Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Rajoo Nagar
February, 2018
[Digital Transformation]
2
Digital Enterprise Edge
3
What is TP (Threat Protection) Performance?
AV
FW
+ APP
CONTROL
IPS
Threat Protection Performance is measured when FW, App Control, IPS and AV services are turned on
4
Why is Threat Protection Performance Important?
Notes/Sources:
1. Fortinet Threat Landscape Report Q3 2017
2. Accenture 2017 Cost of Cybercrime Study
3. 2017 Sans Incident Response Survey
5
Why is it Important to Inspect Secure (SSL) Traffic?
6
SSL Traffic Increasingly Insecure
80% 50%
Of Enterprise Web Traffic will Of attacks targeting enterprises
be encrypted by 2019* will use SSL in some form
by 2019*
Source: Gartner
7
Fortinet Addresses Stringent Throughput, Threat
Protection & SSL Needs
Introducing
FortiGate 6000 Series
8
FortiGate 6000 Series
A New Line of Very High End Next Generation Firewall Appliance
9
FortiGate 6000 Series – Fastest Threat Protection Appliance
One License. One FortiOS. One User Interface. Single Pane of Glass.
10
FortiGate 6000 Series – Industry’s Highest SSL Inspection
11
Where Does the 6000 Series Fit in the Network?
CLOUD
Enterprise Edge
Expanded digital attack surface (Threat WAN
Protection performance)
Need to inspect encrypted SSL traffic
Scale to support growing volume of
network & cloud traffic
12
FortiGate 6000 Series – Architectural Innovation
Advanced NGFW Architecture
» Clear data plane and management plane separation
» Hardware load balancing to achieve very high performance and session rates
» Eliminates bottleneck introduced by traditional NGFW packet processing approaches, allowing
support for exponentially increasing endpoint connections without imposing performance penalties
13
FortiGate 6300F / 6301F
14
FortiGate 6500F / 6501F
15
Core Network Security Product Range
Fabric Topology
Policy/Objects FortiGate 01 - Unlimited
NGFW
Application Control
IPSec
URL
Switching IPS
Routing AV
FortiGate 01 - Unlimited
Sandboxing
Switch Controller
FortiGate 6000
AP Controller FortiGate 1000-3000
FortiGate 100-900
FortiGate 30-90
Rugged
16
Industry Comparison
FortiGate 6000 Series Disrupting the NGFW Landscape
Real-World SSL Inspection on all FortiGate Datasheets
NGFW (FW + P
Measured with IPS enabled
P P
App Control +
Enterprise Mix
▬ Unknown
HTTP1024B for real-world scenario
IPS) (private mix)
Threat Prevention
(FW + App P P
Unknown ▬ ▬
Control + IPS + Enterprise Mix
(private mix)
AV)
18
Fortinet Support of Industry Mandated Ciphers for SSL
19
6000 Series vs. Industry Average Spec Comparison
FortiGate Industry Average
Specification Enterprise Benefits using 6300F
6300F (Based on same price)
Firewall 239 Gbps 75 Gbps 3x higher firewall throughput compared to industry average
Note: Industry average is calculated based on NGFW appliances from Palo Alto Networks,
Checkpoint, and Cisco
20
Comparison of Similarly Priced NGFW*
Palo Alto
Specifications Check Point Cisco FirePower FORTINET
Networks
PA-5260 23800 FP-4140 FP-4150 FG-6300F FG-6301F
Appliance Model
(3U) (2U) (1U) (1U) (3U) (3U)
FW Throughput 72.2 Gbps (w/ AC) 43 Gbps 25 Gbps (w/ AC) 30 Gbps (w/ AC) 239 Gbps 239 Gbps
NGFW Throughput
30 Gbps 7.2 Gbps 20 Gbps 24 Gbps 80 Gbps 80 Gbps
(FW + AC + IPS)
Threat Prevention
Throughput 30 Gbps TP 4.5 Gbps Not published Not published 60 Gbps 60 Gbps
(FW + AC + IPS + AV)
2x 1TB HDD or 2x
Storage 240GB SSD, 2TB HDD 400 GB 400 GB Nil (FortiAnalyzer) 2TB SSD (NVMe)
480GB SSD
Fortinet has disrupted the NGFW Landscape with the 6000 series
Up to 10x faster Threat Prevention for the same price
More storage, higher port density, higher session capacity
Fortinet’s latest NGFW is the fastest in the industry, widening the gap between us and other NGFW offerings
* Publicly available performance numbers from datasheet and website
21
Comparison Based on Broader Selection Criteria
Palo Alto
NGFW Selection Criteria Fortinet Check Point Cisco
Networks
22
Fortinet Leading and Recommended …as a NGFW FortiGate
Enterprise Firewall
NSS Labs 2017 Next Generation Firewall (NGFW) Security Value Map™
23
..And Leading as Data Center Security Gateway (DCSG) FortiGate
Enterprise Firewall
FG-3000D FG-7060E
Both Recommended
Best TCO
Fastest IPS Performance
Near Perfect Exploit block
100% Evasions blocked
24