FortiGate Secure LAN Edge Controller
FortiGate as a Dedicated LAN Edge Controller
The FortiGate, in addition to its full suite of security functions, is a fully capable Wi-Fi and Switch Controller, able to manage FortiAPs, FortiSwitches, and extend Network Access Control (FortiLink NAC) to the edge of the LAN — Fortinet's LAN Edge solution.
The Fortinet LAN Edge solution consolidates network management into our industry-leading FortiGate. This solution provides comprehensive security for the LAN and WLAN infrastructure. With a single console for security and network functions, management is greatly simplified on a day-to-day basis, and security is fully integrated with every part of the network.
FortiGate LAN Edge Functions
All FortiGates include the following LAN Edge functions out of the box. No additional licensing is needed.
The FortiGate Wi-Fi and Switch Controller
The FortiGate Wi-Fi and Switch Controller manages FortiAP and FortiSwitch units in the network via FortiLink (below), extending the Fortinet security fabric to the LAN Edge, where end-devices connect to the network. In an overused phrase, a single pane of glass manages all the LAN access ports — FortiSwitch physical and FortiAP virtual.
FortiLink
FortiLink technology enables FortiAPs and FortiSwitches to become extensions of the FortiGate security appliance. When connected via FortiLink, traffic is tunneled to the FortiGate for full security inspection without the need to configure trunk lines on the FortiSwitches. Please note that FortiAPs do not require FortiSwitches to connect via FortiLink to their FortiGate controller. FortiAPs and FortiSwitches are complementary, but not mutually required.
FortiLink NAC
FortiLink NAC can dynamically assign devices to VLANs based on multiple criteria detected by FortiAPs or FortiSwitches. It can identify devices by multiple criteria, including device pattern (such as OS, MAC address, or HW vendor), user identity, VLAN attributes, or integrate with FortiClient EMS tags. For example, Internet of Things (IoT) sensors could be automatically identified and assigned to a specific VLAN with targeted policies that only allow communication with their control server. FortiLink NAC will also generate an inventory of connected devices, providing network administrators greater visibility.
FortiAP -- Standard and Unified Threat Protection Models
FortiAP devices come in a variety of models that support the latest Wi-Fi technologies, including Wi-Fi 6 and 6E. Indoor, outdoor, and high-density models are available, as well as wall-plate models for the hospitality industry. The U-series (Unified Threat Protection) offer the additional power of FortiGuard services on the FortiAP.
Both the standard FortiAP and FortiAP-U families are available in 2x2 (two MIMO stream) and 4x4 (four MIMO stream) models. Advanced models support dual 5 GHz mode for the most demanding Wi-Fi environments. The FAP-831 is an 8x8 Multi-User MIMO model for high density cases, such as lecture halls or auditoriums. FortiGates require no additional licenses to manage FortiAPs, although there are FortiGate model-specific AP limits.
FortiSwitch -- Ethernet Switching
Reliable, highly-performing, and purpose-built, Ethernet FortiSwitches are available in a variety of models to address needs from the small office access layer to the datacenter. All models support FortiLink and can be managed and configured directly from a FortiGate. MCLAG (Multi-Chassis Link Aggregation Group) is supported on most models for network redundancy.
In a LAN Edge deployment, it is vital to align the switch uplink speed with the capacity of the FortiGate. Avoid too little FortiGate with too much FortiSwitch. PoE (Power over Ethernet) access switches can provide power for FortiAPs. FortiGates require no additional licenses to manage FortiSwitches, although there are FortiGate model-specific switch limits.
LAN Edge Design
Fortinet LAN Edge Solutions are very flexible and can be adapted to a wide variety of network needs. Some guidelines follow, but it is best to work with an experienced Fortinet reseller to ensure the chosen products align with your networking needs.
Dedicated vs Perimeter LAN Edge Controller
There are two broad design approaches to using a FortiGate as a LAN Edge Controller: SD-Branch and Dedicated Controller.
SD Branch/Branch
The SD-Branch/Branch design is built around the main internet access FortiGate also directly controlling any LAN Edge devices. This design is typical of Branch and SMB offices. Total number of FortiAPs should initially be around 50% of the FortiGates listed tunneled-traffic maximum. That quantity leaves capacity for growth and new, advanced Wi-Fi technologies. FortiSwitches in these type of deployments will be access layer models that deliver PoE (Power over Ethernet) to the FortiAPs and connect directly to the FortiGate.
