Using Fortigate virtual instead of Fortigate physical
Hi!
I need a new internal "segmentation-firewall". On the perimeter, there is a ha-pair of FG-200E. The new segmentation-firewall filters between different Client- / Server-Security-Zones...
...but I need 10GbE for backup-jobs between the internal segments.
So: I need a ha-device, that can do: 5 Gbps IPS and full 10 Gbps for "non-NGFW-traffic" for single streams.
Long introduction, but: What do you think about buying two FG-VM08v as VMs (HA-pair) to handle that traffic on VMWare (without SR-IOV, as I do not have Ent. plus). Is this a good idea? The alternative would be a pair of 1000Ds or 1200Ds because the smaller devices do not have 10 GbE-interfaces...
VMs seem to be much cheaper...
Thank you for your thoughts
KPS
