Ladies and gentlemen, thank you for standing by and welcome to the Fortinet Q3 2019 earnings announcement call. At this time, all participants are in a listen-only mode. After the speaker presentation, there will be a question and answer session. To ask a question during the session, you will need to press star one on your telephone. Please be advised that today's conference is being recorded. If you require any further assistance, please press star zero. I would now like to hand the call over to your speaker, Mr. Peter Salkowski, Vice President of Investor Relations. Please go ahead, sir.
Thank you, Sheree. Good afternoon and happy Halloween, everyone. This is Peter Salkowski, Vice President of Investor Relations at Fortinet. I am pleased to welcome everyone to our call to discuss Fortinet's financial results for the third quarter of 2019. Speakers on today's call are Ken Xie, Fortinet's Founder, Chairman, and CEO, and Keith Jensen, CFO. This is a live call that will be available for replay via webcast on our investor relations website. Ken will begin our call today providing a high-level perspective on our business. Keith will then review our financial and operating results, providing our guidance for the fourth quarter and update our 2019 guidance before opening the call to your questions. During the Q&A session, we ask that you please keep your questions brief and limit yourself to one question and one follow-up to allow others to participate.
Before we begin, I'd like to remind everyone that on today's call, we will be making forward-looking statements, and these forward-looking statements are subject to risks and uncertainties, which could cause actual results to differ materially from those projected. Please refer to our SEC filings, in particular, the risk factors in our most recent Form 10-K and Form 10-Q for more information. All forward-looking statements reflect our opinions only as of the date of this presentation, and we undertake no obligation and specifically disclaim any obligation to update forward-looking statements. Also, all references to financial metrics that we make on today's call are non-GAAP unless otherwise stated. Our GAAP results and GAAP to non-GAAP reconciliation is located in our earnings press release and in the presentation that accompany today's remarks, both of which are posted on our investor relations website.
Lastly, all references to growth are on a year-over-year basis, unless noted otherwise. I will now turn the call over to Ken.
Thanks, Peter, and thank you to everyone for joining today's call to preview our third quarter 2019 result. We are pleased with our strong bookings, product and service revenue, operating margin, and the free cash flow performance in the third quarter. Contributing to our strong third quarter result were our advanced FortiSPU-driven FortiGate technology, integrated Security Fabric solution, hybrid and multi-cloud offerings, and significant adoption of our secure SD-WAN solution. Total revenue was up 21% to $548 million, and the product revenue accelerated to 20% growth. During the third quarter, Fortinet was named a leader for the third consecutive year in the Gartner Magic Quadrant for network firewall. This recognition validates our advantage enabling enterprise customers to create a security-driven network that delivers integrated and ultimate security to all network environments.
Today, Fortinet announced the release of a new FortiGate 60F, the most popular and best-selling desktop next-generation firewall in the industry. The 60F leverage Fortinet SoC4 SPU that enable secure SD-WAN. It delivers security compute rating for threat protection, SSL inspection, and the next-generation firewall performance of four to 47 times faster than industry average appliance. The security compute rating compares the performance of our FortiSPU enhanced appliance with industry average solution in the same price range utilize generic CPU for networking and security capabilities. 80% of WAN edge solution needs security, and IDC estimate that WAN edge total addressable market will increase from $1.3 billion in 2018 to $5.2 billion by 2023. Our secure SD-WAN solution clearly outperformed in the quarter. According to Gartner, in the second quarter of 2019, Fortinet ranked the third with faster growth and 11% of SD-WAN market share.
This fast market share growth validate that our FortiGate solution with secure SD-WAN is clearly resonate with enterprise customers. Traditional network security borders are dissolving as mobile, cloud, and IoT technology change the way people work and the volume of data they need to secure. Edge computing require high-performance secure networking capability, and 5G roll out are in the early stage of providing mobility innovation, and with demanding low latency and security solution. As a leader in hybrid multi-cloud as well as edge security, Fortinet ability to offer security-driven networking and both edge and cloud security with low latency and high performance is a clear competitor advantage. Going forward, we see four drivers for market share growth for Fortinet.
First, our refreshing portfolio of FortiGate with new FortiSPU has a huge Security Compute Rating advantage compared with all other competitors. This FortiGate will continue to lead in the transition to security-driven networking and secure SD-WAN adoption that will allow Fortinet to gain an additional market share. Second, Fortinet Security Fabric allow us to offer a broad, automated, and integrated secure solution for end-to-end protection as customer consolidate towards a few security vendors. Third, Fortinet's broad range of hybrid and multi-cloud solution enable us to provide security to the cloud and from the cloud. Fourth, Fortinet is well-positioned to lead the transition to 5G and IoT security as a result of our FortiASIC technology, which provide a huge advantage for embedded and integrated security with much lower cost and faster performance. On Monday, we announced acquisition of endpoint security company, enSilo.
The acquisition enhances Fortinet's Security Fabric offering and strengthen our real-time automated detection and response capability around endpoint and EDR data. I would like to take this opportunity to welcome enSilo team to Fortinet. On November 18, we are celebrate Fortinet's 10-year anniversary as a publicly traded company. I want to thank the Fortinet team and our partner for their ongoing hard work and our customer for their support. You have all contributed to our great success. Now I will turn the call over to Keith for a closer look at our third quarter performance and our guidance for the fourth quarter and the full year.
