IT Connection from Current Analysis
| How to Login | How to Navigate |
Home Products Suppliers Real-Time Analysis   Sign Up Now - FREE Sample Reports FAQs About Us
SAMPLE REPORT: Updates to this report may be available to subscribers.
IT Connection Product Assessment reports provide in-depth analysis of technology products and services. Each Product Assessment report includes expert analyst advice and recommendations on what to look for when making buying decisions. Click here to view sample reports.

Enterprise Technology and Software
Product Assessment  
More information | Products | Suppliers | Real-Time Analysis |

 

Product Assessment: Fortinet - FortiGate Security Appliances
Report Date: November 11, 2010
Analyst: Braunberg, Andrew
Service: Business Technology and Software  
Market: Enterprise Security
Class: Firewalls and VPNs Compare
Current Perspective:
Report Summary: Fortinet continues its leadership in unified threat management, focusing on inspection techniques that blur the lines between firewall, IPS, and active threat defense and expanding its appliance portfolio with offerings for the mid-market.

Summary
Buying Criteria
Current Perspective
5Rating: 5
The Fortinet FortiGate family of enterprise security appliances is very threatening in the enterprise firewall and VPN market. Fortinet has established itself as a strong competitive threat and a pioneer in the unified threat management market segment, and it has solidified its position with a combination of products and services that have generated strong customer momentum and raised the profile of Fortinet across the market. All of that puts growing pressure on the market incumbents from a feature, functionality, and security services perspective. Fortinet is not only setting the bar with comprehensive integrated threat defense solutions, but it has also built a broad portfolio that has led to many customer wins against major competitors in significant accounts.

Fortinet’s FortiGate series of appliances combine the full features of a firewall and VPN appliance with many advanced integrated services, including IPS/IDS, anti-virus, QoS/bandwidth shaping, and content filtering (URL and anti-spyware), as well as advanced features such as SSL VPN functionality and routing capabilities. Fortinet offers real-time (subscription-based) protection services via its push-based FortiGuard services that keep threat signatures and virus definitions up to date automatically. Fortinet is well positioned to compete across multiple markets, from SOHO to enterprise and MSSP, and against far larger and more entrenched competitors. In October 2010, the company introduced virtual appliance versions of FortiGate, and it will follow with virtualized versions of its FortiManager and FortiAnalyzer management and reporting tools.

Fortinet’s FortiOS 4.0 upgrade added four major new capabilities, including WAN optimization, data loss prevention, application control, and SSL inspection, along with hundreds of other improvements. Fortinet’s portfolio includes a carrier-class platform that scales to the largest of enterprises and hosting/ISP/carrier applications, enabling it to compete with the small handful of vendors that offer ultra-high-capacity UTM offerings for that market. Additionally, Fortinet’s virtualization capabilities position it well for the emerging virtualized security appliance universe towards which the industry is headed.
Strengths and Weaknesses
Strengths• Fortinet’s FortiGate security solution rivals the best multi-service devices in the advanced firewall/VPN market with anti-virus, firewall, VPN, SSL VPN, WAN optimization, application control, DLP, content filtering, QoS, IM security, bandwidth shaping, anti-spyware, and anti-spam capabilities, plus a full services offering to ensure up-to-date definitions for signature-based features.

• Fortinet has nearly two dozen products and platforms that scale from SOHO capacity all the way through carrier-grade in terms of scale and performance. Fortinet has no lack of applicable products to address specific market needs. Fortinet leverages an intelligent licensing model, charging only on a per-box basis for its hardware, rather than cumbersome per-user licensing.

• Fortinet appliances leverage ASIC acceleration for major inspection and encryption functions. The FortiGate’s firewall, VPN, and content inspection engine all benefit from the ASIC acceleration, differentiating it from all the software-based multi-service security solutions on the market, while also differentiating it from many competitors’ deep inspection techniques, which are purely software-based as well. Fortinet’s latest generation of FortiASIC NP processors are making their way into the product portfolio with impressive results. The new generation of “B” designated appliances delivers impressive raw performance and port density.

• Fortinet has received strong marks in enterprise-class product reviews for the flexibility and robustness of its policy engine. The product also passed the stringent and respected NSS Group certification program after two rounds of signature updates. These reviews proved FortiGate’s performance and IPS/IDS capabilities in a lab environment and serve as a validation point for the company’s products and architecture.

