FortiGate 600E Series Data Sheet

Transcription

DATA SHEETFortiGate 600E SeriesNext Generation FirewallSecure SD-WANSecure Web GatewayIPSFG-600E and FG-601EThe FortiGate 600E series provides an application-centric, scalable, and secure SD-WANsolution with Next Generation Firewall (NGFW) capabilities for mid-sized to large enterprisesdeployed at the campus or branch level. Protects against cyber threats with system-on-a-chipacceleration and industry-leading secure SD-WAN in a simple, affordable, and easy to deploysolution. Fortinet’s Security-Driven Networking approach provides tight integration of thenetwork to the new generation of security.Securityn Identifies thousands of applications inside network trafficfor deep inspection and granular policy enforcementnnProtects against malware, exploits, and maliciouswebsites in both encrypted and non-encrypted trafficPrevent and detect against known and unknown attacksusing continuous threat intelligence from AI-poweredFortiGuard Labs security servicesPerformancen Delivers industry’s best threat protection performance andultra-low latency using purpose-built security processor(SPU) technologynProvides industry-leading performance and protection forSSL encrypted trafficCertificationn Independently tested and validated for best-in-classsecurity effectiveness and performancenReceived unparalleled third-party certifications from NSSLabsNetworkingn Delivers advanced networking capabilities that seamlesslyintegrate with advanced layer 7 security and virtualdomains (VDOMs) to offer extensive deploymentflexibility, multi-tenancy and effective utilization ofresourcesnDelivers high-density, flexible combination of varioushigh-speed interfaces to enable best TCO for customersfor data center and WAN deploymentsManagementn Includes a management console that is effective, simpleto use, and provides comprehensive network automationand visibilitynnProvides Zero Touch Integration with Fortinet’s SecurityFabric’s Single Pane of Glass ManagementPredefined compliance checklist analyzes the deploymentand highlights best practices to improve overall securitypostureSecurity Fabricn Enables Fortinet and Fabric-ready partners’ productsto provide broader visibility, integrated end-to-enddetection, threat intelligence sharing, and automatedremediationFirewallIPSNGFWThreat ProtectionInterfaces36 Gbps10 Gbps9.5 Gbps7 GbpsMultiple GE RJ45, GE SFP, and 10 GE SFP Slots1

DATA SHEET FortiGate 600E SeriesDEPLOYMENTN ext GenerationFirewall (NGFW)Secure SD-WAN§ Reduce the complexity and maximize your ROI byintegrating threat protection security capabilities intoa single high-performance network security appliance,powered by Fortinet’s Security Processing Unit (SPU)§ Full visibility into users, devices, and applications acrossthe entire attack surface and consistent security policyenforcement irrespective of asset location§ Protect against network exploitable vulnerabilitieswith industry-validated IPS that offers low latency andoptimized network performance§ Automatically block threats on decrypted traffic using theindustry’s highest SSL inspection performance, includingthe latest TLS 1.3 standard with mandated ciphers§ Proactively block newly discovered sophisticatedattacks in real-time with AI-powered FortiGuard Labsand advanced threat protection services included in theFortinet Security FabricSecure Web Gateway (SWG)§ Secure web access from both internal and external risks,even for encrypted traffic at high performance§ Enhanced user experience with dynamic web and videocaching§ Block and control web access based on user or usergroups across URLs and domains§ Prevent data loss and discover user activity to known andunknown cloud applications§ Block DNS requests against malicious domains§ Multi-layered advanced protection against zero-daymalware threats delivered over the webCAMPUS§ Consistent business application performance withaccurate detection, dynamic WAN path steering on anybest-performing WAN transport§ Accelerated multi-cloud access for faster SaaS adoptionwith cloud-on-ramp§ Self-healing networks with WAN edge high availability,sub-second traffic switchover-based and real-timebandwidth compute-based traffic steering§ Automated overlay tunnels provides encryption andabstracts physical hybrid WAN making it simple to manage.§ Simplified and intuitive workflow with FortiManger formanagement and zero touch deployment§ Enhanced analytics both real-time and historical providesvisibility into network performance and identifies anomalies§ Strong security posture with next generation firewall andreal- time threat protection IPS§ Purpose-built security processors delivering industryvalidated IPS performance with high throughput and lowlatency§ Deploy virtual patches at the network level to protectagainst network exploitable vulnerabilities and optimizenetwork protection time§ Deep packet inspection at wire speeds offers unparalleledthreat visibility into network traffic including trafficencrypted with the latest TLS 1.3§ Proactively block newly discovered sophisticated attacksin real-time with advanced threat protection provided bythe intelligence services of the Fortinet Security FabricFortiSandboxAdvanced ThreatProtectionFortiManagerCentralized Provisioning &Automated Overlay ManagementFortiAPSecure AccessPointFortiSwitchSwitchingFortiClientEndpoint ProtectionFortiGateSegmentationFortiSwitchSecure AccessSwitchFortiGateNGFWFortiManagerSingle redSecurity & LogManagementFortiAPSecure AccessPoint ecIPSlsnenTuENTERPRISEBRANCH LSMP FortiGateSecure SD-WANFortiAnalyzerAnalytics-poweredSecurity & Log ManagementLarge Campus Network DeploymentEnterprise Branch Deployment(NGFW)(Secure SD-WAN)2

