Managed FortiGate. 24x7. Fortinet experts on your side.
Full lifecycle management for your FortiGate firewall and SD-WAN environment — deployment, configuration, vulnerability patching, and change management handled by Fortinet's certified global NOC.
Per-device pricing by FortiGate model. 12-month minimum. FortiAP, FortiSwitch, and FortiExtender included under the parent FortiGate subscription.
While your FortiGate operates alone
Are PSIRT vulnerabilities on your FortiGate patched automatically, or are CVEs queuing up unaddressed?
Are FortiOS firmware upgrades managed by Fortinet-certified engineers following upgrade best practices?
Are FortiGate policy changes, SD-WAN rules, and VPN tunnels managed through a documented change process?
If your FortiGate management tunnel drops, is someone notified within 10 minutes around the clock?
Device Coverage
Your entire FortiGate stack. One subscription per device.
Each FortiGate requires its own service entitlement. LAN Edge devices connected to a managed FortiGate may be covered under the same subscription — contact us to confirm pricing for your device mix.
FortiGate Firewalls
Next-gen firewall and SD-WAN appliance — the core managed device
Common use case
All FortiGate hardware and virtual models. Each device requires its own subscription entitlement.
FortiAP Access Points
Wireless access points managed through the parent FortiGate
Common use case
Campus, office, and branch wireless deployments managed via FortiGate controller.
FortiSwitch
Campus and branch LAN switching managed through the parent FortiGate
Common use case
Access and distribution switching — fully managed under the parent FortiGate subscription.
FortiExtender
LTE/5G failover and WAN extension for remote or temporary sites
Common use case
Backup connectivity, primary WAN for remote sites, and mobile or temporary deployments.
HA clusters require a separate entitlement per cluster member — a 2-node HA pair requires 2 subscriptions.
What We Do
Three phases. Fully managed.
Every managed FortiGate environment moves through Fortinet's proven framework. Select a phase to see exactly what's covered.
Deploy
Fully managed by Fortinet NOC
Your FortiGate and LAN Edge devices are deployed quickly according to Fortinet security best practices and aligned with your business requirements. No guesswork, no shortcuts.
Business outcome: Devices configured to best practices from day one. Your team skips the learning curve — Fortinet's experts handle it.
FortiGate firewall policies, SD-WAN zones and steering rules, VPN tunnels, and LAN Edge devices
System hardening, intrusion prevention, application control, DNS/web/email filtering per Fortinet best practices
Site-to-site VPN, remote access VPN, ZTNA access proxies, and SD-WAN overlay networks
Configuration reviewed against Fortinet security guidelines before handoff to operations
Responsibility Model
No ambiguity. Every activity accounted for.
The allocation below reflects standard responsibilities — the final RACI is confirmed and signed during onboarding.
Fortinet NOC
Owns and executes
Customer
Approves or coordinates
Deploy & Configure
Initial setup, hardening, and connectivity before handoff to operations.
FortiGate initial deployment & best practice config
Firewall policies, SD-WAN, security profiles
SD-WAN zones, steering rules, and tunnel setup
Static/dynamic routing, DIA, multi-datacenter
LAN Edge deployment (FortiAP, FortiSwitch, FortiExtender)
Included under parent FortiGate
VPN setup (site-to-site, remote access, ZTNA)
IPSec, SSL-VPN, ZTNA access proxies
Physical installation and cabling
Device racking, power, and physical connectivity
Internet connectivity and basic network access
WAN link up and reachable before NOC onboards
Operate & Change Management
Ongoing rule management, monitoring, and ITIL-aligned change process.
Change request evaluation & implementation
ITIL-aligned — every change evaluated and documented
Configuration backup & revision control
FortiManager Cloud — rollback to any previous version
Device monitoring & proactive alerting
Real-time via service portal, 24x7x365
Change request approval
You approve before any change is implemented
Service portal access & ticket submission
Submit requests and track status
Optimize & Security
Continuous patching, firmware management, and posture improvement.
Vulnerability management & auto-patching
Medium+ PSIRT vulnerabilities patched automatically
Firmware upgrade planning & execution
Risk-reducing best practices by Fortinet experts
Security posture assessments
Against Fortinet guidelines — gaps surfaced proactively
FortiManager Cloud maintenance & patching
Platform kept current by Fortinet
Technical support / break-fix (Fortinet TAC)
You contact TAC directly for break/fix issues
RMA coordination & onsite activities
Hardware replacement and physical work
SLA Commitments
Response targets by priority.