Dedicated LAN Edge Controller/ISFW Firewall
The dedicated LAN Edge Controller/ISFW Firewall, also sometimes called an overlay design is typical for campus networks with larger numbers of FortiAPs and a pre-existing switching network. The FortiGate LAN Edge Controller is usually dedicated to the Wi-Fi traffic. The FortiGate provides Wi-Fi controller functions, and serves as a Wi-Fi traffic concentrator and security inspection point, but is an ISFW (Internal Segmentation Firewall), rather than the primary Internet uplink. FortiAPs can tunnel FortiLink to the FortiGate LAN Edge Controller through an existing switch network, or FortiSwitches may be deployed specifically to support the FortiAPs.
FortiAP Requirements
Determine the number of FortiAPs needed first, which is primarily driven by how much floor space needs to be covered, with adjustments to the local wireless conditions. Wi-Fi design is highly location dependent, and a wireless site-survey from your reseller is always recommended.
For planning purposes, a FortiAP typically covers 1500 sq ft (150 sq m) and accommodates 60 active devices per service radio, or 120 devices per FortiAP. The 2x2 models are common in retail, public access, and similar lighter use. The 4x4 models are more common in offices and heavier use environments. However, all devices will perform well with all FortiAP models. Consult a Fortinet reseller about external antenna or specialty models, such as the FAP-23JF.
The UTP (Unified Threat Protection) models can deliver FortiGuard services on the FortiAP itself, offloading from the FortiGate, and can operate in dual 5 GHz mode, making channel planning more flexible.
FortiAPs can be powered by standards-based PoE access switches that match the requirements of the particular model. Power injectors or AC power can be used when PoE switches are unavailable. FortiAPs can connect to a FortiGate via FortiLink over any IP network with full functionality, including providing FortiLink NAC for wireless devices; FortiSwitches are not necessarily required.
More in depth wireless design resources can be found here.
Number of FortiSwitches -- Access Ports
Start with the determining the number of access ports for your needs, both for the FortiAPs and for any other wired devices. PoE access layer FortiSwitches can be used to power the FortiAPs as well as provide the Wi-Fi uplink, and can power other devices such as IoT devices or desk phones. The PoE output level and total power budget needs to be aligned with the powered device needs.
FortiSwitches can also provide the wired port-based FortiLink NAC function, identifying devices by various criteria and assigning them to policy determined VLANs automatically. If such devices need PoE power, that must be covered by the access switch PoE power budget.
A switch FortiLink uplink must be directly connected to either a FortiGate LAN Edge Controller or another FortiSwitch that is, in turn, FortiLink connected to a FortiGate. Unlike FortiAPs, they cannot be tunneled through another vendor's switch.
In an SD-Branch design, a single access FortiSwitch connected directly to a FortiGate may be all that is needed. However, a large campus with hundreds or thousands of FortiAPs will certainly require core and distribution switch layers with MCLAG redundancy. Full Ethernet switch network design is beyond the scope of this document, but more in depth wired design resources can be found here.
Size the LAN Edge Controller FortiGate
The scale of the FortiAP and FortiSwitch network will determine the necessary sizing of the FortiGate LAN Edge Controller. The FortiGate should be sized as usual, based on throughput (by inspection type), but with the addition of accounting for the tunneled FortiAP and FortiSwitch limits.
In order to leave room for growth, we recommend the FortiGate have a capacity for twice the number of FortiAPs (tunneled) and FortiSwitches to be deployed. Because of the different ways traffic is handled on the FortiGate, the FortiAP and FortiSwitch numbers are independent and can be evaluated separately. One LAN Edge device type does not affect the limit on the other type.
The most conservative FortiGate throughput number is the Threat Protection Throughput (Enterprise Mix), and that will be cited in the following examples. However, keep in mind that FortiAP-U series APs can offload FortiGuard Services. When that is the case, the higher NGFW number should be used for the FortiGate. In a branch deployment, the throughput should be more than the Internet uplink. In a dedicated controller environment, it is likely to be the same number in that the wireless end users are probably the primary Internet users.
Finally, the more critical and larger the LAN Edge Network, the more likely the LAN Edge Controller should actually be a pair of FortiGates in High Availability (HA) mode.
Cloud Management and Network Transition Options
Fewer and fewer networks of any size are deployed as pure greenfield. Most are established and have a refresh cycle with the NGFW, Ethernet, and Wi-Fi -- all refreshed at different times. Fortinet has options for those who want to transition to our Secure LAN Edge solution but are unable to do so all at once.
FortiLAN Cloud provides central cloud management for FortiAPs and FortiSwitches without an onsite FortiGate. Fortinet LAN Edge equipment can be deployed to a site and managed in FortiLAN Cloud, and later transitioned to FortiGate in the future.
FortiGate Cloud also provides cloud-based and remote management of FortiGates, and is completely compatible with everything above. FortiGate Cloud, via cloud management of a FortiGate, in turn manages the LAN Edge FortiAPs and FortiSwitches. FortiGate Cloud also adds one year of cloud log storage and backups, and is included in the FortiGate SMB bundles.
Example Specs/BoMs — FortiGate, FortiAP, FortiSwitch
NB - these are example BoMs, and should not be used as strict 'recipes.' Customer environments vary, and a full network design will be necessary to get the right number of FortiAPs, FortiSwitches, ports, and power requirements.
Light Retail / Small Branch
PRODUCTS | NEED | SUGGESTED SOLUTIONS |
---|---|---|
FortiAPs | 4000 square feet, no walls, light Wi-Fi | FAP-231G |
Access FSW | 4 PoE ports, bt power | FSW-108-FPOE |
Aggregation FSW | Not needed | -- |
FortiGate | SMB class firewall + WiFi & switch controller | FGT-60F |
SFP | Not needed | -- |
An open area allows wider FAP coverage, Wi-Fi use is light, 1 wired register, 1 wireless printer, cost conscious, SMB Bundle.
Mid Size Branch
QTY | FortiAPs | Access FSW | Aggregation FSW | FortiGate | SFPs |
---|---|---|---|---|---|
30,000 square feet (20 FAP) | FAP-431G/231G | Multi-Gig switches, bt PoE | FSW- M426E or similar | MCLAG, SFP+ connectors | FSW-1024E or 1048E |
Enterprise package, redundant pair | 10GE copper | Dual FGT-100F, HA mode | |||
10GE SFP+ copper connectors |
Thirty thousand square feet, multi-gig access switches in a redundant MCLAG pair, extra PoE ports for PoE desk phones, redundant FortiGates as dedicated WiFi and Switch controllers (ISFW), Enterprise bundle.
Mid Range Enterprise
QTY | FortiAPs | Access FSW | Aggregation FSW | FortiGate | SFPs |
---|---|---|---|---|---|
225 000 sq ft (150 FAP) | FAP-431G/231G | Multi-Gig switch, bt PoE | FSW- M426E or similar | MCLAG, SFP+ connectors | FSW-1024E or 1048E |
Enterprise package, redundant pair | 10GE SFP+ copper connectors | 2 FGT-600F, HA mode |
Large office building, multiple floors, 225 000 sq ft (150 FAPs), switch redundancy, redundant FortiGates as dedicated WiFi and Switch controllers (ISFW), Enterprise bundle.
Large Campus / School District
QTY | FortiAPs | Access FSW | Aggregation FSW | FortiGate | SFPs |
---|---|---|---|---|---|
Indoor and outdoor coverage, | FAP-431G/231G + FAP-234F | Multi-Gig switch, bt PoE | FSW- M426E or similar | MCLAG, SFP+ connectors | FSW-1024E/1048E/3032E |
Enterprise package, redundant pair | 10/40 GE fiber | 2 FGT-1800F, or similar |
Eight hundred Indoor FortiAPs, 100 outdoor FortiAPs, MultiGig PoE access switches, aggregation switches, switch redundancy, redundant FortiGates as dedicated WiFi and Switch controllers (ISFW), Enterprise bundle.
Top Sellers - LAN Edge FortiGates
BASE PRODUCT | RECOMMENDED FORTIAP | MAX FORTIAP | MAX FORTISWITCH | RECOMMENDED BUNDLE | SUPPORT BUNDLE | RENEWAL |
---|---|---|---|---|---|---|
SMALL RETAIL / BRANCH | ||||||
FG-40F | 4 | 8 | 8 | SMB | FG-40F-BDL-879-DD | FC-10-0040F-879-02-DD |
FG-60F | 16 | 32 | 16 | SMB | FG-60F-BDL-879-DD | FC-10-0060F-879-02-DD |
FG-80F | 24 | 48 | 16 | SMB | FG-80F-BDL-879-DD | FC-10-0080F-879-02-DD |
FG-100F | 32 | 64 | 32 | Enterprise | FG-100F-BDL-811-DD | FC-10-F100F-811-02-DD |
LARGE BRANCH / MID RANGE | ||||||
FG-200F | 64 | 128 | 64 | Enterprise | FG-200F-BDL-811-DD | FC-10-F200F-811-02-DD |
FG-400F | 128 | 256 | 72 | Enterprise | FG-400F-BDL-811-DD | FC-10-0400F-811-02-DD |
FG-600F | 256 | 512 | 96 | Enterprise | FG-600F-BDL-811-DD | FC-10-0600F-811-02-DD |
HIGH END / LARGE CAMPUS / SCHOOL DISTRICT | ||||||
FG-1000F | 1024 | 2048 | 196 | Enterprise | FG-1000F-BDL-811-DD | FC-10-F1K0F-811-02-DD |
FG-1800F | 1024 | 2048 | 196 | Enterprise | FG-1800F-BDL-811-DD | FC-10-F18HF-811-02-DD |
FG-2600F | 1024 | 2048 | 196 | Enterprise | FG-2600F-BDL-811-DD | FC-10-F26HF-811-02-DD |
FG-3000F | 1024 | 2048 | 300 | Enterprise | FG-3000F-BDL-811-DD | FC-10-F3K0F-811-02-DD |
FG-3500F | 1024 | 2048 | 300 | Enterprise | FG-3500F-BDL-811-DD | FC-10-F3K0F-811-02-DD |
FG-3700F | 1024 | 2048 | 300 | Enterprise | FG-3700F-BDL-811-DD | FC-10-F3K6E-811-02-DD |
FG-4200F | 2048 | 4096 | 300 | Enterprise | FG-4200F-BDL-811-DD | FC-10-F42HF-811-02-DD |
FG-4400F | 2048 | 4096 | 300 | Enterprise | FG-4400F-BDL-811-DD | FC-10-F44HF-811-02-DD |
A country suffix code (-A, -B, -C, -D, -E, -F, -I, -J, -K, -N, -P, -S, -T, -U, -V, -W, or -Y) applies to all AP models based upon country of deployment. Work with your local supplier for the correct model in your regulatory domain. A - United States, Canada, and Latin America. E - United Kingdom and Europe.
