Firewalls & Security

Official Fortinet brand partner

FortiGate firewalls, supplied and configured across the UAE

We are a Fortinet brand partner, so you buy at partner pricing rather than reseller list price. Sized properly, configured by engineers who do this every week, and supported after handover — across Dubai, Sharjah, Abu Dhabi, the northern emirates and the wider GCC.

FortiGate 100F next-generation firewall supplied and configured by H7 Labs in the UAE

Most firewalls in the UAE are doing half a job

We get called into a lot of networks where a good firewall is sitting in the rack doing almost nothing useful. The licence expired eighteen months ago. Inspection was switched off because someone complained the internet felt slow. Every rule is any-to-any because that was quicker on install day. Nobody has looked at a log since.

The box was never the problem. Buying a firewall is easy. Sizing it for the traffic you actually have, configuring it so it inspects without choking, and keeping it current — that is the work, and it is what we do.

Buying through a Fortinet partner

Most IT companies in the UAE buy FortiGate units from a distributor and add their own margin. We hold partner status with Fortinet, which changes both the price and what we can do for you afterwards.

What partner status means What you get
Partner pricing Hardware and FortiGuard subscriptions at partner rates, not reseller list price. Schools and larger rollouts improve again.
Correct bundles Fortinet sells hardware and protection bundles in combinations that are easy to get wrong. We quote the bundle that matches what you actually need.
Renewals handled We track your expiry dates and tell you before they lapse, rather than after your protection quietly stops.
Support escalation We raise cases with Fortinet directly instead of passing you down a chain of resellers.
Roadmap visibility We know which models are being replaced, so you are not buying hardware at the end of its life.

Renewing an existing FortiGate? Send us the serial number and current expiry date. We will quote the renewal at partner pricing and tell you honestly whether the unit is still the right size for your network.

Which FortiGate do you need?

Sizing is where most firewall purchases go wrong. Buy too small and you end up switching off the inspection you paid for. Drag to your user count for a starting point.

10300600+

A typical UAE private school runs 150 to 400 devices once staff, students and access points are counted.

90G for 120 users

Count devices, not people. In a school every student tablet, staff laptop, access point, camera and panel is a device on the network, and most schools undercount by half.

The current range

Model Suits Typical use
30G / 50GUp to about 50 devicesSmall offices, clinics, retail units, nursery sites
70G50 to 150 devicesBranch offices, small schools, sites needing PoE
90G150 to 300 devicesBusy branches, mid-size schools, SD-branch hubs
120G / 100F300 to 500 devicesLarger campuses, sites needing high port density
200G500+ devicesLarge school campuses, corporate head offices
400F and aboveEnterprise and data centreMulti-site cores, heavy encrypted traffic

Size on threat-protection throughput, not firewall throughput. Firewall throughput is the figure with inspection off — it looks impressive and it is not the number your traffic will actually see. We quote against the protected figure.

What the throughput numbers actually mean

Every datasheet quotes several figures and they are not interchangeable. Here is the FortiGate 900G, a unit we deploy at campus and head-office scale, with its published numbers side by side.

Measure FortiGate 900G What is switched on
Firewall throughput164 GbpsPlain forwarding. No inspection. The flattering number.
IPS throughput42 GbpsIntrusion prevention running
NGFW throughput31 GbpsFirewall, IPS and application control
Threat protection30 GbpsAll of the above plus malware protection. The honest number.
SSL inspection16.7 GbpsEncrypted traffic being opened and checked
IPsec VPN55 GbpsSite-to-site tunnels

Notice the gap: 164 Gbps on paper, 30 Gbps once the security is doing its job. That is not a fault, it is physics — and it is exactly why a unit sized on the headline figure ends up with inspection switched off six months later.

Fortinet logo — H7 Labs is a Fortinet brand partner in the UAE FortiGate 100F 1U rack firewall front panel showing copper and SFP ports
FortiGate 100F. One rack unit with high copper port density, SFP and 10GE slots — the model we quote most often where a campus needs plenty of ports without adding switches.

One thing to check before you buy a G-series unit

Fortinet removed SSL VPN from the entry-level G-series models — the 50G, 70G and 90G — on current FortiOS releases. If your staff connect remotely through the FortiClient SSL VPN today, that option is gone on those units.

