Your FortiGate deployed right. First time.
From greenfield deployment to legacy firewall migration or model upgrade — our certified engineers handle the entire installation. Security rules, VPN configuration, UTM profiles, cutover support, and handoff. Fixed scope. Fixed price.
100% remote delivery. One FortiGate or HA pair per engagement. Add-on services available for complex requirements.
Covers FortiGate 40F through 3500F series — greenfield, legacy migration, or model upgrade. Security policies, UTM profiles, IPsec and SSL-VPN, and HA pair configuration all included in fixed scope.
Before cutover
Have your existing policies been mapped to FortiGate security profiles before migration?
Is your FortiGate HA cluster configured and failover-tested before the cutover window?
Are your UTM profiles — IPS, antivirus, web filter, application control — configured for your traffic?
Are your IPsec and SSL-VPN tunnels documented and ready to migrate on cutover day?
Do you have active FortiGuard subscriptions for the security features you plan to enable?
Model Coverage
All FortiGate series. Three deployment scenarios.
Every model tier is covered. Every deployment scenario is supported. The scope of work scales with the complexity of the model.
Greenfield
New FortiGate deployment in a new environment — no existing firewall to migrate from.
Legacy Migration
Replace an existing non-Fortinet firewall. Rules and profiles migrated via FortiConverter.
FortiGate Upgrade
Upgrade from an existing FortiGate model to a new FortiGate — configuration carried forward.
Models 30–90
Entry-Level NGFW
Small offices, branch locations, remote sites
Security/NAT rules
Up to 20
Interfaces
Up to 5
UTM profiles
1 set
Cutover hours
2 hours
MSRP
$7,650
Models 100–900
Mid-Range NGFW
Growing businesses, distributed locations
Security/NAT rules
Up to 35
Interfaces
Up to 10
UTM profiles
2 sets
Cutover hours
4 hours
MSRP
$10,200
Models 1000–3000
Enterprise NGFW
Data centres, campus deployments, regional hubs
Security/NAT rules
Up to 50
Interfaces
Up to 20
UTM profiles
3 sets
Cutover hours
4 hours
MSRP
$13,387
Models 4000–7000
High-Performance NGFW
Large enterprises, carrier-grade, multi-site core
Security/NAT rules
Up to 75
Interfaces
Up to 24
UTM profiles
5 sets
Cutover hours
4 hours
MSRP
$17,212
Scope of Work
Exactly what's included — by model.
No surprises. Every deliverable is defined before engagement starts. What's not listed is out of scope — available as an add-on or custom SOW.
Security & NAT Rules
Migrate existing rules from legacy firewall or create new — Layer 3/4 security and NAT rules only.
Models 30–90
Up to 20 rules
Models 100–900
Up to 35 rules
Models 1000–3000
Up to 50 rules
Models 4000–7000
Up to 75 rules
UTM Security Profiles
Each profile set includes IPS, gateway antivirus, DNS filter, web filter, and application control policy.
Models 30–90
1 profile set
Models 100–900
2 profile sets
Models 1000–3000
3 profile sets
Models 4000–7000
5 profile sets
Interface & VPN Configuration
Physical and logical interface configuration plus 1 IPSec VPN tunnel. SSL VPN and additional tunnels available as add-ons.
Models 30–90
5 interfaces + 1 VPN
Models 100–900
10 interfaces + 1 VPN
Models 1000–3000
20 interfaces + 1 VPN
Models 4000–7000
24 interfaces + 1 VPN
Cutover & Next-Day Support
Night or weekend cutover hours included in a single session, plus next-day troubleshooting support.
Models 30–90
2 hrs cutover + 2 hrs next-day
Models 100–900
4 hrs cutover + 4 hrs next-day
Models 1000–3000
4 hrs cutover + 4 hrs next-day
Models 4000–7000
4 hrs cutover + 4 hrs next-day
Included on all model tiers
Greenfield deployment, legacy migration, or FortiGate upgrade
Single device or HA pair configuration
Log forwarding to up to 2 destinations
SNMP monitoring & alerting setup
Security Fabric connection to existing fabric
Configuration review sessions with your team
What's not included: Advanced routing (BGP, OSPF, SD-WAN, VRRP), user management, switch/AP configuration, third-party VPN configuration, and integrations not listed above. Available as add-on services or a custom SOW.
Responsibility Model
We deploy. You approve.
Responsibility is assigned before engagement starts — the final RACI is confirmed during the discovery call.