Top Sellers - FortiAP
PRODUCT | SKU | SUPPORT |
---|---|---|
STANDARD MODELS | ||
FAP-431G | FAP-431G-suffix* | FC-10-PG431-247-02-DD |
FAP-433G | FAP-433G-suffix* | FC-10-PG433-247-02-DD |
FAP-231G | FAP-231G-suffix* | FC-10-PG231-247-02-DD |
FAP-233G | FAP-233G-suffix* | FC-10-PG233-247-02-DD |
FAP-431F | FAP-431F-suffix* | FC-10-F431F-247-02-DD |
FAP-433F | FAP-433F-suffix* | FC-10-F433F-247-02-DD |
FAP-432F | FAP-432F-suffix* | FC-10-PF432-247-02-DD |
FAP-231F | FAP-231F-suffix* | FC-10-PF231-247-02-DD |
FAP-234F | FAP-234F-suffix* | FC-10-P234F-247-02-DD |
UTP MODELS | ||
FAP-U431F | FAP-U431F-suffix* | FC-10-P431F-247-02-DD |
FAP-U433F | FAP-U433F-suffix* | FC-10-P433F-247-02-DD |
FAP-U432F | FAP-U433F-suffix* | FC-10-PU432-247-02-DD |
FAP-U231F | FAP-U433F-suffix* | FC-10-P231-247-02-DD |
FAP-U234F | FAP-U433F-suffix* | FC-10-PU234-247-02-DD |
Top Sellers - FPoE FortiSwitch
PRODUCT | MODELS | SKU | SUPPORT |
---|---|---|---|
FortiSwitch-108F-FPOE | FS-108F-FPOE | FC-10-F108F-247-02-DD | |
FortiSwitchRugged-112D-POE | FSR-112D-POE | FC-10-W112D-247-02-DD | |
FortiSwitch-124F-FPOE | FS-124F-FPOE | ||
FortiSwitch-148F-FPOE | FS-148F-FPOE | FC-10-148FF-247-02-DD | |
FortiSwitch-224D-FPOE | FS-224D-FPOE | FC-10-W0226-247-02-DD | |
FortiSwitch-248E-FPOE | FS-248E-FPOE | FC-10-W248E-247-02-DD | |
FortiSwitch-424E-FPOE | FS-424E-FPOE | FC-10-S424F-247-02-DD | |
FortiSwitch-448E-FPOE | FS-448E-FPOE | FC-10-S448F-247-02-DD | |
FortiSwitch-524D-FPOE | FS-524D-FPOE | FC-10-W0505-247-02-DD | |
FortiSwitch-548D-FPOE | FS-548D-FPOE | FC-10-W0501-247-02-DD |
A country suffix code (-A, -B, -C, -D, -E, -F, -I, -J, -K, -N, -P, -S, -T, -U, -V, -W, or -Y) applies to all AP models based upon country of deployment. Work with your local supplier for the correct model in your regulatory domain. A - United States, Canada, and Latin America. E - United Kingdom and Europe.
Order Information: FortiGate a LAN Edge Controller
The Fortinet LAN Edge solution consolidates network management into our industry-leading FortiGate. This solution provides comprehensive security for the LAN infrastructure and simpler management on a day-to-day basis. Fortinet enables the deployment of large-scale networks with minimal technical expertise via built-in best-practice configurations. Zero-touch provisioning delivers quick and easy application of device templates to sites at scale. FortiLink NAC creates improved visibility and segmentation, enabling auto-discovery of devices to implement "least privilege" access.
