The short version
All three make good business firewalls. The difference is what you pay for each year, what happens if you stop paying, and who is going to look after it.
- UniFi gateway. Best value for most small businesses, especially if the switches and Wi-Fi are UniFi. IPS, VPN and multi-site SD-WAN are included without a licence. There’s an optional subscription for more threat signatures, but nothing stops working without it.
- Fortinet FortiGate. The security-led choice. Deep filtering, application control, sandboxing and reporting through FortiGuard subscriptions, plus 24x7 vendor support. Budget for the renewal every year.
- Cisco Meraki MX. The polished cloud-managed choice for organisations that run many sites from a central IT team. Licensing is mandatory: let it lapse and the device stops passing traffic.
If you’re a small office with one or two sites and no compliance driver, start with a UniFi gateway and spend the difference on getting it configured properly. If security reporting, web filtering evidence or an insurer’s questionnaire is what you’re buying for, a FortiGate with the right bundle usually earns its renewal.
UniFi vs FortiGate vs Meraki MX at a glance
| UniFi gateway | Fortinet FortiGate | Meraki MX | |
|---|---|---|---|
| Intrusion prevention | Included, no licence | Included in FortiGuard bundles | Advanced Security edition or above |
| Web and category filtering | Basic filtering included; category filtering with CyberSecure | URL and DNS filtering in the UTP bundle and above | Advanced Security edition or above |
| SD-WAN between sites | Site Magic, licence-free | Included in FortiOS at no extra cost | Auto VPN in every edition |
| Remote-access VPN | WireGuard, OpenVPN, Teleport | IPsec (SSL VPN tunnel mode removed in FortiOS 7.6.3) | Client VPN |
| If the subscription lapses | Gateway keeps working; CyberSecure extras stop | Keeps firewalling; signatures go stale, category filtering blocks web traffic by default | Devices stop passing traffic after a 30-day grace period |
| Vendor support | Through the reseller and Ubiquiti | FortiCare Premium, 24x7, included in bundles | Included with the licence |
| Who it suits | Small and growing businesses, multi-site on a budget | Security-led and compliance-driven businesses | Central IT teams with many branches |
Sophos and WatchGuard sit in the same space as Fortinet: subscription-led security appliances with central management. The same questions apply if one is on your shortlist.
Fortinet vs UniFi: what is actually different?
Both route, firewall, run VPNs and inspect traffic. The difference is how deep the security goes and how it is paid for.
UniFi gateways include signature-based intrusion detection and prevention, content, country, domain and ad filtering, WireGuard and OpenVPN servers, site-to-site VPN and Site Magic SD-WAN, all without a licence. Ubiquiti’s CyberSecure subscription, launched with UniFi Network 9.0, adds a larger threat signature set powered by Proofpoint, and category-based content filtering backed by Cloudflare. At launch Ubiquiti listed it at US$99 a year for the standard tier and US$499 a year for CyberSecure Enterprise on the larger gateways. If you stop paying, the gateway carries on with the built-in protection.
FortiGate is a next-generation firewall first. Fortinet sells its security services as FortiGuard bundles:
- Advanced Threat Protection (ATP): IPS, antivirus, cloud sandboxing, application control and inline CASB.
- Unified Threat Protection (UTP): ATP plus URL and DNS filtering, video filtering and anti-botnet.
- Enterprise Protection: UTP plus data loss prevention, attack surface monitoring and IoT detection.
Every bundle includes FortiCare Premium support, which Fortinet describes as 24x7 with a one-hour response for critical issues. That’s a real difference from UniFi, where support runs through your reseller or installer.
The practical version: if you need to show an auditor or insurer which categories of website staff can reach, what was blocked and why, a FortiGate with UTP produces that evidence more naturally. If you need a solid firewall with IPS and VPN for an office, a UniFi gateway does that for a fraction of the running cost.
FortiGate vs Meraki: which way to go?
