Enterprises require a high-speed, high-capacity firewall to stay ahead of ever-increasing network performance requirements as well as continued evolution of the threat landscape, at datacenter and campus locations.
Eliminate Security Bottlenecks
With 52 Gbps of firewall throughput and low latency, the FortiGate 1000D represents an excellent entry model for small data centers and delivers a high performance, high capacity data center firewall. IPv6 parity, 10 GE ports and dramatic increases in VPN performance enable you to keep pace with your evolving network.
Deeper Visibility
At the same time, 8 Gbps of next generation threat prevention performance allows you to run top rated intrusion prevention, application control and antimalware capabilities for deeper inspection of content, applications, user and device activity. Rich console views and reports together with a flexible policy engine provide the visibility and control to empower employees yet secure your enterprise.
Breakthrough Performance
This breakthrough performance — including 10x data center and 5x next generation performance — is made possible by custom hardware, including the latest FortiASIC™ NP6 and CP8 processors, as well as the consolidated security features of the FortiOS network security platform.
Key Features & Benefits | |
---|---|
Superior firewall throughput, ultralow latency | 10x data center firewall performance eliminates performance bottlenecks |
Impressive throughput | 5x next generation performance enables multi-function inspection on one appliance |
Custom FortiASIC NP6 and CP8 processors | The latest in purpose-built processors enable best-in-class performance and superior cost per gigabit protected |
High speed, high density ports | 2x 10 GE and 32x GE ports support evolving network requirements and avoid security bottlenecks |
Top rated security technologies | Increases protection from advanced threats |
Interfaces
By removing the Internal Switch Fabric, the NP Direct architecture provides direct access to the SPU-NP for the lowest latency forwarding. NGFW deployments require some attention to network design to ensure optimal use of this technology.
Fortinet’s new, breakthrough SPU NP6 network processor works inline with FortiOS functions delivering:
The SPU CP8 content processor works outside of the direct flow of traffic, providing high-speed cryptography and content inspection services including:
High speed connectivity is essential for network security segmentation. The FortiGate 1000D provides 10 GE slots that simplify network designs without relying on additional devices to bridge desired connectivity
Control all the security and networking capabilities across the entire FortiGate platform with one intuitive operating system. Reduce operating expenses and save time with a truly consolidated next generation security platform.
FortiGuard Labs offers real-time intelligence on the threat landscape, delivering comprehensive security updates across the full range of Fortinet’s solutions. Comprised of security threat researchers, engineers, and forensic specialists, the team collaborates with the world’s leading threat monitoring organizations, other network and security vendors, as well as law enforcement agencies:
Our FortiCare customer support team provides global technical support for all Fortinet products. With support staff in the Americas, Europe, Middle East and Asia, FortiCare offers services to meet the needs of enterprises of all sizes:
FortiGuard Labs delivers a number of security intelligence services to augment the FortiGate firewall platform. You can easily optimize the protection capabilities of your FortiGate with the FortiGuard Enterprise Bundle. This bundle contains the full set of FortiGuard security services plus FortiCare service and support offering the most flexibility and broadest range of protection all in one package.
FortiGate deployed as data center core firewall
Data Center Core Firewall
Organizations deploying the NP (Network Processor) 6 powered FortiGate 1000 Series firewalls at their data center will enjoy superior protection and performance with industryleading, high capacity firewall technologies that deliver exceptional throughput and ultra-low latency, enabling the security, flexibility, scalability and manageability expected on a core platform. These firewalls come with numerous high-speed 40 GE and 10 GE interfaces which are ideal for segmenting network physically. Running on the latest FortiOS, these platform are virtualization and cloud-ready. They support next-generation data center architectures, multi-tenant requirements, provide APIs for rapid orchestration and easy integration with third-party ecosystems.
Mid-Enterprise Edge Firewall
Fortinet’s FortiGate 1000 Series firewalls are perfect for growing large enterprises with their agile and high performance network security capabilities. These FortiGates not only deliver protection exceeding expectations, they are suitable for consolidating other security components. This allows organizations to significantly reduce TCOs and simplifies the network. Unlike other NGFWs (Next Generation Firewalls), the FortiGates are powered by FortiASICs which provide security without compromises performance. They run on the World’s most advanced security operating systems that meet each organizations unique requirements. Advanced features such as integrated endpoint control and token server helps organizations to rapidly deploy enhanced security to their mobile workforce while device-based policies aid to implement BYOD securely. FortiGate deployed as data center core firewall FortiGate deployed.
FortiGate deployed as mid-enterprise edge firewall
FortiGate 1000D Specifications | |
---|---|
Interfaces and modules | |
Hardware Accelerated GE/10 GE SFP/SFP+ Slots | 2 |
Hardware Accelerated GE SFP Slots | 16 |
Hardware Accelerated GE RJ45 Ports | 16 |
GE RJ45 Management / HA Ports | 2 |
USB Ports (Client / Server) | 1 / 2 |
Console Port | 1 |
Onboard Storage | 256 GB |
Included Transceivers | 0 |
System performance and capacity | |
IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 52 / 52 / 33 Gbps |
IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) | 52 / 52 / 33 Gbps |
Firewall Latency (64 byte, UDP) | 3 μs |
Firewall Throughput (Packet per Second) | 49.5 Mpps |
Concurrent Sessions (TCP) | 11 Mil |
New Sessions per Second (TCP) | 280,000 |
Firewall Policies | 100,000 |
IPsec VPN Throughput (512 byte) | 25 Gbps |
Gateway-to-Gateway IPsec VPN Tunnels | 20,000 |
Client-to-Gateway IPsec VPN Tunnels | 50,000 |
SSL-VPN Throughput | 3.6 Gbps |
Concurrent SSL-VPN Users (Recommended Maximum) | 10,000 |
IPS Throughput (HTTP / Enterprise Mix) 1 | 8 / 4.2 Gbps |
SSL Inspection Throughput 2 | 4 Gbps |
Application Control Throughput 3 | 8 Gbps |
NGFW Throughput 4 | 5 Gbps |
Threat Protection Throughput 5 | 3 Gbps |
CAPWAP Throughput 6 | 11 Gbps |
Virtual Domains (Default / Maximum) | 10 / 250 |
Maximum Number of FortiAPs (Total / Tunnel) | 4,096 / 1,024 |
Maximum Number of FortiTokens | 5,000 |
Maximum Number of Registered Endpoints | 8,000 |
High Availability Configurations | Active-Active, Active-Passive, Clustering |
Dimensions and power | |
Height x Width x Length (inches) | 3.48 x 17.20 x 17.95 |
Height x Width x Length (mm) | 88.5 x 437 x 456 |
Weight | 24.70 lbs (11.20 kg) |
Form Factor | Rack Mount, 2 RU |
AC Power Supply | 100–240V AC, 50–60 Hz |
Power Consumption (Average / Maximum) | 153 W / 220.8 W |
Current (Maximum) | 100V / 5A, 240V / 3A |
Heat Dissipation | 753.40 BTU/h |
Redundant Power Supplies | Yes, Hot swappable |
Operating environment and certifications | |
Operating Temperature | 32–104°F (0–40°C) |
Storage Temperature | -31–158°F (-35–70°C) |
Humidity | 20–90% non-condensing |
Operating Altitude | Up to 7,400 ft (2,250 m) |
Compliance | FCC Part 15 Class A, C-Tick, VCCI, CE, UL/cUL, CB |
Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 |
Note: All performance values are “up to” and vary depending on system configuration. IPsec VPN performance is based on 512 byte UDP packets using AES-256+SHA1.
1. IPS performance is measured using 1 Mbyte HTTP and Enterprise Traffic Mix.
2. SSL Inspection is measured with IPS enabled and HTTP traffic, using TLS v1.2 with AES256-SHA.
3. Application Control performance is measured with 64 Kbytes HTTP traffic.
4. NGFW performance is measured with IPS and Application Control enabled, based on Enterprise Traffic Mix.
5. Threat Protection performance is measured with IPS and Application Control and Malware protection enabled, based on Enterprise Traffic Mix.