Thank you, Ken. Let me first note that except for revenue, financial amounts are non-GAAP, and growth rates are based on comparisons to the third quarter of 2018, unless otherwise stated. The slide references I make refer to the presentation posted on our investor relations website. I'd now like to provide a summary of our strong third quarter performance. As part of the summary, I will highlight how the diversification in our business by geography, customer and industry segments, and solutions, has contributed to solid growth and consistent execution. Let's start with revenue. Total revenue of $548 million was up 21%, led by strong revenue growth from our fabric and cloud segments. Revenue from our largest segment, network security, was up 19%. Product revenue growth was 20%. 20% growth represents, first, an acceleration off the 14% growth we achieved in the first half of the year.
Second, growth off increasingly more difficult year earlier comparisons as growth accelerated through 2018. Third, a growth rate that we estimate is double the industry growth rate. Product revenue of $197 million benefited from the segment growth noted a moment ago, as well as growth in both appliance and software solutions. Given the significance of our historical SMB business and the consistent trend in our renewals, we believe the impact on our business of an industry refresh cycle is muted. Consistent with Ken's earlier comments related to our SD-WAN market share, growth benefited from the market's rapid adoption of our FortiGate-based secure SD-WAN offering. Our higher margin service revenue increased 21% to $351 million and represented 64% of total revenue, up 10 points in four years. FortiGuard's subscription security revenues increased 23% to $193 million, while FortiCare technical support and other services revenue increased 19% to $158 million.
Renewal rates remained very consistent with prior periods. Deferred revenue at the beginning of the third quarter accounted for over 90% of services revenue and 60% of total revenue recognized in the quarter. For the fourth quarter, we expect the deferred revenue balance to provide a similar level of predictability, accounting for similar percentages of service and total revenue. Total deferred revenue increased 26% to just shy of $2 billion. Short-term deferred revenue increased 21% to $1.1 billion. On a geographic basis, revenue growth for the Americas accelerated to 24%, despite a more difficult year earlier comparison. EMEA growth accelerated to 21%. Turning to billings. Total billings of $627 million were up 19% and benefited from the diversification of our business across geographies, customer and industry segments, and solutions. Network security billings, which includes products and services, increased 16% and accounted for 74% of total billings.
Billings growth for non-network security, which includes both products and services, outpaced network security billings. We generated billings in over 80 countries where their individual billings were less than 3% of our total billings. In aggregate, these 80 countries represented nearly 55.0% of total billings. While we saw somewhat slower growth in the U.K. and Germany, it was clearly offset by strong growth in several other EMEA countries. While service providers and MSSP remain one of our top segments, accounting for 17% of total billings, we experienced an equivalent contribution from the government segment and a strong contribution from the financial services segment. Looking now at deal sizes. Deals over $1 million increased 77% to 53 deals.
Secure SD-WAN was a leading contributor to the increase in the number of deals in excess of $1 million, accounting for eight deals in the third quarter, up from one deal of over $1 million last year. We are pleased to see the geographic diversity in all of our large deals, with over 40% of them coming from EMEA and APAC. The number of deals over 250,000 and 500,000 each increased 26% to 333 and 130 deals respectively. Average contract term of 26 months was flat year-over-year and down one month quarter-over-quarter. To offer one final note on diversification, since Q1 of 2017, we have not had a single transaction in a quarter that represented more than 2% of quarter billings. Back to the income statement. Gross margin improved 170 basis points to 78.2%. Product gross margin improved 330 basis points to 60.7%.
Product gross margin benefited from an attractive discounting environment, deal mix, software revenue growth, and a stable product transition environment. Now while we're very pleased with the product gross margin performance in the third quarter, we expect it to return to more normalized levels in the fourth quarter. Services gross margin increased 70 basis points to 88%. Operating margin increased 250 basis points to 26.4%, driven by the improvement in gross margin and operating expense leverage associated with our strong revenue performance. Total headcount increased 17% to 6,590. Given the strong operating income performance, GAAP net income was $80 million, up $21 million, or 36%. Moving to the statement of cash flow summarized on slide seven and eight. Free cash flow was $204 million, up 29%, resulting in a free cash flow margin of 37%, up 230 basis points.
The increase reflects strong third quarter billings, collections, and the flow-through of the increase in operating profit to net income. Capital expenditures for the third quarter were $17 million below expectations due to the timing of construction spending. We expect fourth quarter capital expenditures to be $40 million-$50 million, resulting in a full-year capital expenditures of between $90 million and $100 million. In the quarter, we repurchased approximately 335,000 shares of our common stock for a total cost of over $26 million at an average per share price of $78.70. At the end of the third quarter, the remaining share repurchase authorization was $616 million. As I turn to the guidance provided on slide nine, I'd like to remind everyone of our diversification in our model, again, by geographies, customer, and industry segments, and solutions, continuing to provide and contribute to our growth and the consistency in our financial performance.
