What a FortiGate consultant actually does

Most FortiGate estates in India were not designed. They were delivered. A reseller quoted the box, a junior engineer racked it, a base config was pasted in, and the firewall has been accreting rules ever since. Five years later nobody can tell you why policy 847 exists, and nobody dares delete it.

That is the gap a FortiGate consultant fills. A reseller’s business model ends at the invoice — box sold, licence renewed, done. Mine starts where the invoice stops. I look at your traffic, your applications, your compliance obligations, and I design the policy base, the inspection profile and the high-availability layout that the estate should have had from day one. Design first, box second. Sometimes the outcome of a consulting engagement is that you do not need new hardware at all; you need the hardware you already own configured the way Fortinet intended.

FortiGate consultant in India — firewall rule audits and tuning by Sanjay Seth

I have been hands-on with firewalls since 1993 and running Fortinet estates across India for well over a decade. What follows is what I am actually called in to do, the warning signs I see most often, and how an engagement with me runs.

The four engagements I am called for

Rule-base audits and shadow-rule cleanup

This is the single most common request. A rule base that has grown organically for years accumulates shadowed rules — entries that can never match because an earlier, broader rule catches the traffic first. It accumulates duplicates, orphaned objects pointing at decommissioned servers, and “temporary” any-any rules from a 2019 migration that became permanent. I audit the policy base against real traffic logs, flag what is dead, what is shadowed and what is dangerously broad, and hand you a cleanup sequence that can be executed without an outage.

IPS and SSL-inspection tuning for real workloads

Out of the box, most FortiGates I inspect have SSL inspection switched off everywhere, or switched on with a certificate-based exemption list so long it may as well be off. Both are understandable — a badly tuned inspection profile breaks applications and the helpdesk pays the price. My work here is to build inspection baselines per traffic class: what gets deep inspection, what gets certificate inspection, what is exempted and why. Then I tune IPS signatures against your actual workload so protection is on and the phones stay quiet.

HA cluster design

High availability is bought as a checkbox and deployed as an afterthought. I regularly find clusters where the failover has never been tested, where session pickup is disabled, where the heartbeat shares a switch with production traffic, or where the standby unit is three firmware builds behind and will not take over cleanly. A proper HA engagement covers topology, monitored interfaces, session sync, firmware discipline across both units, and — the part everyone skips — a witnessed failover test with a rollback plan.

FortiAnalyzer log-pipeline repair

When an auditor or an incident responder asks for logs, the answer is too often “the FortiAnalyzer has them, probably, somewhere.” Disk quotas misconfigured, log filters dropping exactly the events that matter, devices silently unregistered after a firmware change. I rebuild the log pipeline end to end: what each FortiGate sends, what the FortiAnalyzer retains, how long it is kept, and how it maps to what CERT-In reporting and your auditors actually ask for.

Signs your FortiGate estate needs a consultant

  • Policies nobody dares delete. If the answer to “what does this rule do?” is a shrug, your rule base is a liability, not a control.
  • SSL inspection off everywhere. The majority of enterprise traffic is encrypted. If you are not inspecting it, your IPS and web filter are watching a shrinking fraction of what crosses the wire.
  • Firmware two trains behind. Being deliberately one release behind current is prudent. Being two full trains behind usually means vulnerabilities with public exploits are unpatched on your perimeter.
  • Logging that misses what auditors ask. If your last audit or incident review involved the phrase “we don’t have logs for that period”, the pipeline is broken.
  • HA that has never failed over. An untested cluster is a single point of failure with extra hardware.
  • Nobody owns the estate. The reseller installed it, the IT team inherited it, and the last person who understood the config left in 2022.

If two or more of those sound familiar, you do not need a new firewall. You need a FortiGate optimization service — a structured pass over what you already run.

How I work through a FortiGate engagement

Every engagement follows the same arc, whether it is a single cluster in Delhi or a forty-site fleet under FortiManager.

Assess. I start with read-only access and the logs, never with a change window. I review the policy base, the inspection profiles, the HA state, the firmware posture and the log pipeline, and I interview the people who live with the box day to day. The output is a findings document ranked by risk, not by what is easiest to sell.