• Fortinet offers a suite of logging and policy-based provisioning tools for large enterprise deployments. These tools centralize logging functions and configuration, policy, device management, and security event analysis functions on dedicated management appliances. The latest versions of these tools allow for advanced closed-loop actions to be taken to initiate threat defense, if desired.

• Fortinet offers an in-house developed client with integrated personal firewall and threat prevention engine, which significantly lowers an owner’s TCO by simplifying configuration and policy management tasks while eliminating the overhead of an expensive software OEM relationship.
Weaknesses• Fortinet has an overwhelming number of products for the market segments it targets. With over 20 products at last count, the Fortinet portfolio is arguably too broad for the markets Fortinet is in. This results in higher volumes of product in the channel and makes it more difficult for enterprise customers to identify the appropriate device for their specific environments.

• While Fortinet’s core security features are well tested and documented in terms of performance and customer validation, newer features such as Fortinet’s SSL VPN technology are neither proven nor backed by customer testimonial. In particular, SSL VPN is a market where competitors dedicated million of dollars in development, R&D, and acquisition moneys, and it is questionable that Fortinet can offer as robust a solution given its size and focus.

• While Fortinet’s appliances are aggressively priced, the company commands a significant yearly premium for definition, signature, and content filtering database subscriptions. Understandably, these databases are less costly than a third-party non-integrated solution, but they represent anywhere from 15% (virus/IPS definitions) to 40% (content filtering) of the list price of the product, per year. In contrast, some vendors leverage a behavioral model (rather than a massive signature database) and may charge little or nothing for definition updates.


Buying/Selecting Criteria Depth of Defense Rating: 4
• Fortinet offers a full range of remote access mechanisms including both traditional IPSec VPN as well as an SSL VPN access mode, and it supports a dedicated desktop client with client security features and policy management capabilities.

• Fortinet’s security offering is amongst the broadest in the industry for a single-device appliance. Support for firewall, IPSec and SSL VPN, anti-virus, anti-spyware, anti-spam, intrusion detection and prevention, content (URL) filtering, and deep, protocol-aware inspection techniques gives Fortinet an edge over many competitors that must address these challenges via a multi-box solution.

• Fortinet offers protocol-based inspection support for a broad range of protocols, which contributes to stronger security and potentially more accurate threat/intrusion detection and prevention. Fortinet also provides a competitive response to the “deep packet inspection” message of competitors. New protocols that Fortinet supports include several VoIP protocols, SIP and SCCP. Fortinet further augments its deep inspection with signature and anomaly-based threat detection engines.

• The 3950B series products are capable UTM devices that support firewall/VPN, IPS, AV, Web filtering, application control, DLP and anti-spam. Fully outfitted, the 3950B can deliver 120 Gbps of firewall throughput (100 Gbps for the 3951B), 48 Gbps of IPSec VPN throughput (40 Gbps for the 3951B), 10 Gbps of IPS throughput (10 Gbps for the 3951B), and 1.5 Gbps of AV throughput (1.5 Gbps for the 3951B).

• Fortinet continues to expand the functional footprint of its appliances. FortiOS 4.0 supports several important new features. These include: WAN optimization, application control, data leakage prevention, and SSL inspection. The FortiOS 4.0 MR 2 release includes richer AV support, VoIP support, deeper integration with FortiClient, and new integration with FortiMobile SSL VPN client.
Encryption Rating: 3
• Fortinet has documented performance metrics for encryption on each of its enterprise appliances. However, these performance metrics are chiefly based on 3DES benchmarking numbers, not AES-128 or AES-256 benchmarks. Fortinet claims to accelerate all encryption in hardware. High-end performance is 48 Gbps on the FortiGate 3950B (with a Fortinet Mezzanine Card).

• Fortinet has demonstrated proven performance in multiple public tests that have examined various aspects of the solutions’ performance, including basic firewall/VPN performance, IDS/IPS performance, and multi-service threat prevention performance.

• FortiOS 4.0 addressed a critical blind spot for enterprises by adding the ability to act as an SSL proxy, decrypt traffic to inspect it, and then apply policies before re-encrypting legitimate traffic and sending it along. Malware writers are using encryption to hide the communication between bots and command and control servers, so this capability addresses a newer threat type.
Management Rating: 4
• Fortinet offers multiple tools designed to simplify device deployment, policy management, log collection, and analysis. These products are broken up into two platforms: FortiManager and FortiAnalyzer. Fortinet released v4.0 updates to both products in June 2009.