We will dive deeper into this consistency and visibility and predictability of our financial model at our Investor Day on November 18th. With that, I'd like to remind everyone of the forward-looking disclaimer Peter presented at the start of the call, as it applies to all forward-looking statements, including the guidance I'm about to provide. In the fourth quarter, we expect billings in the range of $750 million-$765 million. Revenue in the range of $595 million-$610 million. Non-GAAP gross margin of 75.5%-76.5%. Non-GAAP operating margin of 25.5%-26%. Non-GAAP earnings per share of $0.69-$0.71, which assumes a share count of 176 million-178 million. We expect a non-GAAP tax rate of 24%. For 2019, we expect billings in the range of $2 billion 550 million-$2 billion 565 million.
Revenue in the range of $2.135 billion-$2.150 billion. Total service revenue in the range of $1.355 billion-$1.365 billion. non-GAAP gross margin of 76.5%-77%. non-GAAP operating margin of 24%-24.5%. non-GAAP earnings per share of $2.39-$2.41, which assumes a share count of between 175 million and 177 million. We expect our non-GAAP tax rate to be 24%. We expect cash taxes of between $56 million-$58 million. Like Ken, I'd like to extend a warm welcome to the enSilo team. Before I turn the call back over to Peter, I'd like to thank our partners, our customers, the Fortinet team, for all their support and hard work. It's because of your dedication and efforts that Fortinet is able to celebrate 10 years as a publicly traded company on November 18th.
Ken, back then you closed the day with a market cap of $1 billion. Today, your market cap is over $14 billion. Nicely done. Peter, back to you.
Thank you, Keith. operator, we're ready, to open it up for Q&A, please.
Thank you. As a reminder, to ask a question, you will need to press *1 on your telephone. We ask that you please limit yourself to one question and one follow-up question. You may then return to the queue. To withdraw your question, please press the # key. Please stand by while we compile the Q&A roster. Our first question comes from Fatima Boolani with UBS
Good afternoon. Thank you for taking the question. Keith, I'll start with you. You've had a fairly feverish pace of gateway and new FortiGate releases over the course of this year. You're talking about FortiSPU refreshing through the base. I'm wondering if you can comment on general ASP trends, how you're managing around cannibalization of ASPs, given the extent and spectrum of the appliances you have, and any color you can sort of provide us on product shipment trends. I do have a follow-up as well.
Hi, Fatima. It's nice to hear from you. Kind of a number of topics in there. I'll try and recall each and every one of them. I think if you look at our product suite of FortiGate, we have about 75 different FortiGate firewalls. That probably compares to some other people that maybe are closer to 15. Why that's important, you assign some sort of life cycle to those products, and you pretty quickly come up with the idea that we're refreshing our products at the pace of probably eight, 10, or 12 a year. I think we've become pretty good at it, and I think part of that being good at it means both in terms of how we manage our inventory, but also how we manage that transition with our customers.
I'm not going to comment specifically on ASPs, other than to say that I was very pleased with the trend up of ASPs in the quarter. It's been a very consistent upward march in ASPs overall. I would attribute some of that to the fabric products, which are driving, when I talk about ASPs, total billings for a solution, if you will. I think that's contributing to our ASPs. I probably missed something else. No?
That's super helpful. Just shifting gears to the secure SD-WAN traction. The eight deals that you called out that were in excess of a million dollars in the quarter, I wanted to peel back the onion on that to get a better sense of who the buying audience is here, and if you can speak to the competitive dynamics. Relative to the one deal you did last year, I think that's a pretty significant improvement. Just wanted to peel back on some of the dynamics of the strength there. Thank you.
Maybe I'll let Ken talk about the competitive dynamics, and I can talk just a little bit about who the buyers are first. Clearly, the SD-WAN market is tilted more towards the enterprise and less towards the SMB, and we see that in our customer mix shift in the SD-WAN. Ken?
Yeah. Also, because like I said, 80% enterprise customer need SD-WAN with security solution. That's where we're the only one can integrate security and SD-WAN together in a single box. That's a huge advantage. Also the computing power, we call the Secure Computing Region, which gave us huge computing capability. We can easily add additional function, whether from security side or from the network side. Just like even with the SD-WAN alone, the performance much better than any other competitor. For them, they have a very limited computing power, can rarely add any other function, whether networking security. That gave us kind of a huge advantage going forward.
Thank you.
Thank you. Our next question comes from Sterling Auty with JP Morgan.
Yeah, thanks. Hi, guys. At this point, can you give us a sense of just how big is SD-WAN as a percentage of your business?
I'd probably point to Gartner had a report out, I think in the second quarter, that noted that our market share was 11% of SD-WAN. I think our market share a year ago was zero, according to the report. I think there's some information there that you could look at.
Okay. Ken, with some of these terms, SD-WAN and then secured internet access, so the Zscaler, what Palo Alto's doing, maybe can you just take a minute and help frame for investors that are asking me to better understand what is SD-WAN actually giving to your customers versus what is the secure internet access that's replacing MPLS, et cetera? How do they differ, and what's your opportunity in both sides of the coin?
