Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SecurityPlus
Contributor II

FortiGate Sizing - Church

How does one go about selecting a FortiGate model for use in a church. Through most of the week there are only 8 users on the network. For a few hours on Sunday there may be 100 users. The use case on Sunday is fairly basic using the common UTM feature to keep guest users safe on the web. Traffic shaping will be used for video streaming from one computer. Third party wireless access points will be used. In one installation an SD-WAN with a 100 Mb / 12 Mb connections will be in use. In another installation a single 25 Mb fiber connection will be used. Cost needs to be a careful consideration. Would a 60E be appropriate?
4 Solutions
ede_pfau

Second thought: why not arrange for a test FGT and let it run for 2 weeks? That would totally ensure the FGT is fit for the job, and it doesn't cost anything (or better, much).

Ede Kernel panic: Aiee, killing interrupt handler!

View solution in original post

Ede Kernel panic: Aiee, killing interrupt handler!
Toshi_Esumi

My opinion is similar to Ede's. I would try a 60E first. Probably just ok unless you start adding a lot of FortiGuard/UTM services like IPS, etc.

View solution in original post

James_G

Hi, I have a couple of locations where I have a WiFi network put in for staff to connect mobile devices to when they are on site, isolated network from corporate, just internet access. Both sites have 100mbs link to isp, and peak at over 300 devices connected, all being served by a couple of fgt 50e devices each site in HA. The 50e units are rock solid stable and manage everything the users can throw at them, the only day I ever had an issue was when iOS 11 was released and the 50% of users with apple devices all downloaded on the same day! And... that was a limit of the isp not the firewall. The 50e are amazing units for this task, I have web filter, app control and av enabled, as said before, never seen the little unit struggle.

View solution in original post

James_G

Reply to edu_pfau: It’s about knowing your requirement, true the asic based units will smoke the cpu only in vpn, ips and dlp traffic, that see offload to np and cp asic, web filter and av are not so. As mentioned, I have 50e units that are working fine for the public WiFi access type role. To counter that, I also have a fair number of the older 60d units that are shockingly slow running security profiles on, but my usage of these units are just traffic flow and vpn back to head office, so no external web access, in that role they rock and have silly fast vpn throughput. I would agree the 60e is probably best of both worlds.

View solution in original post

13 REPLIES 13
ede_pfau

Watch out! The 50E series lacks the NP network ASIC. You see that by comparing the latency (180 µs) vs. that of the 60E (3 µs). Certain traffic like IPsec VPN is not accelerated and it's throughput is drastically lower.

Whether this is worth the difference in price is up to you.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

 I did some work with  baptist and SDA church and we used a 100C back in the day. Granted no UTM features where used. They had at least 100-200 members.

 

I highly doubt you will need proxy or tls-inspection,nor AV/AS....

 

Any of the branch SOHO should cover a small church and since the delegation should be listening to the pastor they should  not be browsing the internet ;)

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
James_G

Reply to edu_pfau: It’s about knowing your requirement, true the asic based units will smoke the cpu only in vpn, ips and dlp traffic, that see offload to np and cp asic, web filter and av are not so. As mentioned, I have 50e units that are working fine for the public WiFi access type role. To counter that, I also have a fair number of the older 60d units that are shockingly slow running security profiles on, but my usage of these units are just traffic flow and vpn back to head office, so no external web access, in that role they rock and have silly fast vpn throughput. I would agree the 60e is probably best of both worlds.
SecurityPlus

Very helpful! Thanks.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors