Thoughts on 10GbE without SFP+ FortiGate
Interested in peoples' opinions and suggestions on this.
I’ve added a few 10GbE links to our office setup, mostly for fast NAS access, and will soon move some of our nodes to 10GbE as well. Right now these are all directly connected with copper RJ45 10GBASE-T (hosts with Intel X550-T), but adding the nodes will require a 10GbE switch. As will the vmware platform we're considering for next year or the year after.
I would like to have a FortiGate in between some of these new 10GbE hosts, mostly for IPS and some AV. Note that I DON'T need 10GbE to the wan.
The "cheapest" FortiGate with a few SFP+ ports is the 500E, which is way more than we need. We won't have a vmware platform to run a VM FortiGate using the platform's 10GbE nics till much later, so that isn't really an option.
I'm considering a 100D, 140E, or 200E with a couple big 802.3ad link aggregate interfaces (8x or more physical interfaces each) to give me close to 10GbE to the 10GbE switch. I can run some tests on a current 100D to check feasibility of this. But it's hard to know how much IPS or AV throughput I'll actually get for these cases. For example, the 200E spec sheet lists 1.8Gbps NGFW Throughput, but how does that translate to an 802.3ad aggregate of 8 interfaces? Would be nice if the answer was 8 x 1.8Gbps but that seems unlikely.
Any thoughts on this? Reasons this should or shouldn't work? A better/easier way?
Thanks.