Both are subscription platforms, so the comparison is about operating model.
Meraki MX is managed entirely from the Meraki cloud dashboard. Its strength is Auto VPN, which builds site-to-site tunnels between MX appliances with very little configuration, and the same dashboard runs Meraki switches, Wi-Fi and cameras. On the co-termination model, the Enterprise edition gives you the firewall and Auto VPN only. IDS/IPS, content filtering and malware protection need the Advanced Security or Secure SD-WAN Plus edition. Meraki’s newer subscription model includes IDS/IPS and content filtering in both of its tiers.
FortiGate can be managed device by device, through FortiGate Cloud or through FortiManager for larger estates. It gives an administrator more control, and more to learn.
The licensing difference matters most. Fortinet documents that a FortiGate keeps working as a firewall if FortiGuard licences expire. IPS and antivirus keep running on the last signatures they received, but category web filtering stops and, by default, drops web and DNS traffic, so a lapse is still disruptive. Meraki is stricter: under co-termination licensing, once licences expire and a 30-day grace period passes, Meraki says devices shut down until licensing is back in compliance.
In return, Cisco states that Meraki MX appliances carry a limited lifetime hardware warranty with next-day advance replacement, which is generous.
Licensing and renewals: what are you committing to?
| UniFi | FortiGate | Meraki MX | |
|---|---|---|---|
| Licence required to operate | No | No, but security services need FortiGuard | Yes |
| Optional or recurring | CyberSecure, optional, annual | FortiGuard bundle, typically renewed annually or for a multi-year term | Licence per appliance, on a term |
| Hardware warranty | 1 year when bought through a reseller (2 years direct from Ubiquiti’s store); UI Care extends replacement cover to five years on qualifying devices | Via FortiCare | Limited lifetime, next-day advance replacement |
Meraki and Fortinet licence pricing varies by model, term and reseller, so get it quoted for the full term you plan to keep the hardware, usually five years. Put the year-six renewal in the comparison too, because that’s when businesses find out what a cheap first year really cost.
UniFi licensing and running costs covers the UniFi side in more detail.
How big a firewall does the business need?
Size the firewall against your internet speed with the security features switched on, not against its headline firewall throughput. Inspection is what slows a firewall down.
Published inspected throughput, at the time of writing (October 2026):
| UniFi (IPS routing) | Fortinet (threat protection) | Meraki MX (advanced security) |
|---|---|---|
| Cloud Gateway Ultra: 1 Gbps | FortiGate 40F: 600 Mbps | MX67 / MX68: 400 Mbps |
| Cloud Gateway Max: 2.3 Gbps | FortiGate 50G: 1.1 Gbps | MX75 / MX85: 1 Gbps |
| Dream Machine Pro / SE: 3.5 Gbps | FortiGate 70G: 1.3 Gbps | MX95: 2 Gbps |
| Dream Machine Pro Max: 5 Gbps | FortiGate 90G: 2.2 Gbps | |
| Enterprise Firewall: 12.5 Gbps |
Each vendor tests differently. Fortinet’s threat protection figure includes more inspection than a UniFi IPS figure, for example. Use the numbers to rule models out within a vendor rather than to rank vendors against each other.
Three practical rules:
- Match the inspected figure to the fastest connection, including the backup. A site on a 1 Gbps fibre or NBN service needs a model rated at or above 1 Gbps with inspection on.
- Allow for VPN. Remote staff and site-to-site tunnels use capacity the headline number doesn’t show.
- Allow for growth. Connection speeds tend to go up during a firewall’s life. Buying one size up is usually cheaper than replacing it in year three.
SD-WAN and VPN between sites
All three connect branches without a separate licence for the basic capability:
- UniFi Site Magic links UniFi sites licence-free. Ubiquiti says it supports a full mesh of up to 20 sites, or hub-and-spoke up to 1,000.
