Interface reference
A separate public deployment screenshot is not used here because it would be misleading or expose account details. The official project page below is the authoritative visual reference.
Open Fortinet documentation →What Fortinet and FortiGate are
Fortinet is a cybersecurity company that manufactures the FortiGate line of next-generation firewalls (NGFWs). FortiGate appliances provide stateful firewalling, deep packet inspection (DPI), intrusion prevention (IPS), application control, VPN termination, web filtering and threat intelligence — all in a single platform backed by FortiGuard Labs' threat feeds.
FortiGate is one of the most widely deployed enterprise firewalls globally. Its application-control engine can identify and block specific applications and protocols — including VPN services like ProtonVPN, Private Internet Access, OpenVPN and WireGuard — at the application layer (Layer 7), even when they use standard ports like 443.
How I have used it
I worked with Fortinet products during my role at ITHQ Ltd as part of the managed-services security stack. This gave me practical exposure to how FortiGate policies work — including application-control policies, DPI configuration and VPN policy enforcement.
That enterprise experience directly informed the ProtonProxy egress-testing project in my lab, where I compared direct VPN connections with a Tailscale/WireGuard exit-node architecture to understand FortiGate application-control behaviour in an authorised lab. Understanding how the firewall detects and blocks VPN traffic was the starting point for designing a tunnel that survives DPI.
Why this matters
Understanding enterprise firewalls from both sides — how to configure them to enforce policy, and how to architect around their limitations — is valuable in any security or networking role. You cannot effectively defend a network without understanding what your firewall can and cannot detect, and you cannot troubleshoot connectivity issues without understanding what the DPI engine is doing to your traffic.
How to deploy or reproduce it
Use a licensed FortiGate VM evaluation or authorised appliance in an isolated lab. Configure management access, interfaces and a basic policy set before testing VPN, routing or security profiles.
Keep firmware and licences within vendor terms and avoid exposing the management interface directly to the public internet.