• FortiManager deals with the management of an enterprise-wide multi-device Fortinet deployment from a device and policy perspective. FortiManager can manage up to 4,000 FortiGate appliances on the high end. The FortiManager family runs from the FortiManager 3000B to the FortiManager 100. The product enables the creation and management of security policies based on individual users and groups of users. Enhancements in v4.0 include improved disaster recovery features and improved workflow that allows a single policy to be deployed across all managed devices.

• FortiAnalyzer is a purpose-built security logging platform that collects data and events from Fortinet appliances and offers a reporting and security event analysis system designed to create management-level reports of enterprise-wide security events. The v4.0 release of FortiAnalyzer includes a vulnerability management component. The device provides recommendations for protecting against found vulnerabilities. One FortiAnalyzer box can log up to 2,000 FortiGate appliances on the high end. The FortiAnalyzer family runs from the FortiAnalyzer 4000A to the FortiAnalyzer 100B.

• Individual Fortinet appliances can be managed from a command line interface or via a Web interface. The Fortinet Web interface has received good marks for ease of use, though there are some challenges, specifically regarding correlating events from the IPS/IDS engine with specific policies and rules, as well as some challenges in managing a large enterprise rule set from the Web management interface. In particular, managing a rule set of greater than 100 rules becomes more cumbersome via the Web interface.

• Fortinet offers multiple technical support programs. These include a choice of 8x5, 24x7, and Premier levels of support. Software updates are available online 24x7. Hardware maintenance programs are also available.
Scalability Rating: 4
• The FortiGate family of products is large and growing. Fortinet positions products in this family from service provider down to SMB. The 5000 series of FortiGate blade chassis products targets MSSPs and large enterprises. Fortinet positions its mid-market offerings as running from the FortiGate-200B up to the FortiGate-1240B. The SMB products run from the FortiGate 110C to the FortiGate 50B.

• Fortinet is beginning to leverage a new generation of customized ASIC processors. This allows Fortinet to deliver impressive performance and a “pay as you grow” flexibility in hardware requirements. The 3950B, for example, supports five mezzanine card expansion slots and the 3951B supports four expansion slots. Each mezzanine card is designed to provide a combined physical port and processing resource. Each card can host FortiASIC NP4 or SP2 modules. The NP4, which was introduced last year, is a network processor, and the SP2, which is just being introduced, is a multi-core, multi-threaded security processor.

• Fortinet delivers impressive port density in its appliances. For example, the 3950B supports up to 12 total network interfaces (16 for the 3951B), up to 12 10GbE SFP interfaces (10 for the 3951B), four GbE interfaces (three for the 3951B), and two 10/100/1000 interfaces (two for the 3951B). Both products include two SR SFP+ transceivers. The 3040B has a total of 20 ports on the system comprised of modular SFP+ (eight), SFP (ten), and traditional RJ-45 (two) ports.

• Fortinet accelerates its VPN, firewall, and content inspection functions in a custom-designed ASIC. Fortinet’s rated performance number, like most products in this segment, is based on simple firewall operation, not an “all-on” configuration. However, Fortinet has added significant horsepower to its mid-market offerings in the expectation that they will increasingly be used as UTM devices.

• The higher-end FortiGate appliances support advanced mezzanine card (AMC) modules. Available double-width modules are: ADM-XB2, two-port 10GigE FortiASIC Module; ADM-XE2, two-port 10GigE Security Processing Module; ADM-FB8, eight-port GigE FortiASIC Module; and ADM-FE8, eight-port GigE Security Processing Module. Available single-width modules are: ASM-FB4, four-port GigE FortiASIC Module; ASM-CE4, four-port GigE Security Processing Module; ASM-S08, 80GB Hard Disk Storage Module; ASM-CX4, four-port GigE TX By-Pass Module; ASM-FX2, two-port GigE SX By-Pass Module; and ASM-ET4, four-port T1/E1 WAN Module. Fortinet also supports several Fortinet Mezzanine Cards (FMC): FMC-XD2, two-10GbE port 20GbE SFP Firewall Acceleration Module; FMC-XG2, tw0-10BbE port IPS Acceleration Module; and the FSM-064, 64GB SSD module.

