Back to main siteBack Contact us
FortiGate

Fortinet

Network Firewall

Inspection at the edge, without the usual performance tax

FortiGate firewalls run their heaviest inspection work on purpose-built silicon rather than a general processor. That is the reason the same appliance can decrypt and examine encrypted traffic without becoming the slowest link in the network, which is where most next generation firewalls quietly give up.

Schedule a Network Review
INTERNET encrypted FORTIGATE DECRYPT INSPECT RE-ENCRYPT NETWORK clean dedicated silicon, not the main processor
firewall + IPS + malware + TLS throughput
The specification trap

The headline throughput figure is never the one you will get

Firewall datasheets quote a maximum throughput measured with inspection switched off. Turn on intrusion prevention, then malware scanning, then decryption of encrypted traffic, and the usable figure falls at every step, frequently to a fraction of the number the purchase was based on.

This matters more every year, because the overwhelming majority of traffic is now encrypted. A firewall that cannot afford to decrypt is a firewall inspecting almost nothing, while still appearing on the network diagram as a control.

Purpose Built Processing Silicon

Security processing is handled by dedicated chips, which is what keeps inspection throughput close to the headline rate rather than a fraction of it.

One Operating System Across The Range

The same software runs from the smallest branch appliance to the data centre, so a policy learned once applies everywhere and staff transfer between sites.

Converged Networking And Security

Routing, software defined wide area networking and security run on the same device, which removes a separate box and a separate contract at every branch.

Branch economics

One appliance replaces the stack a branch used to need

A typical branch office historically required a router, a firewall, and often a separate device managing the link to head office. Each was a purchase, a support contract, a configuration and a thing to fail independently.

Converging those into one platform is where the cost argument is won, particularly for organizations with many small sites. The saving is not only the hardware; it is the number of distinct things a small IT team has to understand and keep patched.

Function at a branchNow provided by
Internet routingOne appliance
Firewall policyOne appliance
Intrusion preventionOne appliance
Site to site connectivityOne appliance
Web filteringOne appliance
Talk to an Expert

The first useful step is sizing against the traffic you actually carry with inspection enabled, not against the datasheet maximum.

A strong fit

Multi-site organizations, anywhere encrypted traffic inspection is a requirement, and estates where consolidating networking and security into one platform removes real operational load. The performance characteristics are the genuine technical differentiator and they are worth testing rather than taking on trust.

What it asks of you

The platform is deep, and depth means configuration. An organization without networking expertise in house should budget for the appliance to be configured and maintained by a partner, because a powerful firewall running a default policy is an expensive way to have no firewall at all.

In short

Ask what your firewall is actually inspecting

If encrypted traffic passes through untouched, most of the inspection you believe you have is not happening, and that is worth establishing before renewal.

Review Your Perimeter

Get in touch with Your Company

Questions about this solution? Reach us directly.