Fortinet integrator in Switzerland
We design, deploy and operate complete Fortinet architectures — from the perimeter firewall to the management plane. Eight NSE certifications in the team, across the networking and security operations tracks.
Why this ecosystem
Stacking well-built products does not make a defence. Every console has its own logic, its own object database, its own log format. The integrator spends the time translating between tools, and the operator eventually stops correlating: the firewall alert and the endpoint alert describe the same incident without ever meeting.
Fortinet's proposition fits in one sentence: a single management plane. FortiManager pushes configuration and keeps the change history, FortiAnalyzer collects and correlates, and the devices share one object database. The value is not in any product taken alone — it is in the fact that they speak to each other natively.
Our independence from vendors remains a principle: we are not a single-brand reseller and we do not recommend Fortinet by default. But when consolidation is the right call — a heterogeneous estate to bring back under control, a small team, a traceability requirement — this is the ecosystem we know best.
Our work covers the whole cycle: audit of the existing estate, target architecture, proof of concept, migration in waves, then operations or a handover to your teams.
- Eight NSE certifications, from NSE 1 to NSE 7
- Secure Networking and Security Operations tracks
- Architecture, deployment, migration and operations
- Taking over existing estates and configuration debt
- Fortinet when it fits — never by default
The ecosystem, seen from the architecture
The products we integrate
Twenty-two references, grouped by their role in the architecture. Not all of them are justified on the same project — sorting them is part of the work.
Perimeter and remote access
The firewall remains the compulsory crossing point, but it no longer works alone. FortiGate handles filtering, TLS inspection, segmentation and SD-WAN between sites. FortiProxy takes over outbound web filtering when the volume or the granularity justify it. FortiSASE applies the same rule set to endpoints working outside the walls, without backhauling all the traffic to headquarters. FortiPAM frames administrative access: secrets vault, session recording, temporary elevation.
LAN network and Wi-Fi
FortiSwitch and FortiAP are managed from the FortiGate: one VLAN database, one policy, and segmentation stops being a document and becomes a configuration. FortiNAC identifies whatever connects — including what carries no agent, cameras, controllers, printers — and places each device in the right segment. FortiAuthenticator carries 802.1X, multi-factor authentication and session identity.
Endpoint and data
FortiClient carries the tunnel and the posture check before access is granted. FortiEndpoint and FortiEDR cover behavioural detection and remediation on the endpoint, with containment that does not wait for human analysis. FortiDLP handles the data loss side: what leaves through email, the web or removable media.
Applications and cloud
FortiWeb protects exposed applications — web application firewall, API protection, bot mitigation — where the network firewall sees nothing but legitimate HTTPS. FortiADC balances the load, terminates TLS and keeps published services available. FortiCNAPP covers cloud posture: drifting configurations, excessive permissions, vulnerable images.
Email and collaboration
FortiMail filters inbound and outbound, authenticates the domain (SPF, DKIM, DMARC) and addresses sender spoofing, which remains the most profitable vector for an attacker. FortiMail Workspace Security extends the protection to collaboration suites: shares, workspaces, hosted attachments.
Advanced detection
FortiSandbox detonates in a controlled environment what no signature recognises. FortiNDR analyses internal traffic and spots lateral movement, which crosses no perimeter firewall. FortiDeceptor plants decoys: assets that have no reason to be touched, and where the slightest contact is a signal with no false positive.
FortiManager centralises the configuration of the whole estate: policy templates, batch deployment, change history and rollback. FortiAnalyzer collects logs from every device, correlates events and produces compliance reports. This pair is what turns a collection of appliances into an operable architecture — and it is where we start on any estate takeover.
Our Fortinet certifications
Eight badges held within the team, from the fundamentals to the expert tracks. These are verifiable facts, not a commercial partnership tier.
How we proceed
Taking over an existing estate is not handled like a greenfield deployment. In both cases the migration runs in reversible waves — never as a single cutover.
This service in practice
Frequently asked questions
A Fortinet estate to design or to take over?
Describe your situation — we always start by looking at what is already there before proposing anything.