Good day, ladies and gentlemen, and welcome to the Fortinet Q2 2019 earnings announcement. At this time, all participants are in a listen-only mode. Later, we will conduct a question and answer session, and instructions will be given at that time. If anyone should require assistance during the conference, please press star then zero on your touchtone telephone. As a reminder, this conference call may be recorded. I would now like to introduce your host for today's conference, Mr. Peter Salkowski, Vice President of Investor Relations. Sir, you may begin.
Thank you, Crystal. Good afternoon, everyone. This is Peter Salkowski, Vice President of Investor Relations at Fortinet. I am pleased to welcome everyone to our call to discuss Fortinet's financial results for the second quarter of 2019. Speakers on today's call are Ken Xie, Fortinet's Founder, Chairman, and CEO, and Keith Jensen, CFO. This is a live call that will be available for replay via webcast on our Investor Relations website. Ken will begin our call today by providing a high-level perspective on our business. Keith will review our financial and operating results and conclude by providing our guidance for the third quarter of 2019. He will provide an update for the full-year guidance before opening the call for questions. During the Q&A session, we ask that you please keep your questions brief and limit yourself to one question and one follow-up question to allow others to participate.
Before we begin, I'd like to remind everyone that on today's call, we will be making forward-looking statements, and these forward-looking statements are subject to risks and uncertainties, which could cause actual results to differ materially from those projected. Please refer to our SEC filings, and particularly the risk factors in our most recent Form 10-K and Form 10-Q for more information. All forward-looking statements reflect our opinions only as of the date of this presentation, and we undertake no obligation and specifically disclaim any obligation to update forward-looking statements. All references to financial metrics that we make on today's call are non-GAAP unless otherwise stated. Our GAAP results and GAAP to non-GAAP reconciliation can be found in an earnings press release and in the presentation that accompany today's remarks, both of which are posted on the investor relations website.
Lastly, all references to growth are on a year-over-year basis, unless noted otherwise. I will now turn the call over to Ken.
Thanks, Peter, and thank you to everyone for joining to this call to discuss our second quarter 2019 result. We are pleased with our strong billings, revenue, operating margin, and cash flow performance during the quarter. Our advanced technology, integrated Security Fabric architecture, broad cloud offering, and secure SD-WAN all contribute to a solid market share gain in the quarter. Increased performance from our infrastructure security and cloud offerings drove total billing growth of 21%, well above the industry average. Non-FortiGate billing was 27% of total billing for the quarter. Revenue was up 18% to $522 million, driven by strong service revenue growth. Product revenue growth was consistent with the 14% increase we achieved in the first quarter, despite a significant and more difficult earlier year comparison.
Today, Fortinet announced three new high-performance next-generation firewalls, the FortiGate 1100E, FortiGate 2200E, and FortiGate 3300E, which illustrate our superior technology advantage and enable our position to securely accelerate the on-ramp to the cloud. Traditional network parameters are dissolving as mobile, cloud, and IoT technology changes the way people work, as well as the volume of data they needed to secure. Fortinet is a leader in hybrid cloud and edge security. During the quarter, we announced the addition of FortiWeb Cloud, Web as a Service to our cloud security portfolio offerings. This SaaS solution enables rapid application deployment. Additionally, Fortinet provide one of the broadest management as a secure service and security as a service offerings. These cloud offerings are easy to implement, easy to integrate, flexible, and scalable. The exploration of IoT technologies is accelerating the movement of data and computing power to the edge.
According to Gartner, 70%-80% of edge data never get to the data center to be processed, and within the next two years, 40% of large enterprise will integrate edge computing, up from 1% in 2017. The ability to offer security-driven networking and at edge with low latency and high performance is critical, especially with the deployment of 5G networks. Only Fortinet offers security and networking into a single secured SD-WAN solution, and our offering is clearly resonate with enterprise customers. During the quarter, the number of customers adopting Fortinet secure SD-WAN solution more than doubled from the previous quarter. Going forward, we see four drivers of market share growth for Fortinet. First, our refreshed portfolio of FortiGate with integrated secure Wi-Fi, SD-WAN, and 5G products are leading a transition to security-driven networking and continue to gain network security market share.
Second, Fortinet Security Fabric offer a broad, automated, and integrated secure solution for end-to-end protection as organizations consolidate towards a fewer security vendors. Third, Fortinet provide a broad range of hybrid and multi-cloud deployment. Fourth, our OT and IoT security offering with FortiASIC SPU technology continuing to provide a cost and performance advantage versus the competition. I want to thank the Fortinet team and our partners for their ongoing hard work and our customers for their support. Now I will turn the call over to Keith for a closer look at our second quarter performance and our guidance for the third quarter and full year.
