, target cloud or hypervisor and preferred deployment schedule. For regional requirements, FourTeck can coordinate the discussion through its main team and relevant regional resources, including FourTeck Kuwait information where appropriate.

Africa Availability

African organisations can also evaluate FortiGate Virtual Firewall for cloud security, hosted workloads, data-centre virtualisation, hybrid connectivity and regional service platforms. FourTeck can help review the exact requirement, including the selected VM class, licensing method, FortiGuard services, support term, cloud or hypervisor target, deployment resources, configuration needs and renewal planning. Availability and fulfilment can depend on the destination country, license region, vendor processing, quantity, cloud-region support, project conditions and any local power or regulatory considerations associated with the broader infrastructure. Buyers should provide the destination, instance quantity, preferred entitlement model, expected traffic, rollout schedule and any installation or support expectations before a quotation is finalised. For East African and wider continental enquiries, see FourTeck Africa and related regional resources such as Kenya and Uganda where they are relevant to the project.

Related options and services to consider

Physical FortiGate appliances

Useful where the security edge needs physical interfaces, appliance-based performance or branch and campus deployment.

Review FortiGate options

Firewall migration services

Plan policy conversion, object clean-up, VPN recreation, routing changes, testing and cutover from an existing firewall platform.

View service support

Central management and analytics

FortiManager and FortiAnalyzer may be suitable when multiple FortiGate instances require consistent administration and central log analysis.

Browse related products

Architecture consultation

Useful when the main question is traffic design, HA, cloud routing, segmentation or the balance between native cloud controls and FortiGate policy.

Discuss the architecture

What buyers commonly need to know before choosing a virtual FortiGate

A buyer researching FortiGate-VM usually starts with a simple question: is the virtual product functionally comparable to a physical FortiGate? The useful answer is that FortiGate-VM runs FortiOS and provides the security and networking services associated with the FortiGate platform, but the deployment characteristics are different. A hardware appliance brings fixed interfaces and purpose-built hardware resources. A virtual firewall receives CPU, memory, storage and network interfaces from the hypervisor or cloud platform. That difference affects sizing, resilience, network design and cost ownership. The security policy may look familiar, but the infrastructure underneath it must be engineered for the required packet flow.

How do you choose between VM01, VM02, VM04 and larger classes?

Start with inspected traffic, not the model number. Work out the highest realistic traffic rate that must pass through the firewall and identify which security services will inspect it. Add encryption, session volume, policy scale and expected growth. Then check which vCPU class can meet the requirement and whether the chosen cloud instance or hypervisor can actually provide enough packet-processing capacity. A 4-vCPU entitlement on an undersized cloud instance does not create 4-vCPU-class performance by itself. The VM class, compute shape and network limits need to be aligned.

Should a cloud project use PAYG or BYOL?

PAYG can suit variable or project-based use because the software charge follows cloud consumption and procurement stays inside the cloud marketplace. BYOL can be more suitable when the organisation wants a separately purchased entitlement, a specific security bundle or a predictable contract structure. The best choice depends on duration, utilisation, support, accounting preference and the bundle required. Microsoft Marketplace currently publishes PAYG software prices by vCPU and notes that its infrastructure charges remain separate, which is a useful reminder to compare total operating cost rather than only firewall license cost.

Another common question is whether FortiGate-VM can run on VMware, Hyper-V, KVM and major public clouds. Current Fortinet documentation covers these environments and also lists platforms such as Nutanix AHV, but support is tied to specific FortiOS builds and platform versions. A procurement team should therefore ask for the exact deployment combination in writing: for example, FortiGate-VM04-S on a specific FortiOS branch for VMware ESXi 8, or a defined BYOL image in a chosen Azure region. This small amount of precision prevents a broad compatibility statement from being mistaken for support of every possible version.

Why cloud-interface limits matter more than buyers expect

Cloud architectures often separate management, trust, untrust, DMZ, transit, partner, inspection and service networks. FortiGate can support many interfaces, but a cloud instance type may permit far fewer. Before selecting the firewall, draw the logical interfaces and map them to the platform. If the design depends on eight NICs but the chosen instance supports four, the problem is architectural, not a FortiGate configuration issue. The solution may involve a different instance class, revised routing design or greater use of subinterfaces and segmentation where supported.

Buyers also ask whether FortiGate-VM is appropriate for SSL inspection and high-threat environments. It can perform advanced inspection when the required FortiOS features and FortiGuard services are licensed, but the workload must be sized for that inspection. Encrypted traffic can consume substantially more processing than simple stateful firewalling, and certificate deployment or exception policy can become an operational project of its own. A responsible design treats “firewall throughput” as one reference point and sizes around the security profile that will actually be enabled.

High availability creates another decision point. FortiGate-VM can be deployed in resilient architectures, yet the recommended pattern is platform-specific. Traditional HA concepts may be used in some virtualised environments, while public clouds can introduce load balancers, route updates, availability zones and cloud-specific failover mechanisms. Buyers should state the recovery objective, tolerated session impact and availability-zone requirement before selecting an HA template. The firewall license count and cloud compute count also need to reflect the number of active or standby instances.

Finally, a useful quotation request should describe more than a license. Include the platform, region, number of instances, traffic estimate, chosen or preferred vCPU class, security bundle, support duration, management tools, migration requirement and implementation responsibilities. That information allows FourTeck to distinguish a simple entitlement request from a complete cloud firewall project and to prepare a more relevant bill of materials without inventing assumptions about performance or scope.