• Fortinet offers both active-active and active-passive high-availability modes, but advanced stateful failover is only available in the active-passive mode.
Total Cost of Ownership Rating: 5
• Fortinet’s devices are competitively priced and frequently offer better performance at a comparable price or equal performance at a lower price when compared to other appliance manufacturers. Fortinet also has one of the broadest appliance portfolios available on the market. The company prides itself on filling every conceivable niche in functionality and performance from SOHO to service providers. Fortinet is currently rolling out new appliances that leverage its next generation of ASIC processors. These new devices are delivering impressive improvements in performance and port density.

• Fortinet has a very straightforward pricing model of one fixed price per box and one fixed price per update service for that box. There is no complex per-user or capacity-based licensing that obscures TCO and frustrates customers.

• Fortinet develops its own remote access and remote security client, dubbed FortiClient. FortiClient is licensed on a per-user basis. The full client supports anti-X, IPSec VPN, personal firewall, anti-spam, Web content filtering, logging, central management and support. A single user license is $15.95, while 1,000 user licenses can be bought for $2.95 per client. Fortinet offers a free version of FortiClient, what it calls a “Demo” version, that provides the same functionality but without the logging, management, and support.

• Content security updates (anti-virus, anti-spam, content filtering, URL blacklists, etc.) are licensed on a yearly, per-service basis. Pricing for content security updates is relatively high, running anywhere from 15% (for AV/IDS) to 40% (for content filtering) of list price per service. (Fortinet also offers a services bundle that combines all subscription services. This package typically ranges between 40% and 45% of the list price of the product.) While straightforward, these services add significantly to the overall TCO of the solution. However, when compared to deploying an external solution, these prices are actually significantly lower in TCO. When contrasted with competitors, customers must consider the frequency of updates, the mechanism for delivering the updates (manual or automated), the cost of the service, and the impact on network performance from enabling the protection.
Metrics General Information
Product Functionality
Unified Threat Management
Device Specific Information
Interface Count
Varies by product
Interface Types
T1/E1, 10/100, Gigabit Ethernet. 10 Gigabit Ethernet is supported, through AMC module.
Redundant Power Supplies
Yes, most appliances support internal redundant power supplies, but FortiGate-310B and -620B support external redundant power supply.
NEBS Compliance
FortiGate-5140B is NEBS ready.
Remote/Out of Band Management
All FortiGate product has a dedicated serial port for management. All Ethernet ports can be configured for inband management.
High Availability Port
High availability is supported on all product and any port can be configured for High Availability.
Routing Protocols
RIP, OSPF, BGP, PIM (dense and sparse)
Product Warranty
1-Year Limited Hardware Warranty / 90-Days Limited Software Warranty
802.1Q VLAN Tagging
Yes
Latest Shipping Software
FortiOS v4.0 MR2
VPN Specific Information
Maximum Concurrent Connections
Varies by product; the new FG-3950B supports up to 10,000 gateway-to-gateway tunnels and 64,000 client-to-gateway tunnels.
3DES Performance
Varies by product; the new FG-3950B supports up to 8 Gbps of AES VPN performance.
3DES Accelerated Performance
Accelerator is built-in into the product and the interface module. Enhancement is possible by adding interface module to increase port density and performance. Accelerated performance for the 3950B is 48 Gbps.
Encryption Algorithms
AES 128, 192 and 256
Network Integration
Both. Transparent and routed/NAT can be supported simultaniously using different VDOMs (Virtual Domain features that is a avialable on every FortiGate product).
Industry Certifications
FIPS 140-2, CC EAL4+, ICSA Labs, NSS Labs, FCC, CE, BSMI, UL, VCCI, C-TICK
Tunneling Protocols
IPSec, PPTP, L2TP, GRE, GTP (On FortiCarrier - specialized software with MSSP features running on FortiGate)
CAs Supported
Microsoft
Key Management
IKE
CA Revocation Methods
Automatic, manual
High Availability Features
