Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Fortigate 60 max users ?

Hello, i have a Fortigate 60 and a network about 50 users. Many of the users use Virtual PC / Vmware so there is about 80-90 connected computers. Lately users have complained about network problems like packet loss and hangs / freezing when using RDP / Citrix remote in peak times, but it varies alot.. some days it works fine.. How many computers can the Fortigate 60 handle or is recomended ? Additional info : I am not running any Antispam / Antivirus on the Fortigate. Our Internet Connection is a 40Mbit Fiber
5 REPLIES 5
romanr
Valued Contributor

I can truely understand the people complaining! Even without any protection profiles enabled 40MBit and sessions from 80-90 computers are actually too much for a FGT-60... Depending of the number of sessions and new session/sec! I don' t remember the performance specs of the 60, but it for sure has far less the throughput of a 50B... which has a theoretical firewall-throuput of 50MBit! Even which no content feature enabled, the lowest models which can practically achieve these values are 60B and 100A! If you don' t need any Fortiguard services a 60B is real cheap thing!! cheers.roman
Not applicable

Thnx for answer ! Yea, it is time to upgrade.. but where can i measure the new session/sec ?
Not applicable

measurment is hard for session number. one internet connection from one computer can create many session. so Always you should think a powerfull model. for 90 computer. you can use fgt110c. fgt 60b has 100mbit firewall throughput and 70.000 session limit. fgt 110c has 500mbit firewall throughput and 500.000 session limit. good luck
UkWizard
New Contributor

If you can answer the following questions, i can run it through the official sizing tool. But be warned, for a 40Mbit connection, it would probably recommend some SERIOUS sized boxes. But again, depends on what you turn on. FGT60 is for small offices really. You could probably reduce the current load on your box by doing some tuning. Like adding an RDP rule at the top with no profile, so that traffic literally just passes through. Answers Needed for sizing; What is the max number of concurrent Firewall users? YES/NO Do you plan to utilize IPsec VPN? YES/NO Do you plan to utilize Antivirus, antispam and/or Web Filtering? YES/NO Do you plan to utilize IPS? YES/NO What speed is your external link? 40Mb? What is your average utilization of your link? 10%/20%/30%/40%/50% ... etc Answer below, where the overall total should add up to be 100% What % of your traffic is HTTP? What % of your traffic is SMTP/IMAP? What % of your traffic is FTP? What % of your traffic is POP3? What % of your traffic is other traffic?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Thnx for all answers !, We are upgrading to FG-110C today so i think this one will get solved :)
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors