Transcription

DATA SHEETFortiGate 100F SeriesNext Generation FirewallSecure SD-WANSecure Web GatewayFG-100F and FG-101FThe FortiGate 100F series provides an application-centric, scalable, and secure SD-WANsolution with Next Generation Firewall (NGFW) capabilities for mid-sized to large enterprisesdeployed at the campus or branch level. Protects against cyber threats with system-on-a-chipacceleration and industry-leading secure SD-WAN in a simple, affordable, and easy to deploysolution. Fortinet’s Security-Driven Networking approach provides tight integration of thenetwork to the new generation of security.Securityn Identifies thousands of applications inside network trafficfor deep inspection and granular policy enforcementnnProtects against malware, exploits, and maliciouswebsites in both encrypted and non-encrypted trafficPrevent and detect against known and unknown attacksusing continuous threat intelligence from AI-poweredFortiGuard Labs security servicesPerformancen Delivers industry’s best threat protection performance andultra-low latency using purpose-built security processor(SPU) technologynProvides industry-leading performance and protection forSSL encrypted trafficCertificationn Independently tested and validated best securityeffectiveness and performancenReceived unparalleled third-party certifications from NSSLabsNetworkingn Delivers advanced networking capabilities that seamlesslyintegrate with advanced layer 7 security and virtualdomains (VDOMs) to offer extensive deploymentflexibility, multi-tenancy and effective utilization ofresourcesnDelivers high-density, flexible combination of varioushigh-speed interfaces to enable best TCO for customersfor data center and WAN deploymentsManagementn Includes a management console that is effective, simpleto use, and provides comprehensive network automationand visibility.nnProvides Zero Touch Integration with Security Fabric’sSingle Pane of Glass ManagementPredefined compliance checklist analyzes the deploymentand highlights best practices to improve overall securitypostureSecurity Fabricn Enables Fortinet and Fabric-ready partners’ productsto provide broader visibility, integrated end-to-enddetection, threat intelligence sharing, and automatedremediationFirewallIPSNGFWThreat ProtectionInterfaces20 Gbps2.6 Gbps1.6 Gbps1 GbpsMultiple GE RJ45, GE SFP and 10 GE SFP slotsRefer to specification table for details1

DATA SHEET FortiGate 100F SeriesDEPLOYMENTSecure Web Gateway(SWG) Next GenerationFirewall (NGFW)§ Reduce the complexity and maximizeyour ROI by integrating threatprotection security capabilities intoa single high-performance networksecurity appliance, powered byFortinet’s Security Processing Unit(SPU)§ Full visibility into users, devices, andapplications across the entire attacksurface, and consistent securitypolicy enforcement irrespective ofasset location§ Protect against network exploitablevulnerabilities with industryvalidated IPS that offers low latencyand optimized network performance§ Automatically block threats ondecrypted traffic using the industry’shighest SSL inspection performance,including the latest TLS 1.3standard with mandated ciphers§ Proactively block newly discoveredsophisticated attacks in real-timewith AI-powered FortiGuard Labsand advanced threat protectionservices included in the FortinetSecurity Fabric§ Secure web access from bothinternal and external risks, evenfor encrypted traffic at highperformance§ Enhanced user experience withdynamic web and video caching§ Block and control web access basedon user or user groups across URLsand domains§ Prevent data loss and discover useractivity to known and unknown cloudapplications§ Block DNS requests againstmalicious domains§ Multi-layered advanced protectionagainst zero-day malware threatsdelivered over the webSecure SD-WAN§ Consistent business applicationperformance with accuratedetection, dynamic WAN pathsteering on any best-performingWAN transport§ Accelerated multi-cloud access forfaster SaaS adoption with cloud-onramp§ Self-healing networks with WANedge high availability, sub-secondtraffic switchover-based and realtime bandwidth compute-basedtraffic steering§ Automated overlay tunnels provideencryption and abstracts physicalhybrid WAN making it simple tomanage§ Simplified and intuitive workflow withFortiManger for management andzero touch deployment§ Enhanced analytics both real-timeand historical provides visibility intonetwork performance and identifiesanomaliesWeb ApplicationServers§ Strong security posture with nextgeneration firewall and real- timethreat protectionInternal UserFortiWebWeb Application FirewallFortiGateSWGExternal UserSecure Web Gateway DeploymentFortiSandboxAdvanced ThreatProtectionFortiSwitchSecure AccessSwitchFortiManagerAutomation-DrivenNetwork ManagementFortiAnalyzerAnalytics-poweredSecurity & Log ManagementFortiGateNGFWFortiAPSecure ized Provisioning &Automated Overlay ManagementFortiAnalyzerAnalytics-poweredSecurity & LogManagementFortiAPSecure AccessPointlsneuncTCAMPUS eIPSENTERPRISEBRANCH LSMP FortiGateSecure SD-WANFortiClientEndpoint ProtectionCampus Deployment (NGFW)Enterprise Branch Deployment (Secure SD-WAN)2