It's kind of a little bit different market and a position. Secure SD-WAN is related to the WAN edge transition. That probably provide much like a software-defined, more smart and reliable way, low cost way to access the enterprise, access the cloud. That's where driving SD-WAN adoption may grow almost 50% year-over-year in the next few years. I think whether it's going to Palo Alto, their say secure access, more about access some of their cloud or some other part. Which if you look by Gartner data, so by 2023, so cloud security is about $4 billion market. Network security, including user secure SD-WAN, is about $28 billion market. It's seven times larger. That's where network security is still the much bigger part compared to overall infrastructure security.
that's where we are the only one, we offer both on the cloud side, we do have a similar solution, but we are more prefer working with service provider for some kind of a secure access or kind of a Zscaler type of solution and more treated as a partner. On the other side, we do believe what do we call a security-driven networking or some other change, which integrate networking security all together, like SD-WAN, like the Wi-Fi, like the 5G. this is much better solution and also enable our kind of technology advantage from the, we call security process unit, compared to the other security solution more used in a general purpose CPU, which has a very limited security computing power to process both the security function, network function.
It's a little bit two different approach, and we do believe our approach is address much bigger market and also with fast growth, fast transition, and we position quite well compared to any other competitors.
Thank you. I appreciate that.
Thank you.
Thank you. Our next question comes from Keith Bachman with Bank of Montreal.
Hi. Thank you very much. Keith, I wanted to target this to you. Your cash flow performance continues to be quite impressive in outpacing revenue growth. I just wanted to ask you about how we should be thinking about this over the next year. Now, part of it is your operating margins in the last year have gone up by over 700 basis points. I was just hoping to distill it down to, A, the operating margin metrics, but, and B, the working capital cycle, how you see that changing, and just alleviate concerns you might have about me asking questions. We'll neutralize this for real estate. I was just thinking about the underlying.
Thank you, Keith. When you look at free cash flow, yes, real estate does come into play, and we expect a fair amount of spending on real estate next year.
Right.
I think at the analyst day on November eighteenth, I think the internal conversation here is whether or not we want to preview, not free cash flow, but at least the real estate spending for 2020. Excuse me, I missed a spoke a moment ago. I think that you've kind of just nailed it in terms of we're executing fairly well on the capital model. Contract terms are holding fairly firm for us. How we pay our customer or pay our vendors is holding fairly firm for us. It's really just a matter of continuing to manage your inventory, continuing to grow your billings, and then watching the margin drop through to that cash flow number.
Is there any reason just to clarify, I mean, it sounds like cash flow could continue to outpace revenue growth. Is that a fair conclusion?
I'm going to just pause on getting closer to guiding on free cash flow if I can.
Okay. All right. That's it for me. Thank you.
Okay. Thanks, Keith.
Thank you. Our next question comes from Saket Kalia with Barclays Capital.
Hey, guys. Thanks for taking my questions here. Keith, I'm sorry, Ken, just maybe to start with you. Obviously, a lot of traction in SD-WAN. I want to ask a hypothetical question. If you put yourself in the shoes of your network security competitors, what don't they have that will either slow or prevent their ability to offer bundled SD-WAN and firewalling? I guess where I'm going with that question is it the custom-built ASIC processing power that we have here, or is it a secret sauce inside the FortiOS? Maybe just to put a bow on the question is, what do you feel like the barrier to entry is with FortiGate and SD-WAN together?
You can look on today's press release. We announced the FortiGate 60F and also introduced a concept we call security computing region. You can see we have a secure computing power capability, probably like from 4x in some of the like threat prevention to like 47x for some networking session, concurrent session, or SSL, some other part. That's why we have so much computing power in this, we call SPU, Security Processing Unit. They do have a generic CPU embedded inside SPU, which can perform any whatever new function we needed, but we've also kind of making a lot of secure computing function when they build into the chip. That's where by industry standard, they have a seven-year advantage, easily like close to 100 times faster and about the same cost.
That's the advantage we have is really the computing power in the security function, the network function, that enable us to easily add, like SD-WAN function, the Wi-Fi function, the 5G function, and also more security function compared to our competitor. They can only leverage the commercial available CPU, which we also leverage that, but we do use an ASIC to enhance that and also build sometimes in it together. That's a few the competitor has some difficult time to catch. Building a chip need a multiple year effort. Same time, today, we have almost 30% of total global unit shipment in the whole network security. That's also the economy of scale also that in play. I feel within few years, we can count more than half of the total unit shipment in the whole network security space.
that also will be making any other competitor has some difficult time if they don't have the economy of scale to catch up. Because building chip, you also need a big investment in the beginning, and then once you have the quantity, the average cost can get lower. we have this investment start almost 20 years ago when company started. that's where all this, like almost 20-year effort investment that enable us to easily add additional function, whether in the networking or in the security. Because what we see, like in my script, is really that the border, the security border disappear. this time, the enterprise refreshing is different, totally different than like what happened in 6, 7 years ago. Now come the next generation firewall with intrusion prevention or some other replace the first generation connection-based firewall.
This time, the border no longer there. You needed the internal segmentation, you need to kind of secure the server, the department, the data, and also you need to secure the WAN connection. That's drive us to make sure we call the security-driven networking and also the fabric approach to secure the whole infrastructure. We have this kind of an investment prepared in the last like 10, 20 years, and we feel we are much better positioned than the competitor, whether they try to do the acquisition, which will be very difficult to integrate, and also without their kind of a dedicated ASIC chip, so they don't have computing power to add additional function there. That's the advantage we have from all this long-term investment, also the planning we have.