Thank you, Ken. Before I start, I'd like to note, except for revenue, financial amounts are non-GAAP and growth rates are based on comparisons to the second quarter of 2018, unless otherwise stated. The slide references I make refer to the presentation posted on our investor relations website. One quick housekeeping note, we made one modification to the billings by product family slide by moving the FortiGate 100 series from the entry-level to the mid-range product family. FortiGate appliances below the 100 series are desktop appliances. Mid-range FortiGates, including the 100 series, are higher performing rack-mounted appliances. For your benefit, we have provided the product family billing trends under both the old and new approaches. I'd now like to summarize our strong second quarter performance. As Ken mentioned, total revenue of $522 million was up 18%, led by service revenue growth of 21%.
On a geographic basis, revenue growth was strong for both the Americas and APAC. Product revenue of $190 million was up 14%. Despite a significantly more difficult year-earlier comparison, product revenue growth was consistent with the first quarter of 2019. Product revenue benefited from the continued success of the E-series and Fabric products. Service revenue grew 21% to $332 million, driven by a 24% increase in FortiGuard security subscriptions. FortiCare technical support and other services increased 16% to $149 million. As shown in our second quarter results, service revenue continues to experience strong growth, improving margins, and offers a high level of predictability. To illustrate these points, I would note, service revenue represents 64% of total revenue, up over 100 basis points. Services gross margin was 87.3%, up 50 basis points.
Deferred revenue provided approximately 90% of service revenue and 60% of total revenue. In the third quarter, we expect similar percentages of service and total revenue to come from our existing deferred revenue balance. Total deferred revenue increased 27% to $1.9 billion. Short-term deferred revenue increased 21% to $1 billion. Turning to billings. Total billings grew 21% to $622 million, driven by strong growth from Security Fabric, cloud, and the secure SD-WAN firewall use case. On a geographic basis, both the Americas and the international emerging regions had strong quarters. Consistent with our prior comments regarding duration, average contract term increased one month year-over-year to approximately 27 months. Service providers and MSSPs remain one of our top customer segments, accounting for 15% of total billings.
Increasing industry diversification, including strong growth from government and financial service verticals, led to a 21% increase in billings. Deals over $1 million increased 28% to 46. The total dollar value of these deals increased 37%. We are pleased with the geographic and customer diversity we are seeing in these large deals, with nearly 40% coming from EMEA and APAC. Consistent with prior quarters, our largest deal in the quarter was significantly less than 2% of total billings. Clearly, our business is not dependent on a handful of large deals in any given quarter. The number of deals over $250K increased 33% to 346, and the number of deals over $500K increased 30% to 147. Network security product and service billings increased 19% and accounted for 73% of total billings.
New firewall use cases, including operational technology and secure SD-WAN, continue to provide a strong tailwind to FortiGate product and service billings growth. Secure SD-WAN was a leading contributor in the quarter and included six deals in excess of $1 million. Non-FortiGate product and service billings grew faster than network security billings, driven by strong growth in infrastructure fabric, cloud, and secure SD-WAN. Moving back to the income statement, gross margin improved 100 basis points to 76.4%. Product gross margin improved 110 basis points to 57.6%. Operating margin increased 250 basis points to 23.6%. Operating expense leverage and the gross margin improvement I just mentioned easily offset a small decrease in the benefit from the change in commission accounting. Total headcount increased 15% to 6,293. Given our strong operating income performance, GAAP net income was $73 million. Moving to the statement of cash flow summarized on slide seven and eight.
Free cash flow was $178 million, up 36% year-over-year, resulting in a free cash flow margin of 34%, up 450 basis points year-over-year. The increase reflects strong second quarter billings and collections, continued inventory management, and the flow-through of the increase in operating profit to net income. Capital expenditures for the second quarter were $17 million. We expect third quarter capital expenditures of between $40 million and $50 million. Given lighter than anticipated construction spending for the first half of the year, our 2019 capital expenditure guidance moved slightly lower to between $110 million and $130 million. Our internal free cash flow models are in sync with the current street consensus estimate for the full year and reflect increased spending on the new campus building in the second half of the year.
In the quarter, we repurchased 470,000 shares of common stock for a total cost of $35 million, or an average per share price of approximately $73.50. At the end of the second quarter, the remaining share repurchase authorization was $643 million and is set to expire at the end of this year. As I turn to the guidance provided on slide nine, I'd like to remind everyone that the forward-looking disclaimer Peter presented at the start of the call applies to the guidance I'm about to provide. For the third quarter, we expect billings in the range of $600 million-$615 million. Revenue in the range of $525 million-$540 million. Non-GAAP gross margin of 75.5%-76.5%. Non-GAAP operating margin of 23%-23.5%. Non-GAAP earnings per share of $0.55-$0.57, which assumes a share count of between 177 million and 179 million.
We expect a non-GAAP tax rate of 24%. For 2019, we expect billings in the range of $2,510 million to $2,540 million. Revenue in the range of $2,100 million to $2,120 million. Total service revenue in the range of $1,340 million to $1,360 million. Non-GAAP gross margin of 75.5%-76.5%. Non-GAAP operating margin of 23%-23.5%. Non-GAAP earnings per share of $2.23-$2.26, which assumes a share count of between 177 million and 179 million. We expect the non-GAAP tax rate to be 24%. We expect cash taxes to be between $52 million and $54 million. Before I turn the call back over to Peter, I'd like to thank our partners, our customers, and the Fortinet team for all their support and hard work. I'll now hand the call back over to Peter.
