Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TuanNguyenatCDAC
New Contributor

Sizing Question

Hello,

we are looking to purchase 2 fortigate firewall device to replace our old ASA.   We are looking at getting a pair of 100F but are not sure if it is under powered for what we need.   our internet connection will be 1gb .   

 

we will be supporting about 10 site-to-site IPsec vpn tunnels. 

we will be hosting various web service that average about 6 mil hits per day.

we will be geoblocking all countries with the exception of Canada and US.

our internal switch that the firewall connects to is 1gb.

 

thank you

 

4 REPLIES 4
xsilver_FTNT
Staff
Staff

Hi,

sizing can be discussed with Fortinet's sales representatives.
Contacts are on https://www.fortinet.com/corporate/about-us/contact-us including references to resellers.

 

Some basic guidelines can be seen in Data Sheets .. here is one for 100F class units
https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/fortigate-100f-series.pdf

 

Have a look to page 7 and "System Performance and Capacity".

 

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

TuanNguyenatCDAC
New Contributor

ok , thanks.

xsilver_FTNT
Staff
Staff

My pleasure. If that solved your question, then feel free to mark it as solved.

Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff

spoojary
Staff
Staff

When considering a firewall upgrade and choosing a specific model, it's essential to consider several factors beyond just the raw bandwidth of your Internet connection. Fortinet's FortiGate series is a strong contender in the Unified Threat Management (UTM) market, but picking the right model is crucial for ensuring performance and security.

Here are some considerations for the FortiGate 100F:

  1. Throughput: The 100F supports a firewall throughput of 20 Gbps and a VPN throughput of 3.6 Gbps, which sounds sufficient for a 1 Gbps Internet connection. However, you'll need to consider the throughput when all UTM features are enabled. Real-world throughput often decreases significantly with UTM features like IPS, application control, and antivirus.

  2. VPN: You mentioned 10 site-to-site IPsec VPN tunnels. The 100F supports up to 200 IPsec VPN tunnels, so you're well within that limit.

  3. Web Services: 6 million hits per day averages to around 70 hits per second. While this isn't particularly high, you should consider the nature of these hits. If they're lightweight web requests, it's not as demanding as, say, large file downloads or video streaming.

  4. Geo-Blocking: Geo-blocking involves examining the source IP of incoming traffic and cross-referencing it with a location database. It can be resource-intensive, especially with high traffic volumes. Ensure the device can handle this at the volume you're expecting without causing undue latency.

  5. Connections Per Second: Given your web services' popularity, you should consider the New Sessions Per Second (New Sessions Rate) specification. It indicates how many new connections the firewall can handle every second. This is especially crucial for busy web services.

  6. High Availability: If you're considering purchasing two units, you might be thinking of a High Availability (HA) setup. Ensure the chosen model supports the type of HA configuration you need (Active-Active or Active-Passive).

  7. Scalability: Think about the potential growth of your organization and traffic. You might want to choose a model that not only meets your current requirements but also has some room for growth.

  8. Total Cost of Ownership (TCO): Don't just consider the device's upfront cost. Think about the recurring costs for support, subscription services (like UTM services, FortiGuard updates), and potential upgrade costs.

Given the factors mentioned above, while the 100F might fit within the described scenario, it would be prudent to engage with a Fortinet sales engineer or partner to undergo a more detailed assessment, taking into account all the services you plan to run on the device, and to determine if it's indeed the right fit for your environment.

Siddhanth Poojary
Labels
Top Kudoed Authors