Skip to content Skip to navigation Skip to footer

Fortinet Data Center Solution

Protect, Consolidate and Scale with FortiGates

Gartner Critical Capabilities for Network Firewalls

Overview

Securing hybrid and hyperscale data centers remains essential to host business-critical applications and data that can’t be moved to the cloud.

FortiGate Next-Generation Firewalls (NGFWs) protect hybrid data centers with dynamic segmentation and coordinated, automated AI/ML-powered FortiGuard services to enable speed and manage all security risks. They offer industry’s fastest NGFW delivering up to 520 Gbps of threat protection with full visibility and ransomware protection. Powered by purpose-built security processing units, they consolidate tens of millions connections per second and up to 1.9 Tbps firewall performance. This enables you to scale your business to meet escalating user demands.

FortiGate NGFWs for the data center combine industry-leading performance with AI/ML-driven security services from FortiGuard Labs to:

  • Manage risks in hyperscale networks by weaving security deep into hybrid IT architectures. This enables protection of any workload, anywhere, anytime.
  • Protect the entire attack surface with contextual, actionable, coordinated, and fully-automated threat protection.
  • Simplify operations, automate workflows, and save time with easy-to-use, single-pane-of-glass management across the Fortinet Security Fabric and 400+ ecosystem partners.
 

Delivering Enterprise Security with FortiGate Network Firewall

Fortinet NGFWs reduce cost and complexity by eliminating point products and consolidating industry-leading security capabilities. These include secure sockets layer (SSL) inspection (including TLS1.3), web filtering, and intrusion prevention (IPS) to provide full visibility and protection for any edge.

马上观看

View by:

FortiGate: High-end NGFW

Threat Protection(威胁检测)
75 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
70 Gbps
Network Interfaces (网络接口)
Multiple 100 GE/40GE QSFP28, multiple 25GE/10 GE SFP28/SFP+, two 25G SFP28 / 10GE SFP+ HA, multiple 1 GE RJ45
Threat Protection(威胁检测)
45 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
50 Gbps
Network Interfaces (网络接口)
Multiple 100 GE/40GE QSFP28, multiple 25GE/10 GE SFP28/SFP+, two 10GE SFP+ HA, multiple 1 GE RJ45
Threat Protection(威胁检测)
20 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
32 Gbps
Network Interfaces (网络接口)
10x 100GE QSFP28, 16x 10GE SFP+, 2x GE RJ45
Threat Protection(威胁检测)
13.5 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
30 Gbps
Network Interfaces (网络接口)
Multiple 40/100 GE QSFP+/QSFP28, 10 GE SFP+ and GE RJ45
Threat Protection(威胁检测)
13 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
24 Gbps
Network Interfaces (网络接口)
Multiple 40 GE QSFP+, 10 GE SFP+ and GE SFP
Threat Protection(威胁检测)
30 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
34 Gbps
Network Interfaces (网络接口)
6x 100 GE QSFP28, 32x 25 GE SFP28, 2x GE RJ45
Threat Protection(威胁检测)
57 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
64 Gbps
Interfaces
Multiple 25GE/10GE SFP25/SFP+ Multiple 100GE/40GE QSFP28
Threat Protection(威胁检测)
25 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
30 Gbps
Network Interfaces (网络接口)
4x 100 GE QSFP28, 24x 25 GE SFP28, 2x GE RJ45
Threat Protection(威胁检测)
17Gbps
SSL Throughput Inspection
21 Gbps
Network Interfaces (网络接口)
4x 40GE QSFP+, 4x 10GE RJ45, 16x 10GE/25GE SFP+/SFP28, 12x GE RJ45
Threat Protection(威胁检测)
15 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
20 Gbps
Network Interfaces (网络接口)
Multiple GE RJ45 and 10 GE SFP+ / GE SFP slots
Threat Protection(威胁检测)
13 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
22 Gbps
Network Interfaces (网络接口)
Multiple 10 GE SFP+ | Multiple GE SFP and GE RJ45
Threat Protection(威胁检测)
13 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
19 Gbps
Network Interfaces (网络接口)
Multiple 10 GE SFP+ | Multiple GE SFP and GE RJ45
Threat Protection(威胁检测)
17 Gbps
SSL Throughput Inspection
20 Gbps
Network Interfaces (网络接口)
4x 100GE QSFP28, 16x 25GE SFP28 / 10GE SFP+, 16x10GE RJ45
Threat Protection(威胁检测)
5.4 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
11.5 Gbps
Network Interfaces (网络接口)
10x 10GE SFP+, 2x 10GE SFP+ bypass, 34x GE RJ45
Threat Protection(威胁检测)
11 Gbps
SSL Throughput Inspection
17 Gbps
Network Interfaces (网络接口)
4x 40GE QSFP+, 20x 10GE/25GE SFP+/SFP28, 12x GE RJ45
Threat Protection(威胁检测)
5.4 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
12.5 Gbps
Network Interfaces (网络接口)
6x 10GE SFP+, , 34x GE RJ45
Threat Protection(威胁检测)
9.1 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
17 Gbps
Network Interfaces (网络接口)
Multiple 40 GE QSFP+, multiple 25GE, 10 GE SFP28/SFP+, two 10GE SFP+ HA, multiple 1 GE SFP, multiple 1 GE RJ45
Threat Protection(威胁检测)
5 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
10.5 Gbps
Network Interfaces (网络接口)
8x 10GE SFP+/GE SFP, 16x GE SFP, 18x GE RJ45
Threat Protection(威胁检测)
4 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
6 Gbps
Network Interfaces (网络接口)
4x 10GE SFP+/GE SFP, 16x GE SFP, 18x GE RJ45
Threat Protection(威胁检测)
7.1 Gbps
SSL Throughput Inspection
10 Gbps
Network Interfaces (网络接口)
2x40GE QSFP+, 4x25GE SFP28, 4x10GE SFP+/SFP, 8x1GE SFP, 16xGE RJ45
Threat Protection(威胁检测)
4 Gbps
SSL Throughput Inspection
4 Gbps
Network Interfaces (网络接口)
2x 10 GE SFP+, 16x GE SFP, 18x GE RJ45

Please see the product page for more information on these and many more Product features.  

FortiGate: Ultra high-end NGFW

Threat Protection(威胁检测)
60 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
90 Gbps
Network Interfaces (网络接口)
Multiple 40/100 GE QSFP28, 1/10/25 GE SFP28, 1/10 GE SFP+ and GE RJ45
Threat Protection(威胁检测)
100 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
130 Gbps
Network Interfaces (网络接口)
Multiple 40/100 GE QSFP28, 1/10/25 GE SFP28, 1/10 GE SFP+ and GE RJ45

Please see the product page for more information on these and many more Product features.  

FortiGate: Chassis-based NGFW

Threat Protection(威胁检测)
520Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
540Gbps
Interfaces
Multiple 10GE SFP+/SFP, Multiple 40GE QSFP28, Multiple 100GE QSFP28, Multiple 400GE QSFP28
Threat Protection(威胁检测)
80 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
79.9 Gbps
Network Interfaces (网络接口)
Multiple 10 GE SFP+/SFP, 40 GE QSFP+, 100 GE CFP2/QSFP28
Threat Protection(威胁检测)
40 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
50 Gbps
Network Interfaces (网络接口)
Multiple 10 GE SFP+/SFP, 40 GE QSFP+, 100 GE CFP2/QSFP28
Threat Protection(威胁检测)
35 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
50 Gbps
Network Interfaces (网络接口)
Multiple 10 GE SFP+/SFP, 40 GE/100 GE QSFP28
Threat Protection(威胁检测)
13.5 Gbps
SSL Inspection Throughput (SSL 检测吞吐量)
17 Gbps
Network Interfaces (网络接口)
2x 40GE QSFP+, 2x 10GE SFP+, 2x GE RJ45

Please see the product page for more information on these and many more Product features.  

FortiGuard Security Services for FortiGate: Next-Generation Firewalls

FortiGate NGFW receives continuous threat intelligence updates from FortiGuard Labs security services. Intrusion prevention, anti-malware, cloud sand-box, application control and web filtering protects enterprises from known and unknown advanced attacks.

View FortiGuard Labs Services and Bundle.

应用控制

通过实时、全面了解用户正在运行的应用,轻松实施可接受的使用策略,从而提高安全性,并满足合规要求。借助 FortiGuard 应用控制服务,您可以快速创建策略,以允许、拒绝或限制对应用或整个应用类别的访问。

Web过滤

通过阻止访问恶意网站、受攻击网站或不良网站来保护组织。

FortiCloud 沙箱

FortiCloud 沙箱服务是一款高级威胁检测解决方案,可执行动态分析,以识别以前未知的恶意软件。FortiCloud 沙箱生成的可执行情报将应用到您网络内的预防控制系统中,从而消除威胁。

反病毒

FortiGuard 反病毒服务可抵御最新病毒、间谍软件及其他内容级威胁。它使用行业领先的高级检测引擎来防止不断演进的新威胁侵袭您的网络并访问重要内容。

入侵防御

FortiGuard入侵防御服务保护组织免遭最新的网络入侵威胁

病毒爆发防护服务

FortiGuard 病毒爆发防护服务 (VOS) 通过 FortiCloud 沙箱分析填补了杀毒更新之间的空白,可检测并阻止在特征库更新期间发现的恶意软件威胁,以免波及整个组织。操作系统将启动对我们全球威胁情报数据库的实时查阅。

内容阻断 & 复原

内容消除与重建 (CDR) 能够实时清除文件中的所有“活动”内容,并生成干净的文件。所有“活动”内容均被视为可疑内容,并予以删除。CDR 将处理所有传入文件,对其进行解构,并删除所有不符合防火墙策略的元素。

IP 信誉和反僵尸网络

FortiGuard IP 信誉服务能够从威胁传感器、CERT、MITRE、合作友商及其他全球来源组成的 Fortinet 分布式网络中聚合恶意源 IP 数据,这些信息来源将协同提供有关恶意数据源的最新威胁情报。从分布式网络网关获取的近乎实时的情报与 FortiGuard 实验室提供的一流研究成果相结合,可确保组织安全无虞,并助力主动拦截攻击。

FortiGate Enterprise Bundle

Our Enterprise (ENT) bundle now includes:

  • CASB - providing visibility, compliance, data security and threat protection for your cloud-based services.
  • Industrial Security Service protection – SCADA (supervisory control and data acquisition) and ICS (industrial control systems). These signatures address attacks against critical infrastructure and manufacturing industries, where we are seeing frequent and sophisticated cyberattacks.
  • Security Rating Service - this service performs checks against your fabric-enabled network and provides scoring and recommendations to your operation teams. The subsequent scorecard can be used to gauge adherence to various internal and external organizational polices, standards, and regulations requirements, including providing a ranking of your firm against industry peers. 

The FortiGuard Enterprise (ENT) Protection bundle is designed to address today’s advanced threat landscape. The Enterprise Bundle consolidates the comprehensive protection needed to protect and defend against all cyberattack channels from the endpoint to the cloud. Including the technologies needed to address today’s challenging OT, compliance, and management concerns. The Enterprise Bundle offers the most comprehensive protection overall. The Enterprise Bundle includes: 

  • NGFW Application Control
  • IPS
  • Antivirus
  • Botnet
  • IP/Domain Reputation
  • Mobile Security
  • Web Filtering
  • Antispam
  • FortiSandbox Cloud
  • Virus Outbreak Protection
  • Content Disarm & Reconstruction 
  • CASB
  • Security Rating 
  • Industrial Security Service
  • FortiCare
FortiGate UTM Bundle

The FortiGuard Unified Protection Bundle (UTM) is our traditional Unified Threat Management security bundle. The Unified Protection Bundle extends threat protection across the entire digital attack surface, providing industry-leading defense against sophisticated attacks. The UTM bundle has you covered for web and email-based attacks. The UTM bundle delivers the best package available for a unified threat protection offering. The UTM Bundle includes: 

  • NGFW Application Control
  • IPS
  • Antivirus
  • Botnet
  • IP/Domain Reputation
  • Mobile Security
  • Web Filtering
  • Antispam
  • FortiSandbox Cloud
  • Virus Outbreak Protection
  • Content Disarm & Reconstruction 
  • FortiCare

The FortiGuard Advantage: 

  • FortiGuard processes over 69 million websites every hour, providing up-to-the-minute reputation and categorization. 
  • Prevent malicious downloads and browser hijacking attacks with top-rated web filtering (VBWeb Verified)
  • Improved email productivity through superior spam prevention validated with 3rd party independent testing (VBSpam + Verified)
FortiGate Advanced Threat Protection Bundle

The FortiGuard Advanced Threat Protection (ATP) bundle provides the foundational security needed to protect and defend against known and unknown cyber threats. The Advanced Threat Protection bundle includes: 

  • NGFW Application Control
  • IPS
  • Antivirus
  • Botnet
  • IP/Domain Reputation
  • Mobile Security
  • FortiSandbox Cloud
  • Virus Outbreak Protection
  • Content Disarm & Reconstruction 
  • FortiCare 24*7
Services Table
Service Advanced Threat Protection
(ATP)
 
Unified Protection
(UTM)
 
Enterprise Protection
(ENT)
 
A La Carte Protection


Threat Intelligence Service
     
Industrial Security Service
   

Security Rating
   

CASB
   

Web Filtering
 

Antivirus + Sandboxing




IPS




Antispam
 

 
Internet DB



 
IP Reputation


 
Application Control



 

Features and Benefits

As the data center grows to keep up with escalating business demands, security needs to scale and perform efficiently. Through consolidation of security, network and application controls, the data center can securely scale with the business.

 

Protect Hybrid

Protect the Data Center Edge
FortiGate NGFWs deliver artificial intelligence (AI)- and machine learning (ML)-enhanced FortiGuard Services and hardware-assisted DDoS to protect local data, applications, and services at data center speeds.

Firewall Segmentation

Consolidate within Data Center Core
FortiGate NGFWs deliver dynamic segmentation to prevent lateral spread of threats and build defense-in-depth.

Firewall Hyperscale

Scale Across Data Center Interconnect
FortiGate NGFWs deliver hyperscale security within, at the edge, and across data centers. They connect and replicate data securely, with support for ultra-fast elephant flows, to safely enable disaster recovery sites and accelerate time to market for advanced research.

security driven networking | security fabric

Security-Driven Networking

Traditional security strategies can’t keep up with the challenges of your expanding attack surface – from remote work, to mobility, to multi-cloud networks. Fortinet Security-Driven Networking addresses these challenges by tightly integrating network infrastructure with security architecture, meaning your network will remain secure as it scales and changes.