Firewall Review: most firewalls keep passing traffic. That is not the same as still doing their job.
A FortiGate is deployed. Rules are configured. VPN is established. Firmware is current at the time. The environment works. Then time passes, and the firewall drifts quietly, rule by rule, exception by exception, firmware cycle by firmware cycle, until something external forces the question.
Inlight IT reviews FortiGate environments before the next policy change, hardware refresh or insurance review brings the firewall into question. Fortinet-experienced engineers examine where the firewall is exposed today, what needs to change first, and whether the existing appliance can be hardened before any replacement is considered.
The situations that make a firewall review overdue
Firewalls do not fail loudly. They drift quietly, rule by rule, exception by exception, firmware cycle by firmware cycle, until something external forces the question. A cyber insurer asks for evidence the environment cannot produce. Essential Eight surfaces a control gap. A renewal quote arrives before anyone knows what should be replaced. An incident reveals an open path no one was watching.
The need for review usually shows up before the firewall fails outright. The situations below are where organisations most often start this conversation.
Nothing announces a problem. The firewall is still passing traffic. The exposure surfaces when a cyber insurance questionnaire, an Essential Eight assessment or an incident asks questions the environment cannot answer.
When a Firewall Review is the right next step
Deployment installs hardware. Management is everything that comes after: continuous rule hygiene, SSL inspection tuning, IPS profile tuning, firmware cadence, FortiGuard service planning, VPN access review, log triage and change governance. Most firewalls have been deployed. Far fewer are being managed. The review establishes the gap between the two states for the specific environment, and where the existing FortiGate can be hardened, it shows what needs to change first.
The hardware is usually right, the management is what has gone missing
Much of the risk in firewall environments is not a missing feature; it is an operating model gap. Deployment installs hardware; management is everything that comes after. The platform is capable of running better. The discipline around it has not been built.
Firewall management, evidenced
Inside the Firewall Review
Seven operating surfaces where exposure usually concentrates, in one view. The output is a prioritised list of what needs to change first, not a generic firewall report, and no hardware recommendation is made before the environment is understood.
The first place drift accumulates, and the last place it gets cleaned up. Firewall rules, NAT entries, source and destination scope, service scope, naming conventions and stale rule identification. Inbound exposure review, port forwarding validation, public service ownership and unnecessary external access. The aim is not cosmetic cleanup; it is to identify open paths nobody is watching.
The encrypted traffic blind spot is now most of the traffic. What is being inspected, what is not, what is excluded and why. Certificate handling, application compatibility, staged rollout planning and privacy considerations. Leaving encrypted traffic entirely uninspected is a major visibility gap; broad inspection without planning disrupts users. The right model is staged and risk-based.
Known vulnerabilities on the device that controls the edge. Current firmware position, PSIRT awareness, known CVE exposure at the version in use, version selection logic, staged deployment approach and rollback planning. Firmware should be governed against a cadence, not patched only when something forces it.
Most VPN environments grant more access than the business intends. User VPN, site-to-site VPN, contractor and vendor access, MFA alignment, split-tunnel posture and legacy remote access methods. Accounts for users who have left, vendor access scoped broadly because it was easier. ZTNA fit assessed where the VPN model no longer matches how the business operates.
Alert noise is how genuine threats get missed. IPS profile selection and tuning, application control posture, web filtering categories, false positive handling and FortiGuard subscription status. Default profiles generate noise that teams stop reading. Tuning is what turns alerts into signal.
The most privileged path is usually the least reviewed. Administrator access, MFA on management interfaces, role-based access, FortiManager and FortiAnalyzer coordination where applicable, log forwarding, retention and escalation ownership. Security Fabric value depends on whether it is being operated, not whether it is enabled.
The firewall configuration is operating documentation, not a static artefact. Configuration backup, restore validation, known-good state documentation, change request review, technical validation, rollback planning, implementation record and post-change checks. The work that makes the next review easier and the next change safer.
Review before replacement, not the other way around
Most firewall environments do not need to be replaced. They need to be reviewed, cleaned up and properly operated. Some genuinely do need replacement, but that decision should follow the review, not precede it.
- The appliance is supported and sized correctly
- SSL inspection load fits within capacity
- FortiOS support continues at the current hardware generation
- The configuration is fragmented but recoverable
- The operating model can be built without a hardware change
- Some environments sit between the two paths
- Harden the existing appliance now
- Sequence replacement against renewal or lifecycle
- Size any new appliance for real SSL inspection load
- Decide with evidence, not a default assumption
- The appliance is end-of-life or approaching end-of-support
- SSL inspection or IPS load exceeds appliance capacity
- Firmware support is constrained by hardware generation
- Licensing or FortiGuard services are impractical to maintain
- SD-WAN, ZTNA or Security Fabric needs exceed the platform
FortiGate is capable. It is not automatically the answer.
FortiGate is one of the most capable firewall platforms available at its price point, and Inlight IT works extensively with Fortinet. Firewall, VPN, SD-WAN, IPS, web filtering, application control, SSL inspection and a ZTNA foundation run in the same FortiOS. The review still starts from the environment, not the product.
The review identifies the right next step based on the environment, not a product assumption. That may be hardening the existing FortiGate. It may be upgrading the appliance. It may be redesigning VPN access. It may be moving some access patterns toward ZTNA. It may be improving the operating model without changing any hardware.