- FortiGate SD-WAN is built into FortiOS on every model at no additional cost, with application-aware path selection across multiple internet links.
- Meraki Auto VPN builds tunnels between MX appliances automatically and is included in every MX edition.
For remote staff, UniFi offers WireGuard, OpenVPN and its Teleport zero-configuration VPN. Fortinet removed SSL VPN tunnel mode from FortiOS 7.6.3 and now recommends IPsec dial-up VPN instead. If you already run FortiGates with SSL VPN, plan that change before you upgrade.
Whichever you choose, the firewall is also what fails over to your backup connection. Business internet failover covers how to design and test that.
Who manages it once it’s installed?
This decides more outcomes than the badge does.
- UniFi is approachable. Routine changes are straightforward, and a partner can monitor many sites from one console. The risk is that “anyone can change it” turns into rules nobody can explain.
- FortiGate rewards someone who knows FortiOS. Policies, inspection profiles and certificates are powerful and easy to get subtly wrong. If nobody on your side or your partner’s works in FortiOS regularly, much of what you’re paying for goes unused.
- Meraki has the gentlest learning curve of the three for multi-site work, as long as the licences are kept current.
Firmware matters on all of them. Firewalls are internet-facing, and every vendor publishes security fixes. Someone has to read the advisories and apply updates in a planned window.
Is a home firewall or the NBN router enough for a small business?
No. The modem-router your provider ships is built for a household. A business needs separate networks for staff, guests, cameras and devices with rules between them, intrusion prevention, remote access for staff and automatic failover. That’s the job of a business gateway.
Plenty of “best home firewall” lists recommend the same UniFi gateways businesses use, which is a fair sign of the value. For a business, the hardware is the smaller part. The design, the rules and someone keeping firmware current matter more. We only work with businesses, so this guide is written for offices, clinics, shops and warehouses rather than homes.
Switches for camera networks
Security integrators ask a related question: where to get reliable switches for camera networks. Three things matter more than the brand:
- PoE budget. Add up every camera’s power draw, including heaters and IR, and leave headroom.
- Separation. Put cameras on their own VLAN, with firewall rules so they can’t reach staff systems or the internet directly.
- Supply. Buy through the vendor’s authorised distribution in Australia. Ubiquiti’s warranty for reseller purchases starts from shipment to the distributor, and grey imports make warranty claims harder.
UniFi switches pair naturally with UniFi Protect, FortiSwitch is managed from a FortiGate, and Meraki MS switches sit in the Meraki dashboard. Staying on the same platform as the firewall keeps visibility in one place.
Which firewall should you choose?
Choose a UniFi gateway when you’re a small or growing business with no specific compliance driver, your switches and Wi-Fi are UniFi or about to be, and you’d rather spend on design and support than on renewals.
Choose a FortiGate when security is the main requirement, you need detailed filtering and reporting, you want vendor support around the clock, or your IT provider already standardises on Fortinet.
Choose Meraki MX when a central IT team runs many sites, values Auto VPN and one dashboard for everything, and is committed to keeping licences current for the life of the hardware.
Don’t choose UniFi when an insurer, auditor or head office requires a specific security vendor or documented 24x7 vendor support. That’s a genuine reason to pay for FortiGate or Meraki.
Mixing is normal. Many sites run UniFi switches and Wi-Fi behind a FortiGate, which keeps the access network simple and puts the security spend where it does the most good. UniFi vs Meraki vs Cisco vs Aruba vs Fortinet compares the wider platforms, and Cisco vs UniFi covers the Cisco side.
Getting a business firewall installed
We design, install and configure business firewalls and gateways for offices, clinics, retail and warehouses across Melbourne and Victoria. That covers sizing, VLAN and firewall rules, VPN for remote staff, and failover to a backup connection, with documentation at handover. Start with Ubiquiti network services, or get in touch with your internet speed, number of sites and what the firewall needs to do, and we’ll recommend the right model, including when that isn’t UniFi.