Yes, Active-Active or Active-Passive; More stateful features when active-passive
VPN Architecture
Hybrid
AES Performance
Varies by product; the new FG-3950B supports up to 8 Gbps (48 Gbps accelerated performance) of AES VPN performance.
NAT Traversal
NAT v1, v2
SSL VPN Tunneling Features
Yes
SSL VPN Translation Features
Yes
SSL VPN Browser Support
IE 7.0/8.0, Firefox 3.0, Apple Safari
VPN Client Information
Client Name
FortiClient
Client Status
In-house
OS Support
Windows 2000, Windows XP 32 and 64-bit, Windows Server 2003 32 and 64-bit, Windows Server 2008 32 and 64-bit, Windows Vista 32 and 64-bit, Windows 7 32 and 64-bit
Authentication Methods
User name/password, X.509, Xauth, MSCHAPv2, PAP, CHAP, VPD
Split Tunnel Support
Yes
Client Lock-Out
Yes. GUI in the FortiClient can be locked download by using either different access right for user group, remote management on FortiManager appliance or creating a property MSI table during installation.
Personal Firewall
Latest FortiClient release adds WAN Optimization support for integration with FortiGate.
Personal Firewall Configuration
Yes
Remote Management
Yes
Client Config Check
Yes
Client Failover
Yes
Firewall Features
Firewall Type
Stateful firewall inspection is supported. Application proxy is also supported for Web filtering, AV and others.
Address Translation
1-to-1 NAT/NAPT, 1-to-MANY NAT/NAPT, bidirectional NAT/NAPT, overlap translational and policy drivern NAT
High Availability Sessions
Yes, in Active/Passive mode
Load Balancing
Yes, via clustering
Protocol Support
SMTPS, POP3S, IMAPS
Firewall Architecture
ASIC + software assist
Virtual Firewalling
Yes and varies by Product, 10 VDOM (Virtual Domain) is supported on most product and high end product can scale up to 250 VDOM.
Management Features
Management Station
Appliance: FortiManager, FortiAnalyzer. Online cloud service: FortiGuard Analysis and Management service.
Management OS Support
Proprietary
Management Devices Supported
Number of devices supported varies by the models of the FortiManager (Management Appliance).
Management Client Support
FortiManager (Management appliance) can manage client runing FortiClient and the numbers of supported ForitClient varies by the models of FortiManager.
Logging Options
FortiGuard Analysis and Management Service. (Online logging and reporting services.)
NMS Integration
API is now available on the management appliance (FortiManager) for integration.
Policy Based Configuration
FortiManager support configuration version control of FortiGate, and the FortiClient end port software.
Management Security
HTTPS (Browser-based, no client)
Value Added Features
Denial of Service Protection
Yes, FortiGate can prevent attacks such as DDOS, Sync flood, port scanning and many others through the built-in IPS engine, traffic shaping, Antivirus scan and application control features.
IDS Intelligence
Full IPS
Anti-Virus Scanning
Yes FortiGate offers antivirus scan on email, ftp, IM, skype and many others. Antivirus package is inhouse developed.
Content Filtering
New value added features in FortiOS 4.0 include: WAN Optimization, DLP, SSL Inspection, Application Control, End Point Control and many others.
Pricing
Solution Hardware Pricing
Varies by product; FG-3950B: $79,995
Add-on Hardware
Various hardware expansion options are available. On the high end, the FMC -XD2 for the 3950-B lists at $23,995.
Software Licenses
No additional software license is required. Subscription service is required for signatures updates for antivirus, antispam, IPS and Web fitlering.
VPN Client Pricing
FortiClient VPN only verison is free as part of the demo verison. Full FortiClient verison include AV, WF, Antispam for 1000 users @ $15.50 ea.
Solution Description & Restrictions
No subscription or user licenses for Firewall, SSL and IPSec VPN features. Yearly subscription applies for AV, WF, IDS and Anitspam signatures.
Support/Maintenance
Hardware Maintenance Costs
Varies by product: FG-1240B:$5998
Maintenance Include S/W Updates
Yes
Software ONLY Maintenance Cost
Support and Software Updates are bundled together (FortiCare)

Top

Follow IT Connection on Twitter
| Home | Products | Suppliers | Real-Time Analysis | Sample Reports | About Us | Sign Up Now | FAQs | Partnership Program | Blogs | Site Map |
Click here to sign up, or contact us at: ITConnection@currentanalysis.com or call +1 703-788-3700.
All materials Copyright Current Analysis, Inc. Reproduction or distribution prohibited without express written consent.