Thank you, Keith. Operator, we are ready for the Q&A session, please.
Thank you. Ladies and gentlemen, if you have a question at this time, please press the star followed by the number 1 key on your touch- tone telephone. If your question has been answered or you wish to remove yourself from the queue, please press the pound key. In the interest of time, we do ask that you please limit yourself to one question and one follow-up. Again, ladies and gentlemen, that's star 1 to ask a question. Our first question comes from Shaul Eyal from Oppenheimer. Your line is open.
Thank you. Good afternoon, gentlemen. Congrats on the strong performance and the improved outlook. Keith, Ken, I'm curious from good acceleration on the SD-WAN front. You've mentioned six deals in excess of $1 million. What's driving this healthy demand and acceleration you're seeing? Can you talk to us about some of the drivers on that front? I have a follow-up.
Yeah, this is Ken. Like I said previously, we believe the infrastructure and we call the security-driven networking side more and more important because the border-secured enterprise disappearing. Almost all attacks come from the internal. That's where the SD-WAN secure all these WAN connection, branch office, and together with internal segmentation security, starting to get more and more important. That's why we see the SD-WAN as a market, as a whole infrastructure security approach. That's the vision we have for the last few years and starting building, we call the security-driven networking infrastructure, and we see more successful for this approach.
Got it. I think we picked up some solid performance during the quarter within the federal arena. Can you provide us with your views on that vertical, how you view it down the road expanding second half this year and into 2020? Just initial thoughts. What specific products and services are you pushing within this vertical?
Shaul, this is Keith. I would probably just step back a tad bit and note that our government vertical includes not only the U.S. government, but also international government agencies as well as state and local government agencies.
Sure.
I think what we thought of the growth in the quarter was actually more on the international front than it was domestically. It'd be a little difficult to respond specifically to other products, if you will, in that segment you're speaking to.
Got it. Okay. That's fair enough. Thank you so much.
Thank you. Our next question comes from Sterling Auty from JP Morgan. Your line is open.
Thanks. Hi, guys. Through much of this quarter, after the March quarter results, there was that healthy debate again about where we are with firewall refresh and what impact the shift to the cloud is going to have on firewall demand, et cetera. You mentioned the use cases. I wonder, Ken, if you could just kind of chime in and give us a sense, what do you think the industry growth opportunity looks like for the core firewall and network security moving forward?
I think the industry is in the transition. The traditional refresh of the firewall, which you see like four, five, six years ago, using the next-gen firewall UTM replaced the traditional connection based of our VPN, is probably only part of the solution now. You need to have the whole infrastructure, like from the firewall connect with all these different kind of SD-WAN, the Wi-Fi, some endpoint, and also the web, and also the cloud. IoT need to be all kind of considered together. I feel that's the new trend. That's also easy to manage and consolidate all these kind of different solution is starting to get more and more important because the management cost starting to get higher for the security. That's where we see the approach we call the whether infrastructure security or security networking, really combine this together, starting to get more important.
That's where the traditional enterprise refresh still going on. I think if you compare to a few years ago, we have a less market share compared to some competitor in enterprise. We are not being impact or influenced very much about the refresh cycle. We do see we have a more broad offering, and most come from internal developed, which integrate and automate in day one, which has much better, kind of easy to manage compared to some competitor come from acquired product. At the same time, the ASIC SPU give us huge performance advantage, especially when you deploy internally and in the very fast local area network. At the same time, when you have the infrastructure approach and also the other IoT, that's where the ASIC advantage that we call SPU, security processor unit, and also starting to get bigger and bigger.
At the same time, once we have bigger market share, the cost per chip also starting to get lower. The economy of scale also start in play. That's making our margin keep improving. I think all this will help us to position going forward for the trend. I believe this kind of infrastructure security trend will keep going in the next 10, 20 years, and we are well-positioned for that change.
Excellent. Maybe one quick follow-up. The Capital One breach, AWS back in the news, probably for the first big high-profile breach since maybe the PlayStation hack back a number of years. Do you think this would be the motivating factor to drive virtual firewall adoption in the cloud?
First, I feel I don't think it will impact the Q2 number, and it just happened very recently. At the same time, this definitely makes people more kind of consider security is more important. On the other side, if you put too many things into a single cloud location, that also can be more risky. That's where from time to time, keep saying you need to have certain balance among the cloud and edge. Different application, different data, you need to have a different way and multiple layers to secure it.
Got it. Thank you.
Thank you.
Thank you. Our next question comes from Brad Zelnick from Credit Suisse. Your line is open.
Great. Thanks so much for taking the questions, congrats on a very clean quarter. I've got one for Ken and a follow-up for Keith. Ken, you talked about more opportunities as network architecture and security moves to the edge, I know this means different things to different people, if I look at the lower-end FortiGate appliances ticking down a bit and seeing some other vendors out there with cloud proxies and customers doing local internet breakouts at the branch office, how, if at all, is this impacting your business, how is Fortinet helping customers as they think about network transformations?