DATA SHEET FortiGate 100F SeriesHARDWAREFortiGate 100F/101FFortiGate 101FSTATUSUSBDMZWAN 1HA11357911X113151719MGMTWAN 2HA224681012X214161820345Shared .2.3.4.5.6.7.8.9.1x USB Port1x Console Port2x GE RJ45 MGMT/DMZ Ports2x GE RJ45 WAN Ports2x GE RJ45 HA Ports12x GE RJ45 Ports2x 10 GE SFP FortiLink Slots4x GE SFP Slots4x GE RJ45/SFP Shared Media PairsPowered by Purpose-BuiltSecure SD-WAN ASIC SOC4nnnnn3Combines a RISC-based CPU withFortinet’s proprietary SecurityProcessing Unit (SPU) content and networkprocessors for unmatched performanceDelivers industry’s fastest application identificationand steering for efficient business operationsAccelerates IPsec VPN performance for best userexperience on direct internet accessEnables best of breed NGFW Security and deep SSLinspection with high performanceExtends security to access layer to enable SDBranch transformation with accelerated andintegrated switch and access point connectivity687Hardware FeaturesSOC41UACDUAL/9480GBDual Power SuppliesPower supply redundancy is essential in the operation ofmission-critical networks. The FortiGate 100F Series offersdual built-in non-hot swappable power supplies.Access Layer SecurityFortiLink protocol enables you to converge security andthe network access by integrating the FortiSwitch into theFortiGate as a logical extension of the NGFW. These FortiLinkenabled ports can be reconfigured as regular ports asneeded.

DATA SHEET FortiGate 100F SeriesFORTINET SECURITY FABRICSecurity FabricThe industry’s highest-performing cybersecurity platform,powered by FortiOS, with a rich ecosystem designed tospan the extended digital attack surface, delivering fullyautomated, self-healing network security.Fabric ManagementCenterFabric SecurityOperationsNOCSOC§ Broad: Coordinated detection and enforcement across theentire digital attack surface and lifecycle with convergednetworking and security across edges, clouds, endpoints,and usersAdaptive CloudSecurity§ Integrated: Integrated and unified security, operation,and performance across different technologies, location,deployment options, and the richest ecosystemZero TrustAccessFORTI OS§ Automated: Context aware, self-healing network andsecurity posture leveraging cloud-scale and advanced AIto automatically deliver near-real-time, user-to-applicationcoordinated protection across the FabricThe Fabric empowers organizations of any size to secure andsimplify their hybrid infrastructure on the journey to systemFortiGuardThreat IntelligenceFortiOS Operating SystemFortiOS, Fortinet’s leading operating system enable theconvergence of high performing networking and securityacross the Fortinet Security Fabric delivering consistent andcontext-aware security posture across network endpoint, andclouds. The organically built best of breed capabilities andunified approach allows organizations to run their businesseswithout compromising performance or protection, supportsseamless scalability, and simplifies innovation consumption.The release of FortiOS 7 dramatically expands the FortinetSecurity Fabric’s ability to deliver consistent security acrosshybrid deployment models of Hardware, Software, andSoftware As-a-Service with SASE and ZTNA, among others.SERVICESFortiGuard Security ServicesFortiGuard Labs offer real-time intelligence on the threatlandscape, delivering comprehensive security updates acrossthe full range of Fortinet’s solutions. Comprised of securitythreat researchers, engineers, and forensic specialists, theteam collaborates with the world’s leading threat monitoringorganizations and other network and security vendors, as wellas law enforcement agencies.FortiCare ServicesFortinet is dedicated to helping our customers succeed, andevery year FortiCare services help thousands of organizationsget the most from their Fortinet Security Fabric solution. Wehave more than 1000 experts to help accelerate technologyimplementation, provide reliable assistance through advancedsupport, and offer proactive care to maximize security andperformance of Fortinet deployments.4

