Looking at a major migration from legacy MPLS+VPNs to a SASE model. Shortlist is down to Fortinet SASE (using their FortiGate-VM and SWG/ZTNA) and Cato Networks.
I've run PoC labs with both. The vendor datasheets are, predictably, useless. Fortinet claims 10Gbps on an XL VM instance. Cato talks about "unlimited scaling" on their global backbone. Real-world throughput with full security stack enabled (FW, IPS, TLS inspection) is what matters.
Our test results from a 30-day bake-off:
* **Fortinet SASE (FortiGate-VM 4xl on AWS):**
* Advertised: 10Gbps firewall, 3Gbps IPS, 2Gbps TLS Deep Inspection.
* Observed (with our traffic mix: 65% web, 25% internal app traffic, 10% video): ~2.1Gbps with all security services on. Dropped to ~1.7Gbps under sustained load (30 min) as CPU soft lockups occurred.
* TLS inspection is the biggest hit. Configuration below. Had to tune `ipsengine` count.
```
config firewall policy
set inspection-mode flow
set ssl-ssh-profile "deep-inspection"
set ips-sensor "standard"
set logtraffic all
end
```
* **Cato SASE (PoC Socket X-1700 appliance):**
* No per-box throughput specs from Cato. They route traffic to their nearest PoP.
* Observed from our three main regions: Sustained ~1.9Gbps with all security features enabled. Performance was consistent, no drop-off. The bottleneck became our own egress link, not their PoP processing.
The big difference isn't the peak number, it's the architecture. Fortinet's throughput is limited by the capacity of the VM or hardware appliance you deploy at each egress point. Cato's is limited by your pipe into their cloud PoP.
Question for those who have deployed at scale: Are you seeing similar patterns? Specifically:
* For Fortinet SASE, how are you scaling beyond a single VM's limits? Active/active clustering? Does the management plane hold up?
* For Cato, have you hit any unexpected throughput walls during peak hours when the shared PoP is under load?
* Any hard numbers on latency penalty for TLS inspection with 2048-bit certs on each?
I care about operational overhead and predictable performance. Marketing fluff gets ignored. Show me your Grafana dashboards or pipeline load-test logs.
-shift
shift left or go home