Skip to main content
ULL1903
New Member
December 30, 2024
Question

SECURITY

  • December 30, 2024
  • 5 replies
  • 2935 views

Hello community, I am thinking about implementing a FortiGate device in my network. However, due to the topology of the network, I have questioned whether or not to replace my Core Router directly with a FortiGate. What has been your experience? Regards.

5 replies

xeniacanary
New Member
December 30, 2024

Replacing your core router with a FortiGate device depends on your network needs. While FortiGate offers robust security features like firewall protection, VPN, and intrusion prevention, core routers handle routing protocols and large-scale traffic. I recommend using FortiGate as a security appliance alongside your core router rather than replacing it entirely, as core routers are optimized for routing functions that FortiGate may not fully support. This approach ensures both strong security and efficient network routing.

dingjerry_FTNT
Staff
Staff
December 30, 2024

Hi @ULL1903 ,

 

Without a network topology diagram, it's really hard to provide you with any recommendations.

 

However, you may use the Core Router as the Gateway for the FortiGate device.

ULL1903
ULL1903Author
New Member
December 30, 2024
Hi dingjerry_FTNT This is a simplified example of how the topology is. Based on the primary need to shield the network from external threats, I was thinking about the implementation between the CCR and Core teams.
 
Your paragraph text.jpg
Toshi_Esumi
SuperUser
SuperUser
December 30, 2024

The simplest is to just replace the core router with the FGT because the diagram doesn't suggest it's handling multiple routing protocols currently.

Toshi

Rajneesh
Staff
Staff
December 30, 2024

Hello @ULL1903 

Following points need to checked:

1. Make sure the device supports the protocols which are running on your existing device.

2. Firewall policies needs to be correctly applied, else it will break the communicationn.

3. Device hardware capability.

4. Network topology as mentioned by the other members, it plays the important role

Yurisk
SuperUser
SuperUser
December 30, 2024

What is the current vendor and model of your Core router ?

ULL1903
ULL1903Author
New Member
December 31, 2024

MK CCR2116-12G-4S+

Cajuntank
Contributor III
December 30, 2024

As others have asked, your topology and requirements would allow for a more complete answer, but for sake of just adding some further insight, using myself as an example, I use a FortiGate solution as my core router at my data center for specific subnets I want to perform security inspection on. So while my Aruba CX equipment does L3 routing for some network subnets from my WAN sites, my FortiGate does L3 routing and security inspection for those subnets at my datacenter I want that added level of protection on.

ULL1903
ULL1903Author
New Member
December 30, 2024
Hi Cajuntank, This is a simplified example of how the topology is. Based on the primary need to shield the network from external threats, I was thinking about the implementation between the CCR and Core teams. Your paragraph text.png
 
 
 
dingjerry_FTNT
Staff
Staff
December 30, 2024

Hi @ULL1903 ,

 

You can either replace the Core Router with the FortiGate or use the Core Router as the next hop/Default Gateway for FortiGate.