DATA SHEET FortiGate 100F SeriesSPECIFICATIONSFORTIGATE 100FFORTIGATE 101FInterfaces and ModulesFORTIGATE 100FDimensions and PowerHardware Accelerated GE RJ45 Ports12Hardware Accelerated GE RJ45Management/ HA/ DMZ PortsHeight x Width x Length (inches)1/2/1Height x Width x Length (mm)WeightHardware Accelerated GE SFP Slots4Hardware Accelerated 10 GE SFP FortiLink Slots (default)2GE RJ45 WAN Ports2GE RJ45 or SFP Shared Ports *4Power Consumption(Average / Maximum)USB Port1Current (Maximum)Console Port1Heat DissipationOnboard StorageIncluded Transceivers0Form Factor(supports EIA/non-EIA standards)AC Power Supply1x 480 GB SSD0System Performance — Enterprise Traffic MixRedundant Power SuppliesOperating Temperature2.6 GbpsStorage TemperatureNGFW Throughput 2, 41.6 GbpsHumidity1 GbpsIPv4 Firewall Throughput(1518 / 512 / 64 byte, UDP)20 / 18 / 10 Gbps4.97 μsFirewall Throughput (Packet per Second)15 MppsConcurrent Sessions (TCP)1.5 MillionFirewall PoliciesIPsec VPN Throughput (512 byte) 1Gateway-to-Gateway IPsec VPN Tunnels2.2 GbpsCAPWAP Throughput (HTTP 64K)15 GbpsHigh Availability Configurations10–90% non-condensing40.4 dBASide to BackUp to 7400 ft (2250 m)FCC Part 15B, Class A, CE, RCM, VCCI,UL/cUL, CB, BSMIICSA Labs: Firewall, IPsec, IPS, Antivirus,SSL-VPN; IPv610 / 1032128 / 645000Active-Active, Active-Passive, Clustering* Copper SFP modules not supportedNote. All performance values are “up to” and vary depending on system configuration.1. IPsec VPN performance test uses AES256-SHA256.2. IPS (Enterprise Mix), Application Control, NGFW and Threat Protection are measured withLogging enabled.3. SSL Inspection performance values use an average of HTTPS sessions of different ciphersuites.5Certifications32–104 F (0–40 C)-31–158 F (-35–70 C)1800Application Control Throughput(HTTP 64K) 2Maximum Number of FortiTokens121.13 BTU/hYes1 Gbps135 000Maximum Number of FortiAPs(Total / Tunnel)100V / 1A, 240V / 0.5A119.77 BTU/h500SSL Inspection Concurrent Session(IPS, avg. HTTPS) 3Maximum Number of FortiSwitchesSupported35.3 W / 39.1 W20001 GbpsVirtual Domains (Default / Maximum)100–240V AC, 50/60 Hz35.1 W / 38.7 W10 000SSL-VPN ThroughputSSL Inspection CPS (IPS, avg. HTTPS) 37.56 lbs (3.43 kg)Rack Mount, 1 RU11.5 Gbps16 000SSL Inspection Throughput(IPS, avg. HTTPS) 37.25 lbs (3.29 kg)56 000Client-to-Gateway IPsec VPN TunnelsConcurrent SSL-VPN Users(Recommended Maximum, Tunnel Mode)Operating AltitudeComplianceFirewall Latency (64 byte, UDP)New Sessions/Second (TCP)Noise LevelForced AirflowSystem Performance and Capacity1.73 x 17 x 1044 x 432 x 254Operating Environment and CertificationsIPS Throughput 2Threat Protection Throughput 2, 5FORTIGATE 101F4. NGFW performance is measured with Firewall, IPS and Application Control enabled.5. Threat Protection performance is measured with Firewall, IPS, Application Control andMalware Protection enabled.

