Sign in
HomeProfessional ServicesService EngagementsFortiGate NGFW Deployment
Available NowFortinet FortiGate · Fixed Scope · Remote Delivery

Your FortiGate deployed right. First time.

From greenfield deployment to legacy firewall migration or model upgrade — our certified engineers handle the entire installation. Security rules, VPN configuration, UTM profiles, cutover support, and handoff. Fixed scope. Fixed price.

100% remote delivery. One FortiGate or HA pair per engagement. Add-on services available for complex requirements.

Covers FortiGate 40F through 3500F series — greenfield, legacy migration, or model upgrade. Security policies, UTM profiles, IPsec and SSL-VPN, and HA pair configuration all included in fixed scope.

Back to Service Engagements

Before cutover

Have your existing policies been mapped to FortiGate security profiles before migration?

Is your FortiGate HA cluster configured and failover-tested before the cutover window?

Are your UTM profiles — IPS, antivirus, web filter, application control — configured for your traffic?

Are your IPsec and SSL-VPN tunnels documented and ready to migrate on cutover day?

Do you have active FortiGuard subscriptions for the security features you plan to enable?

Model Coverage

All FortiGate series. Three deployment scenarios.

Every model tier is covered. Every deployment scenario is supported. The scope of work scales with the complexity of the model.

Greenfield

New FortiGate deployment in a new environment — no existing firewall to migrate from.

Legacy Migration

Replace an existing non-Fortinet firewall. Rules and profiles migrated via FortiConverter.

FortiGate Upgrade

Upgrade from an existing FortiGate model to a new FortiGate — configuration carried forward.

Models 30–90

Entry-Level NGFW

Small offices, branch locations, remote sites

Security/NAT rules

Up to 20

Interfaces

Up to 5

UTM profiles

1 set

Cutover hours

2 hours

MSRP

$7,650

Models 100–900

Mid-Range NGFW

Growing businesses, distributed locations

Security/NAT rules

Up to 35

Interfaces

Up to 10

UTM profiles

2 sets

Cutover hours

4 hours

MSRP

$10,200

Models 1000–3000

Enterprise NGFW

Data centres, campus deployments, regional hubs

Security/NAT rules

Up to 50

Interfaces

Up to 20

UTM profiles

3 sets

Cutover hours

4 hours

MSRP

$13,387

Models 4000–7000

High-Performance NGFW

Large enterprises, carrier-grade, multi-site core

Security/NAT rules

Up to 75

Interfaces

Up to 24

UTM profiles

5 sets

Cutover hours

4 hours

MSRP

$17,212

Scope of Work

Exactly what's included — by model.

No surprises. Every deliverable is defined before engagement starts. What's not listed is out of scope — available as an add-on or custom SOW.

Security & NAT Rules

Migrate existing rules from legacy firewall or create new — Layer 3/4 security and NAT rules only.

Models 30–90

Up to 20 rules

Models 100–900

Up to 35 rules

Models 1000–3000

Up to 50 rules

Models 4000–7000

Up to 75 rules

UTM Security Profiles

Each profile set includes IPS, gateway antivirus, DNS filter, web filter, and application control policy.

Models 30–90

1 profile set

Models 100–900

2 profile sets

Models 1000–3000

3 profile sets

Models 4000–7000

5 profile sets

Interface & VPN Configuration

Physical and logical interface configuration plus 1 IPSec VPN tunnel. SSL VPN and additional tunnels available as add-ons.

Models 30–90

5 interfaces + 1 VPN

Models 100–900

10 interfaces + 1 VPN

Models 1000–3000

20 interfaces + 1 VPN

Models 4000–7000

24 interfaces + 1 VPN

Cutover & Next-Day Support

Night or weekend cutover hours included in a single session, plus next-day troubleshooting support.

Models 30–90

2 hrs cutover + 2 hrs next-day

Models 100–900

4 hrs cutover + 4 hrs next-day

Models 1000–3000

4 hrs cutover + 4 hrs next-day

Models 4000–7000

4 hrs cutover + 4 hrs next-day

Included on all model tiers

Greenfield deployment, legacy migration, or FortiGate upgrade

Single device or HA pair configuration

Log forwarding to up to 2 destinations

SNMP monitoring & alerting setup

Security Fabric connection to existing fabric

Configuration review sessions with your team

What's not included: Advanced routing (BGP, OSPF, SD-WAN, VRRP), user management, switch/AP configuration, third-party VPN configuration, and integrations not listed above. Available as add-on services or a custom SOW.

Responsibility Model

We deploy. You approve.

Responsibility is assigned before engagement starts — the final RACI is confirmed during the discovery call.

