Jump to content

Recommended Posts

Posted

We've recently moved to Exa and were sold a Fortigate 100E on the basis it would be more than capable of handling our requirements as a full UTM device. Since it's installation whenever we turn on deep inspection so we can adequately filter https sites it will crash periodically because the CPU gets maxed out and we lose internet connectivity until we physically restart it. We are on a 200/1000 leased line and I notice on the datasheet for the 100E the capacity of the 100E drops from 7.7Gbps to 190Mbps if SSL inspection is used so I am theorising that in busy times it simply get's overloaded.

 

Has anyone anything similar?

Posted (edited)
We've recently moved to Exa and were sold a Fortigate 100E on the basis it would be more than capable of handling our requirements as a full UTM device. Since it's installation whenever we turn on deep inspection so we can adequately filter https sites it will crash periodically because the CPU gets maxed out and we lose internet connectivity until we physically restart it. We are on a 200/1000 leased line and I notice on the datasheet for the 100E the capacity of the 100E drops from 7.7Gbps to 190Mbps if SSL inspection is used so I am theorising that in busy times it simply get's overloaded.

 

Has anyone anything similar?

 

that's correct it does and only when the wind blows.

 

As a Fortinet Gold MSSP I think we can make fair comment on this. We've been to Fortinets labs in France and tested numerous Fortigate devices to see what you can actually get out of different model variants depending on usage.

 

You can only get that throughput on SSL inspection with near enough everything else turned off. You may wish to try a different firmware revision to see if this helps (sometimes some are a little buggy).

 

Dave

Edited by Dos_Box
  • Thanks 1
Posted
Out of interest, what kind of hardware are they using for those devices? I was under the impression that Fortinet devices used dedicated hardware acceleration for deep packet inspection?

 

Apparently you can only get dedicated hardware acceleration when you use flow-based inspection but when you go to flow based you lose several important features for schools like enforcing safe search, logging keywords and restricting youtube access!

  • Thanks 1
Posted

A 100E ?! I would only consider that on a small site. We run a 200D on a 200 Megabit with all UTM features turned on and it can get quite high on memory and CPU sometimes. You may not have to reboot our older 200B use to do what you are describing and the B was just too under powered. SSH to the box and run the following commands

 

diag sys top-summery

 

then look what is eating up the CPU and get its process ID

 

Then run

 

diag sys kill 15 processid

 

and it should go back to normal operation without having to reboot the whole device.

Posted
Looks like we've got a solution, we are going to fall back to using the fortigate as a firewall only and use Surfprotect Quantum as a filter. It's a shame because the Fortigate is a great unit but it looks as though we would have to go for a 200E / 300D to get the capacity we need in UTM mode.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...