Fortigate buying used pre-owned firewall most frequently asked questions (2024)

Table of Contents

  • Introduction
  • Is it worth buying hardware Fortigate vs free VM evaluation one?
  • Can I get a demo Fortigate appliance?
  • Can I buy a used Fortigate from Fortinet?
  • Is it OK/legal from the Fortinet standpoint to buy the firewall on the secondary market?
  • Will I need a license for my Fortigate to work?
  • Should I transfer the purchased Fortigate to my account in Fortinet?
  • How do I transfer Fortigate to my account in the Fortinet portal?
  • Hidden cost of renewing an existing subscription
  • Should I wipe the firewall, could it be back-doored?
  • Do I need to buy additional hardware?
  • What model should I buy?
  • Seller sold me a firewall without an admin password, what can I do?
  • Where do I get up-to-date firmware for my firewall?

Introduction

Buying a used/pre-owned Fortigate is often the best way to learn to work with thefirewall. Offers are plenty - just hit the search on eBay. But, there is alwaysbut, purchasing a pre-owned Fortigate is not like ordering a used MacBook - manyquestions will arise, not many of which have answers in official docs. In thisarticle I compiled the most frequent/important of them. Disclaimer: I do notwork for Fortinet and this is not an official guide in any way, so do your duediligence.

Is it worth buying hardware Fortigate vs free VM evaluation one?

I’d say free VM is enough if you start learning from zero. As you progress youwill hit the VM evaluation limitations. I list those limits hereFortigate VM Evaluation License 15 Days Limitations and hereFortigate free VM Evaluation License is now permanent, not limited to 15 days, here is how to get it.

The appliance Fortigate, on the other hand, has none of these limitations,even without active subscription. Want to do Deep SSL Inspection? No problem.Trying to configure VPN SSL for Forticlient? Sure.

Can I get a demo Fortigate appliance?

As an individual - no. Fortinet have Not For Resale (NFR) Fortigate appliancesthat are fully functional, but you can only get them as a Partner and even thenwith much effort. If all you want, on the other hand, is to see how FortigateGUI looks and feels without doing anything, you can go herehttps://fortigate.fortidemo.com with theuser/pass demo/demo and log in into a real Fortigate (2000E as of this writing)as read-only admin.

Can I buy a used Fortigate from Fortinet?

No, you can’t. The policy of Fortinet is to sell their products as new via registeredpartners/resellers only, and they have no incentive to supply clients with second-handFortigates.

Is it OK/legal from the Fortinet standpoint to buy the firewall on the secondary market?

Fortinet have no problems with this, so it is OK with them, provided youacquired the firewall in legitimate ways.

Will I need a license for my Fortigate to work?

No, but read on. There is no such thing as "unlicensed"hardware/appliance firewall. Licensing, or more exact subscription is needed for someservices, but many core features, like VPN (IPsec and VPN SSL), Security Rules,QOS, static and dynamic (OSPF, BGP, etc.) routing, VLANs, and such will work outof the box. Even if you hard reset your Fortigate, or more - format itsharddisk erasing everything, the core features will work just fine.

Should I transfer the purchased Fortigate to my account in Fortinet?

It depends. When you buy a new Fortigate from a Fortinet partner, you canoptionally (and most usually do) buy services like hardware warranty, TechnicalSupport, subscriptions for FortiGuard Web Filtering/IPS/AV/etc. services as well. All those additionalservices are linked to an account in the Fortinet portal. It can be thepartner’s account, or the end client account who purchased the firewall and thentransferred to her own account. If you want to use/renew/buy those services foryour Fortigate, then yes - you have your Fortigate (its serial number) to beunder your account in the Fortinet portal.

How do I transfer Fortigate to my account in the Fortinet portal?

You open a ticket with the Customer Service at support.fortinet.com, or send therequest for assets transfer to cs@fortinet.com. Next, Fortinet will send anemail to the current/registered owner for this Fortigate, asking if theyapprove the transfer to your account. Here comes the pitfall - if the owners (asper Fortinet records) of this used firewall do not confirm/reply to thisrequest, you may be denied the transfer or (more probably), asked for a proof ofthe purchase and ownership of the appliance (photo of the admin GUI with theserial number clearly seen). If the Fortinet cannot verify that you lawfullypurchased your unit from an official partner/owner, you may be denied transferof the ownership. This does not stop Fortigate from working, but subscriptionbased services will be unavailable to it.