It is not a fault, it is a direction of travel. Fortinet wants remote access moving to ZTNA instead. But it catches people out, because a straight replacement of an ageing 60F with a 70G can quietly break the way your team works from home.

If you need remote accessYour options
Keep SSL VPN as it isStay on an F-series model, or move up to a 120G or higher where it remains available
Move to the newer approachDeploy ZTNA, which is what Fortinet now recommends. We configure it as part of the rollout.
Site-to-site links onlyIPsec is unaffected on every model. No change needed.

We raise this before quoting, not after installing. It is the kind of detail that decides which model goes in your rack.

What we actually configure

A firewall out of the box protects very little. This is the work that turns it into a security control rather than an expensive router.

AreaWhat we set up
Policy designRules written around who needs what, instead of one permissive rule doing everything
Network segmentationStudents separated from staff, guests from both, cameras and building systems on their own segments
Web and content filteringCategory filtering tuned for the site, with a process for staff to request exceptions
Intrusion preventionIPS and application control enabled and tuned, not left at defaults
Encrypted traffic inspectionSSL inspection deployed where it helps, with exclusions for banking and health traffic
Remote accessIPsec site-to-site, and ZTNA or SSL VPN depending on model and policy
SD-WANTwo internet lines used properly, with automatic failover you can actually test
High availabilityPaired units where downtime is not acceptable
Logging and reportingLogs retained and readable, so an incident can be investigated rather than guessed at
Firmware policyKept on a stable, supported release, with upgrades planned rather than rushed

The bundle is where the money goes

The appliance is the smaller half of the cost. What you subscribe to alongside it decides what the firewall can actually do, and this is where most quotes are either padded or quietly under-specified.

Bundle What it adds Typically right for
Unified Threat Protection Intrusion prevention, anti-malware, and web, DNS and video filtering, plus anti-spam Schools and offices that need solid filtering and threat blocking without extras
Advanced Threat Protection Intrusion prevention and anti-malware, without the web filtering layer Sites that already filter elsewhere
Enterprise Protection Everything above plus inline malware prevention, data loss prevention, attack-surface monitoring and IoT device detection Organisations with compliance obligations or sensitive data
SD-WAN bundle Link monitoring, overlay orchestration and cloud log retention Groups running several sites on multiple internet links

Two things worth knowing. Application control is included with the support subscription rather than sold separately. And all the protection bundles come with round-the-clock support and one-hour response on critical issues — worth checking against what a cheaper quote is actually offering you.

Firewalls for schools

School networks are their own problem. Hundreds of devices, a duty of care to children, inspectors who ask questions, and students who are often more determined than your IT budget.

The school problemHow we handle it
Filtering that has to holdCategory filtering plus safe search enforcement, and blocking of the proxy and VPN apps students use to get around it
Different rules by groupPrimary, secondary and staff each get their own policy, rather than one setting for the whole campus
Protecting student dataSegmentation so a compromised student device cannot reach the management information system
Evidence for inspectionReporting that shows what is blocked and what was attempted, in a form you can hand to an inspector
Everything at 8:30amSized for the morning peak when every class comes online at once, not the quiet afternoon average
No full-time security staffConfigured to run unattended, with us on the end of the phone when something changes

Where this meets UAE regulation

UAE cybersecurity rules have moved from guidance to enforcement. Which framework applies depends on your sector, your emirate and who your clients are — but a correctly configured firewall with real logging sits underneath most of them.

FrameworkWho it applies to
UAE Information Assurance StandardThe federal baseline, mandatory for critical national infrastructure and government entities
DESC ISRDubai government entities and, increasingly, their private-sector suppliers
UAE PDPLAny organisation processing personal data of UAE residents, including schools holding student records
ADHICSHealthcare providers in Abu Dhabi
ISO 27001Not law, but increasingly asked for by enterprise clients and in tenders

We are not a compliance auditor and we will not pretend to be. What we do is make sure the network controls underneath — segmentation, access control, patching, logging — are in place and evidenced, so your audit is about paperwork rather than emergency engineering.

We also supply Sophos

We are a Sophos partner as well as a Fortinet partner, and both are good firewalls. Which one suits you depends on the network, not on which brand we would rather sell.

FortiGate tends to win when

You want switches, access points and firewall managed as one fabric, you run SD-WAN across multiple sites, or you need heavy inspection throughput for the money.

Sophos tends to win when

Your team is small and the day-to-day interface matters more than depth, or you already run Sophos endpoint protection and want the firewall and endpoints talking to each other.

