Read On

In a recent project for one of our customers in the SP space, Fortinet was a clear choice for a solution to deploy CGNAT. Below summarises some of the reasons why, yet there are a number of others that could be included.

Why Fortinet?

Scale

The FortiGate Clustering Protocol (FGCP) provides failover protection, meaning that a cluster can provide FortiGate services even when one of the devices in the cluster encounters a problem that would result in the complete loss of connectivity for a stand-alone FortiGate unit. Failover protection provides a backup mechanism that can be used to reduce the risk of unexpected downtime, especially in mission-critical environments.

FGCP supports failover protection in four ways:

When session-pickup is enabled in the HA settings, existing TCP sessions are kept, and users on the network are not impacted by downtime as the traffic can be passed without reestablishing the sessions.

Synchronizing sessions between FGCP clusters is useful when data centers in different locations are used for load balancing, and traffic must be shared and flow freely based on demand.

A total of 16 clusters can share sessions.

Synchronizing sessions between FGCP clusters | FortiGate / FortiOS 8.0.0 | Fortinet Document Library

FortiOS

Port Block Allocation

Future Proof

Cost

Our view at ICT Networks is that using FortiGates for the purpose of CGNAT delivers upon the right balance of performance and cost. Any Service Provider can consider it for their future requirements when deploying CGNAT.

Written by:

Mark Maloney- CEO, ICT Networks.

July 2026

Helpful Links: