Business firewall and internet routers mounted in a comms rack, the edge device this guide compares

G U I D E

UniFi vs FortiGate vs Meraki: Business Firewalls Compared

A practical comparison of UniFi gateways, Fortinet FortiGate and Cisco Meraki MX as the firewall for a small or mid-sized Australian business.

By Jarrod Lilford, Director/Owner, Kookaburra Comms · Last updated:

For most small businesses running a UniFi network, a correctly sized UniFi gateway is the best-value firewall: IPS, VPN and multi-site SD-WAN are included without a licence, and nothing stops working if an optional subscription lapses. Choose a FortiGate when security is the main requirement and you want deeper filtering, reporting and 24x7 vendor support, and accept the annual FortiGuard renewal. Choose Meraki MX when a central IT team values its dashboard and Auto VPN and will keep licences current, because unlicensed Meraki devices stop passing traffic.

Key facts

The short version

All three make good business firewalls. The difference is what you pay for each year, what happens if you stop paying, and who is going to look after it.

If you’re a small office with one or two sites and no compliance driver, start with a UniFi gateway and spend the difference on getting it configured properly. If security reporting, web filtering evidence or an insurer’s questionnaire is what you’re buying for, a FortiGate with the right bundle usually earns its renewal.

UniFi vs FortiGate vs Meraki MX at a glance

UniFi gateway Fortinet FortiGate Meraki MX
Intrusion prevention Included, no licence Included in FortiGuard bundles Advanced Security edition or above
Web and category filtering Basic filtering included; category filtering with CyberSecure URL and DNS filtering in the UTP bundle and above Advanced Security edition or above
SD-WAN between sites Site Magic, licence-free Included in FortiOS at no extra cost Auto VPN in every edition
Remote-access VPN WireGuard, OpenVPN, Teleport IPsec (SSL VPN tunnel mode removed in FortiOS 7.6.3) Client VPN
If the subscription lapses Gateway keeps working; CyberSecure extras stop Keeps firewalling; signatures go stale, category filtering blocks web traffic by default Devices stop passing traffic after a 30-day grace period
Vendor support Through the reseller and Ubiquiti FortiCare Premium, 24x7, included in bundles Included with the licence
Who it suits Small and growing businesses, multi-site on a budget Security-led and compliance-driven businesses Central IT teams with many branches

Sophos and WatchGuard sit in the same space as Fortinet: subscription-led security appliances with central management. The same questions apply if one is on your shortlist.

Fortinet vs UniFi: what is actually different?

Both route, firewall, run VPNs and inspect traffic. The difference is how deep the security goes and how it is paid for.

UniFi gateways include signature-based intrusion detection and prevention, content, country, domain and ad filtering, WireGuard and OpenVPN servers, site-to-site VPN and Site Magic SD-WAN, all without a licence. Ubiquiti’s CyberSecure subscription, launched with UniFi Network 9.0, adds a larger threat signature set powered by Proofpoint, and category-based content filtering backed by Cloudflare. At launch Ubiquiti listed it at US$99 a year for the standard tier and US$499 a year for CyberSecure Enterprise on the larger gateways. If you stop paying, the gateway carries on with the built-in protection.

FortiGate is a next-generation firewall first. Fortinet sells its security services as FortiGuard bundles:

Every bundle includes FortiCare Premium support, which Fortinet describes as 24x7 with a one-hour response for critical issues. That’s a real difference from UniFi, where support runs through your reseller or installer.

The practical version: if you need to show an auditor or insurer which categories of website staff can reach, what was blocked and why, a FortiGate with UTP produces that evidence more naturally. If you need a solid firewall with IPS and VPN for an office, a UniFi gateway does that for a fraction of the running cost.

FortiGate vs Meraki: which way to go?

Both are subscription platforms, so the comparison is about operating model.

Meraki MX is managed entirely from the Meraki cloud dashboard. Its strength is Auto VPN, which builds site-to-site tunnels between MX appliances with very little configuration, and the same dashboard runs Meraki switches, Wi-Fi and cameras. On the co-termination model, the Enterprise edition gives you the firewall and Auto VPN only. IDS/IPS, content filtering and malware protection need the Advanced Security or Secure SD-WAN Plus edition. Meraki’s newer subscription model includes IDS/IPS and content filtering in both of its tiers.