DATA SHEET FortiGate 600E SeriesHARDWAREFortiGate 600E/601EHAFortiGate 600EUSB157911SFPS1VW1X1CONSOLESFP MGMT1322346810124S25VW2X26100-240VAC6-3A 50/60HzInterfaces1.2.3.4.5.6.1x USB Port1x Console Port2x GE RJ45 MGMT/HA Ports8x GE RJ45 Ports8x GE SFP Slots2x 10 GE SFP SlotsHardware FeaturesNP6CP91U10GEACDUAL/480GBNetwork ProcessorPowered by SPU§ Fortinet’s custom SPU processorsdeliver the power you need to detectmalicious content at multi-Gigabitspeeds§ Other security technologies cannot protect againsttoday’s wide range of content- and connectionbased threats because they rely on general-purposeCPUs, causing a dangerous performance gap§ SPU processors provide the performance neededto block emerging threats, meet rigorous third-partycertifications, and ensure that your network securitysolution does not become a network bottleneck3Fortinet’s new, breakthrough SPU NP6 network processorworks inline with FortiOS functions delivering:§ Superior firewall performance for IPv4/IPv6, SCTP andmulticast traffic with ultra-low latency§ VPN, CAPWAP and IP tunnel acceleration§ Anomaly-based intrusion prevention, checksum offload,and packet defragmentation§ Traffic shaping and priority queuingContent ProcessorFortinet’s ninth generation custom SPU CP9 contentprocessor works outside of the direct flow of traffic andaccelerates the inspection.

DATA SHEET FortiGate 600E SeriesFORTINET SECURITY FABRICSecurity FabricThe industry’s highest-performing cybersecurity platform,powered by FortiOS, with a rich ecosystem designed tospan the extended digital attack surface, delivering fullyautomated, self-healing network security.Fabric ManagementCenterFabric SecurityOperationsNOCSOC§ Broad: Coordinated detection and enforcement across theentire digital attack surface and lifecycle with convergednetworking and security across edges, clouds, endpoints,and usersAdaptive CloudSecurity§ Integrated: Integrated and unified security, operation,and performance across different technologies, location,deployment options, and the richest ecosystemZero TrustAccessFORTI OS§ Automated: Context aware, self-healing network andsecurity posture leveraging cloud-scale and advanced AIto automatically deliver near-real-time, user-to-applicationcoordinated protection across the FabricThe Fabric empowers organizations of any size to secure andsimplify their hybrid infrastructure on the journey to systemFortiGuardThreat IntelligenceFortiOS Operating SystemFortiOS, Fortinet’s leading operating system enable theconvergence of high performing networking and securityacross the Fortinet Security Fabric delivering consistent andcontext-aware security posture across network endpoint, andclouds. The organically built best of breed capabilities andunified approach allows organizations to run their businesseswithout compromising performance or protection, supportsseamless scalability, and simplifies innovation consumption.The release of FortiOS 7 dramatically expands the FortinetSecurity Fabric’s ability to deliver consistent security acrosshybrid deployment models of Hardware, Software, andSoftware As-a-Service with SASE and ZTNA, among others.SERVICESFortiGuard Security ServicesFortiGuard Labs offer real-time intelligence on the threatlandscape, delivering comprehensive security updates acrossthe full range of Fortinet’s solutions. Comprised of securitythreat researchers, engineers, and forensic specialists, theteam collaborates with the world’s leading threat monitoringorganizations and other network and security vendors, as wellas law enforcement agencies.FortiCare ServicesFortinet is dedicated to helping our customers succeed, andevery year FortiCare services help thousands of organizationsget the most from their Fortinet Security Fabric solution. Wehave more than 1000 experts to help accelerate technologyimplementation, provide reliable assistance through advancedsupport, and offer proactive care to maximize security andperformance of Fortinet deployments.4

DATA SHEET FortiGate 600E SeriesSPECIFICATIONSFG-600EFG-601EInterfaces and ModulesFG-600EHardware Accelerated 10 GE SFP Slots2Height x Width x Length (inches)Hardware Accelerated GE RJ45Interfaces8Height x Width x Length (mm)Hardware Accelerated GE SFP Slots8GE RJ45 Management Ports2USB Ports2RJ45 Console Port1Onboard StorageIncluded Transceivers0WeightForm FactorPower SourcePower Consumption(Average / Maximum)2x 240 GB SSD2x SFP (SX 1 GE)System Performance — Enterprise Traffic MixIPS Throughput 210 GbpsNGFW Throughput 2, 49.5 GbpsThreat Protection Throughput 2, 57 GbpsIPv4 Firewall Throughput(1518 / 512 / 64 byte, UDP)36 / 36 / 27 GbpsIPv6 Firewall Throughput(1518 / 512 / 64 byte, UDP)36 / 36 / 27 GbpsFirewall Throughput (Packet per Second)1.54 μs40.5 MppsConcurrent Sessions (TCP)8 MillionNew Sessions/Second (TCP)450 000Firewall PoliciesIPsec VPN Throughput (512 byte) 1Gateway-to-Gateway IPsec VPN Tunnels7 GbpsConcurrent SSL-VPN Users(Recommended Maximum, Tunnel Mode)10 000SSL Inspection Throughput(IPS, avg. HTTPS) 38 Gbps800 000Application Control Throughput(HTTP 64K) 215 GbpsCAPWAP Throughput (HTTP 64K)18 GbpsMaximum Number of FortiTokensHigh Availability Configurations6A@100VHeat Dissipation832 BTU/hRedundant Power Supplies(Hot Swappable)OptionalOperating Environment and CertificationsOperating TemperatureHumidityNoise LevelForced AirflowOperating AltitudeComplianceCertifications32–104 F (0–40 C)-31–158 F (-35–70 C)10–90% non-condensing59 dBASide and Front to BackUp to 9843 ft (3000 m)FCC Part 15 Class A, RCM, VCCI, CE,UL/cUL, CBICSA Labs: Firewall, IPsec, IPS, Antivirus,SSL-VPN, USGv6/IPv610 / 10961024 / 5125000Active-Active, Active-Passive, ClusteringNote: All performance values are “up to” and vary depending on system configuration.1. IPsec VPN performance test uses AES256-SHA256.2. IPS (Enterprise Mix), Application Control, NGFW and Threat Protection are measured withLogging enabled.3. SSL Inspection performance values use an average of HTTPS sessions of different ciphersuites.5129 W / 244 W5500SSL Inspection Concurrent Session(IPS, avg. HTTPS) 3Maximum Number of FortiAPs(Total / Tunnel)100–240V, 50/60 Hz2000SSL-VPN ThroughputMaximum Number of FortiSwitchesSupported16.6 lbs (7.5 kg)Rack Mount, 1 RU10 00050 000Virtual Domains (Default / Maximum)16.1 lbs (7.3 kg)20 GbpsClient-to-Gateway IPsec VPN TunnelsSSL Inspection CPS (IPS, avg. HTTPS) 31.75 x 17.0 x 15.044.45 x 432 x 380Current (Maximum)Storage TemperatureSystem Performance and CapacityFirewall Latency (64 byte, UDP)FG-601EDimensions and Power4. NGFW performance is measured with Firewall, IPS and Application Control enabled.5. Threat Protection performance is measured with Firewall, IPS, Application Control andMalware Protection enabled.