Two metrics define each SLA: how quickly the NOC evaluates your request, and how quickly they begin implementation after you approve. Final SLA terms are defined in your service agreement.
High — Critical
Business-critical changes that must be implemented ASAP to avoid significant disruption or risk
Evaluation
NOC reviews request
1 hour
Implementation
After your approval
2 hours
Coverage
24x7x365
Medium — High
Moderately urgent changes that do not require immediate action
Evaluation
NOC reviews request
4 hours
Implementation
After your approval
1 business day
Coverage
24x7x365
Low — Medium
Non-time-sensitive changes that can be scheduled
Evaluation
NOC reviews request
1 business day
Implementation
After your approval
2 business days
Coverage
Business hours
Transparent Pricing
Per device. Per year. No surprises.
Pricing is based on your FortiGate model and subscription length. Longer terms mean lower costs. Contact us for a quote tailored to your device count and term preference.
Subscription Structure
Managed FortiGate Service
Pricing model
Per FortiGate device — annual subscription
Subscription terms
1, 3, or 5 years — longer terms offer better pricing
Setup fee
One-time, first year only — covers onboarding and initial configuration
LAN Edge devices
FortiAP, FortiSwitch, FortiExtender — contact us to confirm coverage and pricing
HA clusters
Each cluster member requires a separate entitlement
Minimum term
12 months
How to Get Pricing
Pricing varies by FortiGate model and subscription length. Book a 30-minute briefing — we'll review your FortiGate environment, confirm device models, and provide a custom quote typically within 48 hours.
Compliance & Certifications
SOC 2 Type II
Annual third-party audit of security controls and processes
ISO 27001
Information security management certification
Fortinet data handling
Follows Fortinet's published privacy practices
Getting Started
From contract to live operations in under a week.
Fortinet targets onboarding within 3 business days. Here's exactly what happens at each step.
Day 1
Purchase & Registration
You purchase the Managed FortiGate Service subscription through Zent. We register the contract code in your FortiCloud account and associate it to your FortiGate device(s).
What we need from you
FortiGate model(s) and serial numbers
FortiCloud account access
Basic network connectivity on each device
Days 1–3
Onboarding & Configuration
Fortinet's NOC team receives your onboarding request via the MFGS portal. They configure your FortiGate(s) to best practices — firewall policies, SD-WAN rules, security profiles, and LAN Edge devices.
What we need from you
Business requirements and network topology
Approval of proposed configuration
Day 3+
Go-Live & Operations
Your FortiGate is now under 24x7 managed operations. You receive portal access for submitting change requests, viewing device status, and tracking service history.
What you get
MFGS service portal access
Real-time device monitoring dashboard
FortiManager Cloud read-only access
Service Catalog
40+ use cases. All handled by Fortinet's NOC.
The Managed FortiGate Service covers a comprehensive catalog across six domains. Highlights below — the full catalog is available during your briefing.
NGFW
22 use cases
Firewall policies, system hardening, HA clusters, IPS, web/DNS/email filtering, traffic shaping, VDOMs, VIPs, load balancing, SNMP
Secure SD-WAN
5 use cases
Static & dynamic application steering, direct internet access, single and multi-datacenter SD-WAN topologies
Remote Access
5 use cases
Site-to-site IPSec VPN, remote access VPN with FortiClient, SSL-VPN, SSL-to-IPSec migration
LAN Edge
4 use cases
FortiAP deployment, FortiSwitch deployment, FortiExtender WAN extension, guest WiFi captive portal
Security Fabric
2 use cases
Automation stitches, automated endpoint quarantine with FortiClient EMS
ZTNA
2 use cases
HTTPS access proxy, TCP forwarding access proxy
Common Questions
Before you ask — we've answered it.
Ready to hand off your FortiGate operations?
Book a 30-minute briefing. We'll review your FortiGate environment, confirm device models, and provide a custom quote within 48 hours.
Pricing varies by FortiGate model and term. Delivered by Fortinet's certified global NOC.