NETWORK SECURITY & FORTINET

FortiGate, FortiNAC and segmentation, designed and deployed hands-on.

FortiGate firewalls, FortiClient EMS and FortiNAC, designed together with the switching and VLANs they depend on. Delivered by the consultant who runs this stack day to day for a Premier League football club, across a stadium and a training ground. Utilis is independent and does not resell Fortinet hardware or licences.

2 sites A stadium and a training ground, run as one production estate, with broadcast partners on dedicated VLANs every match day.
HA FortiGate high-availability pairs, with IPS, web filtering, VPN and ZTNA, and FortiClient EMS on the endpoints.
0 Hardware or licences resold. You buy from whichever supplier you choose; we design, deploy and document.

Independent advice. Utilis Technologies is an independent consultancy. We do not resell Fortinet hardware or licences, so what we recommend is not tied to what we could sell you.

WHAT'S INCLUDED

Fortinet & network
security services.

06 — parts
01 — FIREWALLS

FortiGate HA design

Perimeter firewalls designed as high-availability pairs, with policies that are read and justified, not just inherited.

  • HA pairs, with failover tested and not assumed
  • IPS and web filtering profiles matched to each kind of traffic
  • Site-to-site and remote-access VPN, and ZTNA where it fits
02 — ENDPOINTS

FortiClient EMS

The endpoint side of the perimeter. FortiClient is deployed and managed centrally from EMS, with Intune doing the delivery.

  • FortiClient rolled out through Intune, including on macOS
  • VPN and ZTNA profiles managed from EMS, not set by hand
03 — ACCESS CONTROL

FortiNAC rollout

Network access control goes wrong when it is switched on in one go. Devices are profiled first; enforcement then arrives in phases.

  • Profiling: an honest picture of what is plugged in
  • Phased enforcement, a segment at a time
  • Printers, cameras and other headless devices given their own rules
04 — SEGMENTATION

VLAN design

Corporate, guest, operational or OT, and broadcast traffic kept on separate VLANs, with the rules between them enforced on the firewall.

  • Separate VLANs for corporate, guest, operational and broadcast traffic
  • Inter-VLAN rules written down and reviewed
  • A VLAN reference kept current after the project ends
05 — SWITCHING & AUTHENTICATION

HPE/Aruba switching and RADIUS

The switches under the firewall, and who is allowed to log in to them.

  • HPE/Aruba switching, PoE and redundant design
  • RADIUS on NPS for switch administration and Wi-Fi authentication, including moves from FreeRADIUS
  • SNMPv3 in place of older SNMP versions; syslog sent to a known collector
06 — VISIBILITY & DOCUMENTATION

Sentinel logging and documentation

Firewall and endpoint logs feeding Microsoft Sentinel, and a network someone else could pick up from the documents alone.

  • FortiGate and FortiClient EMS as Sentinel log sources
  • Read alongside domain controller, Entra sign-in and Microsoft 365 audit logs
  • A switch index and a VLAN reference handed over
WHY IT IS DONE TOGETHER

A firewall is only as good as the network behind it.

A FortiGate with good policies in front of a flat network protects very little. Network access control without clean VLANs has nothing to enforce. Switch logins shared between engineers leave no audit trail. So the firewall, switching, access control and logging are designed as one piece of work, not four.

This is one pillar of our wider infrastructure and security work, and the Premier League club engagement is written up in the case studies. Firewalls and secure configuration are two of the five controls in Cyber Essentials. If a tenant move is happening alongside the network work, see Microsoft 365 migration.

HOW AN ENGAGEMENT RUNS 04 — steps
01

Audit

Firewall policies, firmware, HA state, switch configurations, VLANs and RADIUS settings read first-hand. You get a written view of what is there and what is exposed.

02

Design

HA, segmentation and NAC policy with the trade-offs spelled out, and a hardware and licence list you can take to any supplier.

03

Deploy

Phased changes with rollback plans. NAC observes before it enforces. Work is scheduled around your busy periods, not ours.

04

Document

A switch index, a VLAN reference and runbooks. Then a standing engagement, or a clean handover to your in-house team or MSP.

FAQ

Fortinet
questions.

05 — questions
No. Utilis Technologies is an independent consultancy and does not resell Fortinet hardware or licences. You buy from whichever supplier you prefer. We specify what is needed, then design, deploy and document it.
Yes, and that is the usual starting point. The first step is an audit of firewall policies, firmware, HA state, switch configuration and VLANs, then a written list of what to fix first. New hardware is only recommended where the existing kit cannot do the job.
In phases. Devices are profiled first, so there is a full picture of what connects to the network. Policies then run without enforcement while the exceptions are found, and enforcement is switched on a segment at a time. Printers, cameras and other devices that cannot authenticate the way a laptop does get their own rules before enforcement reaches them.
By what the traffic is for and who owns it. A sensible starting point is separate VLANs for corporate devices, guest Wi-Fi, operational or OT systems, and any third-party traffic such as broadcast partners, with the rules between them enforced on the firewall.
Yes. FortiGate and FortiClient EMS logs can be sent to Microsoft Sentinel alongside domain controller, Entra sign-in and Microsoft 365 audit logs, so an investigation follows one timeline.

Further reading — Related guide: rolling out network access control without locking everyone out.

Let's look at your network.

Book a free discovery call. Bring your network diagram or just the list of things you are not sure about. You will get a straight view of what needs fixing and in what order — no obligation.