FortiGate 600E Series Data Sheet - CNET Content

Transcription

DATA SHEETNext Generation FirewallSecure SD-WANSecure Web GatewayIPSFortiGate 600E SeriesFortiGate 600E and 601EThe FortiGate 600E series delivers next generation firewall (NGFW) capabilities for mid-sized to largeenterprises deployed at the campus or enterprise branch level. Protects against cyber threats withhigh-powered security processors for optimized network performance, security efficacy, and deep visibility.Fortinet’s Security-Driven Networking approach provides tight integration of the network to the newgeneration of security.Security§ Identifies thousands of applications inside network traffic fordeep inspection and granular policy enforcement§ Protects against malware, exploits, and malicious websites inboth encrypted and non-encrypted traffic§ Prevents and detects against known attacks using continuousthreat intelligence from AI-powered FortiGuard Labs securityservices§ Proactively blocks unknown sophisticated attacks in realtime with the Fortinet Security Fabric integrated AI-poweredFortiSandboxPerformance§ Engineered for Innovation using Fortinet’s purpose-built securityprocessors (SPU) to deliver the industry’s best threat protectionperformance and ultra-low latency§ Provides industry-leading performance and protection for SSLencrypted traffic including the first firewall vendor to provideTLS 1.3 deep inspectionCertification§ Independently tested and validated best security effectivenessand performance§ Received unparalleled third-party certifications from NSS Labs,ICSA, Virus Bulletin, and AV ComparativesNetworking§ Application aware routing with in-built SD-WAN capabilities toachieve consistent application performance and the best userexperience§ Built-in advanced routing capabilities to deliver highperformance with encrypted IPSEC tunnels at scaleManagement§ Includes a management console that is effective and simple touse, which provides a comprehensive network of automation &visibility§ Provides Zero Touch Provisioning leveraging Single Paneof Glass Management powered by the Fabric ManagementCenter§ Predefined compliance checklists analyze the deployment andhighlight best practices to improve the overall security postureSecurity Fabric§ Enables Fortinet and Fabric-ready partners’ products to providebroader visibility, integrated end-to-end detection, threatintelligence sharing, and automated remediation§ Automatically builds Network Topology visualizations whichdiscover IoT devices and provide complete visibility into Fortinetand Fabric-ready partner productsFirewallIPSNGFWThreat ProtectionInterfaces36 Gbps10 Gbps9.5 Gbps7 GbpsMultiple GE RJ45, GE SFP and 10 GE SFP SlotsRefer to the specifications table for details

DATA SHEET FortiGate 600E SeriesDeploymentNext Generation Firewall (NGFW)§ Reduce the complexity and maximize your ROI by integratingthreat protection security capabilities into a single high-Secure Web Gateway (SWG)§ Secure web access from both internal and external risks, evenfor encrypted traffic at high performanceperformance network security appliance, powered by Fortinet’s§ Enhanced user experience with dynamic web and video cachingSecurity Processing Unit (SPU)§ Block and control web access based on user or user groups§ Full visibility into users, devices, applications across the entireattack surface and consistent security policy enforcementirrespective of asset locationacross URL’s and domains§ Prevent data loss and discover user activity to known andunknown cloud applications§ Protect against network exploitable vulnerabilities with industryvalidated IPS that offers low latency and optimized networkperformance§ Block DNS requests against malicious domains§ Multi-layered advanced protection against zero-day malwarethreats delivered over the web§ Automatically block threats on decrypted traffic using theIndustry’s highest SSL inspection performance, includingthe latest TLS 1.3 standard with mandated ciphers§ Proactively block newly discovered sophisticated attacks inreal-time with AI-powered FortiGuard Labs and advanced threatprotection services included in the Fortinet Security FabricIPS§ Purpose-built security processors delivering industry validatedIPS performance with high throughput and low latency§ Deploy virtual patches at the network level to protect againstnetwork exploitable vulnerabilities and optimize networkprotection timeSecure SD-WAN§ Deep packet inspection at wire speeds offers unparalleled threat§ Consistent business application performance with accuratedetection, dynamic WAN path steering and optimization§ Multi-cloud access for faster SaaS adoption with end-to-visibility into network traffic including traffic encrypted with thelatest TLS 1.3§ Proactively block newly discovered sophisticated attacks in realtime with advanced threat protection provided by the intelligenceend optimization§ Simplification with zero touch deployment and centralizedservices of the Fortinet Security Fabricmanagement with auto-provisioning, analytics and reporting§ Strong security posture with next generation firewall and realtime threat protectionFortiSandboxAdvanced rk ManagementFortiManagerAutomation-DrivenNetwork ManagementFortiSwitchSecure AccessSwitchFortiAnalyzerAnalytics-poweredSecurity & Log ManagementFortiGateNGFWFortiAPSecure NCHFortiAPSecure AccessPoint ecIPSlsnenTu LSMP FortiGateSecure SD-WANFortiClientEndpoint ProtectionFortiGate 600E deployment in y & LogManagementFortiGate 600E deployment in Enterprise Branch(Secure SD-WAN)