FORTIGATE APPLIANCES
FG/FWF-40F | FG/FWF-60F | FG-70F | FG/FWF-80F | |
---|---|---|---|---|
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 16 / 8 | 64 / 32 | 64 / 32 | 96 / 48 |
Max FortiSwitches | 8 | 16 | 16 | 16 |
Firewall Throughput (1518/512/64 byte UDP) | 5 / 5 / 5 Gbps | 10 / 10 / 6 Gbps | 10 / 10 / 6 Gbps | 10 / 10 / 7 Gbps |
BRANCH AND MID RANGE BUNDLES | ||||
FortiGate | FG/FWF-40F | FG/FWF-60F | FG-70F | FG/FWF-80F |
Enterprise Bundle | FG-40F-BDL-811-DD | FG-60F-BDL-811-DD | FG-70F-BDL-811-DD | FG-80F-BDL-811-DD |
- Enterprise Renewal | FC-10-0040F-811-02-DD | FC-10-0060F-811-02-DD | FC-10-0070F-811-02-DD | FC-10-0080F-811-02-DD |
SMB Bundle - includes FortiGate Cloud | FG-40F-BDL-879-DD | FG-60F-BDL-879-DD | FG-70F-BDL-879-DD | FG-80F-BDL-879-DD |
- SMB Renewal | FC-10-0040F-879-02-DD | FC-10-0060F-879-02-DD | FC-10-0070F-879-02-DD | FC-10-0080F-879-02-DD |
FortiGate Cloud alone | FC-10-0040F-131-02-DD | FC-10-0060F-131-02-DD | FC-10-0070F-131-02-DD | FC-10-0080F-131-02-DD |
SELECT BRANCH VARIANTS | 40F LTE | 61F Storage | 71F Storage | 80F storage |
Variant | ||||
Enterprise Bundle | FG-40F-3G4G-BDL-811-DD | FG-61F-BDL-811-DD | FG-71F-BDL-811-DD | FG-81F-BDL-811-DD |
- Enterprise Renewal | FC-10-F40FG-811-02-DD | FC-10-0061F-811-02-DD | FC-10-0071F-811-02-DD | FC-10-0081F-811-02-DD |
SMB Bundle - includes FortiGate Cloud | FG-40F-3G4G-BDL-879-DD | FG-61F-BDL-879-DD | FG-71F-BDL-879-DD | FG-81F-BDL-879-DD |
- SMB Renewal | FC-10-F40FG-879-02-DD | FC-10-0061F-879-02-DD | FC-10-0071F-879-02-DD | FC-10-0081F-879-02-DD |
FortiGate Cloud alone | FC-10-F40FG-131-02-DD | FC-10-0061F-131-02-DD | FC-10-0071F-131-02-DD | FC-10-0081F-131-02-DD |
Variant | FortiWiFi 40F | FortiWiFi 60F | FortiWiFi 80F | FortiWiFi 80F + storage |
Enterprise Bundle | FWF-40F-code*-BDL-811-DD | FWF-60F-code*-BDL-811-DD | FWF-80F-2R-code*-BDL-811-DD | FWF-81F-2R-code*-BDL-811-DD |
- Enterprise Renewal | FC-10-W040F-811-02-DD | FC-10-W060F-811-02-DD | FC-10-W080F-811-02-DD | FC-10-W081F-811-02-DD |
SMB Bundle - includes FortiGate Cloud | FWF-40F-code*-BDL-879-DD | FWF-60F-code*-BDL-879-DD | FWF-80F-2R-code*-BDL-879-DD | FWF-81F-2R-code*-BDL-879-DD |
- SMB Renewal | FC-10-W040F-879-02-DD | FC-10-W060F-879-02-DD | FC-10-W080F-879-02-DD | FC-10-W081F-879-02-DD |
FortiGate Cloud alone | FC-10-W040F-131-02-DD | FC-10-W060F-131-02-DD | FC-10-W080F-131-02-DD | FC-10-W081F-131-02-DD |
Variant | FortiWiFi 40F LTE | FortiWiFi 60F + storage | 80F PoE | FortiWiFi 80F PoE |
Enterprise Bundle | FWF-40F-3G4G-code*-BDL-811-DD | FWF-61F-code*-BDL-811-DD | FG-80F-POE-BDL-811-DD | FWF-81F-2R-POE-code*-BDL-811-DD |
- Enterprise Renewal | FC-10-F40FI-811-02-DD | FC-10-W061F-811-02-DD | FG-81F-POE-BDL-811-DD | FC-10-WP81F-811-02-DD |
SMB Bundle - includes FortiGate Cloud | FWF-40F-3G4G-code*-BDL-879-DD | FWF-61F-code*-BDL-879-DD | FG-80F-POE-BDL-879-DD | FWF-81F-2R-POE-code*-BDL-879-DD |
- SMB Renewal | FC-10-F40FI-879-02-DD | FC-10-W061F-879-02-DD | FG-81F-POE-BDL-879-DD | FC-10-WP81F-879-02-DD |
FortiGate Cloud alone | FC-10-F40FI-131-02-DD | FC-10-W061F-131-02-DD | FG-80F-POE-BDL-131-DD | FC-10-WP81F-131-02-DD |
