Hey everyone! New here, and still trying to get my head around a lot of networking hardware stuff. I mostly live in the data pipeline world (Airflow, SQL, that kind of thing), but I've been tasked with helping spec out a firewall for a new small remote branch office. It's a bit outside my usual wheelhouse, so I'm hoping for some real-world advice.
We're looking at a FortiGate 40F. The datasheet says it can do 500 Mbps with UTP (Unified Threat Protection) enabled. For our branch, that would be more than enough bandwidth, but I'm inherently skeptical of "up to" numbers from my time dealing with data transfer benchmarks. Is hitting that 500 Mbps UTP number realistic in a production environment, or is that more of a best-case, lab-only scenario?
Our setup would be pretty simple: maybe 20-25 users, basic internet traffic, some VPN for connecting back to HQ, and standard security features (AV, IPS, web filtering). No crazy server loads or anything. I just don't want to be the guy who signs off on this and then we're all crawling because the box can't handle the inspection load.
Any of you run 40Fs in a similar small branch? What kind of actual throughput are you seeing with all the security services turned on? Any gotchas or tuning tips to get it perform well?
Thanks in advance for helping a networking rookie out!
-- rookie
rookie
Your skepticism is well founded, coming from a world where benchmarks meet reality. That 500 Mbps UTP number is absolutely a lab-optimized figure, using 64-byte packets, a single synthetic traffic flow, and likely with only a subset of the UTP features cranked to their most performant settings.
In your described environment with 20-25 users, you probably won't hit a hard ceiling at 500, but you also won't see it. Real throughput will depend entirely on the inspection soup you cook up. Deep packet inspection for SSL, full IPS signatures, and aggressive web filtering with categorization lookups will shave a significant chunk off that top-line number. The mix of traffic matters too; a bunch of small, chatty TLS connections from web apps is harder on the CPU than a few large video streams.
I've seen 40Fs handle a 200 Mbps internet pipe for a similar office without breaking a sweat, but that was with a fairly conservative security profile. If your needs are truly basic, you'll be fine. Just don't expect headroom for a future gigabit circuit if you plan to use all the bells and whistles. The datasheet number is a starting point for derating, not a promise.
Trust but verify.