If there is a time gap between the dateof subscription expiration and your order to renew it, you pay one time for thisgap as well. That is, say you bought a Fortigate with a subscription bundlethat expired 3 months ago and you want to renew this bundle - Fortinet will bill this3 month gap as well. And so forth, up to 6 months back. Also worth noting that tobe able to buy/renew a subscription for a Fortigate, it has to be still supportedand active. You cannot buy, for example, subscription for Fortigate 110C. To seethe end of life status for a Fortigate search for Fortinet Product Life Cycle.

Should I wipe the firewall, could it be back-doored?

When you get someone’s firewall, it is always a good idea to reset itsconfiguration to thefactory defaults. You can do it on CLI with execute factoryreset. This willreset the configuration to the default one but will leave the firmware FortiOSintact. Many recommend to go further andformat the flash that holds FortiOS firmware to boot from. The downside toformatting the flash is you have to do TFTP network boot afterwards, and haveimage of FortiOS ready, noteveryone would want to do so.

Do I need to buy additional hardware?

You may need a console cable, if a Fortigate was not reset to the defaultconfigs and so will not allocate IPs via DHCP. The console cable is the usualone, like you may have seen with the Cisco equipment. IMPORTANT: when buying a usedfirewall, make sure it includes a power adapter, as the new one will costyou at least 100$.

What model should I buy?

For learning purposes even the smallest models will do. The available featuresare almost identical for small and big (expensive) models. For example, thesmallest Fortigate 30E also supports up to 5 VDOMs, High Availabilty in cluster,and such. The important consideration here is the latest supported FortiOSversion for a given model. Fortinet stops supporting small models much soonerthan the larger ones. As an example, Fortigate 30E has the latest FortiOS available6.2.11, while a slightly larger model Fortigate 60E has FortiOS 7.2.3available. This means if you buy the (cheaper) 30E model, you will not be able touse features introduced in 6.4/7.0/7.2 versions. This may be important to you ornot, but be aware.

Seller sold me a firewall without an admin password, what can I do?

It happens, especially when a seller offers a Fortigate in "power test only"condition, that you will have no admin-level user/password to manage it. Thebest case scenario is that you will be able to reset admin password on boot upvia console using maintainer built-in account. Just search Google forFortigate Resetting a lost Admin password. The worst case scenario is that youhave no admin password AND previous owner disabled maintainer feature - youwill get an error trying to use maintainer account PASSWORD RECOVERYFUNCTIONALITY IS DISABLED. What happens next depends on a specific model -small models (Fortigate 40F, 80F, etc.) have RESET button on the face panel,which, while pressed, will reset the configuration to the factory default. Thelarge models do not have such one. Conclusion - if you’re not sure of the seller, checkthat your model can be reset with the button in its data sheet beforehand. Ihave collected most of the data sheets here if you need to:Fortigate Firewalls Hardware - CPU model and number, Memory (RAM) and hard disk size datasheet table

Where do I get up-to-date firmware for my firewall?

You can only legally get new firmware, provided it exists for a given model, if you havean active Forticare contract. Chances are your used Fortigate will have allcontracts/subscriptions expired already. So, see entry above aboutbuying/renewing subscriptions or you may try your luckasking for firmware on the Internet (Reddit/Telegram/Forums/etc.). The firmware upgrade is just adownloadable file that will work no matter in which way you got it.

Follow me on https://www.linkedin.com/in/yurislobodyanyuk/ not to miss what Ipublish on Linkedin, Github, blog, and more.

Fortigate buying used pre-owned firewall most frequently asked questions (2024)

FAQs

How do I transfer ownership of FortiGate firewall? ›

Go to Dashboard > Status. In the Licenses widget, click the Support link, then click Transfer FortiGate to Another Account. You can also transfer an account from System > FortiGuard.

Will a FortiGate firewall work without a license? ›

Just like other firewalls, Fortinet firewalls include a base license. It means the firewall will function without any kind of additional licensing. If you don't want to spend extra on your network security, you can work with the basic license. The only thing is you will get basic features and minimum protection.

Which FortiGate firewall is best? ›

The FortiGate 90G series of next generation firewalls (NGFWs) are designed to deliver the highest performance and efficiency in a compact, fanless desktop form factor to address the complex power and security needs in small offices and branches.

What is your opinion of Fortinet's FortiGate firewall? ›

In this way, FortiGate can identify and spot malware, attacks by hackers, and many other threats and block threats. Fortinet recently has an overall 4.5 rating from 1,900+ reviews. As a top vendor of cybersecurity, Fortinet's mission save people, devices, and data everywhere from hacking.

How do I transfer Fortinet assets to another account? ›

To transfer the FortiGate to another FortiCare account:

Log in to the FortiGate. Go to Dashboard > Status. In the Licenses widget, click FortiCare Support, then Transfer FortiGate to Another Account.

How do I clone a firewall policy in FortiGate? ›

Go to Firewall policy -> select the policy and 'right-click' with the mouse to get the options. Select Copy option and then again 'right-click' on the same policy or on the policy, before or after it is wanted to place the cloned policy.

What is exempt in FortiGate? ›

- 'Allow' -> destination is allowed from the static URL list, FortiGate proceeds with checking the category to decide further action. - 'Exempt' -> destination is exempted from further inspection and traffic is allowed.

Does FortiGate work without subscription? ›

Provisioning FortiGates to FortiGate Cloud does not require a subscription. For limitations without a subscription, see Feature comparison. All devices must be registered on the Fortinet Support site. For pricing information, contact your Fortinet partner or reseller.

What happens if FortiGate firewall license expires? ›

Antivirus scanning continues to work, but the antivirus database is not updated and no new signatures are added. For more information, see Antivirus. Category-based Web and DNS filtering stops working, as URLs and domains are sent to FortiGuard in real-time to determine the category.

Which firewall is most commonly used? ›

What are the most common types of firewalls used in network security policies and procedures for IT services?
  • Packet filtering firewalls.
  • Stateful firewalls. Be the first to add your personal experience.
  • Application layer firewalls. ...
  • Proxy firewalls. ...
  • Next-generation firewalls. ...
  • Here's what else to consider.
Jan 3, 2024

Why buy Fortinet firewall? ›

How Fortinet Can Help. FortiGate Next Generation Firewalls (NGFW) seamlessly integrates advanced networking and robust security providing industry-leading threat protection and decryption with a custom ASIC architecture for superior performance and energy efficiency at scale.

Is Fortinet better than Cisco? ›

Fortinet's patented SD-WAN ASIC and decentralized fully autonomous controller architecture ensures optimal user experience under any load. Because of its piecemeal architectural approach, Cisco SD-WAN has chronic performance and scaling limitations that can significantly impact user experience.

What is the weakness of Fortinet? ›

Weaknesses. As with any company, Fortinet has a number of weaknesses that could impact its future growth and success: Limited market share: While Fortinet has made significant gains in the network security market, it still faces stiff competition from larger, more established players like Cisco and Juniper Networks.

What makes Fortinet special? ›

Fortinet is uniquely positioned to deliver Secure Networking, Universal SASE, and Security Operations solutions as integrated platforms underpinned by AI-driven technologies​, unified management, leading threat intelligence, and one of the largest open ecosystems in the industry.

Is Fortinet reputable? ›

Fortinet has more than 2,400 reviews, with more than 80% of reviewers indicating they would recommend the company to others. Below are some reviews employees recently shared on Glassdoor about Fortinet: “[Fortinet is] a great company with an amazing technology vision.”

How do I change the administrator account in FortiGate? ›

To do this, create a new administrator account with the super_admin admin profile and log in as that administrator. Then go to System > Admin > Administrators and Edit the admin administrator and change the Administrator name.

How do I change the master account in Fortinet? ›

You cannot change the master user of the account. Master users can add users to the account and assign roles, permissions, and assets to the users.

How do I remove a license from FortiGate? ›

To delete license:
  1. Select the checkbox in the license row. You can select multiple checkboxes at a time.
  2. Click the Delete button to delete the license(s) you have selected.

How do I disconnect admin from FortiGate? ›

Go to System Settings > Dashboard. In the System Information widget, in the Current Administrators field, click the Current Session List button. The Admin Session List opens in the widget. Select the administrator or administrators you need to disconnect.

Top Articles
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 5630

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.