Sign in
HomeManaged InfrastructureService CatalogManaged FortiGate SD-WAN
Available NowFortinet Managed Security Service · SOC 2 Type II · ISO 27001

Managed FortiGate. 24x7. Fortinet experts on your side.

Full lifecycle management for your FortiGate firewall and SD-WAN environment — deployment, configuration, vulnerability patching, and change management handled by Fortinet's certified global NOC.

Per-device pricing by FortiGate model. 12-month minimum. FortiAP, FortiSwitch, and FortiExtender included under the parent FortiGate subscription.

While your FortiGate operates alone

Are PSIRT vulnerabilities on your FortiGate patched automatically, or are CVEs queuing up unaddressed?

Are FortiOS firmware upgrades managed by Fortinet-certified engineers following upgrade best practices?

Are FortiGate policy changes, SD-WAN rules, and VPN tunnels managed through a documented change process?

If your FortiGate management tunnel drops, is someone notified within 10 minutes around the clock?

Device Coverage

Your entire FortiGate stack. One subscription per device.

Each FortiGate requires its own service entitlement. LAN Edge devices connected to a managed FortiGate may be covered under the same subscription — contact us to confirm pricing for your device mix.

FG

FortiGate Firewalls

Next-gen firewall and SD-WAN appliance — the core managed device

Core service

Common use case

All FortiGate hardware and virtual models. Each device requires its own subscription entitlement.

FAP

FortiAP Access Points

Wireless access points managed through the parent FortiGate

Included

Common use case

Campus, office, and branch wireless deployments managed via FortiGate controller.

FSW

FortiSwitch

Campus and branch LAN switching managed through the parent FortiGate

Included

Common use case

Access and distribution switching — fully managed under the parent FortiGate subscription.

FEX

FortiExtender

LTE/5G failover and WAN extension for remote or temporary sites

Included

Common use case

Backup connectivity, primary WAN for remote sites, and mobile or temporary deployments.

HA clusters require a separate entitlement per cluster member — a 2-node HA pair requires 2 subscriptions.

What We Do

Three phases. Fully managed.

Every managed FortiGate environment moves through Fortinet's proven framework. Select a phase to see exactly what's covered.

Deploy

Fully managed by Fortinet NOC

Your FortiGate and LAN Edge devices are deployed quickly according to Fortinet security best practices and aligned with your business requirements. No guesswork, no shortcuts.

Business outcome: Devices configured to best practices from day one. Your team skips the learning curve — Fortinet's experts handle it.

We configure

FortiGate firewall policies, SD-WAN zones and steering rules, VPN tunnels, and LAN Edge devices

We harden

System hardening, intrusion prevention, application control, DNS/web/email filtering per Fortinet best practices

We connect

Site-to-site VPN, remote access VPN, ZTNA access proxies, and SD-WAN overlay networks

We validate

Configuration reviewed against Fortinet security guidelines before handoff to operations

Responsibility Model

No ambiguity. Every activity accounted for.

The allocation below reflects standard responsibilities — the final RACI is confirmed and signed during onboarding.

Fortinet NOC

Owns and executes

Customer

Approves or coordinates

01

Deploy & Configure

Initial setup, hardening, and connectivity before handoff to operations.

FortiGate initial deployment & best practice config

Firewall policies, SD-WAN, security profiles

Fortinet NOC

SD-WAN zones, steering rules, and tunnel setup

Static/dynamic routing, DIA, multi-datacenter

Fortinet NOC

LAN Edge deployment (FortiAP, FortiSwitch, FortiExtender)

Included under parent FortiGate

Fortinet NOC

VPN setup (site-to-site, remote access, ZTNA)

IPSec, SSL-VPN, ZTNA access proxies

Fortinet NOC

Physical installation and cabling

Device racking, power, and physical connectivity

Customer

Internet connectivity and basic network access

WAN link up and reachable before NOC onboards

Customer
02

Operate & Change Management

Ongoing rule management, monitoring, and ITIL-aligned change process.

Change request evaluation & implementation

ITIL-aligned — every change evaluated and documented

Fortinet NOC

Configuration backup & revision control

FortiManager Cloud — rollback to any previous version

Fortinet NOC

Device monitoring & proactive alerting

Real-time via service portal, 24x7x365

Fortinet NOC

Change request approval

You approve before any change is implemented

Customer

Service portal access & ticket submission

Submit requests and track status

Customer
03

Optimize & Security

Continuous patching, firmware management, and posture improvement.