That makes a ton of sense, Ken. Just maybe for a quick follow-up for you, Keith. Keith, I think you talked about strong renewal rates with FortiGuard and FortiCare. Just to make sure it's asked, can you just talk about attach rates for FortiGuard and FortiCare and whether there were any changes in trends on particular SKUs that you saw in terms of 24/7 support or lower or whatever, just in terms of different trends for FortiGuard or FortiCare?
Yeah, no, I think that's a good question. The renewal rates not only in total were very consistent, but also by those two different product lines or service lines, both FortiCare and FortiGuard. In terms of the services, we continue to see the UTM bundle of services perform very well. we continue, and it's been going on now for a few years, continue to see the shift on the support side from eight by five to 24 by seven, particularly on new deals.
Very helpful. Thanks, guys.
Thank you.
Thank you. Our next question comes from Melissa Franchi with Morgan Stanley.
Great. Thanks for taking my question. Ken, I wanted to ask about the service provider space in the quarter. By my calc, I am calculating revenue down a little bit year-over-year. Can you just maybe give us an update on what you're seeing in terms of the buying behavior in that segment, and then what your expectation is as we close out the year and head into 2020?
I believe our service provider do grow in year-over-year, probably like close to 10%, but slower than the average growth in the overall company growth. Service provider, not just Fortinet, but you can look in the networking company, they all kind of slow down. I believe they're in the transition time. I think, like I said, service provider, there's a two-part. Probably Keith data can help add more is that one is really the service provider offered a security service to their customer. The other part is really service provider secure their own infrastructure. The first part, service provider offer service to the customer side, we don't see any slowdown. They do try to see how to deploy some other service, like a Zscaler kind of service to leverage their position, their connection, their data center to offer some other service.
we do see that ramp up pretty quickly. that's what making that space more competitive. service provider, because they have infrastructure, they own infrastructure, so they have a huge cost advantage compared to some new player, which they have to build their own data center or have to buy the bandwidth, which has a huge cost, that's making them profit very difficult. the second part for secure their own infrastructure, that part we do see some kind of a slowdown, and whether because they try to figure out like a different approach structure of 5G or some other part. we do believe that will suddenly ramp up probably next year, because we do see a lot of testing, evaluation, and we do participate in lot of big half and also design the future infrastructure together.
Yeah. Melissa, I think Ken's spot on. I think really looking at it in two different pieces of it, one is selling into their infrastructure and the second is the MSSP. I think that selling into the infrastructure 2018, for a variety of reasons probably, and for many companies, was a very good year for people selling into the infrastructure. 2019 is probably suffering a little bit, just by comparison. Then the second part of it is the MSSP, the managed security service providers. I think we feel very good about what we're seeing there with our telcos, both in the U.S. and internationally.
Okay. That's helpful. Just one quick follow-up. Since it seems like you guys are gaining share, just looking at product growth, just wondering what the competitive response has been, particularly around pricing and discounting.
We have a much better total cost of ownership, TCO, compared to any of our competitor. You can look and that's where we're using this Security Compute Rating to compare. You can see easily our cost is a fraction of any of our competitor have to perform the same security function or support, right? We don't see, like in the next few years, we will have lost any of this advantage compared to competitor if they really want to competing on the cost, on the performance side, and also on the security, because we have much more computing power, we can enable much more security function and also go much deeper in the security function than any of our competitors. That's where we You can see the margin we're keeping improving.
For us to grow faster is really try to have like a more sales coverage, more marketing coverage, and at the same time, working closely together with the partner, with the customer, to follow the change in the whole industry, and whether the fabric approach or security-driven networking, internal segmentation, the 5G and the OT/IT security. There's a lot of thing we're working right now we believe will benefit both our customer and partner in the next five to 10 years.
Yeah, Melissa, I'll just add to this, to that, as Keith. Discounting in the quarter was clearly a tailwind for us. We were very, very pleased where we ended up on the discounting spectrum year-over-year.
Great. Thank you very much.
Thank you. Our next question comes from Tal Liani with Bank of America.
Hey, thanks, guys. This is Dan Bartus on for Tal. Wanted to ask two technology questions. The first is your endpoint acquisition. Did I hear right that it's mainly about adding the EDR capabilities? If so, how do you think this may impact your Symantec partnership, if at all?
I think we do have some of our own endpoint solutions. This acquisition will help us enhance that. Our approach is more driven by the network security part, which is FortiGate, which is a part of Fabric. We do have a very close partnership with Symantec, and at the same time, on the go-to-market strategy, we're also working very closely together. They do have a much bigger coverage in a lot of enterprise, and then we have more coverage in the network security. It's a win-win partnership that will benefit both companies.
Got you. Makes sense. kind of related, sorry if I missed it, but these SD-WAN deals that you guys are doing, are they also typically taking your secure web gateway offering, or are they typically pairing it with another vendor? maybe you can talk about how that might change, whether it's a large or mid-size enterprise.