DATA SHEET FortiGate 600E SeriesHardwareFortiGate 600E/601EHAFortiGate 600EUSB3579SFP11S1VW1X1CONSOLESFP MGMT11224681012S243VW2X256100-240VAC6-3A 50/60HzNP6CP91U10GEACDUAL/480GBInterfaces1. USB Port2. Console Port3. 2x GE RJ45 MGMT/HA Ports4. 8x GE RJ45 Ports5. 8x GE SFP Slots6. 2x 10 GE SFP SlotsNetwork ProcessorPowered by SPU§ Custom SPU processors deliver thepower you need to detect maliciouscontent at multi-Gigabit speeds§ Other security technologies cannot protect againsttoday’s wide range of content- and connection-basedthreats because they rely on general-purpose CPUs,Fortinet’s new, breakthrough SPU NP6 network processor worksinline with FortiOS functions delivering:§ Superior firewall performance for IPv4/IPv6, SCTP, and multicasttraffic with ultra-low latency down to 2 microseconds§ VPN, CAPWAP, and IP tunnel acceleration§ Anomaly-based intrusion prevention, checksum offload, andpacket defragmentation§ Traffic shaping and priority queuingcausing a dangerous performance gap§ SPU processors provide the performance neededto block emerging threats, meet rigorous third-partycertifications, and ensure that your network securitysolution does not become a network bottleneckContent ProcessorFortinet’s new, breakthrough SPU CP9 content processor worksoutside of the direct flow of traffic and accelerates the inspection ofcomputationally intensive security features:§ Enhanced IPS performance with unique capability of full signaturematching at ASIC§ SSL Inspection capabilities based on the latest industry mandatedcipher suites§ Encryption and decryption offloading3

DATA SHEET FortiGate 600E SeriesFortinet Security FabricSecurity FabricThe Security Fabric is the cybersecurity platform that enables digitalinnovations. It delivers broad visibility of the entire attack surface tobetter manage risk. Its unified and integrated solution reduces thecomplexity of supporting multiple-point products, while automatedworkflows increase operational speeds and reduce response timesacross the Fortinet deployment ecosystem. The Fortinet SecurityFabric overs the following key areas under a single managementcenter:§ Security-Driven Networking that secures, accelerates, andunifies the network and user experience§ Zero Trust Network Access that identifies and secures usersand devices in real-time, on and off of the network§ Dynamic Cloud Security that protects and controls cloudinfrastructures and applications§ AI-Driven Security Operations that automatically prevents,detects, isolates, and responds to cyber threatsFortiOSFortiGates are the foundation of the Fortinet Security Fabric—the§ Control thousands of applications, block the latest exploits, andcore is FortiOS. All security and networking capabilities across thefilter web traffic based on millions of real-time URL ratings inentire FortiGate platform are controlled with one intuitive operatingaddition to true TLS 1.3 support.system. FortiOS reduces complexity, costs, and response times by§ Automatically prevent, detect, and mitigate advanced attackstruly consolidating next-generation security products and serviceswithin minutes with an integrated AI-driven security and advancedinto one platform.§ A truly consolidated platform with a single OS and pane-of-glassfor across the entire digital attack surface.§ Industry-leading protection: NSS Labs Recommended, VB100,AV Comparatives, and ICSA validated security and performance.§ Leverage the latest technologies such as deception-basedthreat protection.§ Improve and unify the user experience with innovative SD-WANcapabilities with the ability to detect, contain, and isolate threatswith automated segmentation.§ Utilize SPU hardware acceleration to boost network securityperformance.security.ServicesFortiGuard Security ServicesFortiCare Support ServicesFortiGuard Labs offer real-time intelligence on the threat landscape,Our FortiCare customer support team provides global technicaldelivering comprehensive security updates across the full rangesupport for all Fortinet products. With support staff in the Americas,of Fortinet’s solutions. Comprised of security threat researchers,Europe, Middle East, and Asia, FortiCare offers services to meet theengineers, and forensic specialists, the team collaborates with theneeds of enterprises of all sizes.world’s leading threat monitoring organizations and other networkand security vendors, as well as law enforcement agencies.4For more information, please refer to forti.net/fortiguardand forti.net/forticare

