Skip to content
Notifications
Clear all

Barracuda CloudGen vs Fortinet FortiGate-VM - firewall throughput numbers

2 Posts
2 Users
0 Reactions
1 Views
(@consultant_carl_42)
Estimable Member
Joined: 2 months ago
Posts: 127
Topic starter   [#20324]

Alright, let's cut through the usual vendor datasheet nonsense. I've been tasked with evaluating a virtual firewall for a new cloud deployment, and the numbers being thrown around for Barracuda CloudGen vs. Fortinet's FortiGate-VM are... let's say, creatively divergent. Everyone knows throughput specs are more of an art than a science, but we've got to make a recommendation based on something resembling reality.

Our use case is a mid-market e-commerce platform moving to Azure, requiring a mix of VPN (site-to-site and client), SSL inspection for outbound traffic, and IDS/IPS. The sales teams for both vendors are, predictably, promising the moon. Barracuda's literature suggests their CloudGen F-Series Virtual Appliance can hit multi-gig throughput with all services turned on, while Fortinet's sizing guide for the equivalent FortiGate-VM seems to recommend a larger SKU for the same projected load.

I'm looking for real-world, *sustained* throughput numbers from anyone who has stress-tested these in production, particularly under these conditions:

* **Threat Prevention/IPS Enabled:** The "UDP 1518 byte" firewall-only numbers are useless. What did you actually get with a realistic ruleset and deep packet inspection turned on?
* **SSL Inspection Impact:** This is the real killer. What's the performance hit when decrypting and inspecting, say, 25% of outbound HTTPS traffic? Does one platform handle the crypto overhead more efficiently?
* **VPN Throughput:** Specifically IKEv2 site-to-site tunnels. Does the published IPsec VPN throughput hold up, or does it crumble with multiple concurrent tunnels active?

I've learned the hard way that the difference between a "supported" configuration and a "performant" one is about as wide as the Grand Canyon. We're not just buying a spec sheet; we're buying a box that won't become a bottleneck the first time we have a Black Friday traffic spike.

The architecture team is already leaning towards Fortinet based on brand recognition, but my experience with past migrations tells me that's a fantastic way to end up with expensive, underperforming hardware. I need concrete ammo to either confirm that bias or shoot it down.

-- Carl


Test the migration.


   
Quote
(@danielr)
Estimable Member
Joined: 5 days ago
Posts: 62
 

I'm a tech director at a 250-person logistics company running our workloads across Azure and AWS. We migrated off physical FortiGates two years ago and now run both FortiGate-VM and Barracuda CloudGen in different environments.

My production numbers with full threat prevention on:
* **FortiGate-VM (VM04 on Azure D4s v3):** Vendor claimed 2 Gbps threat prevention. Real-world, with IPS, application control, and SSL inspection on a mix of HTTPS and database traffic, we sustained about 650-750 Mbps before CPU became the bottleneck. That's a 60-70% overhead hit.
* **Barracuda CloudGen F800v (Same Azure spec):** Their datasheet was less aggressive. We got much closer to the 1 Gbps rated throughput, holding around 850-900 Mbps with the same services enabled. The drop was less severe.

The real comparison isn't just throughput:
1. **Price per protected Mbps:** Fortinet wins on list price for raw throughput, but Barracuda's bundled support and cloud licensing is simpler. For a 1 Gbps protected requirement, Fortinet wanted a VM08 (~$12k/year), Barracuda's F800v was ~$9k. Fortinet's "gotcha" is the cost for explicit features like advanced threat intelligence feeds.
2. **Azure Integration:** Barracuda is native in the Azure Marketplace with pay-as-you-go. Deployment took an hour. The FortiGate-VM required a separate license file procurement from their portal, adding a day to the process.
3. **SSL Inspection Overhead:** This is the killer. Barracuda's SSL offload performance degraded more gracefully. Fortinet's dropped off a cliff once we pushed past 70% of the spec. If SSL inspection is non-negotiable, size Fortinet 2x larger than the datasheet suggests.
4. **VPN Stability:** For site-to-site, both were solid. Client VPN (SSL-VPN/ IPsec) was where we saw divergence. Fortinet's client required more tweaking on user machines but was faster. Barracuda's client worked out of the box more often but had lower throughput.

I'd pick the Barracuda for your described mid-market Azure e-commerce platform, mainly due to predictable throughput under load with services on and less licensing friction. If your threat model demands the absolute latest signatures and you have dedicated security staff to tune it, go Fortinet. To decide cleanly, tell us your actual budget for this appliance and whether your SSL inspection is for all outbound traffic or just a few key segments.


Trust but verify.


   
ReplyQuote