Actually, for the secure web gateway, the WAF market, a lot of them to access all this, and same time, you do need to have at least one connection there. it's actually helping both. at the same time, you look at a lot of other live players. because they don't have the device on the premise there. Like I said, the networking side and the cloud side are totally different concept. The cloud cannot replace the network. They need a network site to access the cloud. the same time, from the user angle, they probably need to be using the secure computing region to measure whether the cost or how deep the security they can go, and also how the performance they can get.
Sometimes when you forward the data to the cloud, that data also starting to become less secure, whether you cannot write it and keep during the process of forwarding of the cloud cost for secure computing reading much worse compared to some appliance there. That's where they need from a total cost ownership and also total security angle to address what kind of architecture approach they have. I do believe both sides have their own kind of advantage, and the same time, I don't think that both sides is really eating up each other's market share. It's a little bit different approach.
Got it. Thanks very much, Ken.
Thank you. Our next question comes from Michael Turits with Raymond James.
Hey, guys. Good evening. Two questions. One, you've mentioned, Keith, a couple of times that you benefited from discounting. Can you talk about, first of all, is that across the board? Is that, again, just in the gateway network segment, or is it across the board? What's driving that? Because this has typically been a very competitive market where discounting has been strong.
Discounting was across the board. I think we got a fair amount of lift out of the Americas on it. I saw it across the board, both in terms of geographies and across product offerings or product suites. I think it really brings home the notion that, and Ken alluded to it for security effectiveness, security performance, security power. For what you're paying for a Fortinet solution versus what you're getting, we have a competitive advantage there. the discounting part of the conversation should, and I think we saw in the quarter, hit our competitors who are going up against us more harder than it hits us.
Okay. Ken, it was very interesting what you said about competing or selling into the service providers from an MSP perspective and talking about them utilizing a Zscaler as a solution also. Typically, you've been very strong in selling your appliances there. Is that a competitive or substitute product for you right now to sell against Zscaler? How are you competing with that offering?
We are more like supporting a service provider offer similar solution. A service provider, they do own a lot of data center connectivity infrastructure. In the past, they offer a little bit different kind of service, whether using the appliance or securing the data center. Now they also can offer certain, whether they call the process the secure data in the data center or some other approach, right? That's where we most supporting service provider, give them the flexibility, what kind of a service, what kind of a way they want to offer, we are supporting behind. By forwarding the traffic data to their data center to process, or they want to process locally on the edge and leverage the other part, like I said, the clean pipe or some other way to approach.
We do offer them multiple solution for service provider, depend on the service provider and their customer need. That's just like the scheduler type of service. Just one type of service some service provider offering right now.
Great. Thank you, guys.
Thank you.
Thank you. Our next question comes from Shaul Eyal with Oppenheimer.
Thank you. Good afternoon, gentlemen. Congrats on strong set of results and the guidance for the upcoming quarter. Keith, not to beat a dead horse, but I want to go back to the gross margin healthy performance this quarter. You've mentioned several times that it's going to be back probably to a more normalized range, but on the other hand, you also flagged the favorable discounting trend, the ASP, the product mix. Can you drill down slightly more into those components? Was it the discounting? Was it the product mix? Anything specific that stood out or just a combination? I have a follow-up.
Yeah, we had, quote-unquote, "Contributions" to the gross margin from the discount, but also the deal mix that came through in the quarter. We also had, as some of our products have matured, you tend to get cost savings on a per unit cost. We saw that trend continue through the quarter. we also had a little bit of benefit on what we would call our indirect product COGS, things like reserves and so forth, and overhead. All three of those contributed to it in the quarter. I would-
I think the one side you see sometimes when you sell a product, there's certain competition, whether on the discounting or price competition. On the other side, because we have a huge computing power, SPU, so we can easily add additional function like SD-WAN, which enable additional service. Service tend to have a much better margin compared to the product. That will help. The other trend we see is what we call the fabric approach. It's a multi-product selling together. That's where the fabric grows much faster than a FortiGate part. That's also making the sales cost, the deal size get bigger. That's also helping improve the margin. That's what we do see sometime when there's competition, you may compete on certain product pricing, but overall, we're keeping improving the margin by additional service, by additional product bundled together.
Got it. This is great color. Thank you for that addition, Ken. I want to touch also on Europe, on EMEA. Very consistent performance in the region, but you flagged out, I believe, both the U.K. and Germany. Can you talk to us a little bit about some of the dynamics that you have seen there during the quarter?
Yeah, I think I only flagged it because we anticipated that we were going to get asked about it. I would offer that U.K. and Germany were slightly below the rest of the company in terms of total growth. Again, given our diversification of business, it's not significant enough to have really any sort of impact on our growth rate.
Fair enough. Thank you so much.
Thank you. Our next question comes from Jonathan Ho with William Blair.
Hi, good afternoon, and congrats on the strong results. I just wanted to maybe start out with a little bit of color in terms of the initial reception for some of your, I guess, AWS-based products like the WAF as a service and maybe any commentary you have around cloud spending on the public cloud.
Well,
Look, I think we may offer a little more granularity on it in a couple of weeks at the Analyst Day, but both cloud and Fabric are growing more than twice the rest of the company in terms of growth period over the period. You want to talk more about WAF or?
