What should replace my two FortiGate 60Fs: UniFi, pfSense, or staying with Fortinet?

0
3
Asked By MellowCedar47 On

I'm evaluating replacements for two FortiGate 60Fs, mainly because the recurring licensing cost has become difficult to justify rather than because the hardware has been unreliable.

BV01 is the primary site, with servers and virtual machines, production networks, cameras, internal operations, guest Wi-Fi, public-facing personal and business services, and an ERP accessed remotely through Cloudflare One. It is also the site where I need genuine 10Gbps capability and where a firewall outage would have the greatest impact.

BV00 is a much smaller branch connected to BV01 through a site-to-site VPN. It mostly serves home users, a small VM network, Home Assistant, an off-site backup vault, and a redundant domain controller. BV02 has already moved to a UCG-Fiber and has been perfectly adequate for its small office workload, although it has not been heavily stressed.

The current Fortinet renewal cost is about $480 per year plus VAT per unit. I also received quotes for upgrading to a FortiGate 70G at BV00 and a 90G at BV01. Including the first year of hardware and licensing, those were roughly $880 and $2,170 respectively, followed by renewals of about $495 and $1,220 per year. That puts the combined annual renewal cost around $1,715 before VAT, so simply moving to newer FortiGates does not solve the budget issue.

My current alternatives are a UDM-Pro-Max at BV01 and a UDM-SE at BV00, or possibly a Netgate/pfSense appliance for BV01. I understand that UniFi does not match Fortinet feature-for-feature, especially regarding granular security inspection and subscription-based security services. I'm willing to accept some reduction in capability if it is not significant in day-to-day operation.

For people who have used UniFi as the primary gateway at a genuinely busy production site: do you notice the reduced inspection depth in practice? Is a UDM-Pro-Max meaningfully better than another UCG-Fiber for this workload, and would pfSense be a safer choice for the main site? I'm also interested in other vendors that offer a reasonable balance of performance, support, and recurring cost.

4 Answers

Answered By AmberQuill62 On

pfSense or a Netgate appliance is a more credible alternative for BV01 than a consumer-oriented router. You get much more control over routing, VPNs, firewall rules, and services, and commercial support is available if you buy the appropriate package. The tradeoff is that you take on more design, maintenance, monitoring, and troubleshooting responsibility than you would with a fully supported Fortinet deployment.

SilverMeadow14 -

Commercial pfSense support can be quite good, so lack of a traditional firewall vendor does not automatically mean being on your own. The important questions are whether you have tested failover, spare hardware, backups, and someone who can operate it during an incident.

Answered By BrightWalnut73 On

Before choosing, compare the cost of downtime and the value of support with the subscription savings. A low-cost option can be perfectly reasonable if the business accepts the risk and you have a recovery plan, but it should be an explicit risk decision rather than assuming that all gateways are interchangeable. For BV00, UniFi seems much easier to justify given the lighter workload. For BV01, I would either keep Fortinet, use a supported pfSense/Netgate design with redundancy or a spare, or evaluate a business-focused platform such as Sophos rather than treating a UDM as a direct enterprise firewall replacement.

Answered By NorthstarMica8 On

The main argument for staying with Fortinet is not just features; it is the support, replacement process, and predictable response when the firewall is critical. UniFi hardware can be attractive and capable, but its enterprise support and failure-handling model are not in the same category. If BV01 really has customer-facing services and business applications, the annual cost may be justified by the risk reduction alone.

QuietHarbor26 -

That is fair, but the budget pressure is real. In a smaller business environment, several hundred dollars per year per device can be a substantial part of the IT budget, so the decision is not simply about whether the Fortinet features are worth having.

Answered By CopperLynx31 On

I would be cautious about making UniFi the firewall for the most important site just to reduce licensing costs. It is often a very good choice for switching, wireless, and cameras, but the gateway platform has a flatter security model and less mature enterprise support. It may work perfectly for a while, but the consequences of an outage or a security incident are more important than the purchase price.

VelvetPine5 -

That leaves the practical choice as either accepting a firewall feature and support downgrade with UniFi, or paying for Fortinet or another business-focused platform. Sophos XGS could be worth pricing, although the total cost may not be dramatically lower.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.