blog

Advanced optimization and monitoring of Fortigate networks

Advanced optimization and monitoring of <span class='blue'>Fortigate</span> networks
August 6th, 2026

Challenges specific to large-scale FortiGate environments

The large-scale deployment of Fortinet FortiGate architectures for data centers, multi-site environments, global SD-WAN, advanced network segmentation and hybrid infrastructures requires a high degree of rigor. A growing number of appliances, VPN tunnels, SSL inspection, SD-WAN and high availability add a layer of operational complexity that multiplies with the number of sites managed.

For network and security teams, the challenges are manifold: maintaining complete visibility, detecting anomalies before they impact users and ensuring optimal security without sacrificing performance. These challenges make it essential to have a platform capable of collecting, correlating and analyzing heterogeneous data in real time. This is precisely where ServicePilot provides a powerful, modern solution tailored to large FortiGate infrastructures.

1. Large volume of metrics and events

FortiGate devices generate thousands of metrics and events per minute covering sessions, threats, web filtering, VPN, SD-WAN, dynamic routing and more. Without a platform capable of absorbing, correlating and visualizing this data, monitoring quickly becomes unmanageable.

2. Increasing number of appliances and sites

In large organizations, you often find HA clusters, firewalls distributed across multiple sites and appliances dedicated to specific functions. Monitoring must be centralized but it must also be capable of drilling down to the granular level of each device.

3. Hybrid monitoring: Network + Security

A FortiGate is not just a firewall. It can also serve as:

  • A router
  • A SD-WAN controller
  • A proxy
  • An IDS/IPS
  • A VPN concentrator

Monitoring must cover all these layers, without being limited to simple availability.

4. Correlation between performance and security

A CPU spike can be caused by an attack, VPN overload, misconfiguration, an application workload surge or other factors. Only a platform capable of correlating network, system and security metrics can provide a reliable view.

How ServicePilot simplifies FortiGate monitoring

1. CSV and API for Rapid Bulk Provisioning

Once the prerequisites are met (installation of ServicePilot Agents for polling, view modeling, API keys), you can deploy hundreds of firewalls in just a few seconds using a CSV file and the ServicePilot API.

A CSV file intended for ServicePilot (per package) generally contains the following information:

  • Equipment name
  • View (Group or classification folder)
  • Policies to apply
  • Collection Agent
  • User-defined tags (environment, site, criticality, etc.)
  • IP address or FQDN
  • Package-specific parameters

Each line represents an item to be monitored.

Template for firewalls:

# Creation of a Fortigate Firewall resource per site with a Poller Agent per Customer
name,oldname,view,policy,agents,description,tags,ip_address_fqdn,interfaces,interface_filter,enable_monitoring_of_sdwan,discover_only_connected_sdwan,enable_monitoring_of_ipsec

# Customer 1 Firewalls
FW1A,,C1 - Site A - Network,snmpv2,C1-Poller,,,10.1.1.1,true,*,true,true,true
FW1B,,C1 - Site B - Network,snmpv2,C1-Poller,,,10.1.1.2,true,*,true,true,true
FW1C,,C1 - Site C - Network,snmpv2,C1-Poller,,,10.1.1.3,true,*,true,true,true
...

# Customer 2 Firewalls
FW2A,,C2 - Site A - Network,snmpv2,C2-Poller,,,10.2.1.1,true,*,true,true,true
FW2B,,C2 - Site B - Network,snmpv2,C2-Poller,,,10.2.1.2,true,*,true,true,true
FW2C,,C2 - Site C - Network,snmpv2,C2-Poller,,,10.2.1.3,true,*,true,true,true
...

The CSV file is then imported into ServicePilot using a simple PowerShell script and the ServicePilot API.

2. Automatic monitoring and intelligent discovery

Once the Fortinet FortiGate package is deployed, ServicePilot automatically detects:

  • FortiGate model components
  • Interfaces
  • VPN tunnels
  • SD-WAN links
  • FortiSwitches
  • FortiAPs, etc.

3. Metrics collection and correlation

ServicePilot collects and correlates a wide range of metrics, enabling fast troubleshooting of issues affecting firewall performance:

  • Network
  • System
  • SSL VPN
  • HTTP, Voice and Messaging
  • Antivirus and IPS/IDS
  • SD-WAN
  • IPSec VPN
  • Dial-up
  • FortiSwitch
  • FortiAP
Fortigate statistics Detailed Fortigate statistics

It is also possible to add NetFlow data and logs.

The result: faster anomaly detection and a clear understanding of root causes.

4. Maps and dashboards for distributed environments

Each element is integrated into maps and ready-to-use dashboards, without the need for complex manual configuration. Large infrastructures benefit from:

  • Multi-site overviews
  • Dynamic maps
  • Consolidated dashboards
  • Drill-down to the finest-grained element
Geographic map

This allows you to switch from a macro view to a micro analysis in just a few clicks.

5. Alerting, AI, capacity and optimization

ServicePilot alerts are contextualized and take into account the role of the equipment, the site, thresholds and dependencies between services to generate relevant alerts.

ServicePilot helps you anticipate:

  • CPU overloads
  • Session limits
  • VPN congestion
  • Hardware upgrade needs

ServicePilot’s alerting mechanisms go far beyond traditional static thresholds. Using behavioral analysis models, ServicePilot’s AI automatically detects deviations from the normal behavior of each FortiGate, enabling the detection of anomalies before they impact users.

This is essential for large infrastructures where needs and growth are constant.

Typical use cases

✔️ Monitoring a fleet of 200+ FortiGate devices spread across multiple countries.
ServicePilot centralizes visibility, detects anomalies and streamlines the work of SOC/NOC teams.

✔️ SD-WAN performance analysis.
Visualize SLAs and link performance to verify the effectiveness of routing policies.

✔️ Advanced monitoring of user and site-to-Site VPNs.
Track connections, throughput, errors, congestion and usage trends.

✔️ Security and network correlation for sensitive environments.
Attack detection, impact analysis and visibility into associated performance metrics.

Why use ServicePilot for large infrastructures

Fortinet infrastructures are powerful but monitoring them can become a challenge as they expand. With ServicePilot, you get a platform that simplifies complexity, improves visibility and enhances security while optimizing performance.

  • Rapid deployment, even in large-scale environments
  • Out-of-the-box dashboards tailored for Fortinet appliances
  • Intelligent correlation, essential for large-scale architectures
  • Scalability designed for multi-site organizations
  • Relevant alerts and AI that reduce operational noise
  • Capacity analysis to anticipate future needs

Did you like the article? Feel free to share it