Hi!
I need a new internal "segmentation-firewall". On the perimeter, there is a ha-pair of FG-200E. The new segmentation-firewall filters between different Client- / Server-Security-Zones...
...but I need 10GbE for backup-jobs between the internal segments.
So: I need a ha-device, that can do: 5 Gbps IPS and full 10 Gbps for "non-NGFW-traffic" for single streams.
Long introduction, but: What do you think about buying two FG-VM08v as VMs (HA-pair) to handle that traffic on VMWare (without SR-IOV, as I do not have Ent. plus). Is this a good idea? The alternative would be a pair of 1000Ds or 1200Ds because the smaller devices do not have 10 GbE-interfaces...
VMs seem to be much cheaper...
Thank you for your thoughts
KPS
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Have you considered a simpler solution such as getting a pair of 10G switches that can do line rate routing and L4 ACLs on hw?
Hi!
Yes, that would be possible, but I hope to get a solution with better security. Currently, I am using a Linux-Cluster as segmentation-firewall. That is cheap and fast, but I think, I should have an "Enterprise-grade-IPS" between the zones.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.