DATA SHEET FortiGate 600E SeriesSpecificationsFORTIGATE 600EFORTIGATE 600EFORTIGATE 601E10 GE SFP Slots2Height x Width x Length (inches)GE RJ45 Interfaces8Height x Width x Length (mm)GE SFP Slots8WeightGE RJ45 Management Ports2Form Factor (supports EIA / non-EIA standards)USB Ports2Power Consumption (Average / Maximum)RJ45 Console Port1Power SourceLocal StorageIncluded Transceivers–2x 240 GB SSD2x SFP (SX 1 GE)10 GbpsOperating Environment and CertificationsOperating Temperature36 / 36 / 27 GbpsIPv6 Firewall Throughput(1518 / 512 / 64 byte, UDP)36 / 36 / 27 GbpsFirewall Latency (64 byte, UDP)Firewall Throughput (Packet per Second)2 μs8 MillionNew Sessions/Second (TCP)450,000Firewall Policies10,000IPsec VPN Throughput (512 byte) 120 GbpsGateway-to-Gateway IPsec VPN Tunnels2,000Client-to-Gateway IPsec VPN Tunnels50,000SSL-VPN Throughput7 GbpsConcurrent SSL-VPN Users(Recommended Maximum, Tunnel Mode)10,000SSL Inspection Throughput (IPS, avg. HTTPS) 38 Gbps800,000Application Control Throughput (HTTP 64K) 215 GbpsCAPWAP Throughput (HTTP 64K)18 GbpsVirtual Domains (Default / Maximum)10 / 10Maximum Number of FortiSwitches Supported96Maximum Number of FortiAPs (Total / Tunnel)1,024 / 512High Availability Configurations32–104 F (0–40 C)Storage Temperature-31–158 F (-35–70 C)Humidity10–90% non-condensingNoise LevelOperating Altitude59 dBAUp to 9,843 ft (3,000 m)ComplianceFCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CBCertificationsICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN;USGv6/IPv65,500SSL Inspection Concurrent Session(IPS, avg. HTTPS) 3Maximum Number of FortiTokensoptional40.5 MppsConcurrent Sessions (TCP)SSL Inspection CPS (IPS, avg. HTTPS) 3129 W / 244 W100–240V 50–60Hz832 BTU/h9.5 GbpsIPv4 Firewall Throughput(1518 / 512 / 64 byte, UDP)16.6 lbs (7.5 kg)Rack Mount, 1 RU6A @ 100VNGFW Throughput 2, 4System Performance and Capacity44.45 x 432 x 38016.1 lbs (7.3 kg)Heat DissipationIPS Throughput 27 Gbps1.75 x 17.0 x 15.0Current (Maximum)Redundant Power Supplies (Hot Swappable)System Performance — Enterprise Traffic MixThreat Protection Throughput 2, 5FORTIGATE 601EDimensions and PowerInterfaces and Modules5,000Active-Active, Active-Passive, ClusteringNote: All performance values are “up to” and vary depending on system configuration.1. IPsec VPN performance test uses AES256-SHA256.2. IPS (Enterprise Mix), Application Control, NGFW, and Threat Protection are measured with Logging enabled.3. SSL Inspection performance values use an average of HTTPS sessions of different cipher suites.4. NGFW performance is measured with Firewall, IPS, and Application Control enabled.5. Threat Protection performance is measured with Firewall, IPS, Application Control, and MalwareProtection enabled.5

DATA SHEET FortiGate 600E SeriesOrder InformationProductSKUDescriptionFortiGate 600EFG-600E2x 10 GE SFP slots, 10x GE RJ45 ports (including 1x MGMT port, 1x HA port, 8x switch ports), 8x GE SFP slots,SPU NP6 and CP9 hardware accelerated.FortiGate 601EFG-601E2x 10 GE SFP slots, 10x GE RJ45 ports (including 1x MGMT port, 1x HA port, 8x switch ports), 8x GE SFP slots,SPU NP6 and CP9 hardware accelerated, 2x 240 GB onboard SSD storage.1 GE SFP LX Transceiver ModuleFG-TRAN-LX1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP RJ45 Transceiver ModuleFG-TRAN-GC1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP SX Transceiver ModuleFG-TRAN-SX1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP slots.10 GE SFP Transceiver Module, Short RangeFG-TRAN-SFP SR10 GE SFP transceiver module, short range for all systems with SFP and SFP/SFP slots10 GE SFP Transceiver Module, Long RangeFG-TRAN-SFP LR10 GE SFP transceiver module, long range for all systems with SFP and SFP/SFP slots10 GE Copper SFP Transceiver Module, up to 30mFS-TRAN-SFP GC10 GE copper SFP RJ45 transceiver. For FortiSwitch only, up to 30m.10 GE SFP Active Direct Attach Cable, 10m / 32.8 ftSP-CABLE-ADASFP 10 GE SFP active direct attach cable, 10m / 32.8 ft for all systems with SFP and SFP/SFP slotsOptional Power SupplySP-FG300E-PSAC power supply for FG-300/301E, FG-400/401E, FG-500/501E, FG-600/601E, FAZ-200F/300F/800F and FMG-200F/300F.Optional AccessoriesBundlesFortiGuardBundleFortiGuard Labs delivers anumber of security intelligenceservices to augment theFortiGate firewall platform.You can easily optimize theprotection capabilities of yourFortiGate with one of theseFortiGuard ified ThreatProtectionThreatProtectionFortiCareASE 124x724x724x7FortiGuard App Control Service FortiGuard IPS Service FortiGuard Advanced Malware Protection (AMP) — Antivirus, Mobile Malware,Botnet, CDR, Virus Outbreak Protection and FortiSandbox Cloud Service FortiGuard Web Filtering Service FortiGuard Antispam Service FortiGuard Security Rating Service FortiGuard Industrial Service FortiGuard IoT Detection Service 2 FortiConverter Service IPAM Cloud 2 SD-WAN Orchestrator Entitlement 2 SD-WAN Cloud Assisted Monitoring SD-WAN Overlay Controller VPN Service FortiAnalyzer Cloud FortiManager Cloud 1. 24x7 plus Advanced Services Ticket Handling2. Available when running FortiOS 6.4www.fortinet.comCopyright 2020 Fortinet, Inc. All rights reserved. Fortinet , FortiGate , FortiCare and FortiGuard , and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common lawtrademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other resultsmay vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except tothe extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event,only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests.Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current versionof the publication shall be applicable. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication withoutnotice, and the most current version of the publication shall be applicable.FST-PROD-DS-GT6H2FG-600E-DAT-R10-202004

SSL-VPN Throughput 7 Gbps Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) 10,000 SSL Inspection Throughput (IPS, avg. HTTPS) 3 8 Gbps SSL Inspection CPS (IPS, avg. HTTPS) 3 5,500 SSL Inspection Concurrent Session (IPS, avg. HTTPS) 3 800,000 Application Control Throughput (HTTP 64K) 2 15 Gbps