The review matters, what happens after it matters more
A Firewall Review is not a one-off audit document. It is the starting point of a more disciplined firewall operating model. The sequence below is how the engagement moves from review to ongoing management.
Review current exposure
Rules, NAT, VPN, administrator access, FortiOS firmware, FortiGuard services, SSL inspection, IPS, application control, web filtering, logging, backup and change control. The aim is to identify where the firewall is exposed today, before any hardware or policy change is committed to.
Map business dependencies
Users, sites, applications, VPNs, exposed services, integrations and operational dependencies mapped against the existing configuration. Firewall changes can break applications, VPNs, Microsoft 365 paths and site connectivity; mapping first means remediation does not become disruption.
Prioritise remediation
Externally exposed services, known CVEs, weak administrator access, stale VPN accounts, unsupported firmware, broad inbound rules and missing logging usually require earlier action than cosmetic cleanup. The output distinguishes urgent exposure from hygiene improvement.
Harden and tune
Stale rule removal, scope tightening, open service reduction, VPN access improvement, SSL inspection staged into production, IPS profile tuning, firmware updates, logging improvements, administrator access strengthening, FortiGuard alignment and backup validation.
Firewall management treated as an operating discipline, not a product configuration
Firewall risk is rarely a missing feature. It is usually an operating model gap. Inlight IT approaches firewall work as the discipline around the appliance, not the appliance itself. What that means in practice:
01Fortinet-experienced engineers
The review is performed by engineers who operate FortiGate environments daily. Rule hygiene, SSL inspection posture, FortiOS lifecycle, IPS tuning and FortiGuard planning are not concepts being applied for the first time on your environment.
02Review before replacement
The default starting position is that the existing appliance can probably be hardened. Replacement is sometimes right, but rarely first. The review establishes which path applies for the specific environment.
03An operating model, not a one-off audit
A Firewall Review is the starting point of an ongoing management discipline. Rule hygiene, firmware cadence, log ownership, change governance and VPN access review continue after the review is complete.
04Security and networking together
Firewall policy connects to SD-WAN, branch connectivity, Microsoft 365 paths, VPN, ZTNA and future SASE design. The firewall is reviewed as part of the network and security model, not as an isolated device.
05Continuous ownership after the work
A FortiGate reviewed once and then left to drift accumulates the same issues the review just resolved. The review only holds its value if the operating discipline continues after the work is done.
Recent firewall review and uplift work
Questions that come up before a Firewall Review
What happens in a Firewall Review scoping conversation?
A scoped review of the current FortiGate environment: rule base, NAT, VPN, administrator access, firmware posture, FortiGuard service status, SSL inspection, IPS, application control, web filtering, logging, backup configuration, Security Fabric coordination and change control. The output is a prioritised view of what needs to change first and whether the existing appliance can be hardened or needs replacement. It is not a sales presentation for new hardware.
What is the difference between a deployed FortiGate and a managed FortiGate?
A deployed FortiGate is configured once and left running. A managed FortiGate is continuously maintained: rules audited and tightened, firmware updated on a defined cadence, SSL inspection tuned, IPS profiles reviewed, VPN access controlled and policy adjusted as the network and threat landscape change. Misconfiguration drift is how most firewall environments accumulate exposure over time. Management is what closes that gap.
Does my firewall actually need SSL inspection?
Not every traffic flow should be decrypted, but some SSL inspection is usually required if the organisation wants meaningful visibility into encrypted web traffic. HTTPS is now the primary delivery channel for modern malware. Leaving encrypted traffic entirely uninspected creates a major visibility gap; turning on broad inspection without planning disrupts users and applications. The right model is staged, risk-based, with defined exclusions and proper certificate handling.
What happens if a FortiGuard subscription lapses?
The firewall continues to pass traffic, but the security services that depend on current threat intelligence start to degrade. IPS, antivirus, web filtering and DNS security stop receiving updates. Connectivity still works, security posture weakens over time. Renewal planning should happen before expiry, not after alerts start appearing.
Can Inlight IT manage a FortiGate deployed by another provider?
Yes. The environment can be reviewed and brought into a managed operating model regardless of who originally deployed it. The first step is understanding the current configuration, access model, firmware posture, licensing, logging, VPN setup, rule base and business dependencies. From there, what needs to be cleaned up, hardened, documented and managed going forward becomes clearer.
Does a Firewall Review require any disruption to live operations?
Generally no. The review itself is read-only, examining configuration, posture, logs and policy. Remediation work that follows the review is sequenced against business hours, application dependencies and rollback planning, and changes that affect traffic flow or inspection are tested and staged. The review does not require taking the firewall offline.
When is FortiGate the wrong platform?
Where the environment requires a cloud-native firewall architecture rather than an appliance-led model, where application access is better solved through ZTNA or SASE than traditional VPN, where internal segmentation requires broader network redesign before firewall replacement, or where the actual problem is operational ownership rather than the platform itself. The review identifies the right next step based on the environment, not a product assumption.
Does this work alongside our internal IT team?
Yes. The review and ongoing management can sit alongside an internal IT team or an existing MSP. Inlight IT provides Fortinet engineering depth, review discipline, firmware governance and ongoing operating ownership where the internal team does not have the scale or specialisation to maintain it. The internal team retains business context and day-to-day responsibility.