6. CAPWAP performance is based on 1444 byte UDP packets.
* Maximum loading on each PoE/+ port is 30 W (802.3at).
Download the Fortinet FortiGate 1000D Data Sheet (PDF).
Licença | FortiGate 1000D Enterprise Protection | |
---|---|
1 ano – FortiGate-1000D 1 Year Enterprise Protection (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam, Security Rating, IoT Detection, Industrial Security, FortiConverter Svc, and FortiCare Premium) | #FC-10-01006-811-02-12 |
Licença | FortiGate 1000D Unified Threat Protection (UTP) | |
1 ano – FortiGate-1000D 1 Year Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium) | #FC-10-01006-950-02-12 |
Licença | FortiGate 1000D FortiCare Premium Support | |
1 ano – FortiGate-1000D 1 Year FortiCare Premium Support | #FC-10-01006-247-02-12 |
Licença | FortiGate 1000D FortiCare Elite Support | |
1 ano – FortiGate-1000D 1 Year FortiCare Elite Support | #FC-10-01006-284-02-12 |
Licença | FortiGate-1000D Upgrade FortiCare Premium to Elite | |
1 ano – FortiGate-1000D 1 Year Upgrade FortiCare Premium to Elite (Require FortiCare Premium) | #FC-10-01006-204-02-12 |
Licença | FortiGate 1000D Advanced Threat Protection | |
1 ano – FortiGate-1000D 1 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) | #FC-10-01006-928-02-12 |
Licença | FortiGate 1000D Services | |
1 ano – FortiGate-1000D 1 Year Advanced Malware Protection (AMP) including Antivirus, Mobile Malware and FortiGate Cloud Sandbox Service | #FC-10-01006-100-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard IPS Service | #FC-10-01006-108-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard URL, DNS & Video Filtering Service | #FC-10-01006-112-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard Industrial Security Service | #FC-10-01006-159-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard Security Rating Service | #FC-10-01006-175-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard IoT Detection Service | #FC-10-01006-231-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard SD-WAN Underlay Bandwidth and Quality Monitoring Service | #FC-10-01006-288-02-12 |
1 ano – FortiGate-1000D 1 Year FortiAnalyzer Cloud with SOCaaS: cloud-based central logging & analytics. Include all FortiGate log types, IOC Service, Security Automation Service, FortiGuard Outbreak Detection Service and SOCaaS | #FC-10-01006-464-02-12 |
1 ano – FortiGate-1000D 1 Year FortiConverter Service for one time configuration conversion service | #FC-10-01006-189-02-12 |
1 ano – FortiGate-1000D 1 Year FortiGuard AI-based Inline Sandbox Service | #FC-10-01006-577-02-12 |
1 ano – FortiGate-1000D 1 Year FortiAnalyzer Cloud: cloud-Based central logging & analytics. Include All FortiGate log types, IOC Service, Security Automation Service and FortiGuard Outbreak Detection Service. | #FC-10-01006-585-02-12 |
Licença | FortiGate Cloud | |
1 ano – FortiGate-1000D 1 Year FortiGate Cloud Management, Analysis and 1 Year Log Retention | #FC-10-01006-131-02-12 |
1 ano – FortiGate Cloud / FortiLAN Cloud – 1 Year MultiTenancy Account | #FCLE-10-FCLD0-161-02-12 |
1 ano – Enables zero touch bulk provisioning for your FortiGate, FortiWifi, or FortiAP products. | #FDP-SINGLE-USE |
Licença | FortiGate-1000D Managed FortiGate service, available 24×7, with Fortinet NOC experts performing device setup, network, and policy change management | |
FortiGate-1000D 1 Year Managed FortiGate service, available 24×7, with Fortinet NOC experts performing device setup, network, and policy change management | #FC-10-01006-660-02-12 |