We deliver

We own it end-to-end

Shared

Both teams involved

You coordinate

We support or need access

01

Pre-Deployment

Planning, access, and sign-off before a single config is touched.

Discovery assessment & network review

We map your current environment

We deliver

Network topology & requirements

You provide diagrams and constraints

You coordinate

Legacy firewall configuration review

We audit what's migrating

We deliver

Infrastructure access provisioning

You grant dashboard and device access

You coordinate

Migration plan & cutover window

Agreed jointly before execution

Shared
02

Deployment

Configuration, rule migration, and security profile setup.

FortiGate hardware/virtual configuration

Full platform setup by our engineers

We deliver

Security/NAT rule migration & creation

Layer 3/4 rules per model scope

We deliver

UTM security profile setup

IPS, AV, DNS, web filter, app control

We deliver

Security policy approval

You review and sign off on policies

You coordinate

Logging, monitoring & alerting

Up to 2 log destinations + SNMP

We deliver

VPN configuration

1 IPSec tunnel included

We deliver
03

Cutover & Handoff

Go-live execution, validation, and documentation transfer.

Cutover execution & validation testing

Night/weekend window, single session

We deliver

Network access during cutover

You maintain site/device availability

You coordinate

Business-critical traffic confirmation

Jointly validate key flows are live

Shared

Next-day support & troubleshooting

2–4 hrs post-cutover coverage

We deliver

Configuration documentation & handoff

Full runbook delivered to your team

We deliver

Transparent Pricing

Fixed price. Per model tier. No surprises.

One price covers the full deployment scope for your FortiGate model. Pricing shown is MSRP — contact us for your actual rate.

Models 30–90

Entry-Level NGFW

$7,650

MSRP per deployment

Includes

Up to 20 security/NAT rules

1 UTM profile set

Up to 5 interfaces

2 hours cutover support

SKU: JL9624

Models 100–900

Mid-Range NGFW

$10,200

MSRP per deployment

Includes

Up to 35 security/NAT rules

2 UTM profile sets

Up to 10 interfaces

4 hours cutover support

SKU: JL9625

Models 1000–3000

Enterprise NGFW

$13,387

MSRP per deployment

Includes

Up to 50 security/NAT rules

3 UTM profile sets

Up to 20 interfaces

4 hours cutover support

SKU: JL9627

Models 4000–7000

High-Performance NGFW

$17,212

MSRP per deployment

Includes

Up to 75 security/NAT rules

5 UTM profile sets

Up to 24 interfaces

4 hours cutover support

SKU: JL9626

Pricing Notes

Pricing is per single deployment event — one FortiGate or one HA pair per SKU

Multiple devices in the same cutover require separate SKU purchases or a custom quote

Third-party firewall migration (FortiConverter license) is purchased separately

Advanced configurations (BGP, SD-WAN, VRRP) are available as custom add-ons

Pricing shown is MSRP — contact us for discounted rates

Add-On Services

Extend the scope. Same delivery standard.

Complex deployments often require scope beyond the base service. Each add-on is fixed-price and delivered as part of the same engagement.

IPSec VPN Add-On

JL9629

Additional IPSec VPN tunnels beyond the included tunnel. Includes 1 hour of troubleshooting. Third-party device configuration not included.

$1,275 per tunnel

Security/NAT Rules Add-On

JL9628

Migrate or create additional security/NAT rules — up to 250 rules per NGFW or HA pair — beyond what's included in the base deployment.

$3,825

Virtual FortiGate Deployment

JL9631

Deploy FortiGate NGFW in a virtual environment (VMware, KVM, Hyper-V). Purchased in addition to the primary deployment SKU for the correct model.

$2,550

SSL VPN Portal

JL9630

Create one SSL VPN web portal at your public IP address. Certificate and user operations are not included in this scope.

$5,100

Additional UTM Profile Set

JL9633

Create one additional set of UTM profiles (IPS, antivirus, DNS filter, web filter, application control) beyond what's included in your model tier.

$2,550 per set

Configuration Assistance (CAS) — Annual

JL9632

Annual 50-hour contract for minor configuration additions and modifications to existing FortiGate deployments. Can be applied across multiple sites.

$15,937 / year

Configuration Assistance (CAS) — 8 Hours

NN4358

Single 8-hour block of configuration assistance for minor changes and modifications to existing FortiGate deployments.

$2,550 per block

Common Questions

Before you ask — we've answered it.

Ready to deploy your FortiGate?

A 30-minute assessment call reviews your environment, confirms the right model tier, and scopes any add-ons required. Quote typically within 24 hours.

Assessment call → Quote & timeline → Schedule deployment window → Execute & handoff.

Back to Service Engagements