Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
andrew_ang
New Contributor

Choosing Between FortiGate 100D and 200D

I'm setting up a new office that will have a little under 200 users. I'm not sure which product to use. I'm thinking of getting either 2 units of the 100D set up in HA mode, or a single 200D. With the 100D, I can setup a full mesh with a set of stacked switches to avoid single points of failure. I'm a little worried about the lifetime of 100D if we turn on logging since its using flash storage. And getting a fortianalyzer is out of the budget. Any advice? Thanks. Andrew
13 REPLIES 13
andrew_ang

Hi Ralph, My thoughts exactly. :)

emnoc
Esteemed Contributor III

Good post  Ralph

 

As far as  how many users a 100D or 200D  can really support has so many ????s , but as long as you know what the capabilities of the 2 and monitor what you do-enable, you should be okay. I have a site with a 100C with 300users but that firewall is like 100% rock solid, never given me a problem uses a eMAN circuit at 20-30megs and very little to lite sslvpn-users and 2 vpn-tunnels

 

 

YMMV

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
cbun
New Contributor

Wait for new "E" models.

 

A Fortigate 60E can compete with a 100D or even 200D in certain areas.A Fortigate 90E is currently listed within online shops, but no datasheet is available, yet. So I expect this one to have a way better performance than a 200D at a much lower price. Get 2 pieces of FG-90E/FG-91E.

andrew_ang

Hi Ralph,

 

Yes, I did consider that. What I'm planning to do is to make use of a 60D in the cabinet, and use that as a "manual" backup in the worst case that the 200D fails. We have a technical services department that should be able to handle the physical port switch. Not ideal, but might be better than nothing.

 

I will need to turn off any UTM functions for the 60D and have it act as a regular firewall. Configuration management is going to be a headache, since I need to make sure any changes on the 200D (Port forwarding, etc.) get propagated to the 60D, and that would need to be done by hand.

 

Andrew

Labels
Top Kudoed Authors