Skip to main content
andrew_ang
New Member
September 8, 2016
Question

Choosing Between FortiGate 100D and 200D

  • September 8, 2016
  • 2 replies
  • 17754 views
I'm setting up a new office that will have a little under 200 users. I'm not sure which product to use. I'm thinking of getting either 2 units of the 100D set up in HA mode, or a single 200D. With the 100D, I can setup a full mesh with a set of stacked switches to avoid single points of failure. I'm a little worried about the lifetime of 100D if we turn on logging since its using flash storage. And getting a fortianalyzer is out of the budget. Any advice? Thanks. Andrew

    2 replies

    ede_pfau
    SuperUser
    SuperUser
    September 8, 2016

    You could log into memory. The default mem size for this is ~ 90KB but can be configured to 10% of the built-in RAM (in these cases, 200 MB). Even 4 MB, if logs are chosen wisely, can cover a lot of time and events.

    That said, if I had a choice and only budget for 2x 100D or 1x 200D, I'd always take the 200D. If protecting and scanning my 200 users is overwhelming my FGT then a cluster won't help. Prepare for a quick express hardware exchange service and take the more powerful one. If absolutely necessary, request budget for a cluster member next year.

    emnoc
    New Member
    September 8, 2016

     And getting a fortianalyzer is out of the budget.

     

    you have so many other options free to low cost;

     

     

    * forticloud ( free with set limits)

     

    * if you have a virtualize env a simple stroke linux/bsd  host  with let's say 8-20gig of storage  is more than adequate

     

    * a physical host setup  for logging  if you don't have a virtualize env

     

    Everybody jump on the "local logging limits" and in fact more many other  similar  sized firewalls from  the others  vendors DellSonicwall/ASA/etc..... have  the same or similar  restrictions and  people get by with these in similar sized offices

     

    Now between the 2  models, the user count is one issue but what do you plan on doing ( explicit proxy, web-url filter, AS,etc.....)

     

    What bw upstream ( 1 , 2,3,4,5, gigs or are we talking megs )

     

    But units are ready available the 200D would be more

     

    Neither have hardware acceleration so that point is mute ( you need a 300D or better  but the price jumps $$$$s )

     

     

     

     

     

     

     

     

     

    Alby23
    New Member
    September 8, 2016

    HA should NEVER be considered as a solution in order to increase firewall performance in a new implementation.

    You have to dimension the performance on a single-unit basis.

    At most, you could consider A-A at the end of the life of the apparatus just to have the time to order/configure new appliance generation; at the end... not at the beginning.

    andrew_ang
    New Member
    September 8, 2016

    Thanks for the feedback everyone.

     

    OK. So that means 100D is out. I plan to use Application Control, IPS, Web Proxy/Filtering, and am planning to test out the AV. I also have 4 VPN Point to Point tunnels. Bandwidth is planned at 2x40Mbps LB from 2 different ISPs, and we may increase if needed.

     

    We had a 60D previously and I chose that because of the advertised throughputs, and that's where it kept locking up because the application control was eating up the CPU. So I had to carefully choose the NGN services and turned off a couple of them on the policies.

     

    Do you think 200D would be able to accommodate plus/minus 200 users?

    Alby23
    New Member
    September 8, 2016

    It's a bit borderline.

    200 users, 80 cumulative Mbps Internet and all or almost all utm features is a lot of computational power.

    You could surely accomplish this with a 200D but you have to fine tune it; a 300D has an overwelming power due to the NP6 and IPS performance.