we are looking to purchase 2 fortigate firewall device to replace our old ASA. We are looking at getting a pair of 100F but are not sure if it is under powered for what we need. our internet connection will be 1gb .
we will be supporting about 10 site-to-site IPsec vpn tunnels.
we will be hosting various web service that average about 6 mil hits per day.
we will be geoblocking all countries with the exception of Canada and US.
our internal switch that the firewall connects to is 1gb.
When considering a firewall upgrade and choosing a specific model, it's essential to consider several factors beyond just the raw bandwidth of your Internet connection. Fortinet's FortiGate series is a strong contender in the Unified Threat Management (UTM) market, but picking the right model is crucial for ensuring performance and security.
Here are some considerations for the FortiGate 100F:
Throughput: The 100F supports a firewall throughput of 20 Gbps and a VPN throughput of 3.6 Gbps, which sounds sufficient for a 1 Gbps Internet connection. However, you'll need to consider the throughput when all UTM features are enabled. Real-world throughput often decreases significantly with UTM features like IPS, application control, and antivirus.
VPN: You mentioned 10 site-to-site IPsec VPN tunnels. The 100F supports up to 200 IPsec VPN tunnels, so you're well within that limit.
Web Services: 6 million hits per day averages to around 70 hits per second. While this isn't particularly high, you should consider the nature of these hits. If they're lightweight web requests, it's not as demanding as, say, large file downloads or video streaming.
Geo-Blocking: Geo-blocking involves examining the source IP of incoming traffic and cross-referencing it with a location database. It can be resource-intensive, especially with high traffic volumes. Ensure the device can handle this at the volume you're expecting without causing undue latency.
Connections Per Second: Given your web services' popularity, you should consider the New Sessions Per Second (New Sessions Rate) specification. It indicates how many new connections the firewall can handle every second. This is especially crucial for busy web services.
High Availability: If you're considering purchasing two units, you might be thinking of a High Availability (HA) setup. Ensure the chosen model supports the type of HA configuration you need (Active-Active or Active-Passive).
Scalability: Think about the potential growth of your organization and traffic. You might want to choose a model that not only meets your current requirements but also has some room for growth.
Total Cost of Ownership (TCO): Don't just consider the device's upfront cost. Think about the recurring costs for support, subscription services (like UTM services, FortiGuard updates), and potential upgrade costs.
Given the factors mentioned above, while the 100F might fit within the described scenario, it would be prudent to engage with a Fortinet sales engineer or partner to undergo a more detailed assessment, taking into account all the services you plan to run on the device, and to determine if it's indeed the right fit for your environment.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.