Skip to content
FortiGateFortinetcybersecuritynetwork

FortiGate: the 10 security settings to enable right after installation

Deep SSL inspection, DNS filtering, geo-blocking, MFA on admin, logging, updates: the 10 settings we apply to every FortiGate before it goes into production.

19 September 2026 · 3 min read · ALLSAFE SOLUTIONS

Secured server room

A FortiGate out of the box passes traffic and blocks little. Its value comes from configuration. Here are the ten settings we apply systematically, in this order, before declaring a firewall in production. Most take under ten minutes.

1. Secure administration

Rename the default admin account, enforce a long password, enable MFA with FortiToken, restrict the admin interface to internal networks or a VPN, and close it entirely on the internet side. A firewall manageable from anywhere is the first target of automated scans.

2. Update the firmware, then schedule

Install the latest mature release of the branch Fortinet recommends, then enable automatic signature updates. A FortiGate on two-year-old firmware is exposed to public, mass-exploited vulnerabilities.

3. Enable deep SSL inspection

Over 90% of web traffic is encrypted. Without deep inspection, antivirus and web filtering see nothing. Push the FortiGate certificate to endpoints by group policy, then switch to deep inspection, with exceptions for banking and health.

4. Attach security profiles to every outbound rule

Antivirus, web filtering, application control, IPS and DNS filtering must be attached to all rules towards the internet, not only the “default” one. A forgotten rule without profiles is a hole.

5. Filter DNS

DNS filtering blocks malicious domains before the connection even starts, including for devices without an agent: printers, cameras, IP phones. It is the most cost-effective protection in the UTP bundle.

6. Geo-block inbound

If your business receives no connections from certain countries, block them inbound: it removes a large share of intrusion attempts with no effect on your activity. VPN stays reachable from the countries your staff travel to.

7. Segment the network

Endpoints, servers, telephony, cameras, guest WiFi and IoT in separate VLANs, with explicit rules between them and security profiles internally too. That is what stops a compromised laptop from reaching the servers, a principle detailed in Zero Trust for an SMB.

8. Harden the VPN

SSL or IPsec VPN with MFA, strong encryption, and access limited to needed resources rather than the whole network. Better still: ZTNA, which exposes no port and checks the device before each connection.

9. Enable logging and send it elsewhere

Log all traffic and security events, shipped to FortiAnalyzer, FortiCloud or an external collector. A log kept only on the appliance disappears with it, and it is the first thing you need after an incident.

10. Back up the configuration and monitor

Encrypted configuration backup after every change, and monitoring of the device: availability, load, SD-WAN links, VPN tunnels, security alerts. Our clients under a managed services contract have these alerts handled by our team before they notice them.

Bonus: what to disable

SIP ALG if you run IP telephony, the cause of half of all dropped-call problems, as we explain in IP telephony: 10 mistakes that ruin call quality. And the “any to any” rules added “temporarily” during troubleshooting.

These ten points are our go-live checklist. If someone else installed your FortiGate, a half-day audit is enough to check what is missing.

Let’s talk about your project.

Free initial audit, reply within one business day.

Request a call back
← All articles
CallWhatsAppFree audit