We deliver
We own it end-to-end
Shared
Both teams involved
You coordinate
We support or need access
Pre-Deployment
Planning, access, and sign-off before a single config is touched.
Discovery assessment & network review
We map your current environment
Network topology & requirements
You provide diagrams and constraints
Legacy firewall configuration review
We audit what's migrating
Infrastructure access provisioning
You grant dashboard and device access
Migration plan & cutover window
Agreed jointly before execution
Deployment
Configuration, rule migration, and security profile setup.
FortiGate hardware/virtual configuration
Full platform setup by our engineers
Security/NAT rule migration & creation
Layer 3/4 rules per model scope
UTM security profile setup
IPS, AV, DNS, web filter, app control
Security policy approval
You review and sign off on policies
Logging, monitoring & alerting
Up to 2 log destinations + SNMP
VPN configuration
1 IPSec tunnel included
Cutover & Handoff
Go-live execution, validation, and documentation transfer.
Cutover execution & validation testing
Night/weekend window, single session
Network access during cutover
You maintain site/device availability
Business-critical traffic confirmation
Jointly validate key flows are live
Next-day support & troubleshooting
2–4 hrs post-cutover coverage
Configuration documentation & handoff
Full runbook delivered to your team
Transparent Pricing
Fixed price. Per model tier. No surprises.
One price covers the full deployment scope for your FortiGate model. Pricing shown is MSRP — contact us for your actual rate.
Models 30–90
Entry-Level NGFW
$7,650
MSRP per deployment
Includes
Up to 20 security/NAT rules
1 UTM profile set
Up to 5 interfaces
2 hours cutover support
SKU: JL9624
Models 100–900
Mid-Range NGFW
$10,200
MSRP per deployment
Includes
Up to 35 security/NAT rules
2 UTM profile sets
Up to 10 interfaces
4 hours cutover support
SKU: JL9625
Models 1000–3000
Enterprise NGFW
$13,387
MSRP per deployment
Includes
Up to 50 security/NAT rules
3 UTM profile sets
Up to 20 interfaces
4 hours cutover support
SKU: JL9627
Models 4000–7000
High-Performance NGFW
$17,212
MSRP per deployment
Includes
Up to 75 security/NAT rules
5 UTM profile sets
Up to 24 interfaces
4 hours cutover support
SKU: JL9626
Pricing Notes
Pricing is per single deployment event — one FortiGate or one HA pair per SKU
Multiple devices in the same cutover require separate SKU purchases or a custom quote
Third-party firewall migration (FortiConverter license) is purchased separately
Advanced configurations (BGP, SD-WAN, VRRP) are available as custom add-ons
Pricing shown is MSRP — contact us for discounted rates
Add-On Services
Extend the scope. Same delivery standard.
Complex deployments often require scope beyond the base service. Each add-on is fixed-price and delivered as part of the same engagement.
IPSec VPN Add-On
JL9629Additional IPSec VPN tunnels beyond the included tunnel. Includes 1 hour of troubleshooting. Third-party device configuration not included.
$1,275 per tunnel
Security/NAT Rules Add-On
JL9628Migrate or create additional security/NAT rules — up to 250 rules per NGFW or HA pair — beyond what's included in the base deployment.
$3,825
Virtual FortiGate Deployment
JL9631Deploy FortiGate NGFW in a virtual environment (VMware, KVM, Hyper-V). Purchased in addition to the primary deployment SKU for the correct model.
$2,550
SSL VPN Portal
JL9630Create one SSL VPN web portal at your public IP address. Certificate and user operations are not included in this scope.
$5,100
Additional UTM Profile Set
JL9633Create one additional set of UTM profiles (IPS, antivirus, DNS filter, web filter, application control) beyond what's included in your model tier.
$2,550 per set
Configuration Assistance (CAS) — Annual
JL9632Annual 50-hour contract for minor configuration additions and modifications to existing FortiGate deployments. Can be applied across multiple sites.
$15,937 / year
Configuration Assistance (CAS) — 8 Hours
NN4358Single 8-hour block of configuration assistance for minor changes and modifications to existing FortiGate deployments.
$2,550 per block
Common Questions
Before you ask — we've answered it.
Ready to deploy your FortiGate?
A 30-minute assessment call reviews your environment, confirms the right model tier, and scopes any add-ons required. Quote typically within 24 hours.
Assessment call → Quote & timeline → Schedule deployment window → Execute & handoff.