Yeah, I think we'll probably go through more detail, even with some sales executive or even partner customer to present together in the Analyst Day in the next couple of weeks.
Got it. Just as a follow-up, one of the things that we wanted to understand a little bit better is just the entire SD branch concept where you're selling more than just SD-WAN, but maybe bundling some other products in conjunction with the core SD-WAN and gateway. Can you maybe talk about how does that maybe add to the size of the deals or maybe help differentiate Fortinet just by being able to offer a lot more capability?
Yeah. SD Branch maybe refer to some branch SMB part, which they more prefer, like a single box, easy to manage, and at the same time, can extend into the Wi-Fi, some other networking area. We do see, not also growing together with SD-WAN approach, but it's just a subset of the total infrastructure approach we have. We do see as the other part, whether the fabric and the SD-WAN, some other part, it's kind of like the concept we call security-driven networking. That's where within the big enterprise, you need to do internal segmentation, but within the branch, you probably try to consolidate some kind of different product or different solution together.
Great. Thank you.
Thank you.
Thank you. Our next question comes from Walter Pritchard with Citi.
Hi, thanks. I guess two related questions. Question to follow up. On the 26% that was the non-network security, can you help us understand, maybe stack rank product families, and especially interested if SD-WAN is now the largest product in that piece that's non-network security?
No, SD-WAN has got no real impact on the mix, if you will, of the business between FortiGate and non-FortiGate, if that's the question. In terms of the contributors and the fabric suite of products, it's the same it's been before, which is FortiManager, FortiAnalyzer, as well as our virtual firewalls.
Yeah. The SD-WAN functions is included in the FortiGate. It's part of the FortiOS function there. The SD-WAN is not counted within the 26%. It's other non-FortiGate part. I think the SD-WAN probably SD branch probably help a little bit, but SD-WAN is always in the FortiGate.
Okay. just related to cloud security, you mentioned virtual firewalls. Can you talk about what drove within that cloud category, the performance in the quarter? Sounds like that was a driver of the strength.
That's where we see we have a multi-cloud, hybrid cloud, and also a more consistent offer, broad offering for customer, whether they use the appliance on their enterprise or whatever, or go to the cloud or virtualize it. It's really the broad offering. Consistency give the customer flexibility, whether they want to deploy the function on-premise in the appliance, or they want to deploy in the cloud, and they can easily move back and forth. Also what's interesting, we did some calculation using what we call a Security Compute Rating. The cloud offering tend to have a much higher cost compared to the appliance on-premise offering that we have using whether, like, ASIC accelerated approach or some other approach. Sometime it probably because customer want to have certain flexibility or the management issue, they may still choose not.
We can easily point out to the customer it's their choice, and we offer all these broad coverage both on the multiple cloud provider or the function we have. We offer almost 10 different products. You can buy whether appliance or you can buy the virtualized on the cloud. On FortiGate, FortiManager, Analyzer, FortiSandbox, and FortiSIEM. There's quite a broad offering we offer to customer. Give them the flexibility to select whatever they want to deploy.
Yeah, when we talk cloud, not only with the cloud providers, but it's also private clouds as well that we're providing solutions to.
Okay. Thank you.
Thank you.
Thank you. Our next question will come from Gregg Moskowitz with Mizuho.
Okay, thank you very much, and good afternoon, guys. Getting back to the enSilo acquisition, Ken, obviously, there are many endpoint security vendors out there, and so I was curious if you could elaborate on what drew you to them in particular.
They are our, we call it, fabric partner. That's where they've been working together quite a while and working well together, and also have a very successful go-to-market approach, just like the same thing we did for the FortiNAC. What's the company? Bradford Networks that we did about one year ago. That's where now we have close to 100 FortiP artner, Forti fabric partner. That's where probably more need to starting from that angle first, make sure we can working together first.
Okay, that's really helpful. Just for Keith, so as you mentioned, both the Americas and EMEA grew very well this quarter. Your revenue growth in Asia Pac, though, I think did decelerate, and I know that you were facing a tougher compare. Just wondering if there was anything else that you would call out.
No, I think that, I guess that's going to give us something to work on in the fourth quarter, right? Is getting Asia Pacific back to a healthier growth pattern than we saw in the third quarter. Probably a little bit of hiring lagged for the first part of the year. I think by comparison, we feel very good about the conversation we had at the beginning of the year about needing to get the U.S. and the America team focused on hiring, and we see the results of that. I think we'll spend a little time with APAC in the next quarter.
Yeah, that's probably the major part of it, but also very small part is also APAC. They kind of sell a little bit more low-end, and then we do have some kind of product transition. That's where some service provider, some partner, they wait a little bit, like when we announce the 60F today, make it available right away. That's where we're hoping, because the new generation will have a much better performance and about the same cost.
Okay. That's great color. Thanks very much.
Thank you. Our next question comes from Daniel Ives with Wedbush.
Yeah, thanks. Can you talk about government deals? Are they starting to get larger in terms of, especially as there's a move to cloud on the security side? Are you starting to see those changes on the federal in terms of pipeline?
