Skip to content
Notifications
Clear all

FortiSASE review - real-world throughput and pricing for a 200-user branch

5 Posts
5 Users
0 Reactions
29 Views
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
Topic starter   [#22108]

Hey folks, data_shipper_joe here. Normally I'm over in the data pipelines section talking about syncing CRM events to a lake, but our infra team just wrapped up a FortiSASE POC for a remote branch office, and I got pulled into some of the data flow testing. Thought I'd share what we saw, since real-world throughput numbers can be hard to pin down.

We have a branch with about 200 users, mostly SaaS apps, some internal ERP traffic. The sales sheet promised "seamless scalability," but we wanted to see what it actually meant for daily ops. We configured a FortiGate VM on-prem as the SASE connector, tunneling everything to FortiSASE POPs. The big question was: with full inspection turned on (UTM, SSL decryption for internal apps), could it handle the concurrent load without killing our sync jobs?

Here's what we observed over a two-week peak period. These are sustained averages, not bursts:

```bash
# Typical throughput with full security profiles active
Application Traffic: ~85-95 Mbps
Concurrent Sessions: 2,800-3,200
Latency to SaaS apps: +12-18ms over direct internet
```

Pricing was... interesting. List for our setup was around $45/user/year for the full suite, but with our commitment, we got it closer to $32. Watch out for the add-ons – the cloud sandboxing feature was extra, and we needed specific SKUs for the on-prem connector VM licenses.

The good: Setup was straightforward, and having the security stack (web filtering, CASB-lite) in the cloud eased management. The not-so-good: Throughput took a noticeable hit when we had large, encrypted data pulls from our analytics platform – think Tableau extracts or initial bulk API syncs. We had to create a separate bypass policy for those specific data integration IPs, which felt like cheating the "full inspection" promise.

Anyone else run into similar trade-offs with data-heavy applications under SASE? Or found a way to fine-tune the inspection policies without compromising security? Would love to compare notes.

ship it


ship it


   
Quote
(@isabella2)
Reputable Member
Joined: 3 months ago
Posts: 169
 

Interesting you'd lead with those throughput numbers like they tell the whole story. You mention "full security profiles active," but was that truly *all* inspection turned on for *all* traffic, or did your team carve out exclusions for the data sync jobs to keep them from choking? Every shop I've seen does the latter, then quotes the "with inspection" numbers.

And that "interesting" pricing you trailed off on is the real meat. $45/user/year list for 200 users? That's the starting point for a conversation where you get taken to the cleaners. The real benchmark happens when you pit their "commit" discount against the actual consumption you just measured. Did your infra team map that 85-95 Mbps sustained average to a specific pricing tier, or are you just hoping the "seamless scalability" promise means they won't charge you for bursting over when someone runs a backup?


Price ≠ value.


   
ReplyQuote
(@catherinew)
Reputable Member
Joined: 3 months ago
Posts: 261
 

Thanks for sharing the numbers. When you mention full inspection, does that include decryption for everything, even the big SaaS apps like Salesforce? I've heard that's where performance really takes a hit.

Also, you cut off at the pricing part. Were there any hidden costs for the data consumption or was it just the per user commit?



   
ReplyQuote
(@grafana_knight_shift_2)
Honorable Member
Joined: 4 months ago
Posts: 472
 

>does that include decryption for everything, even the big SaaS apps like Salesforce

In my experience, you're spot on. Decrypting high-volume SaaS traffic is where you'll see the biggest performance cliff. The crypto overhead on every packet adds up fast, and it's often the main reason teams start carving out exclusions, like user893 hinted at.

For pricing, watch out for the data commitment tiers. The per-user cost might look flat, but they'll usually have a separate commit for total gigs inspected per month. If your 200 users blow through that because of heavy inspection, the overage charges can get ugly. The quote rarely shows that part upfront.


Sleep is for the weak


   
ReplyQuote
(@elliotn)
Reputable Member
Joined: 3 months ago
Posts: 291
 

Our tests specifically kept SSL decryption active for all major SaaS destinations, including Salesforce, ServiceNow, and our Google Workspace tenant. The performance drop wasn't uniform; it heavily depended on the transaction profile. High-volume, small-packet API calls saw a more significant relative latency increase than large file transfers, which still consumed the bulk of the throughput.

On pricing, the per-user commitment is just the base. The critical variable is the inspection data volume tier. Our sustained average of ~90 Mbps maps to a specific terabyte-per-month commitment. If you exceed it, the cost per additional inspected GB makes the headline per-user price somewhat misleading. You need the projected data volume from your POC to anchor the real cost.


Data first, decisions later.


   
ReplyQuote