Buying/Selecting Criteria Depth of Defense
Rating: 4
• Fortinet offers a full range of remote access mechanisms including both traditional IPSec VPN as well as an SSL VPN access mode, and it supports a dedicated desktop client with client security features and policy management capabilities.
• Fortinet’s security offering is amongst the broadest in the industry for a single-device appliance. Support for firewall, IPSec and SSL VPN, anti-virus, anti-spyware, anti-spam, intrusion detection and prevention, content (URL) filtering, and deep, protocol-aware inspection techniques gives Fortinet an edge over many competitors that must address these challenges via a multi-box solution.
• Fortinet offers protocol-based inspection support for a broad range of protocols, which contributes to stronger security and potentially more accurate threat/intrusion detection and prevention. Fortinet also provides a competitive response to the “deep packet inspection” message of competitors. New protocols that Fortinet supports include several VoIP protocols, SIP and SCCP. Fortinet further augments its deep inspection with signature and anomaly-based threat detection engines.
• The 3950B series products are capable UTM devices that support firewall/VPN, IPS, AV, Web filtering, application control, DLP and anti-spam. Fully outfitted, the 3950B can deliver 120 Gbps of firewall throughput (100 Gbps for the 3951B), 48 Gbps of IPSec VPN throughput (40 Gbps for the 3951B), 10 Gbps of IPS throughput (10 Gbps for the 3951B), and 1.5 Gbps of AV throughput (1.5 Gbps for the 3951B).
• Fortinet continues to expand the functional footprint of its appliances. FortiOS 4.0 supports several important new features. These include: WAN optimization, application control, data leakage prevention, and SSL inspection. The FortiOS 4.0 MR 2 release includes richer AV support, VoIP support, deeper integration with FortiClient, and new integration with FortiMobile SSL VPN client.
Encryption
Rating: 3
• Fortinet has documented performance metrics for encryption on each of its enterprise appliances. However, these performance metrics are chiefly based on 3DES benchmarking numbers, not AES-128 or AES-256 benchmarks. Fortinet claims to accelerate all encryption in hardware. High-end performance is 48 Gbps on the FortiGate 3950B (with a Fortinet Mezzanine Card).
• Fortinet has demonstrated proven performance in multiple public tests that have examined various aspects of the solutions’ performance, including basic firewall/VPN performance, IDS/IPS performance, and multi-service threat prevention performance.
• FortiOS 4.0 addressed a critical blind spot for enterprises by adding the ability to act as an SSL proxy, decrypt traffic to inspect it, and then apply policies before re-encrypting legitimate traffic and sending it along. Malware writers are using encryption to hide the communication between bots and command and control servers, so this capability addresses a newer threat type.
Management
Rating: 4
• Fortinet offers multiple tools designed to simplify device deployment, policy management, log collection, and analysis. These products are broken up into two platforms: FortiManager and FortiAnalyzer. Fortinet released v4.0 updates to both products in June 2009.
• FortiManager deals with the management of an enterprise-wide multi-device Fortinet deployment from a device and policy perspective. FortiManager can manage up to 4,000 FortiGate appliances on the high end. The FortiManager family runs from the FortiManager 3000B to the FortiManager 100. The product enables the creation and management of security policies based on individual users and groups of users. Enhancements in v4.0 include improved disaster recovery features and improved workflow that allows a single policy to be deployed across all managed devices.
• FortiAnalyzer is a purpose-built security logging platform that collects data and events from Fortinet appliances and offers a reporting and security event analysis system designed to create management-level reports of enterprise-wide security events. The v4.0 release of FortiAnalyzer includes a vulnerability management component. The device provides recommendations for protecting against found vulnerabilities. One FortiAnalyzer box can log up to 2,000 FortiGate appliances on the high end. The FortiAnalyzer family runs from the FortiAnalyzer 4000A to the FortiAnalyzer 100B.
• Individual Fortinet appliances can be managed from a command line interface or via a Web interface. The Fortinet Web interface has received good marks for ease of use, though there are some challenges, specifically regarding correlating events from the IPS/IDS engine with specific policies and rules, as well as some challenges in managing a large enterprise rule set from the Web management interface. In particular, managing a rule set of greater than 100 rules becomes more cumbersome via the Web interface.
• Fortinet offers multiple technical support programs. These include a choice of 8x5, 24x7, and Premier levels of support. Software updates are available online 24x7. Hardware maintenance programs are also available.
Scalability
Rating: 4
• The FortiGate family of products is large and growing. Fortinet positions products in this family from service provider down to SMB. The 5000 series of FortiGate blade chassis products targets MSSPs and large enterprises. Fortinet positions its mid-market offerings as running from the FortiGate-200B up to the FortiGate-1240B. The SMB products run from the FortiGate 110C to the FortiGate 50B.