The Sophos XGS range

Desktop units from the XGS 88 through to the XGS 138 cover small offices, clinics and branch sites, with threat protection from 2 Gbps upward. Rack models run from the XGS 2100 to the XGS 8500 for campuses and enterprise edges.

Every model includes an integrated zero-trust gateway at no extra cost, and Sophos is the only vendor applying security hotfixes over the air without scheduled downtime.

Sophos logo — H7 Labs is a Sophos firewall partner in the UAE

Tell us the situation and we will say which we would put in, and why.

How a firewall project runs

Six stages, from the first look at your network to the year after.

1

Network review

We look at what you have, what it is carrying, and what is actually switched on. Usually free.

2

Sizing and quote

Model, bundle and licence term, itemised. Sized on protected throughput, with the reasoning shown.

3

Build

Configured and tested before it goes near your rack. Policies, segments, filtering and logging all set.

4

Cutover

Scheduled out of hours or over a weekend, with the old unit kept ready to fall back to.

5

Tuning

The first fortnight always throws up false positives. We stay on it until the noise stops.

6

Renewals and firmware

We track expiry dates and firmware releases so protection never lapses quietly.

Where we work

Our own engineers deploy and support FortiGate across the UAE and the wider GCC — survey, build, cutover, tuning and renewals.

United Arab Emirates

Dubai, Sharjah, Abu Dhabi, Ajman, Ras Al Khaimah, Umm Al Quwain and Fujairah. Onsite response and remote support after handover.

Wider GCC

Saudi Arabia, Qatar, Oman, Kuwait and Bahrain. Full deployment, and a common choice for groups standardising security across more than one country.

Questions we get asked

How much does a FortiGate firewall cost in the UAE?

It depends on the model, the protection bundle and the licence term — hardware is only part of it, and the FortiGuard subscription is what delivers the actual threat protection. As a Fortinet partner we quote at partner pricing rather than reseller list price. Tell us your device count and internet speed and we will send an itemised quote.

Which FortiGate model do I need?

As a rough guide: 30G or 50G up to about 50 devices, 70G to 150, 90G to 300, 120G or 100F to 500, and 200G above that. Size on threat-protection throughput rather than firewall throughput, and count devices rather than people.

Do I need a FortiGuard subscription as well as the hardware?

Yes, if you want the security features. The appliance without a subscription will route and filter by rule, but intrusion prevention, antivirus, web filtering and application control all depend on the FortiGuard services.

What happens when my FortiGate licence expires?

The unit keeps passing traffic, but it stops receiving threat updates, so protection degrades quietly from the day it lapses. Most networks we are called into have been running expired for months. Send us the serial number and we will quote the renewal.

Can you take over a FortiGate someone else installed?

Yes, and we do it regularly. We start with a review of the current configuration, tell you what is misconfigured or switched off, and give you a fixed scope to put it right.

Does the FortiGate 70G or 90G still support SSL VPN?

No. Fortinet removed SSL VPN from the entry-level G-series models on current FortiOS releases. If your staff rely on it, either stay on an F-series unit, move up to a 120G or higher, or migrate to ZTNA — which is the approach Fortinet now recommends. We flag this before quoting.

FortiGate or Sophos — which should we buy?

We supply both. FortiGate usually wins where you want switches and access points managed with the firewall as one fabric, or where you need SD-WAN across sites. Sophos often suits smaller teams and anyone already running Sophos endpoint protection. We will tell you which we would deploy in your situation.

Can you set up content filtering for a school?

Yes. Category filtering, enforced safe search, different policies for primary, secondary and staff, blocking of the proxy and VPN apps students use to bypass it, and reporting you can show an inspector.

Will a firewall make our internet slower?

Only if it is undersized or badly configured. Inspection costs throughput, which is exactly why sizing on the protected figure matters. Done properly, users notice nothing.

Which emirates and countries do you cover?

All seven emirates — Dubai, Sharjah, Abu Dhabi, Ajman, Ras Al Khaimah, Umm Al Quwain and Fujairah — and across the GCC including Saudi Arabia, Qatar, Oman, Kuwait and Bahrain.

Start with a look at what you have

Before we quote anything, we will review your current setup and tell you plainly what is working, what is switched off, and what is out of support. No cost, no obligation, anywhere in the UAE.