I do believe the low end will start and pick up because we're in the middle of refreshing. Like last quarter, we announced the first product, FortiGate 100F, using the new SoC4. I think going forward, there's a few other new product in the low end will come up using the leverage SoC4, which has a performance probably easily 3 to 5x better than the previous version. That's where we're helping drive the low-end growth. On the cloud side, I do see cloud is really as additional, it's complement to what we offer from the infrastructure and also the edge computing. It's a part of the solution. We don't feel it's cloud will be reduced on-premise and also in the edge.
Also the edge, I feel, probably even grow faster than the cloud in the next few years, because from the deployment, from the advantage of the edge compared to cloud, you need to have both solution. They say the edge will eat a cloud. I do believe both will be existing, but the edge computing, edge security need to be more emphasized, addressed, especially we have advantage using the ASIC chip, and it's a lot of application because the real-time, the latency requirement, you had to process it in the edge. In security, I keep saying, edge is good for the prevention, which need to be real-time process, and the cloud will be good for management and certain storage, which may not have to deal with real-time, and also could be for detection.
If you want to do the prevention and inline real-time protection, probably edge has more advantage.
Thank you so much.
If I could just add to Ken's commentary just quickly. I wouldn't lose sight of the fact when you're looking at the mix shift, if you will, on our reporting between low, mid, and high, what I think is actually happening there to a large extent is you're seeing the success of the E-series in the mid-range product family in some ways causing a mix shift. We've talked about the 400 and 600 that we introduced earlier this year as coming online. I've also talked about the 500E for several quarters now, and just to extend that conversation one step further, I would note that when I compare the 500E to its predecessor, 500D, it's moving at about three or 400% faster than its predecessor did.
When I look at those types of numbers, I think you're starting to see the success in the mid-range really skew that mix for us.
That makes total sense, Keith. Just a quick follow-up, a housekeeping item that I might have missed in your prepared remarks, but did you tell us what the year-on-year FortiGate unit shipment growth was? I didn't catch that.
I did not, but I can share that it moved in tandem with product revenue growth, and that's also consistent with the first quarter of this year, moving in tandem with product revenue growth numbers.
Excellent. Thank you so much for taking the questions, guys.
Thank you.
Thank you. Our next question comes from Andrew Nowinski from Piper Jaffray. Your line is open.
Hey, great. Thank you. Congrats on a nice quarter. I wanted to ask about the million-dollar deals that you had. It was very strong growth. Just wondering if you could provide any more color on the drivers of that and whether it was higher sales capacity or as simple as just having a broader portfolio of products now.
I think, Andrew, it's Keith, I'm sorry. I try to make the effort to note, one, the contribution from SD-WAN, which I think was six of the 46 deals that we saw there. We do see ourselves getting deeper into our enterprise installed base, which is driving those larger deals, and continued progress in the enterprise space. I think as if we mapped it out several quarters ago in terms of what our expectations were in terms of moving in that direction, I think you're seeing that reflected in those million-dollar deals.
Also one other point I want to add is really the multi-product sales we call the Fabric, also starting and doing better. That's where you see the non-FortiGate starting grow faster than the FortiGate. That is making a total infrastructure solution. That's also helping make the deal larger.
Okay, got it. Just a follow-up. As it relates to EMEA, it looked like your growth may have decelerated a little bit, relative to last quarter. That is consistent with a lot of other vendors and what they've reported in EMEA. Just wondering, was that just due to the macro in EMEA, or were there some other factors there?
Probably the comparison is a little bit tough, and also, the U.K. has maybe a little bit uncertainty.
Yeah, I think you're spot on with that, Ken. I do think it was a tough compare coming off of last year. Our EMEA number includes Europe, continental Europe, as well as what we call international emerging, which actually performed very well in the quarter. Going back to Europe, yeah, I think what we're sensing there is consistent with the commentary that we've read from other reports, if you will. As Ken noted, the U.K. seems to be in a bit of a doldrums, if you will, across industries, and I think we saw that as well.
Great. Thanks. Keep up the good work, guys.
Thank you.
Thank you. Our next question comes from Jonathan Ho from William Blair. Your line is open.
Hi. Good afternoon. I'd like to echo my congratulations as well. I just wanted to maybe start out with a little bit of color in terms of your go-to-market and channel engagement, and can you maybe give us a sense of what's been successful there, and has this sort of helped drive some of the larger enterprise deals?
Ken and I are arguing about who's going to give the good news, I guess. I think we've matured, we're closer to our partners, and we're better at getting their insights and feedback about what they're looking for to be successful. I think we are mature and becoming more operationally focused. You're seeing us make greater and greater use to protect our channel partners of things like deal registration and applying that very broadly. I'm very pleased with the performance of our channel leadership team as well as everybody on our channel team and how they are engaging with the channel.