FortiGate Appliances
FORTIGATE APPLIANCES | FG/FWF-40F | FG/FWF-60F | FG-70F | FG/FWF-80F |
---|---|---|---|---|
SELECT BRANCH VARIANTS | ||||
Variant | ||||
Enterprise Bundle | ||||
- Enterprise Renewal | ||||
SMB Bundle - includes FortiGate Cloud | ||||
- SMB Renewal | ||||
FortiGate Cloud alone | ||||
FortiWiFi 80F + storage | ||||
Variant | ||||
Enterprise Bundle | FWF-81F-2R-code*-BDL-811-DD | |||
- Enterprise Renewal | FC-10-W081F-811-02-DD | |||
SMB Bundle - includes FortiGate Cloud | FWF-81F-2R-code*-BDL-879-DD | |||
- SMB Renewal | FC-10-W081F-879-02-DD | |||
FortiGate Cloud alone | FC-10-W081F-131-02-DD | |||
Variant | FortiWiFi 80F PoE | |||
Enterprise Bundle | FWF-81F-2R-POE-code*-BDL-811DD | |||
- Enterprise Renewal | FC-10-WP81F-811-02-DD | |||
SMB Bundle - includes FortiGate Cloud | FWF-81F-2R-POE-code*-BDL-879-DD | |||
- SMB Renewal | FC-10-WP81F-879-02-DD | |||
FortiGate Cloud alone | FC-10-WP81F-131-02-DD | |||
FORTIGATE APPLIANCES | FG-100F | FG-200F | FG-400F | FG-600F |
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 128 / 64 | 256 / 128 | 512 / 256 | 1024 / 512 |
Max FortiSwitches | 32 | 64 | 72 | 96 |
Firewall Throughput (1518/512/64 byte UDP) | 20 / 18 / 10 Gbps | 27 / 27 / 11 Gbps | 78.5 / 78.5 / 70 Gbps | 139 / 137.5 / 70 Gbps |
MID RANGE AND HIGH END BUNDLES | ||||
Enterprise Protection Bundle | ||||
Enterprise Bundle | FG-100F-BDL-811-DD | FG-200F-BDL-811-DD | FG-400F-BDL-811-DD | FG-600F-BDL-811-DD |
- Enterprise Renewal | FC-10-F100F-811-02-DD | FC-10-F200F-811-02-DD | FC-10-0400F-811-02-DD | FC-10-0600F-811-02-DD |
FortiGate Cloud -Management, Analysis, 1y Log Retention | FC-10-F100F-131-02-DD | FC-10-F200F-131-02-DD | FC-10-0400F-131-02-DD | FC-10-0600F-131-02-DD |
Unified Threat Protection Bundle | ||||
UTP Bundle | FG-100F-BDL-950-DD | FG-200F-BDL-950-DD | FG-400F-BDL-950-DD | FG-600F-BDL-950-DD |
- UTP Bundle Renewal | FC-10-F100F-950-02-DD | FC-10-F200F-950-02-DD | FC-10-0400F-950-02-DD | FC-10-F6H0F-950-02-DD |
FortiGate Cloud -Management, Analysis, 1y Log Retention | FC-10-F100F-131-02-DD | FC-10-F200F-131-02-DD | FC-10-0400F-131-02-DD | FC-10-0600F-131-02-DD |
FG-1100E | FG-1000F | |||
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 4096 / 2048 | 4096 / 2048 | ||
Max FortiSwitches | 196 | 196 | ||
Firewall Throughput (1518/512/64 byte UDP) | 80 / 80 / 45 Gbps | 196 / 196 / 134 Gbps | ||
MID RANGE AND HIGH END BUNDLES | ||||
Enterprise Protection Bundle | ||||
Enterprise Bundle | FG-1100E-BDL-811-DD | FG-1000F-BDL-811-DD | ||
- Enterprise Renewal | FC-10-F11HE-811-02-DD | FC-10-F1K0F-811-02-DD | ||
FortiGate Cloud -Management, Analysis, 1y Log Retention | FC-10-F11HE-131-02-DD | FC-10-F1K0F-131-02-DD | ||
Unified Threat Protection Bundle | ||||
UTP Bundle | FG-1100E-BDL-950-DD | FG-1000F-BDL-950-DD | ||
- UTP Bundle Renewal | FC-10-F11HE-950-02-DD | FC-10-F1K0F-950-02-DD | ||
FortiGate Cloud -Management, Analysis, 1y Log Retention | FC-10-F11HE-131-02-DD | FC-10-F1K0F-131-02-DD |
FORTIGATE APPLIANCES | FG-1800F | FG-2600F | FG-3000F | FG-3500F |
