Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SNR_Margin
New Contributor

Product Advice

Hello all, I am after some general product advice if you do not mind?

 

First a bit of background as it will put what I'm looking for in context. I recently took over management of a small rack of servers in a data center running behind a Juniper SRX240h Gateway. After I got the Juniper's software up-to-date it's actually been rock solid, however the product has entered EoL and is not officially supported anymore so best practice would suggest I need to replace it. I'd also like a gateway/firewall with some advanced security features like UTM, the current Juniper is setup in its most basic router form.

 

There are actually two of them in the rack, the second is a cold spare I keep configured ready for switching over in the event of the primary failing. They are connected to the internet via a recently upgraded 50Mbps link (previously 20Mbps) which can burst up to 1Gbps when required - although I only see it get to 100Mbps as a result of the 100Mbps port on the Juniper. This is fine though, it never gets above 35Mbps during business/production hours it tends to burst when we run our cloud backups

 

The rack, which as I mentioned is in a data center, consists of about 10 physical servers. It runs various virtual servers including domain controllers, backups, but the most important ones are the 6 web servers. We run VPN's to 3 sites they transfer about 100MB worth of data each night, they're important but not under heavy use.

 

Configuration wise it's setup really simply at the moment, one port has the internet connection plugged in and a second port runs to a network switch. That's it :)

 

So my first question is naturally - which FortiGate would you recommend? I was hoping the 60E/80E would be OK, but I'm wondering if my uses might push me towards the 100E.

 

My second question is regarding the service bundles. There are absolutely no end-users on the network, just the servers. I don't need things like anti-spam or web-filtering for example however I'd really like additional DDoS protection and some IP blocking of known malicious networks. What would I need for this?

 

Thanks in advance

1 REPLY 1
MikePruett
Valued Contributor

80E would suffice. It can do up to 360 Mbps of NGFW.

 

If you only do a solid 35 during business hours you are golden and still have some room.

I would create a policy that has no UTM on it specifically for your backs. Make them super granular and you can flow up to 4 gigs of regular firewall traffic through it.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors