Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cryptochrome
New Contributor III

50E vs 92D

Hi,

 

I am looking to get me a smaller Fortigate for my Home Office / Lab Environment. I have a rather beefy Internet uplink (400 mbits), very few users, but lot's of sessions. A lot of traffic will be run through IPS, some traffic of users (web browsing) will run through the full UTM feature set, incl. SSL decryption.

 

I've been looking at the 50E (or 51E with storage) and thought it might be the right choice, but some of the datasheet's numbers worry me. For example, it says it only has 160 mbit of NGFW throughput. What exactly does this mean? Is this for when I specify users and applications rather than IPs and port numbers?

 

I am also looking at the 92D as an alternative, but it costs much more and the performance numbers are only a little higher for NGFW and IPS, whereas they are dramatically lower in general firewall throughput (still more than I need). 

 

Which of the two is newer? Which one would you recommend? Do you think a 50E will handle 400 mbit Internet with the profile I detailed above? Any other models I should look at (should be desktop model or at least a model that is not loud, e.g. I could live with a 19 inch rack model if the fans are not louder than those in the 92D). 

 

Ideally I am looking for a model that can handle the 400 mbit with every feature (including NGFW). 

 

Thanks!

12 REPLIES 12
cryptochrome
New Contributor III

You are both right. I am managing large enterprise firewall and IPS environments in my job, and while it is true that there is a huge attack surface these days spread across a bazillion different OS and app flavors, we are still not turning on everything there. Even the large datacenter firewalls struggle with too many IPS patterns active, so it's always a compromise between security and performance. We tend to put a lot of work into this and really try to figure out which patterns are actually needed (there is no need to turn on patterns for Novel Groupwise if you're using MS Exchange). 

 

I am just not sure I want to put this much work into it in my lab. It's not just a one-time set it and forget it, it needs constant re-evaluation. 

 

I am going to take a closer look at the 100D. However, if this is a very loud machine, I can't have that in my office and will have to revert to a smaller model. I think the 50E is the best from all the models we discussed so far. It's a compromise, yes.

 

Thanks for your input guys, really appreciate the help.

 

 

storaid

v5.4 is unstable now...

I don't think the 5xE is good choice..

FWF60D x2 FWF60C x3 FGT80C rev.2 FGT200B-POE FAP220B x3 FAP221B x2

FSW224B x1

FWF60D x2 FWF60C x3 FGT80C rev.2 FGT200B-POE FAP220B x3 FAP221B x2 FSW224B x1
cryptochrome
New Contributor III

storaid wrote:

v5.4 is unstable now...

I don't think the 5xE is good choice..

Because of the unstable 5.4 or are there other reasons?

 

Thanks

Labels
Top Kudoed Authors