When we talk about government for our business, you keep in mind it's international governments and it's some U.S. federal, but it also includes on the U.S. side, state and local governments. I wouldn't say that there's anything driving out of the U.S. Fed business that's impacting our business one way or the other in terms of deal sizes.
Okay, thanks. Can you just talk about just generally, like, hiring plans from a sales rep perspective? Like, is that something you think is going to stay steady, accelerate? How would you kind of, from a high level, think about that over the next six to 12 months?
We are improving. You can see last quarter, Q3, we do add more headcount. There's some region, certain verticals still behind, like Keith mentioned, APAC. That's where we're keeping improving there. I think with more sales capacity, with more marketing coverage, I believe we can grow faster.
Thank you.
Thank you.
Thank you. Our next question comes from Brad Zelnick with Credit Suisse.
Hi, thanks for taking the question. This is Ray McDonough on for Brad. Ken, just to follow up on the enSilo acquisition, I know you mentioned you had a strong partnership with them, and the company has some very interesting technology, but having been around for several years and the price you paid seems to imply they weren't generating a lot of revenue or not growing very well or a combo of the two. What, if anything, do you see that you might be able to do with the technology that maybe the company wasn't able to achieve on a standalone basis?
It's pretty interesting. Quite a few of our acquisitions are very similar. They have a great technology. They have a great team there, but then they need much more investment for go-to-market. That's where we tend to like this kind of company so they can leverage our sales force and also our customer base to quickly help them to improve in the go-to-market side. At the same time, we also want to make sure we can integrate well together. We don't want to create too many different product approach, but integration is one of our key. That's where we most starting from the FortiFabric partner side first, then make sure we can integrate, and then that's where the decision we made, and I do believe they have a great product, great team.
Thanks, one for Keith, if I could. I might have missed it, but can you share what unit shipment growth was in the quarter?
We didn't provide it, but I would say that what we're seeing most recently is the unit shipment growth is moving right in tandem with product revenue growth.
Okay, great. Thanks.
Thank you, our next question will come from Kirk Materne with Evercore ISI.
Hey, thanks for taking my question. First, could you give us a sense for the main drivers for your success in competing in the enterprise segment and maybe give us a sense for how the pipeline has evolved over the past year?
I think there's a multiple angle from the technology product side. We feel all solution product technology fit better for the changing for the trend. Like I said, the security border disappear in enterprise, so you need to go inside internal segmentation. You also need to expand in the WAN and also working with service provider for the other cloud approach, mobile approach, all these kind of things. the fabric also because all fabric is most of product we build internally is integrate automate from day one. It work much better compared to some other competitor. They have to all depend on acquisition. that's really helping the enterprise overall infrastructure security and also making the deal larger and also more sticky with the customer.
Yeah, I think the concepts Ken's talking about, the security value is clearly at play here with the enterprises, but also as Ken talked about in his prepared remarks, being in the Gartner Magic Quadrant now for three years in a row has really served to open up the door in getting us invited to RFPs that five years ago we probably didn't even know exist. I think we've become pretty good and benefit from then following that up with things like NSS Labs certifications and recommendations. Too many S's in that, I'm sorry. That third-party testing, if you will, I think once you're in and you have the opportunity, you're offering them these recommendations from third parties together with our security value, does indeed make a pretty compelling opportunity for us.
We more invest in the sales team and also the marketing approach there. That's also helpful. It's really additional sales coverage and more focus in enterprise. We have a better internal tool to tracking whether the enterprise account coverage or the sales productivity. I think all these different part all helping improving enterprise sales.
Okay, great. Earlier you mentioned that we take a look at the Gartner data with regards to SD-WAN. It sounds like SD-WAN is essentially included in FortiGate. I was wondering if you could give us a sense for how we should think about the accounting for a revenue recognition for deals with SD-WAN and any kind of framework we can think about in terms of the uplift that you might see to a deal that's driven by that requirement.
Always good to have a GAAP conversation to close the call, so thank you for that. There's no difference in the accounting for it because you're selling a FortiGate appliance that has embedded with it a whole bunch of different functionalities, one of which SSL would be one as an example, another would be SD-WAN functionality. You recognize the appliance up front. All the appliances, well, I shouldn't say all, the majority of the appliances attach out of FortiCare or FortiGuard security subscription with them. That part of the deal is allocated to deferred revenue and then recognized over time. You still receive on the FortiGate, the appliance, you're still recognizing that revenue up front.
Okay. Thank you.
Thank you. Speakers, I'm showing no further questions in the queue at this time. I would now like to turn the call back over to you for any closing remarks.
Great. Thank you, Sherry. I'd like to thank everyone for joining the call today and let you know that Fortinet will be hosting an Analyst Day on November 18th, as well as attending the following investor conferences during the fourth quarter. We'll be at the RBC conference on November 19th in New York, the Credit Suisse conference in Scottsdale on December 3rd, the UBS conference in New York on December 10th, and the Barclays Conference here in San Francisco on December 11th. Presentations for all of these events will be webcast, and a link to those webcasts will be available on the investor relations website on those dates. If you have any follow-up questions regarding the call, please contact me, and have a great rest of your day.
Well, ladies and gentlemen, this concludes today's conference call. Thank you for your participation. You may now disconnect.