Case study · Cybersecurity

FortiGate HA firewall deployment for a polymer & compounding manufacturing group

The client came to us through the website quote form: one flat network, one out-of-support UTM and no visibility. We rebuilt the perimeter with a FortiGate active-passive cluster, separated production from office traffic, replaced ad hoc remote access with MFA VPN, and now run their security operations around the clock.

Client
Vadodara polymer manufacturing group
Sites
5 (1 HQ, 3 plants, 1 warehouse)
Users
480 staff, 210 OT devices
Engagement
FortiGate deployment + 24x7 managed SOC

Name withheld pending signed reference approval

How it started

The client's quote request

Every engagement starts the same way — a quote request from the website, logged with a reference the client can track in their portal. This is the request that became the project.

Reference
QR-680F230C
Package
Firewall deployment & hardening
Indicative budget
₹4–6 lakh
Send your own request
"Two plants and a head office plus a warehouse, around 480 users and a lot of production equipment on the same network. Our single UTM at head office is out of support and everything routes through it. We want high-availability next-generation firewalls, production kept separate from office traffic, proper VPN for our engineers, and someone to actually watch the alerts. Please quote deployment plus an annual support contract."
Head of IT · Vadodara polymer manufacturing groupSubmitted via the Services page quote form

The challenge

A flat network with no visibility

  • A single out-of-support UTM at head office handled internet traffic for all five sites, with no failover path.
  • Production (OT) equipment shared one flat VLAN with office laptops and guest Wi-Fi.
  • Remote engineers connected over unmanaged third-party remote-desktop tools.
  • No central logging — no one could say what had been blocked, or why, after an incident.

Results after 12 months

0
Security incidents since cutover
94%
Drop in malicious outbound traffic
11 min
Median alert-to-action time
99.98%
Firewall availability (HA pair)

How we delivered it

Seven weeks to cutover, then continuous operations

Week 1–2

1. Assess & design

  • Traffic capture and rule-base audit of the existing UTM
  • Asset discovery across OT, IT, CCTV and wireless segments
  • Interface-and-zone design with a documented policy matrix per zone pair
  • Bill of materials for a FortiGate HA pair at HQ plus branch appliances
Week 3–5

2. Deploy & segment

  • FortiGate active-passive FGCP cluster at HQ with dedicated heartbeat links
  • Virtual-MAC failover verified so sessions survive a unit outage
  • Branch FortiGates joined over IPsec with dual-ISP SD-WAN failover
  • VLAN segmentation across OT, IT, CCTV, guest and management planes
Week 6–7

3. Harden & migrate

  • IPS, web filtering, application control and deep SSL inspection profiles tuned per zone
  • SSL-VPN with multi-factor authentication replacing all third-party remote tools
  • Rule base rebuilt from 380 legacy rules to 96 explicit, logged policies
  • Phased cutover per site inside planned maintenance windows — no production stoppage
Ongoing

4. Operate 24x7

  • Central log collection and correlation with compliance-grade retention
  • 24x7 alert monitoring with defined triage and escalation runbooks
  • Monthly firmware, IPS signature and policy review with a written report
  • Quarterly tabletop incident drill with the client's IT lead

What was deployed

The stack behind it

  • FortiGate next-generation firewall HA pair (active-passive, FGCP)
  • Branch FortiGates with dual-ISP SD-WAN failover
  • Route-based IPsec VPN between all five sites
  • Managed L2/L3 switching with 802.1X port authentication
  • Controller-based enterprise wireless per SSID-to-VLAN policy
  • SSL-VPN with multi-factor authentication
  • Central logging, alerting and monthly reporting
"We went from guessing what our network was doing to getting a written report every month. The cutover happened over two weekends and production never stopped."
Head of IT · Vadodara polymer manufacturing group

Want the same visibility over your network?

We will audit your current firewall and segmentation, and give you a scoped plan with clear timelines.