FortiGate firewalls, FortiClient EMS and FortiNAC, designed together with the switching and VLANs they depend on. Delivered by the consultant who runs this stack day to day for a Premier League football club, across a stadium and a training ground. Utilis is independent and does not resell Fortinet hardware or licences.
Independent advice. Utilis Technologies is an independent consultancy. We do not resell Fortinet hardware or licences, so what we recommend is not tied to what we could sell you.
Perimeter firewalls designed as high-availability pairs, with policies that are read and justified, not just inherited.
The endpoint side of the perimeter. FortiClient is deployed and managed centrally from EMS, with Intune doing the delivery.
Network access control goes wrong when it is switched on in one go. Devices are profiled first; enforcement then arrives in phases.
Corporate, guest, operational or OT, and broadcast traffic kept on separate VLANs, with the rules between them enforced on the firewall.
The switches under the firewall, and who is allowed to log in to them.
Firewall and endpoint logs feeding Microsoft Sentinel, and a network someone else could pick up from the documents alone.
A FortiGate with good policies in front of a flat network protects very little. Network access control without clean VLANs has nothing to enforce. Switch logins shared between engineers leave no audit trail. So the firewall, switching, access control and logging are designed as one piece of work, not four.
This is one pillar of our wider infrastructure and security work, and the Premier League club engagement is written up in the case studies. Firewalls and secure configuration are two of the five controls in Cyber Essentials. If a tenant move is happening alongside the network work, see Microsoft 365 migration.
Firewall policies, firmware, HA state, switch configurations, VLANs and RADIUS settings read first-hand. You get a written view of what is there and what is exposed.
HA, segmentation and NAC policy with the trade-offs spelled out, and a hardware and licence list you can take to any supplier.
Phased changes with rollback plans. NAC observes before it enforces. Work is scheduled around your busy periods, not ours.
A switch index, a VLAN reference and runbooks. Then a standing engagement, or a clean handover to your in-house team or MSP.
Further reading — Related guide: rolling out network access control without locking everyone out.
Book a free discovery call. Bring your network diagram or just the list of things you are not sure about. You will get a straight view of what needs fixing and in what order — no obligation.