FortiGate can be managed device by device, through FortiGate Cloud or through FortiManager for larger estates. It gives an administrator more control, and more to learn.

The licensing difference matters most. Fortinet documents that a FortiGate keeps working as a firewall if FortiGuard licences expire. IPS and antivirus keep running on the last signatures they received, but category web filtering stops and, by default, drops web and DNS traffic, so a lapse is still disruptive. Meraki is stricter: under co-termination licensing, once licences expire and a 30-day grace period passes, Meraki says devices shut down until licensing is back in compliance.

In return, Cisco states that Meraki MX appliances carry a limited lifetime hardware warranty with next-day advance replacement, which is generous.

Licensing and renewals: what are you committing to?

UniFi FortiGate Meraki MX
Licence required to operate No No, but security services need FortiGuard Yes
Optional or recurring CyberSecure, optional, annual FortiGuard bundle, typically renewed annually or for a multi-year term Licence per appliance, on a term
Hardware warranty 1 year when bought through a reseller (2 years direct from Ubiquiti’s store); UI Care extends replacement cover to five years on qualifying devices Via FortiCare Limited lifetime, next-day advance replacement

Meraki and Fortinet licence pricing varies by model, term and reseller, so get it quoted for the full term you plan to keep the hardware, usually five years. Put the year-six renewal in the comparison too, because that’s when businesses find out what a cheap first year really cost.

UniFi licensing and running costs covers the UniFi side in more detail.

How big a firewall does the business need?

Size the firewall against your internet speed with the security features switched on, not against its headline firewall throughput. Inspection is what slows a firewall down.

Published inspected throughput, at the time of writing (October 2026):

UniFi (IPS routing) Fortinet (threat protection) Meraki MX (advanced security)
Cloud Gateway Ultra: 1 Gbps FortiGate 40F: 600 Mbps MX67 / MX68: 400 Mbps
Cloud Gateway Max: 2.3 Gbps FortiGate 50G: 1.1 Gbps MX75 / MX85: 1 Gbps
Dream Machine Pro / SE: 3.5 Gbps FortiGate 70G: 1.3 Gbps MX95: 2 Gbps
Dream Machine Pro Max: 5 Gbps FortiGate 90G: 2.2 Gbps
Enterprise Firewall: 12.5 Gbps

Each vendor tests differently. Fortinet’s threat protection figure includes more inspection than a UniFi IPS figure, for example. Use the numbers to rule models out within a vendor rather than to rank vendors against each other.

Three practical rules:

  1. Match the inspected figure to the fastest connection, including the backup. A site on a 1 Gbps fibre or NBN service needs a model rated at or above 1 Gbps with inspection on.
  2. Allow for VPN. Remote staff and site-to-site tunnels use capacity the headline number doesn’t show.
  3. Allow for growth. Connection speeds tend to go up during a firewall’s life. Buying one size up is usually cheaper than replacing it in year three.

SD-WAN and VPN between sites

All three connect branches without a separate licence for the basic capability:

For remote staff, UniFi offers WireGuard, OpenVPN and its Teleport zero-configuration VPN. Fortinet removed SSL VPN tunnel mode from FortiOS 7.6.3 and now recommends IPsec dial-up VPN instead. If you already run FortiGates with SSL VPN, plan that change before you upgrade.

Whichever you choose, the firewall is also what fails over to your backup connection. Business internet failover covers how to design and test that.

Who manages it once it’s installed?

This decides more outcomes than the badge does.

Firmware matters on all of them. Firewalls are internet-facing, and every vendor publishes security fixes. Someone has to read the advisories and apply updates in a planned window.

Is a home firewall or the NBN router enough for a small business?

No. The modem-router your provider ships is built for a household. A business needs separate networks for staff, guests, cameras and devices with rules between them, intrusion prevention, remote access for staff and automatic failover. That’s the job of a business gateway.

