Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
District9
New Contributor

How to utilise a 5GB WAN on FGT 200E - Workaround?

Hi,

 

We are using a FGT 200E. Our ISP recently upgraded our connect from a 1GB to a 5GB connection (worked out cheaper with the 5GB). We have 5 static WAN IPs (/29). I believe the 200E only support 1GB copper & fibre, no SFP+ support? 

 

How can we utilise the 5GB WAN connection?

 

We don't want to upgrade our FGT to a unit which support 10GB at this moment.

 

We thought about creating another WAN port but get Conflicts with 'wan1' subnet - Subnets overlap. We can try enabling overlap but going by Enable subnet overlap to set IP addresses... - Fortinet Community it advice against this.

 

Just wondering if other users have also encountered the above scenario and what was your solution?

 

Thanks

 

2 REPLIES 2
Cajuntank
Contributor II

So you have 2 major issues with that firewall hardware.

 

1. According to the specs, and this is what you are mentioning about, the firewall cannot handle a 10Gb interface connection. Now, can you "workaround" this some? Possibly. You can inject a switch that does have a 10Gb interface, along with some copper interfaces and using those copper ports, create a LACP group on your switch (that supports this) to an Aggregate set of ports (you'll create) on your firewall to create a WAN interface. Will this up your throughput from your firewall to your ISP via a switch? Yes. Will you get 5Gb of throughput? maybe close to it; however!!! #2

 

2. According to the specs of your 200E, it is only rated at 1.8Gb for NGFW throughput and 1.2Gb for Threat Protection throughput....meaning, if you are using it for anything more than just a simple firewall or IPSec VPN (so no inspection using AV, IPS, Web Filter, App Control, SSL Inspection), then you won't see that 5Gb performance anyway. You will see closer to the spec'd numbers of 1.2Gb or 1.8Gb as per Fortinet's data sheet for this model.

https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_200E_Series.pdf

 

You might want to investigate Fortinet's TradeUp program for your unit.

 

Hope that helps.

District9

Hi Cajuntank, thanks for your reply and information. Looks like an upgrade would be the best route forward. For now, I might experiment with using a using another router (maybe an old router with Openwrt) to pass through DMZ to FGT 200 to overcome the overlap subnet issue to create 2 WAN for SD-WAN. At least I can try to utilise a bit more of the available WAN bandwidth.

 

Many thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors