FortiGate firewalls, supplied and configured across the UAE
We are a Fortinet brand partner, so you buy at partner pricing rather than reseller list price. Sized properly, configured by engineers who do this every week, and supported after handover — across Dubai, Sharjah, Abu Dhabi, the northern emirates and the wider GCC.
Most firewalls in the UAE are doing half a job
We get called into a lot of networks where a good firewall is sitting in the rack doing almost nothing useful. The licence expired eighteen months ago. Inspection was switched off because someone complained the internet felt slow. Every rule is any-to-any because that was quicker on install day. Nobody has looked at a log since.
The box was never the problem. Buying a firewall is easy. Sizing it for the traffic you actually have, configuring it so it inspects without choking, and keeping it current — that is the work, and it is what we do.
Buying through a Fortinet partner
Most IT companies in the UAE buy FortiGate units from a distributor and add their own margin. We hold partner status with Fortinet, which changes both the price and what we can do for you afterwards.
| What partner status means | What you get |
|---|---|
| Partner pricing | Hardware and FortiGuard subscriptions at partner rates, not reseller list price. Schools and larger rollouts improve again. |
| Correct bundles | Fortinet sells hardware and protection bundles in combinations that are easy to get wrong. We quote the bundle that matches what you actually need. |
| Renewals handled | We track your expiry dates and tell you before they lapse, rather than after your protection quietly stops. |
| Support escalation | We raise cases with Fortinet directly instead of passing you down a chain of resellers. |
| Roadmap visibility | We know which models are being replaced, so you are not buying hardware at the end of its life. |
Renewing an existing FortiGate? Send us the serial number and current expiry date. We will quote the renewal at partner pricing and tell you honestly whether the unit is still the right size for your network.
Which FortiGate do you need?
Sizing is where most firewall purchases go wrong. Buy too small and you end up switching off the inspection you paid for. Drag to your user count for a starting point.
A typical UAE private school runs 150 to 400 devices once staff, students and access points are counted.
Count devices, not people. In a school every student tablet, staff laptop, access point, camera and panel is a device on the network, and most schools undercount by half.
The current range
| Model | Suits | Typical use |
|---|---|---|
| 30G / 50G | Up to about 50 devices | Small offices, clinics, retail units, nursery sites |
| 70G | 50 to 150 devices | Branch offices, small schools, sites needing PoE |
| 90G | 150 to 300 devices | Busy branches, mid-size schools, SD-branch hubs |
| 120G / 100F | 300 to 500 devices | Larger campuses, sites needing high port density |
| 200G | 500+ devices | Large school campuses, corporate head offices |
| 400F and above | Enterprise and data centre | Multi-site cores, heavy encrypted traffic |
Size on threat-protection throughput, not firewall throughput. Firewall throughput is the figure with inspection off — it looks impressive and it is not the number your traffic will actually see. We quote against the protected figure.
What the throughput numbers actually mean
Every datasheet quotes several figures and they are not interchangeable. Here is the FortiGate 900G, a unit we deploy at campus and head-office scale, with its published numbers side by side.
| Measure | FortiGate 900G | What is switched on |
|---|---|---|
| Firewall throughput | 164 Gbps | Plain forwarding. No inspection. The flattering number. |
| IPS throughput | 42 Gbps | Intrusion prevention running |
| NGFW throughput | 31 Gbps | Firewall, IPS and application control |
| Threat protection | 30 Gbps | All of the above plus malware protection. The honest number. |
| SSL inspection | 16.7 Gbps | Encrypted traffic being opened and checked |
| IPsec VPN | 55 Gbps | Site-to-site tunnels |
Notice the gap: 164 Gbps on paper, 30 Gbps once the security is doing its job. That is not a fault, it is physics — and it is exactly why a unit sized on the headline figure ends up with inspection switched off six months later.
One thing to check before you buy a G-series unit
Fortinet removed SSL VPN from the entry-level G-series models — the 50G, 70G and 90G — on current FortiOS releases. If your staff connect remotely through the FortiClient SSL VPN today, that option is gone on those units.
