Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
James_G
Contributor III

Firewall sizing - moving from FGT 300D

I have a couple of FGT 300D clusters that I have budget to replace - below is the performance stats at peak load. I will throw this out, what model would you be replacing them with?

 

Thanks for any input :)

 

TVBC-FGT1 # get sys perf stat CPU states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU0 states: 0% user 0% system 0% nice 99% idle 0% iowait 0% irq 1% softirq CPU1 states: 0% user 0% system 0% nice 99% idle 0% iowait 0% irq 1% softirq CPU2 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU3 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq Memory: 8188500k total, 3661616k used (44.7%), 2516180k free (30.7%), 2010704k freeable (24.6%) Average network usage: 142065 / 143177 kbps in 1 minute, 215870 / 216768 kbps in 10 minutes, 474045 / 474543 kbps in 30 minutes Average sessions: 41247 sessions in 1 minute, 40848 sessions in 10 minutes, 40285 sessions in 30 minutes Average session setup rate: 328 sessions per second in last 1 minute, 318 sessions per second in last 10 minutes, 287 sessions per second in last 30 minutes Average NPU sessions: 18906 sessions in last 1 minute, 18607 sessions in last 10 minutes, 18071 sessions in last 30 minutes Average nTurbo sessions: 875 sessions in last 1 minute, 824 sessions in last 10 minutes, 794 sessions in last 30 minutes Virus caught: 0 total in 1 minute IPS attacks blocked: 0 total in 1 minute Uptime: 52 days, 21 hours, 43 minutes WCC-FGT1 # get sys perf stat CPU states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU0 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq CPU1 states: 0% user 0% system 0% nice 99% idle 0% iowait 0% irq 1% softirq CPU2 states: 1% user 0% system 0% nice 99% idle 0% iowait 0% irq 0% softirq CPU3 states: 0% user 0% system 0% nice 100% idle 0% iowait 0% irq 0% softirq Memory: 8188500k total, 3678816k used (44.9%), 2506596k free (30.6%), 2003088k freeable (24.5%) Average network usage: 197348 / 198647 kbps in 1 minute, 155562 / 156545 kbps in 10 minutes, 433258 / 434063 kbps in 30 minutes Average sessions: 29453 sessions in 1 minute, 28829 sessions in 10 minutes, 28542 sessions in 30 minutes Average session setup rate: 168 sessions per second in last 1 minute, 175 sessions per second in last 10 minutes, 185 sessions per second in last 30 minutes Average NPU sessions: 15501 sessions in last 1 minute, 15250 sessions in last 10 minutes, 14803 sessions in last 30 minutes Average nTurbo sessions: 948 sessions in last 1 minute, 828 sessions in last 10 minutes, 865 sessions in last 30 minutes Virus caught: 0 total in 1 minute IPS attacks blocked: 0 total in 1 minute Uptime: 57 days, 21 hours, 23 minutes

5 REPLIES 5
emnoc
Esteemed Contributor III

Why do you want to update them? That's the first question.

 

Those stats shows no performance issues or helpful information for determining a hardware upgrades. Most upgrades are done to stay update in hardware or the product becoming end of life. Or you need more interfaces or faster interface ( 1 vrs 10 vrs 40 gige ) or you near max  traffic session or traffic throughput. You have 3 more years of support of the 300D before it's EoS fwiw.

 

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
James_G
Contributor III

I have a requirement to reconfigure interfaces, create zones between interfaces and policies, change external interface to SD-WAN etc, plus I just need more interfaces. I would rather get this right on an offline firewall, then just swap in at go live.

 

And, I have the budget to do it this year.

 

Part of my thinking is dropping from a 300D to 100F is actually a massive cost saving, hardware and 1 year support is cheaper then just renewing support, I am trying to do due diligence in my head that this is not a crazy move.

 

The raw stats of throughput say 100F is easy enough, how do I confirm this?

emnoc
Esteemed Contributor III

Read the data sheet but don't over look  LACP support. Not 100% sure you can do bonded members in a 100F. I'm doing the same thing now,  but with 40F for cost saving for dialin home agents that works from home. They had FGT60D and the OPEX saving  was worth it. We also found a outfit that bought our old FGT60D for 75 usd per unit, that was the best dial that we could get.

 

I'm sure someone will chime in on the FGT300D vrs FGT100F. Currently in my day role we are migrating customer into FGT300Es from 200Bs  or even worst 200As ;)

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dave_Hall
Honored Contributor

James_G wrote:

The raw stats of throughput say 100F is easy enough, how do I confirm this?

If you can swing it pass your local fortinet dealer, I suggest asking them to provide you with a 100F demo model to play around with, to get a better idea of the performance in your network setting.  Glancing at the firmware availability, it looks like the 100F is going to be either 6.0.8 and higher or 6.2.2 and higher.  

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
James_G

Dave Hall wrote:
James_G wrote:
The raw stats of throughput say 100F is easy enough, how do I confirm this?
If you can swing it pass your local fortinet dealer, I suggest asking them to provide you with a 100F demo model to play around with, to get a better idea of the performance in your network setting.  Glancing at the firmware availability, it looks like the 100F is going to be either 6.0.8 and higher or 6.2.2 and higher.    
I'm on 6.2.3 already :)
Labels
Top Kudoed Authors