Architect. Before anything changes, we agree the target state: what the policy base should look like, which traffic classes get which inspection, how failover should behave, what gets logged and retained. You sign off on the design before I touch a config.

Deploy. Changes go in during agreed windows, in reversible stages, with a tested rollback for each stage. Shadow-rule cleanup happens in batches with hit-count verification between them. Inspection profiles are enabled per traffic class, never globally on a Friday afternoon.

Operate. I hand over documentation your own team can actually maintain — the policy base rationale, the inspection baselines, the failover runbook — and I stay available for the questions that surface in the first weeks after a change.

What you get

A finished engagement leaves you with three concrete artefacts. An audited policy base — every rule either justified or removed, with the reasoning recorded so the next auditor gets an answer instead of a shrug. Inspection baselines — a written statement of what is decrypted, what is exempted and why, which is exactly what DPDP-era compliance reviews ask for. And a performance report — where the box sits on CPU, memory and session counts after tuning, so you know how much headroom you bought back before anyone talks about new hardware.

If you want it run for you

Some organisations want the audit and the design, then prefer their own team to run the estate. Others want the ongoing discipline — firmware cadence, rule hygiene, log review, failover tests — handled for them. For the second group, my team at PJ Networks runs FortiGate fleets as a managed service. As a long-standing Fortinet partner in Delhi, we operate multi-site FortiManager and FortiAnalyzer estates around the clock, and our firewall audit services in India cover the same ground as my consulting audits, delivered on a recurring schedule. I stay personally involved in the architecture on those engagements; the NOC handles the 2 a.m. alerts.

Frequently asked questions

What does a FortiGate consultant cost in India?

It depends on scope. A single-cluster rule-base audit is a few days of work; a multi-site optimisation with FortiManager and FortiAnalyzer remediation runs to several weeks. I price fixed-fee per engagement after a scoping call, so you know the cost before work begins. What I can say from experience: a proper audit almost always costs less than the incident, the failed audit or the unnecessary hardware refresh it prevents.

What is the difference between a FortiGate consultant and a Fortinet partner or reseller?

A reseller’s commercial interest is in selling you hardware and licences. A consultant’s interest is in whether your estate actually works. I am vendor-neutral in my recommendations even though my team at PJ Networks is a Fortinet partner — if the right answer is “keep your current boxes and fix the config”, that is what you will hear from me. Design first, box second.

Can you clean up a rule base with thousands of policies without downtime?

Yes, and I insist on it. Cleanup is staged: I identify shadowed and unused rules from hit counts and traffic logs, disable them in batches rather than deleting outright, and monitor for a soak period before removal. Each batch is reversible in minutes. Done properly, users never notice a rule-base cleanup — they only notice the troubleshooting getting faster afterwards.

Do you work with FortiManager-managed fleets?

Routinely. Much of my work is on estates where policies are pushed from FortiManager rather than configured per box. I audit at the ADOM and policy-package level, check where local overrides have drifted from the managed baseline, and repair the FortiManager-to-FortiAnalyzer log path. Central management done badly is worse than none, because the drift hides — so I pay particular attention to it.

Can you tune IPS without breaking applications?

That is the core of the work. IPS breaks applications when signatures are applied blindly at full severity to all traffic. I profile your applications first, enable signatures per traffic class in monitor mode, review what would have fired, and only then move to blocking. Known-fragile flows — certain banking, legacy ERP and VoIP traffic — get documented exemptions. The result is protection that is actually switched on, which a broken-and-then-disabled profile never achieves.

Do you work remotely or on-site?

Both. Assessment and audit work is largely remote, using read-only access and log extracts — there is no need for me to sit in your server room to read a config. I come on-site for failover testing, for cutover windows where hands on the console are safer, and for workshops with your team. I am based in Delhi, so on-site work across NCR is straightforward, and I travel across India when the engagement calls for it.

Talk to me about your FortiGate estate

If your rule base frightens you, your SSL inspection is switched off, or your last failover test was never, start with a conversation. Book a working session and I will tell you plainly whether you need a cleanup, a redesign or just better discipline on what you have. You can read more about how I work and where I have worked, or browse the rest of the site. Based in Delhi, working with enterprises across India.