Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mutallib
New Contributor

New firewalls vs old

Hi,

Currently we are using dual FG-224B in HA mode. We need to update our firewalls with new and cheaper one. (down grading our fw level)

We are looking either 60D or 90D as our replacements.

 

Can you suggests which have the similar performance comparing with the Spec of 224B.

I have checked their data sheet, and their terminologies have changed and additional information are mentioned; make its confused.

 

Please guide me to decide the unit.

5 REPLIES 5
MikePruett
Valued Contributor

How much data throughput are you needing with IPS/UTM etc?

 

You can use NGFW or IPSEC as a close comparison  to the old UTM parameters. I personally have a hard time suggesting less than a 92D these days but that is because internet connections are getting so damn fast.

Mike Pruett Fortinet GURU | Fortinet Training Videos
kallbrandt

60/90D is a rather big step down from a 224B. If you plan on using anything else then plain firewalling (NAT, stateful packet inspection), go with a 100D.

Richie

NSE7

Richie NSE7
Paul_S

60E will be released this month I believe!

FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x                   [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5  |  Fortimail 5.3.11 Network+, Security+

FG200D 5.6.5 (HA) - primary [size="1"]FWF50B' s 4.3.x, FG60D's 5.2.x, FG60E's 5.4.x [Did my post help you? Please rate my post.][/size] FAZ-VM 5.6.5 | Fortimail 5.3.11 Network+, Security+
Mutallib

But looking at the specs of 224B, which looks less or almost similar 60D. and then I would have to change it within 2 years due to End-of-Life.

 

224B is satisfying our current setup. We have a configured as HA (A/P mode ). Also the company is looking for a cost cutting operation. So the renewal of these 224B (two units) cost as much as new 60D (two units), and their renewal will be less for the coming years.

kallbrandt

Yep, that's some very good points. And the 224B is very old now, so new hardware is a relief in itself.

As long as the company isn't planning on adding a lot the load (more users/servers), you should be good.

 

(I actually had a HA-pair with 2 224B dying on me the same day I was on the premise to swap them for 2 200D... The old 224B lasted 10 years without a glitch, but then the flash went corrupt in both the same day! 10 years is ok though. Sturdy equipment really. Can't blame them for dying... :-))

Richie

NSE7

Richie NSE7
Labels
Top Kudoed Authors