fortigate firewall configuration guide
All insights
ITBUILDERS INTELLIGENCEFortinet

How to Configure a FortiGate Firewall: A Professional's Overview

A basic setup wizard gets you online. A professional FortiGate configuration keeps you secure. The five phases a certified engineer works through, explained.

By ITBuilders Editorial Team6 min read

Buying a capable FortiGate is only half the job. The other half is configuring it correctly — and that's where the security actually lives. A basic setup wizard will get you online in twenty minutes. It will not make you secure. Those are two very different outcomes that look identical on a dashboard.

Here's the uncomfortable part: a misconfigured firewall often leaves an organisation worse off than no firewall at all. It hands you a false sense of security while the back door stays wide open. Everyone assumes they're protected, so nobody looks — which is precisely the gap an attacker wants. A company with no firewall at least knows it's exposed. A company with a badly configured one thinks the problem is solved.

This is the sequence a certified engineer follows to get a FortiGate NGFW configured properly, phase by phase.

Phase 1: Initial setup and network integration

This is the foundation, and rushing it is how problems compound later. A professional setup goes well beyond plugging in cables.

You update to the latest stable firmware first, because that closes known vulnerabilities before anything else touches the network. This matters more than it sounds — appliances routinely ship with firmware that's months old, and the gap between the factory image and current is exactly where published exploits live. Then you configure the interfaces — WAN, LAN, DMZ — with a security-first mindset rather than a "just get it working" one.

The aim is to slot the firewall into your network with minimal disruption while locking down a hardened administrative access point. That last part matters more than people think: an exposed or weakly protected management surface is one of the first things an attacker probes. Administrative access should be restricted to internal management networks, protected by multi-factor authentication, and never — under any circumstances — exposed to the public internet.

Phase 2: Building security policies (the principle of least privilege)

This is the heart of what a firewall does. And across the Saudi enterprise market, we keep finding the same failure — an "Allow All" rule left over from the deployment phase, quietly permitting everything. That single leftover rule undoes most of the security you think you have. It usually gets added during commissioning to prove connectivity works, and then nobody removes it, because nothing appears broken.

A professional configuration follows the principle of least privilege. You build granular policies that permit only the specific traffic a business genuinely needs, and nothing more. Every rule has a stated purpose and a documented justification. Done right, this means that if one segment gets compromised, the threat can't wander laterally through the rest of your network — it hits a wall.

Segmentation belongs in this phase too. A FortiGate isn't only a perimeter device; it's a segmentation engine. Separating user traffic from server traffic, IT from OT, and IoT devices like cameras and printers onto isolated zones is what turns a single compromised laptop into a contained incident rather than a company-wide one.

Phase 3: Enabling and tuning security profiles (the brain)

Your FortiGate subscription includes serious security services, but here's the catch: they do nothing until they're correctly tuned and actually applied to your policies. Out of the box they're decorative. A proper configuration switches on and refines the real engines — antivirus, intrusion prevention (IPS), web filtering, and application control — and binds them to the policies the traffic passes through.

This is where "configured" becomes "protecting." We regularly audit environments where every profile exists in the library and none are attached to a policy. Traffic flows, dashboards look healthy, and nothing is being inspected.

Deep SSL inspection deserves its own mention here. The overwhelming majority of web traffic is encrypted, and a firewall that can't see inside encrypted sessions can't apply any of those engines meaningfully. Enabling it properly requires a distributed CA certificate, sensible exception lists for banking and healthcare destinations, and capacity sized for the decryption load. It's real work. Skipping it means paying enterprise money for a stateful packet filter with a nicer logo.

Phase 4: Configuring secure remote access (VPN)

For the modern workforce in Riyadh, Jeddah, and everywhere between, secure remote access isn't optional. This phase sets up encrypted VPN tunnels — SSL-VPN or IPsec.

But encryption alone isn't the finish line. You layer in strong authentication, specifically multi-factor, so a remote employee can reach company resources without exposing the corporate core to the open internet. A VPN without MFA is a convenient door that also happens to be convenient for attackers — stolen credentials are the most common initial access vector there is, and a password-only VPN turns one phished credential into full network access.

Increasingly, this phase also involves a conversation about whether a broad VPN is the right model at all, or whether ZTNA — granting access per application rather than per network — better fits how your people actually work.

Phase 5: Logging, monitoring, and reporting (the eyes)

You can't protect what you can't see. The final phase configures comprehensive logging — to a platform like FortiAnalyzer — so you get real-time visibility into traffic, generate the security reports SAMA and NCA compliance require, and hold the forensic data you'll need if you ever have to investigate an incident. [1][2]

Without centralised logging, logs stay on the appliance and rotate out within days. When an incident surfaces weeks later, the evidence you need is simply gone.

This is also the phase that saves you during an audit. "We have a firewall" is not evidence. Logs, reports, IPS efficacy data, and a documented review trail are.

Frequently asked questions

Can't I just use the setup wizard? You can, and you'll be online quickly. What you won't be is secure — the wizard doesn't build least-privilege policies, tune security profiles, configure segmentation, or set up proper logging. It gets traffic flowing, which is not the same as protecting it.

How long does a professional configuration take? It depends on environment complexity, but expect the configuration and validation work to be measured in days, plus a tuning period of several weeks after go-live as real traffic patterns emerge.

How often should the configuration be reviewed? Quarterly at minimum. Policy tables accumulate rules, temporary exceptions become permanent, and services get retired while their rules stay. Without a review cadence, the config drifts into insecurity on its own.

What's the most common mistake you see? Security profiles that are configured but never applied to a policy. It's astonishingly common and it means the firewall is inspecting nothing at all, while every dashboard says it's healthy.

Let the experts handle the implementation

A professional configuration is detailed, and getting it wrong doesn't just cause performance headaches — it produces documented security gaps that auditors and attackers both eventually find. One of them is more polite about it than the other.

We're a leading Fortinet partner in Saudi Arabia, and our certified engineers specialise in end-to-end FortiGate implementation and hardening. We handle the whole process — initial architecture through final policy tuning — so your firewall runs at maximum security and performance from day one, not day one hundred.

Don't leave your configuration to chance. Request a professional FortiGate configuration review. Call 920-020-750, email [email protected], or visit itbuilders.com.sa.

Sources & references

  1. Fortinet, FortiOS Administration Guide
  2. Saudi Central Bank (SAMA), Cyber Security Framework
TALK TO A SPECIALIST

Turn this insight into a practical next step.

Discuss your environment with our team and get a clear recommendation grounded in your operational reality.

Start a conversation
CONTINUE READING

Related intelligence