Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RLED
New Contributor

Questions - FG30E and FG50E logging/DMZ + HR4860W OEM FG-61E FortiOS compatibility

Hello Fortinet Comunity, I'm new with Fortinet products, and I'm looking a FW Fortinet (with VPN site-site and DMZ capabilities) as starting point for learn implementing and administering platforms like Fortigate 2000E (v6.2.3 build 1066), and searching into datasheets and FortiOS 6.2.3 supported platforms, I have the following questions:

 

1) Regarding lack of local logging and reporting capabilities of FG30E and FG50E, this can be solved with any Syslog server where logs and info reporting can be exported, right?.

2) Can FG30E and FG50E support VPN site-site and DMZ (even if they haven't a dedicated DMZ interface like FG-61E)?

3) I find a HR4860W that is an OEM FG-61E, those OEM devices can support FortiOS 6.2.3 or be upgraded with any FortiOS version for FG-61E (as any other FG-61E)?.

 

Regards.

12 REPLIES 12
Toshi_Esumi

Totally depending on how you want to use/deploy it. If you just want to study/learn I would look for the cheapest as possible. If it needs to handle more than a few IPSec VPNs I wouldn't go to a device that doesn't have NPU like 100D. 60D might be better for VPNs but now it's considered very slow for all other stuff after E and F series are introduced. We were very glad we could replace those 60Ds to 60Es for many customers. 

RLED

boneyard wrote:

it is a fine starting point, in all honesty for learning any model is fine. you are not going to get a serious benefit from 60E vs 100D or 60D vs 100D or ... there are small differences but most is the same.

 

but that but as mentioned just be aware that the latest available is already not possible on the 100D, so you will get more then enough out of it for the next year, perhaps two depending on how fast your production environment is going to move forward with firmware.

 

personally i wouldn't buy D series for a lab / learning now, i would go for at least E series. but again if you really need something now and the budget only allows D series you will be fine. also keep in mind what you buy probably comes without active UTM licence so you will be missing some functionality there if that is enabled in production.

 

toshiesumi wrote:

Totally depending on how you want to use/deploy it. If you just want to study/learn I would look for the cheapest as possible. If it needs to handle more than a few IPSec VPNs I wouldn't go to a device that doesn't have NPU like 100D. 60D might be better for VPNs but now it's considered very slow for all other stuff after E and F series are introduced. We were very glad we could replace those 60Ds to 60Es for many customers. 

Hello boneyard+toshiesumi, thanks for your answers:

 

1) I check again the 6.2.3 compatibility matrix and I find that the FG-80E (81E) series is above 30E, and has the disk logging capabilities 30E lacks.

 

2) For this and following your advices for cost-benefit, is better to have an E series, if is for learning to eventually be prepared for administering a 2000E, and one to have VPN site-site, DMZ, Layer3 intervlan routing, the 81E or 91E can be a good choice, right?

 

Regards.

 

boneyard
Valued Contributor

yes, 81E is a good choice for that, there are some complaints about the 9xE series, but again for learning that won't bother you i believe.

Labels
Top Kudoed Authors