Skip to content
Notifications
Clear all

What to use instead of Fortinet for a 200-user office?

2 Posts
2 Users
0 Reactions
2 Views
(@latency_lucy_2)
Estimable Member
Joined: 3 months ago
Posts: 53
Topic starter   [#10026]

We're planning a network refresh for our ~200 person office. Currently using a FortiGate 200F, but the renewal is coming up and the pricing is giving us pause. More importantly, we're increasingly cloud-native, and I'm concerned about the appliance model adding latency for our SaaS-heavy traffic.

I've been benchmarking our app performance through the current setup, and the hairpinning for cloud traffic is becoming a measurable bottleneck. We're looking for something that feels more "modern" for a hybrid workforce.

My main criteria:
* **Latency:** Minimizing added milliseconds for internet-bound traffic. Direct cloud access is a priority.
* **Security Posture:** Still need strong firewall, IDS/IPS, and ideally ZTNA capabilities.
* **Management:** Prefer cloud-managed or a significantly simpler on-prem UI.
* **Cost:** Hoping for a better OpEx model than the traditional hardware + hefty subscription.

I'm evaluating a few paths, but would love real-world feedback:

* **Palo Alto Networks:** Their Prisma Access SD-WAN looks interesting, but I've heard the pricing can be even steeper. Anyone have direct performance comparisons for user latency?
* **Cloudflare One:** This is high on my list. The network-as-a-service model seems to align with our traffic patterns. My big question is about the on-ramp for office hardware—what's the recommended edge device, and does it introduce its own processing delay?
* **Zscaler:** Similar to Cloudflare, but I've seen some benchmarks showing higher latency for certain regions. Is their ZIA Private Service truly comparable to an on-prem firewall?
* **A modern firewall from a non-traditional vendor:** Looking at options like Juniper Mist, or even running something like a Palo Alto VM-Series in a colo.

Has anyone made a similar switch for an office of this size? I'm particularly keen on any before/after latency observations or monitoring metrics you tracked. The performance overhead of the security stack is my primary obsession here.


ms matters


   
Quote
(@bench_beast)
Reputable Member
Joined: 1 month ago
Posts: 231
 

Your point about hairpinning latency is key. We moved from a FortiGate 300E to a Zscaler ZIA proxy model for a similar size office. The latency drop for SaaS apps was measurable: 8-12ms average reduction per synthetic transaction test.

Cloudflare One should be high on your list. Their network is fast, but test their client. We had some issues with the always-on ZTNA client on macOS being a resource hog versus their explicit proxy PAC file method.

Palo Alto Prisma Access is good, but the cost was 40% higher for us at that scale. The performance benefit didn't justify the delta.


Benchmarks don't lie.


   
ReplyQuote