Helpful ReplyHot!Need advise about fortigate platform upgrade (FG 100F or 200E?)

Author
Heaven Knows
New Member
  • Total Posts : 7
  • Scores: 2
  • Reward points: 0
  • Joined: 2017/09/22 20:58:06
  • Status: offline
2019/11/28 19:55:10 (permalink)
0

Need advise about fortigate platform upgrade (FG 100F or 200E?)

Dear Brothers
 
My company currently use several fortigate 100D firewall UTM devices
I need to upgrade to new model because atm the CPU of FGT always reachs high usage, and found that Fortigate 100F and Fortigate 200E meet requiments. Any body can give me that which model between them should be compatible for fortigate 100D replacement?
Our company has 1000 CCU, fortigate device run webfilter, dlp, app control, Explicit proxy. We also have some ipsec vpn channel and web ssl vpn for 50 vpn clients.
 
Thanks very much with best regards
 
 
 
 
 
 
 
 
 
 
 
 
 
 
#1
Dave Hall
Expert Member
  • Total Posts : 1542
  • Scores: 167
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: Need advise about fortigate platform upgrade (FG 100F or 200E?) 2019/11/29 08:57:09 (permalink) ☄ Helpfulby heavenknows 2019/11/29 16:12:24
0
From the spec sheets for both 200E and100F, it's hard to say how either model will perform using real numbers - also factoring in how you are crafting the UTM/firewall policies (amount of packet inspection going on), etc.
 
On paper, I would have to personally go with the 200E.  But I would analyze where most of your current CPU usable (on the 200D) is being used ((ipsengine, scanunitd, etc) then determine whether you need to retweak any policy/utm settings.  Even a low-end fgt device can "out perform" a higher-end model if properly configured. IMO.
 

Attached Image(s)


NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#2
James_G
Silver Member
  • Total Posts : 109
  • Scores: 5
  • Reward points: 0
  • Joined: 2016/02/28 02:55:47
  • Status: offline
Re: Need advise about fortigate platform upgrade (FG 100F or 200E?) 2019/11/29 14:55:36 (permalink) ☄ Helpfulby heavenknows 2019/11/29 16:12:16
0
I don't think you can make a wrong choice here, they are so similar in spec that if one is ok, the other will be also I expect. On the same line of thought, if one has performance issues, the other would probably also.

To me it's down to cost.
#3
Heaven Knows
New Member
  • Total Posts : 7
  • Scores: 2
  • Reward points: 0
  • Joined: 2017/09/22 20:58:06
  • Status: offline
Re: Need advise about fortigate platform upgrade (FG 100F or 200E?) 2019/11/29 16:22:04 (permalink)
0
Dave Hall
From the spec sheets for both 200E and100F, it's hard to say how either model will perform using real numbers - also factoring in how you are crafting the UTM/firewall policies (amount of packet inspection going on), etc.
 
On paper, I would have to personally go with the 200E.  But I would analyze where most of your current CPU usable (on the 200D) is being used ((ipsengine, scanunitd, etc) then determine whether you need to retweak any policy/utm settings.  Even a low-end fgt device can "out perform" a higher-end model if properly configured. IMO.
 



Thanks
I often use the cli "diag sys top" on my FGT100D when the CPU reachs high  and  found that high cpu cause by ssl vpn (web ssl vpn and ssl vpn tunnel) , when the CPU reach 95-99%   ssl vpn monitoring showed that there were 20-30 clients vpn session established. There were 3 running pid of "sslvpnd" cause high cpu.
the wad process also cause high cpu and this is normal because it serve the explicit proxy for 8xx client computers .
 
Lookin at the hardware platform,  100f and 200e both have 4GB of memory , 100F CPU is Cortex Arm (don't know the version exactly) and 200E is Celeron G1820. I dont know which CPU supply better perfomance.  FGT 2003 also has NP6 lite and CP9 , i dont know that does it provide better perfomance for UTM.
 
Thanks very much
 
post edited by heavenknows - 2019/11/29 16:31:36

Attached Image(s)

#4
Fullmoon
Platinum Member
  • Total Posts : 868
  • Scores: 13
  • Reward points: 0
  • Joined: 2010/08/02 18:02:10
  • Status: offline
Re: Need advise about fortigate platform upgrade (FG 100F or 200E?) 2019/11/29 18:39:04 (permalink) ☄ Helpfulby Heaven Knows 2019/11/30 03:30:41
0
The specs were not quite from each other. If you plan to have SDWAN setup I would choose 100F over 200E. IMO 100F uses SOC 4 to speed up the process.

Fortigate Newbie
#5
James_G
Silver Member
  • Total Posts : 109
  • Scores: 5
  • Reward points: 0
  • Joined: 2016/02/28 02:55:47
  • Status: offline
Re: Need advise about fortigate platform upgrade (FG 100F or 200E?) 2019/11/30 05:20:06 (permalink) ☄ Helpfulby Heaven Knows 2019/12/01 17:45:18
0
Bit of a sideways thought, have you ever considered IPsec VPN rather then SSL VPN for some of your remote users, with the new models you are looking at, IPsec is totally offloaded to hardware and uses zero CPU.
#6
Heaven Knows
New Member
  • Total Posts : 7
  • Scores: 2
  • Reward points: 0
  • Joined: 2017/09/22 20:58:06
  • Status: offline
Re: Need advise about fortigate platform upgrade (FG 100F or 200E?) 2019/11/30 06:07:46 (permalink)
0
James_G
Bit of a sideways thought, have you ever considered IPsec VPN rather then SSL VPN for some of your remote users, with the new models you are looking at, IPsec is totally offloaded to hardware and uses zero CPU.

Thanks bro
I have to use web ssl vpn for some remote user that doesnt have a dedicated computer to connect to office's resource. Web ssl vpn can use on any computer that has a compatible browsers.
Anyway i will consider ipsec vpn for dedicated laptop/pc using forticlient.
 
 
#7
Jump to:
© 2019 APG vNext Commercial Version 5.5