FortiGate is a volume NGFW with a subscription fabric around it. SecureGuard is a self-hosted next-generation firewall / UTM you run on hardware you own. Objects and zones are one document. You preview the rendered daemon diff, commit atomically, and roll back by id. There is no FortiGuard subscription required to pass packets. We do not sell MDR.
- Community is a working firewall at $0 — same image, small scale, not a countdown.
- No FortiGuard subscription to pass packets. Preview, commit, rollback by id.
Is Community a real FortiGate alternative at $0?
Yes. Community is a working next-generation firewall / UTM at $0: named objects, zones, one canonical document, preview, commit, rollback by id. Same image as paid tiers, at small scale. Packets pass without a FortiGuard subscription. It is not a trial timer.
Does the AI change the firewall on its own?
No. The AI layer proposes changes. A human commits. We do not advertise auto-block. This is not MDR.
Do I need a FortiGuard-style subscription to pass packets?
No. Community at $0 is a working appliance: objects, zones, NAT, preview, commit, rollback. Paid tiers widen scale; they are not a meter on packets.
FortiGate publishes named application control; SecureGuard does not ship that — application control, anti-spam, identity in policy, and off-box analysis are coming soon.
Generic UTM-to-appliance move: UTM replacement. How rollback works: rollback is an id. What is actually built: Platform. Sophos UTM specifically: /sophos-utm.