We're looking at revamping our security with fortinet... fortigates + fortisandboxing + ips. Anybody running a complete setup? What implementation model did you choose (integrated, inline, sniffed)? Did you see a considerable performance drop (we're being quoted at 15% on our ~2gpbs internet link). Any regrets or nasty surprises?
If anybody has any blogs or any documentation site other than the official fortinet site, I'd appreciate it. Doesn't seem to be that much of a community posting about the product(s).
Created on 04-08-2022 10:52 AM
Hello @metanbeky ,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
As per your query, I also found the following links that can be useful.
https://docs.fortinet.com/document/fortigate/6.2.10/cookbook/660221/fortisandbox
Thanks,
Yes, I am running and managing a FSA for a customer. It's fully integrated with Fortigates and FortiMail. Capable of running 8 VMs in parallel, it can handle the start-of-day-rush with a backlog of 400-800 files which is brought to zero within 1-2 hours. About 400 users (office env.) plus WAN traffic from about 10 branch sites are using it. There were no complaints about the retention time span yet.
After some years of operation now, about 1/1000th of all files submitted are flagged as malware. That is, files submitted already after signature checks by FGT and/or FML. With about 100.000 files a month, this is a signifcant security boost for my customer.
Operation is quite easy for most of the time. Some firmware releases had issues so that at some point operation stalled. Rebooted, and after a lengthy authentication with Microsoft (for Windows and Office licenses) it picked up flawlessly again. A real working horse in the basement, so to say.
Re. chosing a hardware or VM model, let's say that a FSA really eats performance. Either you invest in an appliance, or you vamp up your VM hypervisor. Both costs some. If I had to choose again today, I'd opt for a VM.
Using IPS or other UTM features is independent of using a FSA, and mandatory nowadays. IPS mainly protects the servers, sometimes buys some time while patching a security breach ('virtual patching'), AV is used throughout. Adding webfilter does some good, keeping the darkest corners of the internet out of the network, while preserving precious working time (you'll notice by now that I am German).
HTH.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.