Skip to main content
wamendoza
Explorer II
February 22, 2023
Solved

FORTIGATE SIZING

  • February 22, 2023
  • 2 replies
  • 17978 views

Hi team,

 

I would like your help with the following

I have a company that wants to give a kick to an SSG140, and they ask me for a FortiGate hardware to be able to replace it. I don't see that Fortinet has any sizing tool for these cases, so reviewing the datashee of this SSG140, it seems that all the 60, 70 and 80 models fit perfectly, but I want your support, I don't want wrong sizing

 

https://www.juniper.net/documentation/hardware/netscreen-systems/netscreen-systems54/GSG_SSG140.pdf

 

http://www.nha-fl.com/files/SSG140.pdf

Best answer by gfleming

Yes 80F works and you can re-purpose the LAN ports as WAN ports but just be conscious of the total number of usable ports on that box is 10. So you are using half the ports just for WAN connectivity.

2 replies

gfleming
Staff
Staff
February 22, 2023

The Fortinet data sheets are very accurate.

Please let us know what your requirements are.

  • how much throughput do you need?
  • what NGFW features do you require?
    • App Ctrl
    • IPS
    • Web Filter
    • Anti Malware
    • SSL Deep Inspection
  • how many users do you have?
  • will you be using IPSec VPN or SSL VPN (either client or site-to-site)
  • any other features/functionality?
gfleming
Staff
Staff
February 22, 2023

If you are comparing just the specifications for the hardware devices then yes even a FortiGate 60F will work for you. But you have to consider your future needs as well.

 

One thing to note the 80F has dual PSU if you want that

 

Also you will need to order a separate rackmount kit for the 40,60,70,80F firewalls

Cajuntank
Contributor III
February 22, 2023

What is the current and/or expected bandwidth for your Internet? What do you expect to implement in regards to threat protection (AV, Web filter, IPS, File filtering, Deep packet inspection, etc...)?

 

Anything you get, due to the age of your Juniper appliance, will be double if not easily triple the performance on Fortinet's entry level models but everything you do comes at a process cost, so depending on those answers you provide, might change the determination of the model or models to zone in on. So for a simplistic example, if you have a 1Gb shared Internet connection, the 60F would only be able to give you 700Mb of threat protection for example, so probably not the right size appliance...so information like that helps better determine where you might need to focus in on.

wamendoza
wamendozaAuthor
Explorer II
February 24, 2023

Hi friend

 

Sorry for reply late

 

What is the current and/or expected bandwidth for your Internet?

A: Today they have 5 links of all 100mbs

 

What do you expect to implement in regards to threat protection (AV, Web filter, IPS, File filtering, Deep packet inspection, etc...)?

 

A: They want to use all the security features that FortiGate offers like av, web filter, ips, app control etc

Cajuntank
Contributor III
February 24, 2023

"Today they have about 5 internet links of 100 and 50 mbps each"... I guess I am still a little confused then. So just to confirm, you have 5 different ISPs and they are delivering you either 50Mb or 100Mb service each to this 1 firewall? And you have it set where you are load balancing across all 5 different connections?