It is not a fault, it is a direction of travel. Fortinet wants remote access moving to ZTNA instead. But it catches people out, because a straight replacement of an ageing 60F with a 70G can quietly break the way your team works from home.
| If you need remote access | Your options |
|---|---|
| Keep SSL VPN as it is | Stay on an F-series model, or move up to a 120G or higher where it remains available |
| Move to the newer approach | Deploy ZTNA, which is what Fortinet now recommends. We configure it as part of the rollout. |
| Site-to-site links only | IPsec is unaffected on every model. No change needed. |
We raise this before quoting, not after installing. It is the kind of detail that decides which model goes in your rack.
What we actually configure
A firewall out of the box protects very little. This is the work that turns it into a security control rather than an expensive router.
| Area | What we set up |
|---|---|
| Policy design | Rules written around who needs what, instead of one permissive rule doing everything |
| Network segmentation | Students separated from staff, guests from both, cameras and building systems on their own segments |
| Web and content filtering | Category filtering tuned for the site, with a process for staff to request exceptions |
| Intrusion prevention | IPS and application control enabled and tuned, not left at defaults |
| Encrypted traffic inspection | SSL inspection deployed where it helps, with exclusions for banking and health traffic |
| Remote access | IPsec site-to-site, and ZTNA or SSL VPN depending on model and policy |
| SD-WAN | Two internet lines used properly, with automatic failover you can actually test |
| High availability | Paired units where downtime is not acceptable |
| Logging and reporting | Logs retained and readable, so an incident can be investigated rather than guessed at |
| Firmware policy | Kept on a stable, supported release, with upgrades planned rather than rushed |
The bundle is where the money goes
The appliance is the smaller half of the cost. What you subscribe to alongside it decides what the firewall can actually do, and this is where most quotes are either padded or quietly under-specified.
| Bundle | What it adds | Typically right for |
|---|---|---|
| Unified Threat Protection | Intrusion prevention, anti-malware, and web, DNS and video filtering, plus anti-spam | Schools and offices that need solid filtering and threat blocking without extras |
| Advanced Threat Protection | Intrusion prevention and anti-malware, without the web filtering layer | Sites that already filter elsewhere |
| Enterprise Protection | Everything above plus inline malware prevention, data loss prevention, attack-surface monitoring and IoT device detection | Organisations with compliance obligations or sensitive data |
| SD-WAN bundle | Link monitoring, overlay orchestration and cloud log retention | Groups running several sites on multiple internet links |
Two things worth knowing. Application control is included with the support subscription rather than sold separately. And all the protection bundles come with round-the-clock support and one-hour response on critical issues — worth checking against what a cheaper quote is actually offering you.
Firewalls for schools
School networks are their own problem. Hundreds of devices, a duty of care to children, inspectors who ask questions, and students who are often more determined than your IT budget.
| The school problem | How we handle it |
|---|---|
| Filtering that has to hold | Category filtering plus safe search enforcement, and blocking of the proxy and VPN apps students use to get around it |
| Different rules by group | Primary, secondary and staff each get their own policy, rather than one setting for the whole campus |
| Protecting student data | Segmentation so a compromised student device cannot reach the management information system |
| Evidence for inspection | Reporting that shows what is blocked and what was attempted, in a form you can hand to an inspector |
| Everything at 8:30am | Sized for the morning peak when every class comes online at once, not the quiet afternoon average |
| No full-time security staff | Configured to run unattended, with us on the end of the phone when something changes |
Where this meets UAE regulation
UAE cybersecurity rules have moved from guidance to enforcement. Which framework applies depends on your sector, your emirate and who your clients are — but a correctly configured firewall with real logging sits underneath most of them.
| Framework | Who it applies to |
|---|---|
| UAE Information Assurance Standard | The federal baseline, mandatory for critical national infrastructure and government entities |
| DESC ISR | Dubai government entities and, increasingly, their private-sector suppliers |
| UAE PDPL | Any organisation processing personal data of UAE residents, including schools holding student records |
| ADHICS | Healthcare providers in Abu Dhabi |
| ISO 27001 | Not law, but increasingly asked for by enterprise clients and in tenders |
We are not a compliance auditor and we will not pretend to be. What we do is make sure the network controls underneath — segmentation, access control, patching, logging — are in place and evidenced, so your audit is about paperwork rather than emergency engineering.
We also supply Sophos
We are a Sophos partner as well as a Fortinet partner, and both are good firewalls. Which one suits you depends on the network, not on which brand we would rather sell.
FortiGate tends to win when
You want switches, access points and firewall managed as one fabric, you run SD-WAN across multiple sites, or you need heavy inspection throughput for the money.