---|---|---|---|---|
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 |
Max FortiSwitches | 196 | 196 | 300 | 300 |
Firewall Throughput (1518/512/64 byte UDP) | 198 / 197 / 140 Gbps | 198 / 196 / 120 Gbps | 397 / 389 / 221 Gbps | 595 / 590 / 420 Gbps |
MID RANGE AND HIGH END BUNDLES | ||||
Enterprise Protection Bundle | ||||
Enterprise Bundle | FG-1800F-BDL-811-DD | FG-2600F-BDL-811-DD | FG-3000F-BDL-811-DD | FG-3500F-BDL-811-DD |
- Enterprise Renewal | FC-10-F18HF-811-02-DD | FC-10-F26HF-811-02-DD | FC-10-F3K0F-811-02-DD | FC-10-F3K0F-811-02-DD |
FortiGate Cloud -Management, Analysis, 1y Log Retention | FC-10-F18HF-131-02-DD | FC-10-F26HF-131-02-DD | FC-10-F3K0F-131-02-DD | FC-10-F3K5F-131-02-DD |
Unified Threat Protection Bundle | ||||
UTP Bundle | FG-1800F-BDL-950-DD | FG-2600F-BDL-950-DD | FG-3000F-BDL-950-DD | FG-3500F-BDL-950-DD |
- UTP Bundle Renewal | FC-10-F18HF-950-02-DD | FC-10-F26HF-950-02-DD | FC-10-F3K0F-950-02-DD | FC-10-F3K5F-950-02-DD |
FortiGate Cloud -Management, Analysis, 1y Log Retention | FC-10-F18HF-131-02-DD | FC-10-F26HF-131-02-DD | FC-10-F3K0F-131-02-DD | FC-10-F3K5F-131-02-DD |
FORTIGATE APPLIANCES | FG-3700F | FG-4200F | FG-4400F | |
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 4096 / 2048 | 8192 / 4096 | 8192 / 4096 | |
Max FortiSwitches | 300 | 300 | 300 | |
Firewall Throughput (1518/512/64 byte UDP) | 589 / 589 / 420 Gbps | 800 / 788 / 400 Gbps | 1.15 / 1.14 / 0.5 Tbps | |
MID RANGE AND HIGH END BUNDLES | ||||
Enterprise Protection Bundle | ||||
Enterprise Bundle | FG-3600E-BDL-811-DD | FG-4200F-BDL-811-DD | FG-4400F-BDL-811-DD | |
- Enterprise Renewal | FC-10-F3K6E-811-02-DD | FC-10-F42HF-811-02-DD | FC-10-F44HF-811-02-DD | |
FortiGate Cloud -Management, Analysis, 1y Log Retention | n/a | n/a | n/a | |
Unified Threat Protection Bundle | ||||
UTP Bundle | FG-3600E-BDL-950-DD | FG-4200F-BDL-950-DD | FG-4400F-BDL-950-DD | |
- UTP Bundle Renewal | FC-10-F3K6E-950-02-DD | FC-10-F42HF-950-02-DD | FC-10-F44HF-950-02-DD | |
FortiGate Cloud -Management, Analysis, 1y Log Retention | n/a | n/a | n/a |
FortiGate VM Virtual Machines
FORTIGATE VM VIRTUAL MACHINES | VM-01/01V/01S | VM-02/02V/02S | VM-04/04V/04S | VM-08/08V/08S |
---|---|---|---|---|
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 64 / 32 | 1024 / 512 | 1024 / 512 | 4096 / 1024 |
Max FortiSwitches | Implementation dependent | Implementation dependent | Implementation dependent | Implementation dependent |
Firewall Throughput (1518/512/64 byte UDP) | 12 Gbps | 15 Gbps | 28 Gbps | 33 Gbps |
PRIVATE CLOUD | ||||
ATP bundle | FC1-10-FGVVS-993-02-DD | FC2-10-FGVVS-993-02-DD | FC3-10-FGVVS-993-02-DD | FC4-10-FGVVS-993-02-DD |
UTP Bundle | FC2-10-FGVVS-990-02-DD | FC2-10-FGVVS-990-02-DD | FC3-10-FGVVS-990-02-DD | FC4-10-FGVVS-990-02-DD |
Enterprise bundle | FC2-10-FGVVS-815-02-DD | FC2-10-FGVVS-815-02-DD | FC3-10-FGVVS-815-02-DD | FC4-10-FGVVS-815-02-DD |
NB - FortiGate VM does not have a ForitGate Cloud option | ||||
FORTIGATE VM VIRTUAL MACHINES | VM-16/16V/16S | VM-32/32V/32S | VM-UL/ULV/ULS | |
NGFW / PERIMETER FIREWALLS | ||||