We have a better tool today compared to a few years ago to effectively measure the effectiveness of whether the pipeline or the sales productivity, and how each program perform. That's also helping to drive the better efficient growth.
Got it. Just to follow up on the SD-WAN questions that have been asked. I'm just trying to understand, when you look at sort of the SD-WAN opportunities that are out there, my understanding is that people can choose either a cloud solution or maybe a software-defined solution or traditional appliance. What type of mix are you seeing out there as people start to make this shift in terms of their edge opportunities?
For us, we put SD-WAN function inside a FortiGate, part of FortiOS function there. That will give them an integrated single box solution, cover both on the security, SD-WAN networking, all this together, make it very easy to manage. This also can tie to different application which need to be secured. That customer like the solution. Also because we have ASIC advantage built in the FortiGate, there's all the ASIC, especially SoC4, the new one, which can have a much better cost performance compared to some other SD-WAN solution, which if they're using the general purpose CPU, whether the cost very high or they don't have additional computing power to do the security, or they have to have a multiple box solution. That's the advantage, is very huge.
Once we keep investing in marketing sales coverage in this space, we do believe we'll become a leader in the space.
Jonathan, it's Keith. Ken, just let me add to that a little bit for more context. Clearly, in terms of form factors for us, it's a FortiGate appliance that's dominating the SD-WAN market. To add just a tad bit more on that, when you look at it's fairly evenly spread across low-end, mid-range, and high-end FortiGates. It also drags along with it a certain amount of fabric products, but it also brings with it about 70% on average of the BOM is a service component of the mix.
Thank you.
Yeah, the SD-WAN also helping increase the percentage of a service revenue and also match our, we call the wider security-driven networking, or we call the infrastructure security better. It's more like a total solution. Drives some other product sales.
Thank you, and congrats on the strong quarter.
Thank you.
Thank you.
Thank you. Our next question comes from Saket Kalia from Barclays. Your line is open.
Hey, guys. Thanks for taking my questions here. Hey, Keith, maybe just to start with you. You mentioned the service provider business, I think, was about 15% of billings, one of the top verticals, obviously, for Fortinet. Very strong 2018. How are you thinking about that vertical here in 2019?
Yeah, I'm not going to guide the vertical specifically, of course, but I think that what across industry we're seeing was a very strong 2018, whether that was because of tax reform or what have you. The carrier infrastructure seemed to go very well in 2018. When you look at 2019, there's probably really three components of that business. There's that infrastructure for the carrier. There's also the MSSP, there's also the selling with the carriers. I think it's the first one that's been a little more challenged across industries in the first half of this year. You probably couple that with a significant amount of, well, digestion of last year's acquisitions, if you will, of products. Also the mergers and consolidations that are going on in the industry this year are probably causing them to give them a little bit of a pause.
Got it. That's helpful. Ken, maybe for you. A lot of success in core network security with SD-WAN. Maybe outside of the appliance business, I think some questions were asked earlier just about Capital One and public security. Can you just talk a little bit about the public cloud security business at Fortinet, and maybe specifically where you feel the virtual firewall offering is versus competitors, versus where you'd like to see it?
Our approach for the public cloud, hypercloud is a little bit different than competitor. We have the broadest offering, cover both from the cloud provider and also on the function. We have nine or 10 different function from the traditional FortiGate to the FortiWeb, to the mail, to the FortiSIEM, to all these different application. Also they can easily move from cloud provider to cloud provider for the enterprise. This approach give the flexibility for the enterprise customer to adopt different kind of cloud provider or different function based on their need. Same time, we have all this on-premise, also the other thing, if you want to access the cloud, we also have very strong FortiGate with SSL encryption performance. That's also helping both on the cloud side and also on the edge side. That's how this helping.
We see the cloud growth definitely faster than the overall billing growth, and we still feel that cloud is a part of a whole infrastructure security, will continue keeping driving the growth, but which also can help in the on-premise and the edge growth.
Very helpful. Thanks, guys.
Thank you.
Thank you. Our next question comes from Keith Bachman from Bank of Montreal. Your line is open.
Thank you very much, and congratulations on the results, including Keith. Continued good operating cash flow growth. I wanted to ask two questions. The first, Ken, I wanted to direct towards you, and it is a competition question, but along a different metric or different vertical. What I mean by that is, you've talked about the cloud, but I specifically wanted to ask you about your views on the competitive threats or opportunities from the offload engines like Zscaler. Why or why not do you see this as a competitive threat to Fortinet, or do you think you can actually, in some ways, participate in this market through either partnership or directly?
I think we are a little bit more on the partner side, because some application can feed into the Zscaler forward the traffic to the cloud or to their whatever service data center. Some other application, you still need to have all these edge device, like SD-WAN, to keeping the traffic forward to the cloud. Basically, they also need to deal with the local traffic. A lot of security issue we see is infrastructure security, internal segmentation, that also cannot be addressed by this cloud approach. I see it's really the mixed infrastructure hybrid solution is much better than just everything go to the cloud. Also from time to time, just like some other service provider want to offer similar service, we are more behind supporting this kind of solution.
