Im curious if anyone has parted ways with F5 and gone to FortiADC for loadbalancing. GSLB or WAF? If so, how was the journey?
We did a call with Fortinet and it really seems like the fortiADC does all of the F5 LTM and no add on module costs for GTM equivolent and same for WAF. Anyone have any painful expereiences too? want to hear both sides. Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello eneny,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi @eneny ,
Switching from F5 to FortiADC is a major decision, and understanding both positive and negative experiences ccan help you make an informed choice. Here are some key considerations:
Pros:
Cons:
Comparison with Dedicated WAF Solutions
FortiADC includes built-in WAF capabilities, but whether it has "all" the capabilities of a dedicated WAF, such as Fortinet's own FortiWeb or other specialized WAF solutions like F5 ASM, depends on specific needs and use cases. FortiWeb and F5 ASM offer more advanced detection mechanisms, including behavioral analysis, machine learning-based anomaly detection, and more comprehensive signature databases.
FortiADC’s WAF capabilities are robust for many use cases, especially for organizations looking for an integrated solution without additional module costs. However, for highly complex environments or those with stringent security requirements, a dedicated WAF like FortiWeb or F5 ASM might be necessary to provide the depth and breadth of protection required.
Comparison with F5 GTM on DNS Level Load Balancing
While FortiADC provides robust GSLB functionality suitable for many organizations, F5 GTM offers more advanced features, greater flexibility, and deeper integration capabilities, which might be necessary for highly complex or large-scale environments.
Recommendations
In line with the detailed information above, you can plan your migration process by considering the following suggestions:
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
Feel free to request for a demo of FortiADC here before making the decision to switch : https://www.fortinet.com/demo-center/fortiadc-demo
You can get in touch with Fortinet Sales Team as well for more detail: https://www.fortinet.com/corporate/about-us/global-offices
Yeah im not a fan of their new NEXT product line already. Its not finished and there are things we should be able to do that are basic and you cant do them. Also it looks like the old method of partition use is gone and user accounts will be tied to the VIPs/Apps which looks to force you to use APM aka NEXT ACCESS when we didnt use that before. Its running on a K3s cluster and we were told not to look under the hood. Well its as sinle node cluster which from what i read is a bad idea for a prod environment. So we are looking and expanding our horizons i guess. Thanks!
Kindly refer here for documentation regarding FortiADC if you decide to have a read before starting a demo on it: https://docs.fortinet.com/product/fortiadc/7.4
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.