Here are two ways a firewall problem shows up on a Tuesday morning.
In the first office, the internet is up but nothing feels quite right, and it hasn't for months. Nobody noticed that the firewall's security subscription lapsed in the spring. It kept passing traffic, so the only symptom was silence: no new threat signatures, no alerts.
In the second office, the internet is simply gone. The firewall's cloud license expired, the 30-day grace period passed while the renewal notice sat in the inbox of someone who left the company, and the appliance stopped passing traffic.
The first story is a FortiGate. The second is a Meraki MX. Both are good firewalls. They just behave very differently, and that difference should drive your choice more than any spec sheet.
The short version
| FortiGate (Fortinet) | Meraki MX (Cisco) | |
|---|---|---|
| Management | Full local interface on each device, plus central management tools | Cloud dashboard for nearly everything; a local status page covers limited settings such as the device's IP and WAN connection |
| Learning curve | Deeper and more granular; rewards experienced engineers | Simpler and faster to deploy; fewer knobs |
| Security services | FortiGuard subscriptions (sold in bundles) for IPS, antivirus, web filtering and more | Security features tied to the Meraki license tier |
| If the license lapses | Keeps firewalling and VPN; signatures go stale; category web filtering stops | 30-day grace period, then devices stop passing client traffic (co-term and per-device licensing) |
| Multi-office | Built-in SD-WAN and site-to-site VPN, very configurable | Auto VPN between MX sites is a few clicks in the dashboard |
| Best fit | Businesses that want control, detailed policy and on-box management | Businesses that want simple, consistent, cloud-managed sites |
Management: a box you log into vs. a dashboard you live in
A FortiGate is a full firewall you can log into directly. Every policy, route, VPN and security profile can be tuned on the device, and Fortinet offers central management when you have several. That depth is the point: if you need a specific routing behavior or a very particular policy, FortiGate will usually let you build it.
Meraki takes the opposite approach. Policies, VPNs and security settings are managed from Cisco's cloud dashboard, alongside Meraki switches and access points if you use them. Each device also has a local status page for a small set of changes, such as its IP and WAN settings, which is what you use when a device can't reach the cloud. The trade-off is fewer advanced options in exchange for a single, consistent screen for every site. For a business with several similar offices, that consistency is worth a lot.
Licensing: the part that decides how things break
This is the section most comparisons skip, and it's the one that causes outages.
Meraki hardware requires an active license to operate. Meraki's documentation describes a 30-day grace period after expiration; under co-termination and per-device licensing, devices then stop passing client traffic until licensing is back in compliance. Under co-termination, all licenses in the organization share one expiration date, so a lapse can affect every site at once. Meraki's newer subscription licensing handles non-compliance differently, so confirm which model you're on.
FortiGate separates the firewall from its security subscriptions. If FortiGuard lapses, the firewall keeps enforcing your rules and your VPNs stay up. What stops is the intelligence: intrusion-prevention and antivirus signatures stop updating, and category-based web filtering stops working, which, depending on configuration, can block web browsing. Firmware updates and support also depend on an active contract.
What this means in practice: with Meraki, an expired license is loud and fast. With FortiGate, it's quiet and slow. Either way, somebody needs to own the renewal date, and the notices need to go to a mailbox that someone actually reads.
Remote access
Both platforms support remote-access VPN for staff working from home, and both are only as strong as their security configuration. FortiGate pairs with the FortiClient VPN client; Meraki MX offers built-in client VPN and support for Cisco's VPN client on supported models. For most small businesses either works well. The better question is whether you want VPN at all, or whether your applications have moved to Microsoft 365 and the cloud and you mostly need secure identity and device controls instead. Our Microsoft 365 security checklist covers that side.
Multiple offices
If you have two to five offices that should behave identically, Meraki is hard to beat: Auto VPN connects MX sites to each other from the dashboard, and every site looks the same. If your offices differ, need specific routing, or you want to steer traffic across multiple internet lines by application, FortiGate's built-in SD-WAN gives you more control. We cover both approaches on our SD-WAN and VPN page, and compare site-to-site options in IPsec VPN vs. MPLS and Is SD-WAN dead?
How we decide for a client
- Choose Meraki when you want simple, cloud-managed sites, already use or plan to use Meraki switches and Wi-Fi, and value consistency over fine-grained control.
- Choose FortiGate when you need detailed security policy, local management, complex routing or SD-WAN, or you want the firewall to keep passing traffic even if a subscription is late.
- Either way, put the renewal dates on a calendar, send license notices to a shared mailbox, and review firmware and policies at least quarterly. This is part of what our managed IT clients get by default.
Sources
- Meraki Co-Termination Licensing Overview
- Meraki Per-Device Licensing Overview
- Meraki General Licensing FAQs
- Cisco Meraki Local Status Page: Overview
- Fortinet: FortiGate behavior when FortiGuard licenses are expired
Vendor details checked September 2026. Licensing and product features change; confirm current terms with the vendor before you buy.