DATA SHEET FortiGate 600E SeriesORDERING INFORMATIONProductSKUDescriptionFortiGate 600EFG-600E2x 10 GE SFP slots, 10x GE RJ45 ports (including 1x MGMT port, 1x HA port, 8x switch ports), 8x GE SFPslots, SPU NP6 and CP9 hardware accelerated.FortiGate 601EFG-601E2x 10 GE SFP slots, 10x GE RJ45 ports (including 1x MGMT port, 1x HA port, 8x switch ports), 8x GE SFPslots, SPU NP6 and CP9 hardware accelerated, 2x 240 GB onboard SSD storage.1 GE SFP LX Transceiver ModuleFN-TRAN-LX1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP RJ45 Transceiver ModuleFN-TRAN-GC1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP SX Transceiver ModuleFN-TRAN-SX1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP slots.10 GE SFP Transceiver Module, Short RangeFN-TRAN-SFP SR10 GE SFP transceiver module, short range for all systems with SFP and SFP/SFP slots.10 GE SFP Transceiver Module, Long RangeFN-TRAN-SFP LR10 GE SFP transceiver module, long range for all systems with SFP and SFP/SFP slots.10 GE SFP Transceiver, Extended RangeFN-TRAN-SFP ER10 GE SFP transceiver module, extended range for all systems with SFP and SFP/SFP slots.10 GE SFP RJ45 Transceiver ModuleFN-TRAN-SFP GC10 GE SFP RJ45 transceiver module for systems with SFP slots.10 GE SFP Active Direct Attach Cable, 10m / 32.8 ftSP-CABLE-ADASFP 10 GE SFP active direct attach cable, 10m / 32.8 ft for all systems with SFP and SFP/SFP slots.Optional Power SupplySP-FG300E-PSAC power supply for FG-300/301E, FG-400/401E, FG-500/501E, FG-600/601E, FAZ-200F/300F/800F andFMG-200F/300F.Optional d Labs deliversa number of securityintelligence services toaugment the FortiGatefirewall platform. Youcan easily optimize theprotection capabilities ofyour FortiGate with one ofthese FortiGuard Bundles.FortiCareEnterprise ProtectionUnified Threat ProtectionAdvanced ThreatProtection24x724x724x7FortiGuard App Control Service FortiGuard IPS Service FortiGuard Advanced Malware Protection (AMP) — Antivirus,Mobile Malware, Botnet, CDR, Virus Outbreak Protection andFortiSandbox Cloud Service FortiGuard Web and Video1 Filtering Service FortiGuard Antispam Service FortiGuard Security Rating Service FortiGuard IoT Detection Service FortiGuard Industrial Service FortiConverter Service 1. Available when running FortiOS 7.0www.fortinet.comCopyright 2021 Fortinet, Inc. All rights reserved. Fortinet , FortiGate , FortiCare and FortiGuard , and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other productor company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and otherconditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaserthat expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, anysuch warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwiserevise this publication without notice, and the most current version of the publication shall be applicable.FG-600E-DAT-R17-20211202

1 FortiGate 600E Series FG-600E and FG-601E The FortiGate 600E series provides an application-centric, scalable, and secure SD-WAN solution with Next Generation Firewall (NGFW) capabilities for mid-sized to large enterprises