Skip to main content
gatorHeel
New Member
September 20, 2010
Question

edge router

  • September 20, 2010
  • 11 replies
  • 8609 views
Has anyone had success with the 50B, 60B or 60C as an edge router? Our application is essentially an executive office suite building whereby we have a single fiber circuit (15 Mbps) that we provide as a WAN interface to the individual suites. Each suite needs one or more public IPs. We were looking at some pure routers (Cisco 2811, 2911) and L3 switches (Catalyst 3750, 3560) but it seems like for what we need the Fortigate' s might be a better solution. Our only requirements are to route the public IPs and configure the guarantee/max/priority bandwidth features of traffic shaping. We really aren' t interested in the security features because each interface will have it' s own firewall behind it. So my questions are: 1. How does traffic shaping in the 50B/60B/60C compare to rate-limiting and policing in Cisco devices such as the ones listed above? Does it work well for both ingress and egress? 2. In the limited exposure I' ve had with a 50B (very impressed) there were some issues with SIP ALG and a particular SIP trunk provider (requiring that we disable it). If we configure the device in routing/transparent mode, are things like SIP ALG automatically disabled? We need the traffic to pass through Fortigate without any dynamic port mapping, etc. Thanks for any thoughts or feedback.

    11 replies

    rocampo
    New Member
    September 21, 2010
    Since you said you won' t need security features and just need routing and qos. I would go with the cisco solution since this have been tried and tested. You can' t go wrong with this one.
    doshbass
    New Member
    September 22, 2010
    The Fortigate will work perfectly in this scenario and gives you the ability to turn on security features later if required. For example If you are offering the WAN link, maybe you would like to throttle P2P traffic so your WAN link isn' t exhausted. This would appear to a Cisco to simply be port 80, whereas the FG can delve deeper if needed in the future. For the Function you are looking at, NAT mode would be better and you can simply use the FG as router, and be clever with VIPs and IP pools as well if you need it in the future. Don' t forget that you can also use a USB 3G dongle as a backup in case you have a WAN problem. You can always disable helpers if you see a problem and you can effectively turn off the Firewall state features by setting asynchronous-mode.
    gatorHeel
    gatorHeelAuthor
    New Member
    September 22, 2010
    doshbass, That sounds good, but did you mean to say NAT mode? That would involve remapping IPs and possible issues with protocols as SIP that aren' t very NAT friendly. I would need to send public IPs to each user so that they have full access to configure things on their segment as they wish. The only type of security that would be needed/desired in this scenario might be DDoS.
    doshbass
    New Member
    September 23, 2010
    Fortinet uses the term NAT mode to mean Layer 3 routing. I simply meant that rather than transparent which is Layer 2.
    emnoc
    New Member
    September 23, 2010
    So my questions are: 1. How does traffic shaping in the 50B/60B/60C compare to rate-limiting and policing in Cisco devices such as the ones listed above? Does it work well for both ingress and egress? 2. In the limited exposure I' ve had with a 50B (very impressed) there were some issues with SIP ALG and a particular SIP trunk provider (requiring that we disable it). If we configure the device in routing/transparent mode, are things like SIP ALG automatically disabled? We need the traffic to pass through Fortigate without any dynamic port mapping, etc.
    On #1, traffic shaping and packet priority is simple with a fortigate. In order to take advantage of TrafficShaping, you will need unique individual FWpolicies installed for the traffic that you will shape. So keep that in mind Also imho, traffic shapping on ingress is useless, you should rather shape the traffic at the egress and as close to the edge as possible. On #2, what' s specifically is the SIP problem with your SIP trunking and ALG? If your not doing any private-address-2-NAT/PAT translations, than dynamic ports openings should not be as critical. And lastly you should evaluate what you need? A router and firewall are not designed for the same functions and serve a different need. Let a router route data and a firewall perform it' s intended function. And yes a Firewall also does L3routing.
    rwpatterson
    New Member
    September 23, 2010
    ORIGINAL: emnoc Also imho, traffic shapping on ingress is useless, you should rather shape the traffic at the egress and as close to the edge as possible.
    Have you dealt with file sharing and large downloads lately?
    gatorHeel
    gatorHeelAuthor
    New Member
    September 23, 2010
    This device will be placed as close to the edge as possible. I understand that a router and firewall are not designed for the same functions and serve a different need. What I' m having a hard time grasping is that it appears the 50B/60B/60C can function as a pure router (without any firewall services) and can handle the throughput that we need in our application. That being the case would you recommend a 50B/60B/60C or a Cisco 2811/2911 to serve as our router that connects to our ISPs Ethernet hand-off? In my experience Fortinet' s SIP ALG does not work with certain SIP providers. It sends responses to a different port than it was sent on and in my case I had to dsiable (along with the SIP helper).
    emnoc
    New Member
    September 23, 2010
    Don' t know what you mean pure router, I think regardless if your routing, the device is a firewall and will need a FWpolicy NAT or even in Transparent mode. I personally think your mistaking NAT-mode to mean no firewall inspection.
    Have you dealt with file sharing and large downloads lately?
    Yes What I' m saying on ingress, if some one pings floods your pipe or udp or anything non-connection type of protocol, no matter how much ingress shaping you do, is not going to help you as far as bandwidth over that link. You would need to squash that by the upwind devices, and it' s best done at the egress port before it hits any other layer3 device. Traffic shaping on ingress and policing ( which are 2 different things btw ) have to be thought out and looked at very closely, to see what your trying to accomplish and the desired goal & effect. On egress is simpler and more effective to apply for bandwidth control, QoS assurance, and policing of one' s traffic flows. And to prevent link bandwidth starvation.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!