Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Goldy
New Contributor

FG-400 Vs FG-401

Hi guys.

After many years, we are about changing our organizational firewall and move to Fortigate.

We are deliberating between two models:  FG-400F and FG-401F.
The main deference is that FG-401 has an internal storage (SSD), while the FG-400 has none.
My question:

  1.  How crucial is it to have internal storage,
  2. What the risk of not having one.
  3. Does it have any performance influence.

Any help will be appreciated :smiling_face_with_smiling_eyes:

Regards,

Goldy

4 REPLIES 4
ozkanaltas
Valued Contributor III

Hi @Goldy ,

 

If you have FortiAnalyzer, I think you do not need to choose the disc model.

 

Even if there is a disk on the device, FortiGate can keep logs for a maximum of 7 days.

 

Frankly, I have never seen any negative impact of the disk on performance. Just based on my past experiences, I can say that since too much data is written and read on the disk, the risk of corruption is higher than the risk of device failure. In the past, in such a situation, you had to repair the entire device. But I honestly don't know how the situation is right now.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
nathan_h
Staff
Staff

Hi Goldy,

 

In addition to ozkanaltas's comment, it really depends on your requirement on how important logs for you. If you have external logging, you may not need the disk. Keep in mind, that if there is a connectivity issue to the external logging, you may lose the logs. Another advantage of having a disk is logs will still be retained after a reboot. You can actually extend the 7 days retention period but it is not recommended.

 

 

Nathan
FCP-NS, FCP-PCS, FCP-SO, FCSS-NS, FCSS-PCS, FCSS-SASE
Goldy
New Contributor

Many Thanks.
My concern is that we have a lot of traffic (About 12TB daily and 150,000 concurrent connections).
In turn, it might produce many logs.
Also, this FW will work in high availability.

nathan_h

With that amount of logs, you may need FortiAnalyzer for Forward traffic logs. You can still have other logs, such as Event logs, to be stored on the disk.

Nathan
FCP-NS, FCP-PCS, FCP-SO, FCSS-NS, FCSS-PCS, FCSS-SASE
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors