Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ByterunnerHome
New Contributor

OS 5.x stable for production use?

Hello, If the " new" OS 5.x best praxis for production use? How stable is the V5.x for Fg800C? regrads Byte
7 REPLIES 7
simonorch
Contributor

i' ve not hit any show stopping bugs so far but be careful, i think it will depend on what features you use. the more i use v.5 the more i like it

NSE8
Fortinet Expert partner - Norway

NSE8Fortinet Expert partner - Norway
micahawitt
New Contributor III

5.x is nice, i do like it alot, if you have a bigger device that can muscle through the features its ok. Lower end devices like 60 and under i would still use 4.x Sad the 60D doesnt have a 4.x firmware, i had to drop my 40C-wifi to 4.x as 5.x runs at 75% mem even with just av/firewall policies.
DirtyBlueshirt

Expanding on this, I wouldn' t use it on anything with less than 2GB RAM, and even then preferably 4 GB RAM and above to allow breathing room. On my 100D (1st Gen) it kept a stable 65% +/- (2GB RAM) I had to get that unit RMA' d and was replaced with a 2nd Gen 100D (4GB RAM) and memory is much lower, pretty much half.
--- Aaron Slater Security Analyst, Network Engineer, Part-Time Everything Else
--- Aaron Slater Security Analyst, Network Engineer, Part-Time Everything Else
romanr
Valued Contributor

The most important question is: Do you really NEED a feature of OS 5? And if yes - which one? So is it worth the risk? The OS5 seems stable so far, but there are still a lot of bugs and also there is still some development and changes within the next patches - In an overall corporate environment I' d still wait 2-3 patch levels at least. Especially if you extensively use UTM features beyond more or less default settings!! I got some installations at customers already running OS 5 ... The intel based boxes like 300c or your 800c really do run well actually. there are still some bugs with FSSO, Gui Glitches and some others. On the smaller boxes (ARM based boxes) 4.3 seems much more stable. The new Wireless Controller is very good and a really boost in performance. But this is for me right now the only killer feature to upgrade ... The rest of the new feature doesn' t seem fully production ready now (endpoint control, reputation, device policies,...) If you use a FortiAnalyzer there is an additional reason to wait - Fortianalyzer version 5 is far from being ready for production!!! br, Roman
emnoc
Esteemed Contributor III

The more advance features you use, makes you at more risk. Only you can decided what' s right or normal. I wish fortinetSupport would place recommendation for the software download & in the same fashion as JuniperSupport. This could help the consumer make a wise choice or at least know where the mfg' er stands at.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
simonorch
Contributor

I' m currently configuring up a 600C cluster ready to go into production at the end of july and just the changes made in the FW policy and address object areas of the gui has made the job easier. The increased visibility and control coming from device ID and the improved widgets has also been a hit but i agree with the others that the desktop models struggle.

NSE8
Fortinet Expert partner - Norway

NSE8Fortinet Expert partner - Norway
Uwe_Sommerfeld
New Contributor

My experience is OS 5 works just OK as long as you use it as a firewall. You have to be careful with explicit proxy and UTM, depending on which features you use. My personal opinion is the explicit proxy is far from production ready as long as you want SSL filtering.
Labels
Top Kudoed Authors