Decision questions that prevent the wrong virtual firewall purchase

Do I size FortiGate-VM by users or by traffic?

Traffic and inspection workload are more useful than user count. Two companies with 500 users can generate very different traffic if one mostly uses SaaS and the other transfers large engineering data, hosts public applications or inspects heavy east-west traffic. Add session count, encrypted inspection, VPN volume, application mix and growth to the sizing discussion. User count may provide context, but it should not be the primary sizing metric.

Can I increase vCPU later without changing licensing?

That depends on the entitlement model. S-series licenses are based on defined vCPU classes, while other license and FortiFlex models follow their own rules. A cloud platform may also allow the underlying instance to be resized separately. Treat scaling as both a technical and licensing change: check the entitlement, the supported VM resources, the cloud or hypervisor capacity and the maintenance impact before increasing the VM size.

Does the marketplace price include the cloud server?

Not necessarily. Microsoft Marketplace explicitly states that FortiGate PAYG software pricing is additional to Azure compute, storage and network charges. AWS and other marketplaces also separate software consumption from underlying cloud infrastructure according to their commercial models. For a realistic budget, include the VM instance, disks, public addresses, load balancing, data transfer, logging and any other cloud services used by the design.

Will every FortiGuard feature be available on every license?

No. Security services depend on the bundle and current Fortinet packaging, and some marketplace offers have their own bundle rules. Build the requirement from the protections you need and then map that requirement to the available bundle. If a capability is important for compliance or a customer contract, confirm it explicitly in the ordering documentation rather than assuming the bundle name includes it.

What should I provide for an HA quotation?

State the number of availability zones or hosts, desired recovery behaviour, whether both nodes must process traffic, expected state synchronisation, routing method and the platform-native services involved. The answer determines how many firewall entitlements and cloud instances are required and what configuration work must be included. A single “HA required” line is not enough to define the bill of materials.

When should I choose a physical FortiGate instead?

A physical appliance can be preferable when the firewall must terminate physical WAN links directly, provide appliance-based ports at a branch or campus, operate independently of a virtualisation layer, or deliver a hardware form factor that better matches the site. Many organisations use both: physical FortiGate appliances at physical edges and FortiGate-VM where workloads are virtual or cloud-hosted. FourTeck can compare the two approaches around the actual network boundary.

Why businesses contact FourTeck for FortiGate-VM planning

Virtual firewall projects often fail at the edges of responsibility: the security team selects a license, the cloud team selects an instance, procurement expects the marketplace price to include everything, and the application team assumes traffic will automatically traverse the firewall. FourTeck can help bring those decisions into one requirement review. The objective is practical clarity around the VM size, entitlement, service bundle, support term, cloud or hypervisor resources, network interfaces, routing, high availability, migration and management.

This assistance does not replace the customer’s cloud governance or application ownership. It helps define what must be confirmed so a quotation and deployment plan are based on the same assumptions. For broader company information, visit about FourTeck Firewall Dubai, or go directly to the contact page with the target platform and expected workload.

Frequently asked questions

Is FortiGate Virtual Firewall the same as FortiGate-VM?

FortiGate-VM is Fortinet’s virtual appliance family for deploying FortiGate security and networking functions in supported virtualised and cloud environments. “FortiGate Virtual Firewall” is a common descriptive way buyers refer to that family.

Which FortiGate-VM size should I buy?

Choose the VM class from expected inspected throughput, sessions, encryption, interfaces, policy scale, growth and the target platform. Current Fortinet classes range from 1-vCPU through 32-vCPU and unlimited-vCPU entitlement options, but final sizing should be validated for the workload.

Can FortiGate-VM run on VMware, Hyper-V and KVM?

Fortinet currently documents support for VMware ESXi, Microsoft Hyper-V, KVM and additional private-cloud platforms. Exact compatibility depends on FortiOS build and platform version, so confirm the intended combination before deployment.

Can I deploy it in AWS, Azure or Google Cloud?

Fortinet lists AWS, Microsoft Azure, Google Cloud and other major public-cloud platforms for FortiGate-VM. Deployment methods, supported images, routing and marketplace options vary by cloud and region.

What is the difference between BYOL and PAYG?

BYOL uses a separately obtained FortiGate-VM entitlement on a supported image. PAYG obtains the software license through the cloud marketplace and charges according to that marketplace model. Bundle availability and infrastructure charges should be compared before choosing.

Are FortiGuard security services included?

They depend on the bundle and procurement route. Fortinet offers multiple security-service bundles, and marketplace offers can have specific inclusions. Confirm the required IPS, malware, web, DNS and other services against the current orderable SKU.

Does FortiGate-VM support high availability?

FortiGate-VM can be used in resilient designs, but the correct HA architecture depends on the hypervisor or cloud platform, routing method, availability-zone design and business recovery objective. License quantity and instance count must be sized accordingly.

Can FourTeck help migrate from another firewall?

Migration assistance can be included when required. The scope may cover rule and object review, routing, VPNs, security profiles, testing and cutover planning. The effort depends on the existing configuration and target architecture.

How do I request a UAE quotation?

Send FourTeck the target cloud or hypervisor, preferred VM size if known, number of instances, expected traffic, required security bundle, support term, HA requirement, management tools and implementation scope. FourTeck can then confirm current UAE options and prepare the quotation.

Build the FortiGate-VM quote around your real workload

Share the target cloud or hypervisor, traffic requirement, desired security services, number of instances and availability design. FourTeck can help shortlist the VM class, license path and implementation scope before you commit to a deployment.

Scroll to Top
Powered by Joinchat