NSE 4–8 Certified Engineers Fortinet Authorised Partner · India

FortiGate Firewall Installation
& Configuration Services in India

You bought the FortiGate — now get it deployed right. Ogma's NSE-certified engineers handle everything from unboxing to go-live: initial hardening, security policies, VPN, SD-WAN, and FortiGuard subscription activation. Fixed scope. Fixed price. No surprises.

View Scope
120+
FortiGate deployments in India
3–5 Days
Typical go-live for single-site
NSE 4–8
Fortinet certifications held
7 Frameworks
Compliance baselines covered

What's Included in Every Installation

Our standard FortiGate installation scope — no hidden extras.

Initial Hardening

Admin password policies, management interface restrictions, HTTPS-only GUI access, SSH key-based authentication, unused service disablement, and FortiOS 7.4 secure baseline per Fortinet hardening guide.

Network & Interface Config

WAN, LAN, DMZ interface setup, VLAN tagging (802.1Q), routing (static + BGP/OSPF as required), NAT policies, DHCP server, DNS forwarding, and traffic shaping.

Security Policy Setup

Firewall policies with application control, IPS (Intrusion Prevention), antivirus, web filtering, and DNS filtering profiles applied. Least-privilege policy model — default deny with explicit allow.

VPN Configuration

SSL-VPN (FortiClient) for remote users — with split tunnelling, MFA (FortiToken), and LDAP/AD authentication. Site-to-site IPSec tunnels to branch offices or cloud (AWS/Azure). Up to 5 VPN tunnels in scope.

SD-WAN & WAN Redundancy

SD-WAN rule configuration for load balancing and failover across multiple ISP links. Performance SLA probes, application steering (Microsoft 365, Zoom, SAP priority), and dual-WAN failover testing.

Logging, Alerting & Handover

FortiAnalyzer or syslog configuration, email/SNMP alerting for critical events, as-built documentation (network diagram + policy matrix), 30-day post-go-live support, and knowledge transfer to your IT team.

Installation Project Tiers

Fixed-scope, fixed-price — no per-hour surprises. Excludes hardware. Tell us your appliance and scope — we'll quote within 2 hours.

Small Office
FortiGate 40F / 60F / 80F
Competitive · fixed-scope project
Sized to your appliance + policy count
  • Hardening + base config
  • Up to 20 firewall policies
  • SSL-VPN (up to 25 users)
  • 1 site-to-site IPSec tunnel
  • As-built documentation
MOST POPULAR
Mid-Enterprise
FortiGate 100F / 200F / 400F
Competitive · fixed-scope project
Sized to your appliance + policy count
  • Full hardening + policy migration
  • Up to 80 firewall policies
  • SSL-VPN + FortiToken MFA
  • SD-WAN (up to 3 WAN links)
  • Up to 3 IPSec tunnels
  • AD/LDAP integration
Large Enterprise
FortiGate 600F / 900G / 1800F+
Competitive · fixed-scope project
Sized to your appliance + policy count
  • Data centre-grade hardening
  • Unlimited policies in scope
  • Full SD-WAN deployment
  • Up to 5 IPSec/SSL tunnels
  • FortiManager integration
  • 3-month post-go-live support

* HA (high-availability) cluster deployments quoted separately. Multi-site discounts available. Travel/accommodation billed at actuals for on-site.

Why Enterprises Choose Ogma for FortiGate

Fortinet Authorised Partner

Ogma holds Fortinet Partner status with NSE 4, NSE 7, and NSE 8-certified engineers. We've been deploying FortiOS since version 5.x — across banking, manufacturing, healthcare, and government sectors in India.

Pan-India On-Site Delivery

Our engineers deliver on-site in Delhi NCR, Mumbai, Bengaluru, Chennai, Hyderabad, Pune, and Ahmedabad — with remote delivery available pan-India. No subcontracting: the same certified team who quotes is the team that deploys.

Compliance-Ready Baseline

Every FortiGate we install includes a hardening baseline aligned to CIS Benchmarks, CERT-In guidelines, and RBI Cyber Security Framework. You receive an as-built document that serves as audit evidence — ready for PCI-DSS or ISO 27001 assessors.

Our 5-Step Deployment Process

1
Kick-off & Discovery

We review your network diagram, existing firewall rules (if migrating), ISP details, AD/LDAP structure, and compliance requirements. Deliverable: deployment checklist and agreed go-live date.

2
Lab / Pre-Build

FortiGate pre-configured in our lab using your parameters — policies, VPN, SD-WAN, and VLAN structure. This cuts on-site downtime to under 2 hours for most deployments.

3
On-Site Deployment

Hardware racked, cabled, and pre-built config pushed. Parallel run with existing firewall (where possible) before cutover. Thorough UAT: connectivity, VPN, security profile validation.

4
Hardening & Compliance Check

Post-deployment hardening sweep: unused management ports disabled, FortiGuard subscriptions verified, log forwarding tested, firmware patched to latest stable release.

5
Handover & Knowledge Transfer

As-built documentation (PDF + Visio diagram), administrator walkthrough, emergency runbook, and 30-day hypercare support via WhatsApp/email included in every engagement.

Frequently Asked Questions

For greenfield (new) deployments — zero production downtime. For replacements of existing firewalls, we plan a maintenance window (typically 1–2 hours off-peak) for cutover. We do a parallel run for at least 30 minutes before removing the old firewall.

Yes. Ogma is an authorised Fortinet reseller — we can supply FortiGate hardware at competitive prices alongside the installation service. Bundled hardware + deployment packages attract a 10% discount on PS fees.

We deploy the latest stable FortiOS release (currently 7.4.x). We do not deploy GA releases that are less than 30 days old — we wait for initial patch cycles to complete. All firmware is validated against Fortinet's recommended release matrix.

Yes — for FortiGate 40F, 60F, and 80F models, remote installation (via console server or out-of-band access provided by the customer) is fully supported and reduces cost. Models above 100F are recommended on-site for physical cabling and interface validation.

Yes. FortiGuard subscription verification, activation, and profile assignment is included in scope. We confirm IPS, AV, Web Filtering, Application Control, and AntiSpam bundles are active and applied to the correct policies.

Yes — we use Fortinet's FortiConverter tool to migrate rule sets from Cisco ASA, Palo Alto, Check Point, and Sophos. Converted rules are reviewed, cleaned (unused/duplicate rules removed), and optimised before go-live. Migration from another FortiGate model is seamless.

Any issues arising from the deployment — policy issues, VPN connectivity problems, unexpected blocks — are resolved at no additional cost. Scope changes (new offices, new applications, VPN users) are quoted separately as change requests.

Ready to Deploy Your FortiGate?

Tell us your FortiGate model, your network setup, and your go-live date. We'll send a fixed-scope proposal within 24 hours.