Proven Carrier-Grade Network Service (CGN) Solution
The FortiCarrier series has long provided iron-clad security services in many service provider and large enterprise networks. The new FortiCarrier 3000 E-Series focuses on the Carrier-Grade IPv4/v6 Network services, based on the same familiar interface and proven carrier-grade reliability of the FortiCarrier OS.
Coupled with a new architecture that is designed specifically for mobile deployments, the new FortiCarrier 3000 E-Series brings high predictability and service-level consistency to environments that generate massive amounts of connection set-ups and tear-downs. Thanks to Fortinet’s powerful Security Processing Unit (SPU) XP, FortiCarrier 3000 E-Series leads the industry in high-scalability (450 million concurrent sessions) and high-performance (160 Gbps) in a single CGN appliance.
Transparent Connectivity Service for the All-Connected World
The explosive growth of mobile devices and cloud services has created massive networks with no boundaries. To compound the issue, the recent global depletion of public IPv4 addresses strains the existing IPv4 infrastructures and increases the demand for Carrier-Grade Network IPv4 (CG-NAT) services.
Our new FortiCarrier 3000 E-Series fills that requirement with purpose-built Carrier-Grade IPv4/v6 Network service appliances. The platform’s advanced architecture comes with the industry’s largest concurrent connection scale designed to meet the most demanding requirements of IPv4 BYOD roll-outs and tomorrow’s IPv6 IoT expansions of large carrier networks.
FortiCarrier CG-NAT and IPv6 migration service is:
Powered by Fortinet’s high-performance security processors (SPU XP2)
Based on highly-effective and extensible security operating system
Built for operational efficiency and the lowest TCO
Available in two models: FCR-3600E (10 GE) and FCR-3800E (100 GE)
Key Features & Benefits
High Performance in Three Dimensions
Specialized architecture designed for the most demanding IPv4/ v6 mobile network expansions that require massive connection scalability, high forwarding capacity and powerful processor to stabilize core networks from frequent signaling surges.
Reduces Upgrade Churns
Comprehensive Carrier-Grade NAT (NAT44, NAT444) options to meet any legacy IPv4 network upgrade requirements. A broad range of advanced IPv6 Migration technologies are included.
Lowest Total Cost of Ownership
The three-dimensional high-performances combined with the rich feature set in CG-NAT and IPv6 migration technologies enable FortiCarrier 3000 E-Series to offer the lowest total cost of ownership (TCO) of any CGN appliances in the market.
NAT and Session Setup
Fixed/deterministic NAT: private IP to public IP mapping and/or port range mapping
Port block allocation (PBA) mode for lower logging overhead and higher cps rate
Single port allocation (SPA) mode for better port resource sharing
Full cone NAT (EIM/EIF) support
Hairpinning support § User quota control on port resource usage
User quota control on max concurrent session count
Source port preservation pool for special applications
Essential service pool enables better user experience
Resource Pool Management
Software assisted IP selection for dynamic NAT: round robin or random
Session Handling
Per application time-out control
ICMP translation
GRE/PPTP/L2TP translation
IP fragment translation
IP fragments are first defragmented and then translated
Application Layer Gateway support (FTP/TFTP/SIP/MGCP/ PPTP/L2TP/ICMP Error/IP-options)
Logging on NAT mapping or every session
Two logs per mapping/session
Support up to 16 logging servers with hash-based load balance
Syslog over UDP
NetFlow v9 or IPFIX over UDP
Customized template can be supported with advance notice
HA clustering: active/passive mode with hardware-based NAT/ session sync
IPv6 Support and Transition
IPv6 Network address translation support including NAT66, NAT64 and DNS64 (DNS proxy) and NAT46
IPv6 firewall policies
IPv6 in dynamic routing including RIPng and BGP
Dual stack routing
IPv6 Tunneling
SIP over IPv6
DHCPv6, ICMPv6 and IPv6 IPsec VPN
CPU to handle the IPv6 traffic
Mobile Service Providers
The FortiCarrier 3000 E-Series CGN provides two critical functions for mobile broadband services. The architecture’s high scalability can be used to generate more revenue by expanding the subscriber base and the associated IP address infrastructure capacity, from a single internet-facing IP address into hundreds of thousands more private IP addresses.
Additionally, a deployment of the CGN appliance on the Gi/sGi interface also enhances the overall network security by hiding the subscribers’ IP addresses from the internet.
CGN Deployment in Mobile Service Provider Networks
Enterprise or Managed Service Providers
The comprehensive IPv4 and IPv6 feature sets allow FortiCarrier 3000 E-Series CGN to provide maximum deployment flexibility. Broad options of tunneling and encapsulation of IPv4 and IPv6 technologies are available to seamlessly connect any type of IP clients into any type of IP networks and finally to any internet content.
The accompanying diagram shows a typical use case — starting with the expansion of an existing IPv4 network and followed by the introduction of a new IPv6 network. Using different IPv4 and IPv6 transition technologies, both new native IPv6 and IPv4 clients can coexist.
To completely secure the mobile Evolved Packet Core, Fortinet recommends a complementary FortiGate with the FortiOS-Carrier license to be deployed as a Gi/sGi firewall. The same FortiGate can perform a secondary function as a RAN Security gateway to aggregate advanced mobile protocols, such as GTP, SCTP and IPsec.
CGN Deployment in Enterprise or Managed Service Provider Networks
Assinatura 8×5 dos serviços de Proteção UTM, Suporte Avançado do Fabricante, Garantia e Substituição de Hardware, Atualizações e Upgrades de Firmware, VPN, Gerenciamento de Tráfego, Conjunto de Serviços UTM, Controle de Aplicações, Detecção e Prevenção de Intrusos, Antivirus, Controle de Acesso aos Sites, Proteção de Dispositivos Móveis (Application Control, IPS, AV, Botnet IP/Domain, Mobile Malware Service, Web Filtering, Antispam, FortiSandbox Cloud including Virus Outbreak and Content Disarm & Reconstruct Services)
1 Ano – FortiGate-30E 1 Year Unified (UTM) Protection (8×5 FortiCare plus Application Control, IPS, AV, Web Filtering and Antispam, FortiSandbox Cloud)
3 Anos – FortiGate-30E 3 Year Unified (UTM) Protection (8×5 FortiCare plus Application Control, IPS, AV, Web Filtering and Antispam, FortiSandbox Cloud)
5 Anos – FortiGate-30E 5 Year Unified (UTM) Protection (8×5 FortiCare plus Application Control, IPS, AV, Web Filtering and Antispam, FortiSandbox Cloud)
Assinatura 24×7 dos serviços de Proteção UTM, Suporte Abrangente do Fabricante, Garantia e Substituição de Hardware no próximo dia útil (NBD), Atualizações e Upgrades de Firmware, VPN, Gerenciamento de Tráfego, Conjunto de Serviços UTM, Controle de Aplicações, Detecção e Prevenção de Intrusos, Antivirus, Controle de Acesso aos Sites, Proteção de Dispositivos Móveis (Application Control, IPS, AV, Botnet IP/Domain, Mobile Malware Service, Web Filtering, Antispam, FortiSandbox Cloud including Virus Outbreak and Content Disarm & Reconstruct Services)
1 Ano – FortiGate-30E 1 Year Unified (UTM) Protection (24×7 FortiCare plus Application Control, IPS, AV, Web Filtering and Antispam, FortiSandbox Cloud)
3 Anos – FortiGate-30E 3 Year Unified (UTM) Protection (24×7 FortiCare plus Application Control, IPS, AV, Web Filtering and Antispam, FortiSandbox Cloud)
5 Anos – FortiGate-30E 5 Year Unified (UTM) Protection (24×7 FortiCare plus Application Control, IPS, AV, Web Filtering and Antispam, FortiSandbox Cloud)
Serviços de Suporte 8×5 com Garantia e Substituição de Hardware, Atualizações e Upgrades de Firmware, VPN e Gerenciamento de Tráfego
5 Anos – FortiGate-30E 5 Year 8×5 FortiCare Contract
Serviços de Suporte 24×7 com Garantia e Substituição de Hardware no próximo dia útil (NBD), Atualizações e Upgrades de Firmware, VPN e Gerenciamento de Tráfego
5 Anos – FortiGate-30E 5 Year 24×7 FortiCare Contract
Assinatura dos Serviços de Nuvem Fortinet para Gerenciamento, Administração e Análise de Relatórios FortiCloud, além da retenção de Logs de seu Firewall por 1 Ano e Backup das Configurações na Nuvem. A retenção de até 7 dias de Log está disponível para degustação/trial para todos os clientes e equipamentos FortiGate.
5 Anos – FortiGate-30E 5 Year FortiCloud Management, Analysis and 1 Year Log Retention
*** Importante, o período de retenção de Logs é sempre 1 Ano, mesmo ao adquirir 3 ou 5 anos de Gerenciamento e Administração FortiCloud, após o primeiro ano os registros/Logs mais antigos são eliminados a medida que novos são gerados. ***
Precisa comprar, renovar licença, instalar ou migrar seu equipamento ? Planejamos sua aquisição, instalação, implantação ou migração, para mais informações faça contato com a TND Brasil através do telefone (11) 3717-5537 , e-mail [email protected] ou envie uma mensagem.
Este site usa cookies para que possamos oferecer a melhor experiência de usuário possível. As informações dos cookies são armazenadas em seu navegador e executam funções como reconhecê-lo quando você retorna ao nosso site e ajudar nossa equipe a entender quais seções do site você considera mais interessantes e úteis.
Cookies estritamente necessários
O cookie estritamente necessário deve estar sempre ativado para que possamos salvar suas preferências de configuração de cookies.
Se você desabilitar este cookie, não poderemos salvar suas preferências. Isso significa que toda vez que você visitar este site, precisará habilitar ou desabilitar os cookies novamente.