We feel, we just play with our advantages, which can give a much better, strong performance as computing power and also the infrastructure, the total Security Fabric solution, compared with just a different vendor. They may offer some solution good for certain application or a certain deployment scenario. That's where we each play each other's advantage. That probably would be a better way to moving forward.
Makes sense. Thank you for that. Then my follow-up question is just wanted to get your perspective on how you're thinking about non-FortiGate growth potential. The benchmark could be above, at, or below the growth rate of the company. How are you thinking about the opportunities associated with the non-FortiGate helping your portfolio moving forward? That's it for me. Thank you.
Thank you. I think the total addressable market for non-FortiGate, we call the infrastructure approach or Fabric approach, is larger. The issue is that the enterprise facing is management cost is rather high. You have all these different piece of infrastructure security not working together. You need to find a way to consolidate and manage it together, which the FortiFabric approach offered a solution. The way we design the product, working together, automate together from day one, which is different than some other company, depend on acquisition or some other approach, which make it more difficult to integrate or automate. That's why we see the growth so far in the last few quarters are faster than overall billing growth. At the same time, going forward, we also see this even bigger opportunity and probably keeping growth faster than overall growth.
All right. Thank you.
This is Keith again. I would just, the one quick note I would offer that whether you look at in the non-FortiGate side or Security Fabric, just to share, I mean, the growth rates on both the product, the hardware form factor, and the software form factor do indeed outpace, as we noted in the call-
Yep
FortiGate, they're also very similar in terms of their growth rates, both the hardware and the software form factors.
Right. Okay. Thank you, Keith.
Thank you. Our next question comes from Tal Liani from Bank of America Merrill Lynch. Your line is open.
Hey, thanks, guys. This is Dan Bartus is on for Tal. I wanted to ask again about where we're at in this mid-range refresh cycle you're seeing. What stage of maturity are we at for the 500E cycle? Is it natural to think that the 400 and 600 products just continue that cycle?
Yeah, the mid-range refresh pretty much done, I have to say. Also, like Keith said, as the new E-series has much better performance, and the 400, 600 also enhanced compared to the 300, 500. It's relatively new compared to 300, 500. We do see the performance, the cost price ratio also is better. That's pretty much there. Then the next phase move towards the low end. That's coming up.
Okay, great.
Thank you.
You're clearly doing well with SD-WAN and branch office or campus environments, and then you're also doing well with the MSSPs. I'm just curious, how is your growth in the more traditional private data center firewall market, and what do you think the growth outlook for this subsegment is? Thanks.
That's the new product we are announcing today, the 1100E, the 2200E, and 3300E. You can see these products are very more powerful and the best fit for the traditional network security, like whether internal segmentation or the data center. We have the best performance, best security function and all integrate together. I think this will drive the future growth a lot.
Okay, great. Thanks.
Thank you. Our next question comes from Fatima Boolani from UBS. Your line is open.
Hi, this is Katherine McCracken on for Fatima. I wanted to go back to SD-WAN as a demand driver. One of the questions we had is, given that we know FortiGates can be deployed for SD-WAN use cases, what extent are you seeing traditional FortiGates being implemented primarily for SD-WAN purposes?
Go ahead.
It certainly happens. Let's put it that way, without giving a lot of metrics to it. Peter and I were at a customer meeting a few months ago, and that was specifically what was happening.
Yeah, that also will help in drive additional service, supporting revenue. If they want to enable the SD-WAN function for the FortiGate, which they already have, so that also will help us.
Yeah. I'm not saying that's anywhere close to a majority of it. Perhaps it's an outlier.
Okay
it can be done, and we've seen instances of it being done.
Okay. Got it. As a follow-up, on the margin front, in the last couple of quarters, you've mentioned being under-indexed on salespeople, and I was just wondering if sales hiring caught up in the quarter and how we should be thinking about sales and marketing expense for the remainder of the year. Thanks.
We improved. Still not quite there. We wish, you know, it'll take time, and also when they onboard, also needs time to enable ramp up. That I see. Sometimes when you invest in certain sales marketing, probably the return take a little bit longer than you launch the new product. On the other side, we do see that it is still very important to keeping invest in the marketing ourselves.
I would supplement Ken's comment, Katherine, by noting that, of course, it's baked into our guidance in terms of the hiring rate that we just provided. I don't want to overlook what a very strong performance, when I mentioned the Americas, but the U.S. in particular came through in the second quarter. Very high productivity, very high returns, very high growth rate. We're very pleased with their performance, including their success in the Global 2000.
Yeah, basically, there's two part. One part, really, you need to add head count. The other part is really try to enable the sales, has a better closing rate. That's where the training, all this kind of help them get familiar with the product, multiple product solution, also very, very important. We also enhance a lot of in that area.
Got it. Thank you.
Thank you.
Thank you. Our next question comes from Michael Turits from Raymond James. Your line is open.
Hey, this is Keith on for Michael. I just wanted to follow up on an earlier question on service provider and just ask a little bit more specifically how you may be incorporating 5G into your outlook for this year and going forward?