Sophos tends to win when
Your team is small and the day-to-day interface matters more than depth, or you already run Sophos endpoint protection and want the firewall and endpoints talking to each other.
The Sophos XGS range
Desktop units from the XGS 88 through to the XGS 138 cover small offices, clinics and branch sites, with threat protection from 2 Gbps upward. Rack models run from the XGS 2100 to the XGS 8500 for campuses and enterprise edges.
Every model includes an integrated zero-trust gateway at no extra cost, and Sophos is the only vendor applying security hotfixes over the air without scheduled downtime.
Tell us the situation and we will say which we would put in, and why.
How a firewall project runs
Six stages, from the first look at your network to the year after.
Network review
We look at what you have, what it is carrying, and what is actually switched on. Usually free.
Sizing and quote
Model, bundle and licence term, itemised. Sized on protected throughput, with the reasoning shown.
Build
Configured and tested before it goes near your rack. Policies, segments, filtering and logging all set.
Cutover
Scheduled out of hours or over a weekend, with the old unit kept ready to fall back to.
Tuning
The first fortnight always throws up false positives. We stay on it until the noise stops.
Renewals and firmware
We track expiry dates and firmware releases so protection never lapses quietly.
Where we work
Our own engineers deploy and support FortiGate across the UAE and the wider GCC — survey, build, cutover, tuning and renewals.
United Arab Emirates
Dubai, Sharjah, Abu Dhabi, Ajman, Ras Al Khaimah, Umm Al Quwain and Fujairah. Onsite response and remote support after handover.
Wider GCC
Saudi Arabia, Qatar, Oman, Kuwait and Bahrain. Full deployment, and a common choice for groups standardising security across more than one country.
Questions we get asked
How much does a FortiGate firewall cost in the UAE?
It depends on the model, the protection bundle and the licence term — hardware is only part of it, and the FortiGuard subscription is what delivers the actual threat protection. As a Fortinet partner we quote at partner pricing rather than reseller list price. Tell us your device count and internet speed and we will send an itemised quote.
Which FortiGate model do I need?
As a rough guide: 30G or 50G up to about 50 devices, 70G to 150, 90G to 300, 120G or 100F to 500, and 200G above that. Size on threat-protection throughput rather than firewall throughput, and count devices rather than people.
Do I need a FortiGuard subscription as well as the hardware?
Yes, if you want the security features. The appliance without a subscription will route and filter by rule, but intrusion prevention, antivirus, web filtering and application control all depend on the FortiGuard services.
What happens when my FortiGate licence expires?
The unit keeps passing traffic, but it stops receiving threat updates, so protection degrades quietly from the day it lapses. Most networks we are called into have been running expired for months. Send us the serial number and we will quote the renewal.
Can you take over a FortiGate someone else installed?
Yes, and we do it regularly. We start with a review of the current configuration, tell you what is misconfigured or switched off, and give you a fixed scope to put it right.
Does the FortiGate 70G or 90G still support SSL VPN?
No. Fortinet removed SSL VPN from the entry-level G-series models on current FortiOS releases. If your staff rely on it, either stay on an F-series unit, move up to a 120G or higher, or migrate to ZTNA — which is the approach Fortinet now recommends. We flag this before quoting.
FortiGate or Sophos — which should we buy?
We supply both. FortiGate usually wins where you want switches and access points managed with the firewall as one fabric, or where you need SD-WAN across sites. Sophos often suits smaller teams and anyone already running Sophos endpoint protection. We will tell you which we would deploy in your situation.
Can you set up content filtering for a school?
Yes. Category filtering, enforced safe search, different policies for primary, secondary and staff, blocking of the proxy and VPN apps students use to bypass it, and reporting you can show an inspector.
Will a firewall make our internet slower?
Only if it is undersized or badly configured. Inspection costs throughput, which is exactly why sizing on the protected figure matters. Done properly, users notice nothing.
Which emirates and countries do you cover?
All seven emirates — Dubai, Sharjah, Abu Dhabi, Ajman, Ras Al Khaimah, Umm Al Quwain and Fujairah — and across the GCC including Saudi Arabia, Qatar, Oman, Kuwait and Bahrain.
Start with a look at what you have
Before we quote anything, we will review your current setup and tell you plainly what is working, what is switched off, and what is out of support. No cost, no obligation, anywhere in the UAE.