• Fortinet is beginning to leverage a new generation of customized ASIC processors. This allows Fortinet to deliver impressive performance and a “pay as you grow” flexibility in hardware requirements. The 3950B, for example, supports five mezzanine card expansion slots and the 3951B supports four expansion slots. Each mezzanine card is designed to provide a combined physical port and processing resource. Each card can host FortiASIC NP4 or SP2 modules. The NP4, which was introduced last year, is a network processor, and the SP2, which is just being introduced, is a multi-core, multi-threaded security processor.
• Fortinet delivers impressive port density in its appliances. For example, the 3950B supports up to 12 total network interfaces (16 for the 3951B), up to 12 10GbE SFP interfaces (10 for the 3951B), four GbE interfaces (three for the 3951B), and two 10/100/1000 interfaces (two for the 3951B). Both products include two SR SFP+ transceivers. The 3040B has a total of 20 ports on the system comprised of modular SFP+ (eight), SFP (ten), and traditional RJ-45 (two) ports.
• Fortinet accelerates its VPN, firewall, and content inspection functions in a custom-designed ASIC. Fortinet’s rated performance number, like most products in this segment, is based on simple firewall operation, not an “all-on” configuration. However, Fortinet has added significant horsepower to its mid-market offerings in the expectation that they will increasingly be used as UTM devices.
• The higher-end FortiGate appliances support advanced mezzanine card (AMC) modules. Available double-width modules are: ADM-XB2, two-port 10GigE FortiASIC Module; ADM-XE2, two-port 10GigE Security Processing Module; ADM-FB8, eight-port GigE FortiASIC Module; and ADM-FE8, eight-port GigE Security Processing Module. Available single-width modules are: ASM-FB4, four-port GigE FortiASIC Module; ASM-CE4, four-port GigE Security Processing Module; ASM-S08, 80GB Hard Disk Storage Module; ASM-CX4, four-port GigE TX By-Pass Module; ASM-FX2, two-port GigE SX By-Pass Module; and ASM-ET4, four-port T1/E1 WAN Module. Fortinet also supports several Fortinet Mezzanine Cards (FMC): FMC-XD2, two-10GbE port 20GbE SFP Firewall Acceleration Module; FMC-XG2, tw0-10BbE port IPS Acceleration Module; and the FSM-064, 64GB SSD module.
• Fortinet offers both active-active and active-passive high-availability modes, but advanced stateful failover is only available in the active-passive mode.
Total Cost of Ownership
Rating: 5
• Fortinet’s devices are competitively priced and frequently offer better performance at a comparable price or equal performance at a lower price when compared to other appliance manufacturers. Fortinet also has one of the broadest appliance portfolios available on the market. The company prides itself on filling every conceivable niche in functionality and performance from SOHO to service providers. Fortinet is currently rolling out new appliances that leverage its next generation of ASIC processors. These new devices are delivering impressive improvements in performance and port density.
• Fortinet has a very straightforward pricing model of one fixed price per box and one fixed price per update service for that box. There is no complex per-user or capacity-based licensing that obscures TCO and frustrates customers.
• Fortinet develops its own remote access and remote security client, dubbed FortiClient. FortiClient is licensed on a per-user basis. The full client supports anti-X, IPSec VPN, personal firewall, anti-spam, Web content filtering, logging, central management and support. A single user license is $15.95, while 1,000 user licenses can be bought for $2.95 per client. Fortinet offers a free version of FortiClient, what it calls a “Demo” version, that provides the same functionality but without the logging, management, and support.
• Content security updates (anti-virus, anti-spam, content filtering, URL blacklists, etc.) are licensed on a yearly, per-service basis. Pricing for content security updates is relatively high, running anywhere from 15% (for AV/IDS) to 40% (for content filtering) of list price per service. (Fortinet also offers a services bundle that combines all subscription services. This package typically ranges between 40% and 45% of the list price of the product.) While straightforward, these services add significantly to the overall TCO of the solution. However, when compared to deploying an external solution, these prices are actually significantly lower in TCO. When contrasted with competitors, customers must consider the frequency of updates, the mechanism for delivering the updates (manual or automated), the cost of the service, and the impact on network performance from enabling the protection.
Metrics General Information
Product Functionality
Unified Threat Management
Device Specific Information
Interface Count
Varies by product
Interface Types
T1/E1, 10/100, Gigabit Ethernet. 10 Gigabit Ethernet is supported, through AMC module.
Redundant Power Supplies
Yes, most appliances support internal redundant power supplies, but FortiGate-310B and -620B support external redundant power supply.
NEBS Compliance
FortiGate-5140B is NEBS ready.
Remote/Out of Band Management
All FortiGate product has a dedicated serial port for management. All Ethernet ports can be configured for inband management.
High Availability Port
High availability is supported on all product and any port can be configured for High Availability.
Routing Protocols
RIP, OSPF, BGP, PIM (dense and sparse)
Product Warranty
1-Year Limited Hardware Warranty / 90-Days Limited Software Warranty
Latest Shipping Software
FortiOS v4.0 MR2
VPN Specific Information
Maximum Concurrent Connections
Varies by product; the new FG-3950B supports up to 10,000 gateway-to-gateway tunnels and 64,000 client-to-gateway tunnels.
