Sophisticated Linux Implant Discovered Compromising Fortinet Network Security
paulponraj.com
paulponraj.com
But at the end of the day I couldn't get over that no matter how many flaws or bypass I'd find in their products - they just didn't give a shit. Fortinet checks the box for SMB and SLED. It's cheap, it mostly works and they've got a lot of flexibility with how they can integrate. But I never really viewed them as a serious security company. Seeing it from the inside was an eye opener. I had worked for Palo Alto Networks as well and the conversations with PM there were much different.
Given how FortiOS is built, I'd guess there's a lot of other bugs lurking. I especially wouldn't recommend any of these network security manufacturers for VPN. All of them are garbage no matter who you buy. But Fortinet... No way.
What are your alternatives though? Watchguard is another home rolled Linux distro on a box under the hood, SonicWall is a mess, Ubiquiti got rid of their dev team and replaced them with non-US talent, which has caused severe stagnation in their routing products.
I only really trust OpenWRT and Mikrotik, but the latter requires a fair bit of learning and most MSPs and IT groups aren't game for either.
Perhaps select areas of their engineering and business were exemplary and pristine. You don't want anything that touches that to be noticeably shoddy.
A corporate VPN is a "You Had One Job..." situation, and it's very hard job to do sufficiently well.