FortiGuard Security Bundles
UTP, Enterprise Protection, ATP and SD-WAN — what is in each
- Licensing
- Per device, by bundle and term
- Bundles
- UTP, Enterprise Protection, ATP, SD-WAN
- Term
- 1, 3 and 5 year options, co-terminable with FortiCare
A FortiGate with no FortiGuard subscription is a stateful firewall with a VPN. IPS signatures, the antivirus engine, web and DNS filtering, the application control database and inline sandboxing all arrive as subscription services. Unified Threat Protection is the common mid-tier; Enterprise Protection is the broadest; ATP is narrower, centred on antivirus and sandboxing; the SD-WAN bundle covers connectivity rather than threat inspection.
Where it fits — and where it stops fitting
The trap is buying the box on a threat-protection throughput figure and then licensing a bundle that omits the services that figure was measured with. Fortinet's published threat-protection numbers assume IPS, application control and malware protection are all running — write down what you intend to switch on, and we will map it to the right bundle rather than defaulting you to the largest.
Highlights
- Bundle choice matters as much as model choice
- SD-WAN features are licensed separately from threat inspection
- Co-terminated with FortiCare and hardware
- Expired FortiGuard leaves the box passing traffic but not protecting it
Typical deployments
- Matching a bundle to the security features you will actually enable
- Renewing an estate onto one expiry date
- Auditing which subscriptions have silently lapsed
What to work out first
A FortiGate with no FortiGuard subscription is a stateful firewall with a VPN. The IPS signatures, the antivirus engine, the web and DNS filtering, the application control database and the inline sandbox all arrive as subscription services — which is why the bundle choice matters as much as the model choice.
Fortinet sells them as bundles rather than à la carte for most buyers. The Unified Threat Protection bundle is the common mid-tier. Enterprise Protection is the broadest. ATP is narrower, centred on antivirus and sandboxing. The SD-WAN bundle covers connectivity features rather than threat inspection.
The trap is buying the box on a threat-protection throughput figure and then licensing a bundle that does not include the services that figure was measured with. The published numbers assume IPS, application control and malware protection are all running.
Questions worth answering before you order
Which services does your policy actually use?
Write down what you intend to switch on — IPS, web filtering, DNS filtering, antivirus, application control, sandboxing, DLP — and buy the bundle that covers it. We will map it rather than defaulting you to the biggest one.
Are you deploying SD-WAN?
SD-WAN features are licensed separately from threat inspection. Most SD-WAN deployments need both, and that catches people out at renewal.
When does everything expire?
Hardware, FortiCare and FortiGuard can all run to different dates. We co-terminate them so the estate has one renewal date and one purchase order instead of four.
Is anything already expired?
An expired FortiGuard subscription leaves the box running with stale signatures — still passing traffic, no longer protecting it, and rarely alarming loudly enough for anyone to notice. Send us your serials for a free expiry audit.
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Per device, by bundle and term |
|---|---|
| Bundles | UTP, Enterprise Protection, ATP, SD-WAN |
| Term | 1, 3 and 5 year options, co-terminable with FortiCare |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment — tell us the numbers and we will work it through with you.
| Licensing | Per device, by bundle and term |
|---|
Sources
- Fortinet product line overview — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.