Vulnerability management & auto-patching

Medium+ PSIRT vulnerabilities patched automatically

Fortinet NOC

Firmware upgrade planning & execution

Risk-reducing best practices by Fortinet experts

Fortinet NOC

Security posture assessments

Against Fortinet guidelines — gaps surfaced proactively

Fortinet NOC

FortiManager Cloud maintenance & patching

Platform kept current by Fortinet

Fortinet NOC

Technical support / break-fix (Fortinet TAC)

You contact TAC directly for break/fix issues

Customer

RMA coordination & onsite activities

Hardware replacement and physical work

Customer

SLA Commitments

Response targets by priority.

Two metrics define each SLA: how quickly the NOC evaluates your request, and how quickly they begin implementation after you approve. Final SLA terms are defined in your service agreement.

High — Critical

Business-critical changes that must be implemented ASAP to avoid significant disruption or risk

Evaluation

NOC reviews request

1 hour

Implementation

After your approval

2 hours

Coverage

24x7x365

Medium — High

Moderately urgent changes that do not require immediate action

Evaluation

NOC reviews request

4 hours

Implementation

After your approval

1 business day

Coverage

24x7x365

Low — Medium

Non-time-sensitive changes that can be scheduled

Evaluation

NOC reviews request

1 business day

Implementation

After your approval

2 business days

Coverage

Business hours

Transparent Pricing

Per device. Per year. No surprises.

Pricing is based on your FortiGate model and subscription length. Longer terms mean lower costs. Contact us for a quote tailored to your device count and term preference.

Subscription Structure

Managed FortiGate Service

Pricing model

Per FortiGate device — annual subscription

Subscription terms

1, 3, or 5 years — longer terms offer better pricing

Setup fee

One-time, first year only — covers onboarding and initial configuration

LAN Edge devices

FortiAP, FortiSwitch, FortiExtender — contact us to confirm coverage and pricing

HA clusters

Each cluster member requires a separate entitlement

Minimum term

12 months

How to Get Pricing

Pricing varies by FortiGate model and subscription length. Book a 30-minute briefing — we'll review your FortiGate environment, confirm device models, and provide a custom quote typically within 48 hours.

Compliance & Certifications

SOC 2 Type II

Annual third-party audit of security controls and processes

ISO 27001

Information security management certification

Fortinet data handling

Follows Fortinet's published privacy practices

Getting Started

From contract to live operations in under a week.

Fortinet targets onboarding within 3 business days. Here's exactly what happens at each step.

01

Day 1

Purchase & Registration

You purchase the Managed FortiGate Service subscription through Zent. We register the contract code in your FortiCloud account and associate it to your FortiGate device(s).

What we need from you

  • FortiGate model(s) and serial numbers

  • FortiCloud account access

  • Basic network connectivity on each device

02

Days 1–3

Onboarding & Configuration

Fortinet's NOC team receives your onboarding request via the MFGS portal. They configure your FortiGate(s) to best practices — firewall policies, SD-WAN rules, security profiles, and LAN Edge devices.

What we need from you

  • Business requirements and network topology

  • Approval of proposed configuration

03

Day 3+

Go-Live & Operations

Your FortiGate is now under 24x7 managed operations. You receive portal access for submitting change requests, viewing device status, and tracking service history.

What you get

  • MFGS service portal access

  • Real-time device monitoring dashboard

  • FortiManager Cloud read-only access

Service Catalog

40+ use cases. All handled by Fortinet's NOC.

The Managed FortiGate Service covers a comprehensive catalog across six domains. Highlights below — the full catalog is available during your briefing.

NGFW

22 use cases

Firewall policies, system hardening, HA clusters, IPS, web/DNS/email filtering, traffic shaping, VDOMs, VIPs, load balancing, SNMP

Secure SD-WAN

5 use cases

Static & dynamic application steering, direct internet access, single and multi-datacenter SD-WAN topologies

Remote Access

5 use cases

Site-to-site IPSec VPN, remote access VPN with FortiClient, SSL-VPN, SSL-to-IPSec migration

LAN Edge

4 use cases

FortiAP deployment, FortiSwitch deployment, FortiExtender WAN extension, guest WiFi captive portal

Security Fabric

2 use cases

Automation stitches, automated endpoint quarantine with FortiClient EMS

ZTNA

2 use cases

HTTPS access proxy, TCP forwarding access proxy

Common Questions

Before you ask — we've answered it.

Ready to hand off your FortiGate operations?

Book a 30-minute briefing. We'll review your FortiGate environment, confirm device models, and provide a custom quote within 48 hours.

Pricing varies by FortiGate model and term. Delivered by Fortinet's certified global NOC.