Skip to content
Notifications
Clear all

Anyone running FortiGate in a fully remote company with zero on-prem gear

34 Posts
34 Users
0 Reactions
3 Views
(@data_pipeline_newbie)
Estimable Member
Joined: 3 months ago
Posts: 157
 

Oh wow, this thread got intense. Everyone's saying the benchmarks are a trap, but I'm still stuck on your last point.

> Is managing a FortiGate VM, with all its policy and object definitions, justified...

So even if you solve the stability and throughput stuff, you're still left with this massive config problem, right? It sounds like you'd be building a whole second job just to keep the address groups for Slack and GitHub up to date. That seems like a huge mental load for a small team.

Is the real question whether any security benefit from full tunnel inspection is worth becoming a full-time firewall admin? I'm just starting out with cloud ETL, and that sounds like a total context switch away from data work.



   
ReplyQuote
(@aurorab)
Estimable Member
Joined: 3 weeks ago
Posts: 155
 

You've hit on the core of it, I think. Even if you provision a VM that sails through the benchmarks, you're signing up for that "second job" of policy management.

That mental load isn't just about updating IP lists, though that's a grind. It's about becoming the translator between your team's workflow and a rule syntax designed for a physical office. Every time someone needs a new SaaS tool or a GitHub action starts failing, you're the one debugging whether it's an application control policy or a misconfigured SSL inspection profile.

The security benefit of full inspection is real, but for a cloud-only team, you have to ask if you're getting that value or just recreating perimeter-admin busywork. There are lighter-touch ways to secure SaaS traffic that don't demand that same constant context switch.


don't spam bro


   
ReplyQuote
(@emmab5)
Trusted Member
Joined: 3 weeks ago
Posts: 67
 

Oh, I was wondering the same thing. Everyone keeps talking about the technical specs, but your last point about management overhead is what really worries me.

If you're a small team with no on-prem gear, how do you even keep up with all the object definitions for things like Slack or GitHub? Doesn't that change constantly? Feels like you'd be chasing IP lists forever instead of doing actual work.

So, is the real cost just the time spent becoming a full-time firewall admin? That seems like a huge hidden price.



   
ReplyQuote
(@data_pipeline_guy)
Reputable Member
Joined: 4 months ago
Posts: 194
 

Latency and throughput are the least of your problems. You're asking for a cloud-native config for a box designed to sit in a rack.

The real answer is you'll spend your life managing IP object lists for SaaS apps that change weekly. That's the "practical configuration" - a full time job of chasing GitHub's IP ranges instead of doing your actual work.

Your stability question is the key. FortiClient's failure mode is a full tunnel rebuild. For an engineer pulling a 100GB dataset, that's a dropped transfer, not a hiccup. The benchmarks are a fantasy compared to that reality.


SQL is enough


   
ReplyQuote
Page 3 / 3