I have a couple of FGT 300D clusters that I have budget to replace - below is the performance stats at peak load. I will throw this out, what model would you be replacing them with?
Thanks for any input :)
TVBC-FGT1 # get sys perf stat CPU states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU0 states: 0% user 0% system 0% nice 99% idle 0% iowait 0% irq 1% softirq CPU1 states: 0% user 0% system 0% nice 99% idle 0% iowait 0% irq 1% softirq CPU2 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU3 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq Memory: 8188500k total, 3661616k used (44.7%), 2516180k free (30.7%), 2010704k freeable (24.6%) Average network usage: 142065 / 143177 kbps in 1 minute, 215870 / 216768 kbps in 10 minutes, 474045 / 474543 kbps in 30 minutes Average sessions: 41247 sessions in 1 minute, 40848 sessions in 10 minutes, 40285 sessions in 30 minutes Average session setup rate: 328 sessions per second in last 1 minute, 318 sessions per second in last 10 minutes, 287 sessions per second in last 30 minutes Average NPU sessions: 18906 sessions in last 1 minute, 18607 sessions in last 10 minutes, 18071 sessions in last 30 minutes Average nTurbo sessions: 875 sessions in last 1 minute, 824 sessions in last 10 minutes, 794 sessions in last 30 minutes Virus caught: 0 total in 1 minute IPS attacks blocked: 0 total in 1 minute Uptime: 52 days, 21 hours, 43 minutes WCC-FGT1 # get sys perf stat CPU states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU0 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU1 states: 0% user 0% system 0% nice 99% idle 0% iowait 0% irq 1% softirq CPU2 states: 1% user 0% system 0% nice 99% idle 0% iowait 0% irq 0% softirq CPU3 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq Memory: 8188500k total, 3678816k used (44.9%), 2506596k free (30.6%), 2003088k freeable (24.5%) Average network usage: 197348 / 198647 kbps in 1 minute, 155562 / 156545 kbps in 10 minutes, 433258 / 434063 kbps in 30 minutes Average sessions: 29453 sessions in 1 minute, 28829 sessions in 10 minutes, 28542 sessions in 30 minutes Average session setup rate: 168 sessions per second in last 1 minute, 175 sessions per second in last 10 minutes, 185 sessions per second in last 30 minutes Average NPU sessions: 15501 sessions in last 1 minute, 15250 sessions in last 10 minutes, 14803 sessions in last 30 minutes Average nTurbo sessions: 948 sessions in last 1 minute, 828 sessions in last 10 minutes, 865 sessions in last 30 minutes Virus caught: 0 total in 1 minute IPS attacks blocked: 0 total in 1 minute Uptime: 57 days, 21 hours, 23 minutes
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Why do you want to update them? That's the first question.
Those stats shows no performance issues or helpful information for determining a hardware upgrades. Most upgrades are done to stay update in hardware or the product becoming end of life. Or you need more interfaces or faster interface ( 1 vrs 10 vrs 40 gige ) or you near max traffic session or traffic throughput. You have 3 more years of support of the 300D before it's EoS fwiw.
Ken Felix
PCNSE
NSE
StrongSwan
I have a requirement to reconfigure interfaces, create zones between interfaces and policies, change external interface to SD-WAN etc, plus I just need more interfaces. I would rather get this right on an offline firewall, then just swap in at go live.
And, I have the budget to do it this year.
Part of my thinking is dropping from a 300D to 100F is actually a massive cost saving, hardware and 1 year support is cheaper then just renewing support, I am trying to do due diligence in my head that this is not a crazy move.
The raw stats of throughput say 100F is easy enough, how do I confirm this?
Read the data sheet but don't over look LACP support. Not 100% sure you can do bonded members in a 100F. I'm doing the same thing now, but with 40F for cost saving for dialin home agents that works from home. They had FGT60D and the OPEX saving was worth it. We also found a outfit that bought our old FGT60D for 75 usd per unit, that was the best dial that we could get.
I'm sure someone will chime in on the FGT300D vrs FGT100F. Currently in my day role we are migrating customer into FGT300Es from 200Bs or even worst 200As ;)
Ken Felix
PCNSE
NSE
StrongSwan
James_G wrote:The raw stats of throughput say 100F is easy enough, how do I confirm this?
If you can swing it pass your local fortinet dealer, I suggest asking them to provide you with a 100F demo model to play around with, to get a better idea of the performance in your network setting. Glancing at the firmware availability, it looks like the 100F is going to be either 6.0.8 and higher or 6.2.2 and higher.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Dave Hall wrote:I'm on 6.2.3 already :)
James_G wrote:If you can swing it pass your local fortinet dealer, I suggest asking them to provide you with a 100F demo model to play around with, to get a better idea of the performance in your network setting. Glancing at the firmware availability, it looks like the 100F is going to be either 6.0.8 and higher or 6.2.2 and higher.
The raw stats of throughput say 100F is easy enough, how do I confirm this?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1095 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.