FortiPro / Blog / UTM function practically
FortiPro Blog

UTM function practically

15. 7. 2026 · 6 min read
Network switches and servers in the data cabinet

What UTM Means

UTM is an abbreviation for a set of security functions that run on a single device instead of in several separate boxes. The advantage of this arrangement is practical, one management, one overview, and the individual functions complement each other because they operate over the same traffic at the same point in the network. Which specific levels of these functions Fortinet offers and how they are licensed is described in the article about FortiGate licenses.

IPS - prevention of leaks

IPS monitors network traffic and searches for known attack patterns and attempts to exploit software vulnerabilities, for example, an attempt to exploit a vulnerability in a publicly available service before it even reaches the target. It operates in the background without user intervention, when it detects an attack, it blocks the connection before it reaches its destination, and the administrator receives a record of what happened.

When to switch on: practically always. It provides basic protection with no noticeable impact on normal operation and is one of the functions that enables a firewall to do more than just route traffic as described in the article. Firewall or just the router from your provider?

Antivirus on the gateway

It monitors files passing through the firewall, email attachments, downloaded files, and data transferred between branches. It complements rather than replaces antivirus software on individual computers; it is a second layer of control, not the sole defence. The advantage over checking only end-user computers is that malicious files can be intercepted before they even reach the user who might accidentally launch them.

When to switch on: Always wherever a firewall detects file transfer traffic, which is practically in every corporate network.

Web filter

Categorises web pages by content type and enables enabling or blocking entire categories at once, not just individual addresses manually added to the list. Blocks pages with known harmful content, not just inappropriate content: both levels (security and content) can be set independently, so a company can have strict security controls while allowing more relaxed access to regular work-related pages.

When to switch on: almost always at least in basic form, blocking harmful categories. Stricter content settings are then chosen according to the type of operation: different for an office, different for production, different for a school (more in the article). Firewall for schools).

VPN: secure remote access

A VPN creates an encrypted connection between a remote user or branch and the corporate network. It replaces the risky practice of open remote access directly from the internet to a computer desktop, which automated attacks actively seek out, such open access is among the most common ways attackers gain entry into smaller corporate networks.

When to switch on: whenever someone connects to corporate data from outside the office: a laptop away from the premises, a branch office, or working from home. For companies with multiple branches, VPN also eliminates the need to manage connectivity for each location separately.

Gradually, not all at once: None of these functions need to be switched on simultaneously and set to maximum. A sensible approach is to start with basic protection, IPS, antivirus, VPN for remote access, and then fine-tune the strictness of the web filter or deeper inspection of individual applications according to actual usage.

How to assemble functions together

No single function is sufficient on its own; only together do they form a sensible defence. IPS and antivirus detect threats directly during operation, the web filter reduces risk on the user side before harmful content even arrives, and VPN protects the connections of people working outside the company. Each function covers a different part of the path by which a problem can enter the network. That is why they do not replace each other but complement one another.

Which combination makes sense to enable for a specific operation is best determined by a brief initial network audit, not from a general list of recommendations that applies equally to every company. A smaller office will require different settings than a manufacturing plant with multiple branches or a school, even if the functions are technically identical on the same equipment. Precise configuration always depends on how the network actually looks, not on a pre-defined universal template.

We will discuss your network and we will design a solution.

Audit and architectural design within 5 working days free of charge, no obligation.

Get a free quote →