FortiGate 200E Series Data Sheet

Transcription

DATA SHEETFortiGate 200E SeriesNext Generation FirewallSecure SD WANSecure Web GatewayFG-200E and FG-201EThe FortiGate 200E series provides an application-centric, scalable and secure SD-WANsolution with next generation firewall (NGFW) capabilities for mid-sized to large enterprisesdeployed at the campus or enterprise branch level. Protects against cyber threats with systemon-a-chip acceleration and industry-leading secure SD-WAN in a simple, affordable, and easy todeploy solution. Fortinet’s Security-Driven Networking approach provides tight integration of thenetwork to the new generation of security.Securityn Identifies thousands of applications inside network trafficfor deep inspection and granular policy enforcementnnProtects against malware, exploits, and maliciouswebsites in both encrypted and non-encrypted trafficPrevent and detect against known and unknown attacksusing continuous threat intelligence from AI-poweredFortiGuard Labs security servicesPerformancen Delivers industry’s best threat protection performance andultra-low latency using purpose-built security processor(SPU) technologynProvides industry-leading performance and protection forSSL encrypted trafficCertificationn Independently tested and validated for best-in-classsecurity effectiveness and performancenReceived unparalleled third-party certifications from NSSLabsNetworkingn Delivers advanced networking capabilities that seamlesslyintegrate with advanced layer 7 security and virtualdomains (VDOMs) to offer extensive deploymentflexibility, multi-tenancy and effective utilization ofresourcesnDelivers high-density, flexible combination of varioushigh-speed interfaces to enable best TCO for customersfor data center and WAN deploymentsManagementn Includes a management console that is effective, simpleto use, and provides comprehensive network automationand visibilitynnProvides Zero Touch Integration with Fortinet’s SecurityFabric’s Single Pane of Glass ManagementPredefined compliance checklist analyzes the deploymentand highlights best practices to improve overall securitypostureSecurity Fabricn Enables Fortinet and Fabric-ready partners’ productsto provide broader visibility, integrated end-to-enddetection, threat intelligence sharing, and automatedremediationFirewallIPSNGFWThreat ProtectionInterfaces20 Gbps2.2 Gbps1.8 Gbps1.2 GbpsMultiple GE RJ45, GE SFP Slots1

DATA SHEET FortiGate 200E SeriesDEPLOYMENTNext Generation Firewall (NGFW)FortiSandboxAdvanced rk Management§ Reduce the complexity and maximize your ROI byintegrating threat protection security capabilities intoa single high-performance network security appliance,powered by Fortinet’s Security Processing Unit (SPU)FortiAnalyzerAnalytics-poweredSecurity & Log ManagementFortiGateNGFW§ Full visibility into users, devices, applications acrossthe entire attack surface and consistent security policyenforcement irrespective of asset locationFortiAPSecure AccessPoint§ Protect against network exploitable vulnerabilitieswith industry-validated IPS that offers low latency andoptimized network performance§ Automatically block threats on decrypted traffic using theIndustry’s highest SSL inspection performance, includingthe latest TLS 1.3 standard with mandated ciphers§ Proactively block newly discovered sophisticatedattacks in real-time with AI-powered FortiGuard Labsand advanced threat protection services included in theFortinet Security FabricFortiAnalyzerAnalytics-poweredSecurity & LogManagementFortiAPSecure AccessPoint ecIPSlsnenTuENTERPRISEBRANCH FortiClientEndpoint ProtectionNext Generation Firewall (NGFW) Camplus DeploymentSecure SD-WAN§ Consistent business application performance withaccurate detection, dynamic WAN path steering on anybest-performing WAN transportSD-WAN OrchestratorCentralized Provisioning &Automated Overlay ManagementFortiSwitchSecure AccessSwitchFortiSwitchSwitchingCAMPUSLSMP FortiGateSecure SD-WAN§ Accelerated Multi-cloud access for faster SaaS adoptionwith cloud-on-ramp§ Self-healing networks with WAN edge high availability,sub-second traffic switchover-based and real-timebandwidth compute-based traffic steering§ Automated Overlay tunnels provides encryption andabstracts physical hybrid WAN making it simple to manage.§ Simplified and intuitive workflow with SD-WANOrchestrator for management and zero touch deployment§ Enhanced analytics both real-time and historical providesvisibility into network performance and identify anomaliesEnterprise Branch Secure SD-WAN Deployment§ Strong security posture with next generation firewall andreal- time threat protectionSecure Web Gateway (SWG)Web ApplicationServers§ Secure web access from both internal and external risks,even for encrypted traffic at high performanceInternal User§ Enhanced user experience with dynamic web and videocachingFortiWebWeb Application Firewall§ Block and control web access based on user or usergroups across URL’s and domains§ Prevent data loss and discover user activity to known andunknown cloud applicationsFortiGateSWGExternal User§ Block DNS requests against malicious domains§ Multi-layered advanced protection against zero-daymalware threats delivered over the webSecure Web Gateway (SWG) Deployment2

DATA SHEET FortiGate 200E SeriesHARDWAREFortiGate 200E/201E1HAWAN 11357911131517MGMTWAN 224681012141618CONSOLEFortiGate 200ESTATUSALARMHAPOWERUSB2345Hardware FeaturesInterfaces1.2.3.4.5.6.Console PortUSB Port2x GE RJ45 MGMT/HA Ports2x GE RJ45 WAN Ports14x GE RJ45 Ports4x GE SFP Slots6NP6LITENP96CPLITECP1U91URPS//RPS 480GB480GBNetwork ProcessorPowered by SPU§ Combines a RISC-based CPU withFortinet’s proprietary SecurityProcessing Unit (SPU) content andnetwork processors for unmatched performance§ Simplifies appliance design and enablesbreakthrough performance for smaller networks§ Supports firewall acceleration across all packetsizes for maximum throughput§ Delivers accelerated UTM content processing forsuperior performance and protection§ Accelerates VPN performance for high speed andsecure remote access3The SPU NP6Lite network processor works inline with firewalland VPN functions delivering:§ Wire-speed firewall performance for any size packets§ VPN acceleration§ Anomaly-based intrusion prevention, checksum offload,and packet defragmentation§ Traffic shaping and priority queuingContent ProcessorFortinet’s ninth generation custom SPU CP9 contentprocessor works outside of the direct flow of traffic andaccelerates the inspection.

DATA SHEET FortiGate 200E SeriesFORTINET SECURITY FABRICSecurity FabricThe industry’s highest-performing cybersecurity platform,powered by FortiOS, with a rich ecosystem designed tospan the extended digital attack surface, delivering fullyautomated, self-healing network security.Fabric ManagementCenterFabric SecurityOperationsNOCSOC§ Broad: Coordinated detection and enforcement across theentire digital attack surface and lifecycle with convergednetworking and security across edges, clouds, endpointsand usersAdaptive CloudSecurity§ Integrated: Integrated and unified security, operation,and performance across different technologies, location,deployment options, and the richest EcosystemZero TrustAccessFORTI OS§ Automated: Context aware, self-healing network &security posture leveraging cloud-scale and advanced AIto automatically deliver near-real-time, user-to-applicationcoordinated protection across the FabricThe Fabric empowers organizations of any size to secure andsimplify their hybrid infrastructure on the journey to systemFortiGuardThreat IntelligenceFortiOS Operating SystemFortiOS, Fortinet’s leading operating system enable theconvergence of high performing networking and securityacross the Fortinet Security Fabric delivering consistent andcontext-aware security posture across network endpoint, andclouds. The organically built best of breed capabilities andunified approach allows organizations to run their businesseswithout compromising performance or protection, supportsseamless scalability, and simplifies innovation consumption.The release of FortiOS 7 dramatically expands the FortinetSecurity Fabric’s ability to deliver consistent security acrosshybrid deployment models consisting on appliances, softwareand As-a-Service with SASE, ZTNA and other emergingcybersecurity solutions.SERVICESFortiGuard Security ServicesFortiGuard Labs offers real-time intelligence on the threatlandscape, delivering comprehensive security updates acrossthe full range of Fortinet’s solutions. Comprised of securitythreat researchers, engineers, and forensic specialists, theteam collaborates with the world’s leading threat monitoringorganizations and other network and security vendors, as wellas law enforcement agencies.FortiCare ServicesFortinet is dedicated to helping our customers succeed, andevery year FortiCare services help thousands of organizationsget the most from their Fortinet Security Fabric solution. Wehave more than 1,000 experts to help accelerate technologyimplementation, provide reliable assistance through advancedsupport, and offer proactive care to maximize security andperformance of Fortinet deployments.4

DATA SHEET FortiGate 200E SeriesSPECIFICATIONSFORTIGATE 200EFORTIGATE 201EHardware SpecificationsFORTIGATE 200EGE RJ45 WAN Interfaces2Height x Width x Length (inches)GE RJ45 Management/HA Ports2Height x Width x Length (mm)GE RJ45 Ports14WeightGE SFP Slots4USB port1Form Factor (supports EIA / non-EIAstandards)Console (RJ45)1Local StorageIncluded Transceivers—Power Input1x 480 GB SSD0IPS Throughput 22.2 GbpsNGFW Throughput 2, 41.8 GbpsThreat Protection Throughput 2, 51.2 GbpsSystem PerformanceFirewall Latency (64 byte UDP packets)Firewall Throughput (Packets Per Second)20 / 20 / 9 Gbps3 μs13.5 MppsConcurrent Sessions (TCP)2 MillionNew Sessions/Second (TCP)135,000Firewall PoliciesIPsec VPN Throughput (512 byte) 12,00010,000SSL Inspection Throughput(IPS, avg. HTTPS) 3SSL Inspection CPS (IPS, avg. HTTPS) 3CAPWAP Throughput (1444 byte, UDP)1.5 GbpsHigh Availability ConfigurationsOperating TemperatureStorage TemperatureHumidityNoise LevelForced AirflowOperating Altitude32–104 F (0–40 C)-31–158 F (-35–70 C)10–90% non-condensing31.1 dBASide to BackUp to 7,400 ft (2,250 m)ComplianceFCC Part 15B, Class A, CE, RCM, VCCI, UL/cUL, CB, BSMICertificationsICSA Labs: Firewall, IPsec, IPS, Antivirus,SSL-VPN; IPv610 / 1064256 / 1285,000Active / Active, Active / Passive, ClusteringNote: All performance values are “up to” and vary depending on system configuration.1. IPsec VPN performance test uses AES256-SHA256.2. IPS (Enterprise Mix), Application Control, NGFW and Threat Protection are measured withLogging enabled.3. SSL Inspection performance values use an average of HTTPS sessions of different ciphersuites.5374.9 BTU/hOperating Environment and Certifications1,0003.5 GbpsMaximum Number of FortiTokens70.98 / 109.9 W820 MbpsApplication Control Throughput(HTTP 64K) 2Maximum Number of FortiAPs(Total / Tunnel Mode)100–240V AC, 50–60 Hz110 V / 3 A, 220 V / 0.42 A500240,000Maximum Number of FortiSwitchesSupported12.12 lbs (5.5 kg)Rack Mount, 1 RU900 MbpsSSL Inspection Concurrent Session(IPS, avg. HTTPS) 3Virtual Domains (Default / Maximum)11.9 lbs (5.4 kg)10,000Client-to-Gateway IPsec VPN TunnelsConcurrent SSL-VPN Users(Recommended Maximum, Tunnel Mode)Power Consumption (Average / Maximum)1.75 x 17.0 x 11.944.45 x 432 x 3017.2 GbpsGateway-to-Gateway IPsec VPN TunnelsSSL-VPN ThroughputMaximum CurrentHeat DissipationSystem Performance — Enterprise Traffic MixFirewall Throughput(1518 / 512 / 64 byte UDP packets)FORTIGATE 201EDimensions and Power4. NGFW performance is measured with Firewall, IPS and Application Control enabled.5. Threat Protection performance is measured with Firewall, IPS, Application Control andMalware Protection enabled.

DATA SHEET FortiGate 200E SeriesORDERING INFORMATIONProductSKUDescriptionFortiGate 200EFG-200E18x GE RJ45 (including 2x WAN ports, 1x Mgmt port, 1x HA port, 14x switch ports), 4x GE SFP slots. SPU NP6Lite and CP9 hardwareaccelerated.FortiGate 201EFG-201E18x GE RJ45 (including 2x WAN ports, 1x Mgmt port, 1x HA port, 14x switch ports), 4x GE SFP slots, SPU NP6Lite and CP9 hardwareaccelerated,480 GB onboard SSD storage.1 GE SFP LX transceiver moduleFN-TRAN-LX1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP RJ45 transceiver moduleFN-TRAN-GC1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP SX transceiver moduleFN-TRAN-SX1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP slots.Optional nUnified ThreatProtectionAdvanced ThreatProtectionASE 124x724x724x7FortiGuard App Control Service FortiGuard IPS Service FortiGuard Advanced Malware Protection (AMP) — Antivirus,Mobile Malware, Botnet, CDR, Virus Outbreak Protection andFortiSandbox Cloud Service FortiGuard Web and Video2 Filtering Service FortiGuard Antispam Service FortiGuard Security Rating Service FortiGuard IoT Detection Service FortiGuard Industrial Service FortiConverter Service SD-WAN Orchestrator Entitlement SD-WAN Cloud Assisted Monitoring SD-WAN Overlay Controller VPN Service Fortinet SOCaaS FortiAnalyzer Cloud BundlesFortiGuardBundleFortiGuard Labs deliversa number of securityintelligence services toaugment the FortiGatefirewall platform. Youcan easily optimize theprotection capabilities ofyour FortiGate with one ofthese FortiGuard Bundles.FortiCareFortiManager Cloud 1. 24x7 plus Advanced Services Ticket Handling2. Available when running FortiOS 7.0www.fortinet.comCopyright 2021 Fortinet, Inc. All rights reserved. Fortinet , FortiGate , FortiCare and FortiGuard , and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other productor comp

1 FortiGate 200E Series FG-200E and FG-201E The FortiGate 200E series provides an application-centric, scalable and secure SD-WAN solution with next generation firewall (NGFW) capabilities for mid-sized to large enterprises