Plenty of “best home firewall” lists recommend the same UniFi gateways businesses use, which is a fair sign of the value. For a business, the hardware is the smaller part. The design, the rules and someone keeping firmware current matter more. We only work with businesses, so this guide is written for offices, clinics, shops and warehouses rather than homes.

Switches for camera networks

Security integrators ask a related question: where to get reliable switches for camera networks. Three things matter more than the brand:

UniFi switches pair naturally with UniFi Protect, FortiSwitch is managed from a FortiGate, and Meraki MS switches sit in the Meraki dashboard. Staying on the same platform as the firewall keeps visibility in one place.

Which firewall should you choose?

Choose a UniFi gateway when you’re a small or growing business with no specific compliance driver, your switches and Wi-Fi are UniFi or about to be, and you’d rather spend on design and support than on renewals.

Choose a FortiGate when security is the main requirement, you need detailed filtering and reporting, you want vendor support around the clock, or your IT provider already standardises on Fortinet.

Choose Meraki MX when a central IT team runs many sites, values Auto VPN and one dashboard for everything, and is committed to keeping licences current for the life of the hardware.

Don’t choose UniFi when an insurer, auditor or head office requires a specific security vendor or documented 24x7 vendor support. That’s a genuine reason to pay for FortiGate or Meraki.

Mixing is normal. Many sites run UniFi switches and Wi-Fi behind a FortiGate, which keeps the access network simple and puts the security spend where it does the most good. UniFi vs Meraki vs Cisco vs Aruba vs Fortinet compares the wider platforms, and Cisco vs UniFi covers the Cisco side.

Getting a business firewall installed

We design, install and configure business firewalls and gateways for offices, clinics, retail and warehouses across Melbourne and Victoria. That covers sizing, VLAN and firewall rules, VPN for remote staff, and failover to a backup connection, with documentation at handover. Start with Ubiquiti network services, or get in touch with your internet speed, number of sites and what the firewall needs to do, and we’ll recommend the right model, including when that isn’t UniFi.

Frequently asked questions

Is Fortinet better than UniFi for a small business firewall?
It depends on what the firewall has to do. A FortiGate with a FortiGuard bundle gives deeper filtering, reporting and 24x7 vendor support, and suits a security-led business. A UniFi gateway includes IPS, VPN and SD-WAN without a licence and suits most small offices already running UniFi. Neither is better in the abstract.
Should we choose a FortiGate or a Meraki MX?
FortiGate if security features and reporting are the priority and someone on your side or your partner's knows FortiOS. Meraki MX if a central IT team wants a polished cloud dashboard and Auto VPN between sites. Both need ongoing subscriptions, but a lapsed Meraki licence stops traffic, while a FortiGate keeps working with stale signatures.
What is the best firewall for a small business in Australia?
For a typical office of up to a few dozen staff on NBN, a UniFi gateway sized for the connection is the best value, especially if the switches and Wi-Fi are UniFi. A FortiGate is the better pick where compliance, web filtering reports or an insurer's security questionnaire drive the decision.
Does a UniFi gateway need a subscription for IPS?
No. Signature-based IDS and IPS, content and country filtering, VPN servers and Site Magic SD-WAN are included without a licence. CyberSecure is an optional annual subscription that adds a larger Proofpoint signature set and Cloudflare-backed category filtering.
What size firewall do we need for a 1 Gbps NBN connection?
One whose published throughput with inspection switched on is at or above 1 Gbps, not its headline firewall figure. Several entry-level models from every vendor fall short of that once IPS or threat protection is enabled, so check the inspected figure for the features you will actually use.
Do we need a separate firewall if the NBN router has one?
For a business, yes. The modem-router your provider ships is built for homes. A business firewall gives you separate networks for staff, guests, cameras and devices, rules between them, intrusion prevention, VPN for remote staff and automatic failover to a backup connection.

Related services

Related guides

Sources

Need help applying this to your business?

Talk to Kookaburra Comms about how to put this into practice in your environment. Call 03 9008 4199 or send a message.

GET A FREE QUOTE