DATA SHEET FortiGate 100F SeriesORDERING INFORMATIONProductSKUDescriptionFortiGate 100FFG-100F22x GE RJ45 ports (including 2x WAN ports, 1x DMZ port, 1x Mgmt port, 2x HA ports, 16x switchports with 4 SFP port shared media), 4 SFP ports, 2x 10 GE SFP FortiLinks, dual power suppliesredundancy.FortiGate 101FFG-101F22x GE RJ45 ports (including 2x WAN ports, 1x DMZ port, 1x Mgmt port, 2x HA ports, 16x switchports with 4 SFP port shared media), 4 SFP ports, 2x 10 GE SFP FortiLinks, 480GB onboardstorage, dual power supplies redundancy.Optional AccessoriesSKUDescription1 GE SFP RJ45 Transceiver ModuleFN-TRAN-GC1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP SX Transceiver ModuleFN-TRAN-SX1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP slots.1 GE SFP LX Transceiver ModuleFN-TRAN-LX1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP slots.10 GE SFP RJ45 Transceiver ModuleFN-TRAN-SFP GC10 GE SFP RJ45 transceiver module for systems with SFP slots.10 GE SFP Transceiver Module, Short RangeFN-TRAN-SFP SR10 GE SFP transceiver module, short range for all systems with SFP and SFP/SFP slots.10 GE SFP Transceiver Module, Long RangeFN-TRAN-SFP LR10 GE SFP transceiver module, long range for all systems with SFP and SFP/SFP slots.10 GE SFP Transceivers, Extended RangeFN-TRAN-SFP ER10 GE SFP transceiver module, extended range for all systems with SFP and SFP/SFP slots.BUNDLESBundlesFortiGuardBundleFortiGuard Labs deliversa number of securityintelligence services toaugment the FortiGatefirewall platform. Youcan easily optimize theprotection capabilities ofyour FortiGate with one ofthese FortiGuard Bundles.FortiCareEnterprise ProtectionUnified Threat ProtectionAdvanced ThreatProtection24x724x724x7FortiGuard App Control Service FortiGuard IPS Service FortiGuard Advanced Malware Protection (AMP) — Antivirus,Mobile Malware, Botnet, CDR, Virus Outbreak Protection andFortiSandbox Cloud Service FortiGuard Web and Video1 Filtering Service FortiGuard Antispam Service FortiGuard Security Rating Service FortiGuard IoT Detection Service FortiGuard Industrial Service FortiConverter Service 1. Available when running FortiOS 7.0www.fortinet.comCopyright 2022 Fortinet, Inc. All rights reserved. Fortinet , FortiGate , FortiCare and FortiGuard , and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other productor company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and otherconditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaserthat expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, anysuch warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwiserevise this publication without notice, and the most current version of the publication shall be applicable.FG-100F-DAT-R26-20220106

IPsec VPN Throughput (512 byte) 1 11.5 Gbps Gateway-to-Gateway IPsec VPN Tunnels 2000 Client-to-Gateway IPsec VPN Tunnels 16 000 SSL-VPN Throughput 1 Gbps Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) 500 SSL Inspection Throughput (IPS, avg. HTTPS) 3 1 Gbps SSL Inspection