Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KPS
New Contributor III

Using Fortigate virtual instead of Fortigate physical

Hi!

 

I need a new internal "segmentation-firewall". On the perimeter, there is a ha-pair of FG-200E. The new segmentation-firewall filters between different Client- / Server-Security-Zones...

 

...but I need 10GbE for backup-jobs between the internal segments.

 

So: I need a ha-device, that can do: 5 Gbps IPS and full 10 Gbps for "non-NGFW-traffic" for single streams.

 

Long introduction, but: What do you think about buying two FG-VM08v as VMs (HA-pair) to handle that traffic on VMWare (without SR-IOV, as I do not have Ent. plus). Is this a good idea? The alternative would be a pair of 1000Ds or 1200Ds because the smaller devices do not have 10 GbE-interfaces...

 

VMs seem to be much cheaper...

 

Thank you for your thoughts

KPS

 

2 REPLIES 2
IlariExove
New Contributor

Have you considered a simpler solution such as getting a pair of 10G switches that can do line rate routing and L4 ACLs on hw?

KPS
New Contributor III

Hi!

 

Yes, that would be possible, but I hope to get a solution with better security. Currently, I am using a Linux-Cluster as segmentation-firewall. That is cheap and fast, but I think, I should have an "Enterprise-grade-IPS" between the zones.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors