Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ealfonso
New Contributor

SSL Offloading What is your opinion?

Has anybody tried SSL offloading? The reason i am asking is because currently we have a radware ssl accelerator and a foundry load balancer. We are in the process of evaluating different load balancers with an SSL accelerator built in to the box to simplify our configuration. I was wondering if I upgrade to Fortinet 620B and use the load balancing and ssl offloading features of the box will do a good enough job that we dont have to purchase separate load balancers with sssl accelarator..
ealfonso
ealfonso
6 REPLIES 6
red_adair
New Contributor III

This may depend on what Features you rely on. If it' s basic SSL Offloading with,Backend-Server balancing and SSL-ID Stickyness it works pretty solid - also Hardware accelerated (dependin on Model though). You cannot use AntiVirus for example for the offloaded Sessions though. So i' d say it' s solid, but basic, SSL-Offloading and Loadbalancing which may or may not fit depending on your specific requirements. -R.
ealfonso
New Contributor

Red.Adair Do you know if the 620B supports hardware acceleration? and also, does the Fortinet load balancing supports up to layer 7? I am also worried that the Fortinet might now support the older browser with less than 256 cipher.
ealfonso
ealfonso
red_adair
New Contributor III

The 610B does support SSL in Hardware, yes. It supports LB based on some mechanisms, such as Static, Round-Robin, Weighted, First Alive, Least RTT, Least Session. Stickyness (Persistence) can be HTTP Cookie or SSL-Session ID.
ealfonso
New Contributor

Red.Adair Thanks for your input. Since our firewall is Fortinet 400 that cannot be upraded anymore to the new 4.0 code i will just recommend to my boss, to purchase the new Fortinet 620B firewall.
ealfonso
ealfonso
romanr
Valued Contributor

Upgrading 400->620B seems quite tough.... You are sure a 200B or 310B wouldn' t be enough horsepower? cheers.roman
ealfonso
New Contributor

Romanr 310B might do the job. But i would rather go with more just to be sure i am ready for any future and up coming technologies.
ealfonso
ealfonso
Labels
Top Kudoed Authors