Hello,
we are looking to purchase 2 fortigate firewall device to replace our old ASA. We are looking at getting a pair of 100F but are not sure if it is under powered for what we need. our internet connection will be 1gb .
we will be supporting about 10 site-to-site IPsec vpn tunnels.
we will be hosting various web service that average about 6 mil hits per day.
we will be geoblocking all countries with the exception of Canada and US.
our internal switch that the firewall connects to is 1gb.
thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
sizing can be discussed with Fortinet's sales representatives.
Contacts are on https://www.fortinet.com/corporate/about-us/contact-us including references to resellers.
Some basic guidelines can be seen in Data Sheets .. here is one for 100F class units
https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/fortigate-100f-series.pdf
Have a look to page 7 and "System Performance and Capacity".
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
ok , thanks.
My pleasure. If that solved your question, then feel free to mark it as solved.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
When considering a firewall upgrade and choosing a specific model, it's essential to consider several factors beyond just the raw bandwidth of your Internet connection. Fortinet's FortiGate series is a strong contender in the Unified Threat Management (UTM) market, but picking the right model is crucial for ensuring performance and security.
Here are some considerations for the FortiGate 100F:
Throughput: The 100F supports a firewall throughput of 20 Gbps and a VPN throughput of 3.6 Gbps, which sounds sufficient for a 1 Gbps Internet connection. However, you'll need to consider the throughput when all UTM features are enabled. Real-world throughput often decreases significantly with UTM features like IPS, application control, and antivirus.
VPN: You mentioned 10 site-to-site IPsec VPN tunnels. The 100F supports up to 200 IPsec VPN tunnels, so you're well within that limit.
Web Services: 6 million hits per day averages to around 70 hits per second. While this isn't particularly high, you should consider the nature of these hits. If they're lightweight web requests, it's not as demanding as, say, large file downloads or video streaming.
Geo-Blocking: Geo-blocking involves examining the source IP of incoming traffic and cross-referencing it with a location database. It can be resource-intensive, especially with high traffic volumes. Ensure the device can handle this at the volume you're expecting without causing undue latency.
Connections Per Second: Given your web services' popularity, you should consider the New Sessions Per Second (New Sessions Rate) specification. It indicates how many new connections the firewall can handle every second. This is especially crucial for busy web services.
High Availability: If you're considering purchasing two units, you might be thinking of a High Availability (HA) setup. Ensure the chosen model supports the type of HA configuration you need (Active-Active or Active-Passive).
Scalability: Think about the potential growth of your organization and traffic. You might want to choose a model that not only meets your current requirements but also has some room for growth.
Total Cost of Ownership (TCO): Don't just consider the device's upfront cost. Think about the recurring costs for support, subscription services (like UTM services, FortiGuard updates), and potential upgrade costs.
Given the factors mentioned above, while the 100F might fit within the described scenario, it would be prudent to engage with a Fortinet sales engineer or partner to undergo a more detailed assessment, taking into account all the services you plan to run on the device, and to determine if it's indeed the right fit for your environment.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.