It's still very early. At least a few quarter away, you will see anything impact by the 5G or helping from the 5G. We do have the product already there. It's also working with service provider to see what's the best way to secure the 5G network. Also, a lot of other growth, actually, it's come from the OT, IoT, which also leverage the 5G. That's where I see probably the 5G into a certain area, like healthcare, like a certain industry, maybe growth security probably ahead of some other very broad 5G approach for consumer in the carrier space.
Got it. That's helpful. Just separately, could you give us an update on your partnership with Symantec? How much are you going to market together, and how has traction been so far?
I think it's a very good approach. I mean, progress there, and also, that's one of the very important partnership we have, to go to market together. I think there are a few sales that are engaged, working together, and it's helping both company.
Thank you.
Thank you. Our next question comes from Melissa Franchi from Morgan Stanley. Your line is open.
Hi, this is Hamza Fodderwala in for Melissa Franchi. Thank you for taking my questions. Just on the macro front, you touched on EMEA earlier. You also have about a quarter of your revenue coming from APAC. Any concerns within that region? Obviously, the trade tensions, we had some of the new tariff announcements earlier today, and how that could sort of impact growth within the region more broadly. I also noticed you had a recent partnership announcement with Alibaba. Yeah, just any commentary on that would be helpful.
Ham, it's Keith. Perhaps in reverse order. Yes, we're very pleased with the Alibaba announcement that you saw. China by itself has not been a large contributor to our business historically for the last several years. Regarding tariffs, we saw the announcement earlier today. Did some double-checking on that and made sure that we are still fine with our guidance, and we're very fine. We do have some production, as I mentioned before, that's done in China, but the majority is outside of China. I guess the last comment I would offer is that, for us, the Asia Pac area is obviously a very diverse geography, covering many countries, all the way from Australia, New Zealand, up through South Korea, Japan, Taiwan, et cetera.
Got it. Then just on the SD-WAN early momentum, the six deals that you mentioned above $1 million. Were those bundle deals with the SD-WAN use case attached, or were those deals primarily led with the SD-WAN value proposition? That's it.
Yeah, I think it's more led by the SD-WAN. Even some of the not even enabled security function to begin with, but they do see the advantage of a security capability in a box whenever they need it or turn it on.
Thank you very much.
Thank you.
Thank you. Our next question comes from Daniel Ives from Wedbush Securities. Your line is open.
Yeah, Dan. Have sales cycles changed on the larger deals? I mean, are they starting to now shorten, given it seems like it's a little more downhill scheme for you guys as you're signing some of these seven-figure deals?
Yeah, I think the enterprise, by and large, a new enterprise logo, I think the sales cycle is what the sales cycle is. Ken would point out to me that typically there's a fairly robust RFP process that goes out, a short list, a proof of concept testing, and so forth. If you're chasing a new opportunity dislodging an incumbent, I don't sort of see a change there. To the extent that you're talking about an expansion of an existing enterprise logo, I do think you're going to see things like some SD-WAN opportunities that move faster than perhaps other things, and certainly in general, an expansion into an existing account moves faster than a new logo.
Thanks.
Thank you. Our next question comes from Patrick Colville from Arete Research. Your line is open.
Thanks for taking my question and congrats on a pretty awesome quarter. Can I just ask about the SD-WAN and secure switching piece? It's been a seriously impressive part of your business for the last couple of quarters. I just wonder, kind of in the medium term, what do you see as your competitive advantage in that business line versus your competitors? Why will Fortinet sustain this healthy momentum?
Yeah. Like I said, it's the industry transition from the traditional, like a network security only, to more infrastructure. We call it security-driven networking. That's where, because the border disappeared, if you only secure the internet connection in the enterprise, no longer enough, you need to go internal, address the segmentation, different data server, all this kind of things. You also need to make sure the connection to the outside, out to the mobile, also being secured, whether the Wi-Fi or the SD-WAN. That's why we have this approach with our technology from the SPU ASIC chip to the function cover, like for SD-WAN, Wi-Fi, going forward to 5G. That's all kind of working together. At the same time, the fabric also helping making a total solution, multiple layer total solution works better now.
That's why we see the transition for the industry is more like an infrastructure consolidate fabric approach help us drive this transition going forward compared to some of our competitors who, whether more in the traditional network security gateway or kind of only address some part of infrastructure or certain application in the cloud. We feel we have a much better, broader, and kind of more advanced approach, not only for this SD-WAN, but also going forward with 5G, the IoT, OT security, and we see it's a huge potential going forward.
Great. Can I ask just a quick follow-up? There've been some other earnings, like NetApp this evening, for example, missed quite badly, and some other kind of on-prem vendors have had some bad results. Why is it that the firewall market has remained so healthy? You guys are putting out some great numbers and the guidance implies that momentum stays really strong. Why is it that the firewall market and security market has been so different to other on-prem spending areas?
