Fortinet
Inspection at the edge, without the usual performance tax
FortiGate firewalls run their heaviest inspection work on purpose-built silicon rather than a general processor. That is the reason the same appliance can decrypt and examine encrypted traffic without becoming the slowest link in the network, which is where most next generation firewalls quietly give up.
Schedule a Network ReviewThe headline throughput figure is never the one you will get
Firewall datasheets quote a maximum throughput measured with inspection switched off. Turn on intrusion prevention, then malware scanning, then decryption of encrypted traffic, and the usable figure falls at every step, frequently to a fraction of the number the purchase was based on.
This matters more every year, because the overwhelming majority of traffic is now encrypted. A firewall that cannot afford to decrypt is a firewall inspecting almost nothing, while still appearing on the network diagram as a control.
Security processing is handled by dedicated chips, which is what keeps inspection throughput close to the headline rate rather than a fraction of it.
The same software runs from the smallest branch appliance to the data centre, so a policy learned once applies everywhere and staff transfer between sites.
Routing, software defined wide area networking and security run on the same device, which removes a separate box and a separate contract at every branch.
One appliance replaces the stack a branch used to need
A typical branch office historically required a router, a firewall, and often a separate device managing the link to head office. Each was a purchase, a support contract, a configuration and a thing to fail independently.
Converging those into one platform is where the cost argument is won, particularly for organizations with many small sites. The saving is not only the hardware; it is the number of distinct things a small IT team has to understand and keep patched.
| Function at a branch | Now provided by |
|---|---|
| Internet routing | One appliance |
| Firewall policy | One appliance |
| Intrusion prevention | One appliance |
| Site to site connectivity | One appliance |
| Web filtering | One appliance |
The first useful step is sizing against the traffic you actually carry with inspection enabled, not against the datasheet maximum.
A strong fit
Multi-site organizations, anywhere encrypted traffic inspection is a requirement, and estates where consolidating networking and security into one platform removes real operational load. The performance characteristics are the genuine technical differentiator and they are worth testing rather than taking on trust.
What it asks of you
The platform is deep, and depth means configuration. An organization without networking expertise in house should budget for the appliance to be configured and maintained by a partner, because a powerful firewall running a default policy is an expensive way to have no firewall at all.
Ask what your firewall is actually inspecting
If encrypted traffic passes through untouched, most of the inspection you believe you have is not happening, and that is worth establishing before renewal.
Review Your PerimeterGet in touch with Your Company
Questions about this solution? Reach us directly.