FortiGate: the 10 security settings to enable right after installation
Deep SSL inspection, DNS filtering, geo-blocking, MFA on admin, logging, updates: the 10 settings we apply to every FortiGate before it goes into production.
19 September 2026 · 3 min read · ALLSAFE SOLUTIONS

A FortiGate out of the box passes traffic and blocks little. Its value comes from configuration. Here are the ten settings we apply systematically, in this order, before declaring a firewall in production. Most take under ten minutes.
1. Secure administration
Rename the default admin account, enforce a long password, enable MFA with FortiToken, restrict the admin interface to internal networks or a VPN, and close it entirely on the internet side. A firewall manageable from anywhere is the first target of automated scans.
2. Update the firmware, then schedule
Install the latest mature release of the branch Fortinet recommends, then enable automatic signature updates. A FortiGate on two-year-old firmware is exposed to public, mass-exploited vulnerabilities.
3. Enable deep SSL inspection
Over 90% of web traffic is encrypted. Without deep inspection, antivirus and web filtering see nothing. Push the FortiGate certificate to endpoints by group policy, then switch to deep inspection, with exceptions for banking and health.
4. Attach security profiles to every outbound rule
Antivirus, web filtering, application control, IPS and DNS filtering must be attached to all rules towards the internet, not only the “default” one. A forgotten rule without profiles is a hole.
5. Filter DNS
DNS filtering blocks malicious domains before the connection even starts, including for devices without an agent: printers, cameras, IP phones. It is the most cost-effective protection in the UTP bundle.
6. Geo-block inbound
If your business receives no connections from certain countries, block them inbound: it removes a large share of intrusion attempts with no effect on your activity. VPN stays reachable from the countries your staff travel to.
7. Segment the network
Endpoints, servers, telephony, cameras, guest WiFi and IoT in separate VLANs, with explicit rules between them and security profiles internally too. That is what stops a compromised laptop from reaching the servers, a principle detailed in Zero Trust for an SMB.
8. Harden the VPN
SSL or IPsec VPN with MFA, strong encryption, and access limited to needed resources rather than the whole network. Better still: ZTNA, which exposes no port and checks the device before each connection.
9. Enable logging and send it elsewhere
Log all traffic and security events, shipped to FortiAnalyzer, FortiCloud or an external collector. A log kept only on the appliance disappears with it, and it is the first thing you need after an incident.
10. Back up the configuration and monitor
Encrypted configuration backup after every change, and monitoring of the device: availability, load, SD-WAN links, VPN tunnels, security alerts. Our clients under a managed services contract have these alerts handled by our team before they notice them.
Bonus: what to disable
SIP ALG if you run IP telephony, the cause of half of all dropped-call problems, as we explain in IP telephony: 10 mistakes that ruin call quality. And the “any to any” rules added “temporarily” during troubleshooting.
These ten points are our go-live checklist. If someone else installed your FortiGate, a half-day audit is enough to check what is missing.
Let’s talk about your project.
Free initial audit, reply within one business day.





