3DES Performance
Varies by product; the new FG-3950B supports up to 8 Gbps of AES VPN performance.
3DES Accelerated Performance
Accelerator is built-in into the product and the interface module. Enhancement is possible by adding interface module to increase port density and performance. Accelerated performance for the 3950B is 48 Gbps.
Encryption Algorithms
AES 128, 192 and 256
Network Integration
Both. Transparent and routed/NAT can be supported simultaniously using different VDOMs (Virtual Domain features that is a avialable on every FortiGate product).
Industry Certifications
FIPS 140-2, CC EAL4+, ICSA Labs, NSS Labs, FCC, CE, BSMI, UL, VCCI, C-TICK
Tunneling Protocols
IPSec, PPTP, L2TP, GRE, GTP (On FortiCarrier - specialized software with MSSP features running on FortiGate)
CA Revocation Methods
Automatic, manual
High Availability Features
Yes, Active-Active or Active-Passive; More stateful features when active-passive
AES Performance
Varies by product; the new FG-3950B supports up to 8 Gbps (48 Gbps accelerated performance) of AES VPN performance.
SSL VPN Tunneling Features
Yes
SSL VPN Translation Features
Yes
SSL VPN Browser Support
IE 7.0/8.0, Firefox 3.0, Apple Safari
VPN Client Information
OS Support
Windows 2000, Windows XP 32 and 64-bit, Windows Server 2003 32 and 64-bit, Windows Server 2008 32 and 64-bit, Windows Vista 32 and 64-bit, Windows 7 32 and 64-bit
Authentication Methods
User name/password, X.509, Xauth, MSCHAPv2, PAP, CHAP, VPD
Client Lock-Out
Yes. GUI in the FortiClient can be locked download by using either different access right for user group, remote management on FortiManager appliance or creating a property MSI table during installation.
Personal Firewall
Latest FortiClient release adds WAN Optimization support for integration with FortiGate.
Personal Firewall Configuration
Yes
Firewall Features
Firewall Type
Stateful firewall inspection is supported. Application proxy is also supported for Web filtering, AV and others.
Address Translation
1-to-1 NAT/NAPT, 1-to-MANY NAT/NAPT, bidirectional NAT/NAPT, overlap translational and policy drivern NAT
High Availability Sessions
Yes, in Active/Passive mode
Load Balancing
Yes, via clustering
Protocol Support
SMTPS, POP3S, IMAPS
Firewall Architecture
ASIC + software assist
Virtual Firewalling
Yes and varies by Product, 10 VDOM (Virtual Domain) is supported on most product and high end product can scale up to 250 VDOM.
Management Features
Management Station
Appliance: FortiManager, FortiAnalyzer. Online cloud service: FortiGuard Analysis and Management service.
Management OS Support
Proprietary
Management Devices Supported
Number of devices supported varies by the models of the FortiManager (Management Appliance).
Management Client Support
FortiManager (Management appliance) can manage client runing FortiClient and the numbers of supported ForitClient varies by the models of FortiManager.
Logging Options
FortiGuard Analysis and Management Service. (Online logging and reporting services.)
NMS Integration
API is now available on the management appliance (FortiManager) for integration.
Policy Based Configuration
FortiManager support configuration version control of FortiGate, and the FortiClient end port software.
Management Security
HTTPS (Browser-based, no client)
Value Added Features
Denial of Service Protection
Yes, FortiGate can prevent attacks such as DDOS, Sync flood, port scanning and many others through the built-in IPS engine, traffic shaping, Antivirus scan and application control features.
IDS Intelligence
Full IPS
Anti-Virus Scanning
Yes FortiGate offers antivirus scan on email, ftp, IM, skype and many others. Antivirus package is inhouse developed.
Content Filtering
New value added features in FortiOS 4.0 include: WAN Optimization, DLP, SSL Inspection, Application Control, End Point Control and many others.
Pricing
Solution Hardware Pricing
Varies by product; FG-3950B: $79,995
Add-on Hardware
Various hardware expansion options are available. On the high end, the FMC -XD2 for the 3950-B lists at $23,995.
Software Licenses
No additional software license is required. Subscription service is required for signatures updates for antivirus, antispam, IPS and Web fitlering.
VPN Client Pricing
FortiClient VPN only verison is free as part of the demo verison. Full FortiClient verison include AV, WF, Antispam for 1000 users @ $15.50 ea.
Solution Description & Restrictions
No subscription or user licenses for Firewall, SSL and IPSec VPN features. Yearly subscription applies for AV, WF, IDS and Anitspam signatures.
Support/Maintenance
Hardware Maintenance Costs
Varies by product: FG-1240B:$5998
Maintenance Include S/W Updates
Yes
Software ONLY Maintenance Cost
Support and Software Updates are bundled together (FortiCare)