Patrick, it's Keith. Look, I think that you got to keep in mind the significant diversification that we have. Whether that's across geographies or if that's across the fabric products and the firewalls, or if it's the identification and taking advantage of new use cases such as SD-WAN, OT, and such. Perhaps if it was four or five years ago, you could have a conversation with us about being a point solution with firewalls, but this has become a very diversified company.
Great. Thank you for your answers to my questions, and keep up the good work. Cheers.
Thank you. Our next question comes from Gray Powell from Deutsche Bank. Your line is open.
Great. Thanks for working me in. Yeah, I wanted to follow up on the Symantec relationship. At least in the conference circuit, it seems like they're talking up the partnership with Fortinet more and the potential to put Fortinet virtual firewalls into their cloud secure web gateway and how that could help them close the gap against Zscaler. Is that something that you've built into your guidance, and is there any material uplift that we should be thinking about from that relationship?
We have had some billings from the Symantec relationship, but I'm comfortable with my guidance. I'm not calling out Symantec separately or any particular upside to that relationship at this point. I think you've described the use case, if you will, or what the go-to-market cadence is for Symantec and why it makes sense as a business strategy.
Got it. Okay. Thank you.
Thank you.
Thank you. Our next question comes from Ken Talanian from Evercore ISI. Your line is open.
Hi. Thanks for taking the question. You mentioned seeing an increase in the % of support and services, I think as a result of SD-WAN. Are you seeing a broad uptick in support and services, in part from a mix shift to richer firewall configurations? Can you help us understand maybe a bit about the magnitude of that?
Yeah. This is Keith. I'm sorry, Ken. I was just trying to describe for people what an SD-WAN solution looks like when I mentioned that it's going to run about 70% services when I look at my larger deals in the quarter. I wasn't trying to go someplace else with that particular comment. I can probably talk a little bit about some of the dynamics that are happening in FortiGuard/FortiCare. FortiGuard is doing very well. It probably has a number of advantages right now. The company's coming off of a fairly high unit shipment number in 2018, product revenue that attached service contracts to that. You're seeing those services now roll into the income statement. They were previously deferred, so now you're seeing them happen there. You're also seeing what I talked about before, the mix shift a little bit from low-end to mid-range.
That's been happening for a period of time now. To the extent I'm selling more mid-range than I am low-end, that will typically attach a higher ASP on the service contracts, getting a little bit more lift from the bundles, a little more lift from standalone security offerings, things of that nature.
Got it. You described last quarter as rich in renewals. Could you comment on this quarter and just how you're thinking about the remainder of the year?
Yeah. I think it's not surprising that for a tech company, Q1 tends to be the logical time that you have a lot of renewals. If it's not in Q1, you get Q4. Q2, Q3, you may get some governmental entities. You're always going to have renewals throughout the year. I think over time, you start to see a bit of a migration in terms of those renewals because of co-term agreements in the enterprise, et cetera, migrate towards a Q4, Q1 timeframe, and that's pretty much what we expected, and that's what we saw.
Perfect. Thanks very much.
Thank you. Our next question comes from Imtiaz Koujalgi from Guggenheim Partners. Your line is open.
Hey, guys. Thanks for taking my question. I had a question about the Fabric business. Is there a way to maybe figure out the attach rate? How many of the customers are using the Fabric products today in the install base? How much penetration do you have for those products in the install base, and how has that trended in the last quarters?
Yeah. Not something that we talk about publicly, Taz, in terms of attach rates. I will tell you that it continues to steadily trend up.
Got it. A question on billings guide. You had a strong billings number this quarter. Your guidance seems pretty conservative. What are you assuming for duration for next quarter? Anything that's changing, that's making you guide fairly conservatively for next quarter?
I think the nature of our business is that Q2 to Q3 typically is within one or two points of each other. I think we're at that. We had a very good Q2, obviously, you're probably seeing a little bit of that factor into it. On the full year, when you do the math, you'll see that we've put some of the upside from Q2 into the full year guidance. Yeah, I think we feel very good about what we're seeing in terms of the quality of our pipeline, et cetera.
Got it. Just one last one from me. You said that Non-FortiGate obviously grew faster than FortiGate. Any more color on the cloud piece of the Non-FortiGate? I know you usually give some metrics in the past, but any more color on how the cloud piece of Non-FortiGate did this quarter?
Fastest-growing element of the Fabric.
Got it. That's it for me. Thank you, guys.
Thank you. I am showing no further questions from our phone lines. I now like to turn the conference back over to Peter Salkowski for any closing remarks.
Thank you, Crystal. I'd like to thank everyone for joining the call today and let everyone know that Fortinet will be attending the following investor conferences during the third quarter: Oppenheimer on August seventh in Boston. We'll be at the Raymond James Conference on August twenty-first in Chicago, the Dougherty Conference in Minneapolis on September fifth. We look forward to seeing many of you over the next several weeks. If you have any questions, please give me a call or send me an email. Have a great rest of your day. Thank you very much.
Ladies and gentlemen, thank you for participating in today's conference. This does conclude the program. You may all disconnect. Everyone, have a wonderful day.