Maximum FortiAPs (Total/Tunnel) | 4096 / 1024 | 4096 / 1024 | 4096 / 1024 | |
Max FortiSwitches | Implementation dependent | Implementation dependent | Implementation dependent | |
Firewall Throughput (1518/512/64 byte UDP) | 36 Gbps | 50 Gbps | Resource dependent | |
PRIVATE CLOUD | ||||
ATP bundle | FC5-10-FGVVS-993-02-DD | FC6-10-FGVVS-993-02-DD | FC7-10-FGVVS-993-02-DD | |
UTP Bundle | FC5-10-FGVVS-990-02-DD | FC6-10-FGVVS-990-02-DD | FC7-10-FGVVS-990-02-DD | |
Enterprise bundle | FC5-10-FGVVS-815-02-DD | FC6-10-FGVVS-815-02-DD | FC7-10-FGVVS-815-02-DD | |
NB - FortiGate VM does not have a ForitGate Cloud option |
FortiAP
FORTIAP STANDARD | FAP-431G | FAP-433G | FAP-231G | FAP-233G | FAP-431F | FAP-433F | FAP-432F | FAP-231F | FAP-234F |
---|---|---|---|---|---|---|---|---|---|
Wi-Fi Generation | 6E | 6E | 6E | 6E | 6 | 6 | 6 | 6 | 6 |
MIMO/Antennas | 4x4, Internal | 4x4 External (6GHz Int) | 2x2, internal | 2x2 External | 4x4, Internal | 4x4 External | 4x4 External | 2x2, Internal | 2x2, Internal |
Use | Indoor | Indoor | Indoor | Indoor | Indoor | Indoor | Outdoor | Indoor | Outdoor |
Majority of clients | Laptops, all | Laptops, all | Phones/Tablets, all | Phones/Tablets, all | Laptops, all | Laptops, all | Laptops, all | All, light use | All, light use |
Radios | 3 | 3 | 3 | 3 | 3 | 3 | 3 | 3 | 3 |
Ethernet ports | 2 x 5GE | 2 x 5GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 2 x GE | 2 x GE |
PoE (802.3xx) | 1bt, or 2at | 1bt, or 2at | at | at | at | at | bt | at | at |
Hardware | FAP-431G-suffix* | FAP-433G-suffix* | FAP-231G-suffix* | FAP-233G-suffix* | FAP-431F-suffix* | FAP-433F-suffix* | FAP-432F-suffix* | FAP-231F-suffix* | FAP-234F-suffix* |
NB - no license required for FortiGate management | - | - | - | - | - | - | - | - | - |
FortiLAN Cloud Management (when NOT managed by FortiGate) | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD |
FortiCare is only applicable when used with FortiLAN Cloud | |||||||||
FortiCare Premium | FC-10-PG431-247-02-DD | FC-10-PG433-247-02-DD | FC-10-PG231-247-02-DD | FC-10-PG233-247-02-DD | FC-10-F431F-247-02-DD | FC-10-F433F-247-02-DD | FC-10-PF432-247-02-DD | FC-10-PF231-247-02-DD | FC-10-P234F-247-02-DD |
FortiCare Elite | FC-10-PG431-284-02-DD | FC-10-PG433-284-02-DD | FC-10-PG231-284-02-DD | FC-10-PG233-284-02-DD | FC-10-F431F-284-02-DD | FC-10-F433F-284-02-DD | FC-10-PF432-284-02-DD | FC-10-PF231-284-02-DD | FC-10-P234F-284-02-DD |
FORTIAP STANDARD | FAP-831F | FAP-431F | FAP-433F | FAP-432F | FAP-231F | FAP-221E | FAP-223E | FAP-C24JE | FAP-23JF |
Wi-Fi Generation | 6 | 6 | 6 | 6 | 6 | 5 | 5 | 5 | 6 |
MIMO/Antennas | 8x8, internal | 4x4, Internal | 4x4 External | 4x4 External | 2x2, Internal | 2x2, Internal | 2x2 External | 2x2, Internal | 2x2, Internal |
Use | stadium/auditorium | Indoor | Indoor | Outdoor | Indoor | Indoor | Indoor | Indoor wall plate | Indoor wall plate |
Majority of clients | Phones/Tablets, all | Laptops, all | Laptops, all | Laptops, all | All, light use | All, light use | All, light use | Hotel Rooms | Hotel Rooms |
Radios | 3 | 3 | 3 | 3 | 3 | 2 | 2 | 2 | 3 |
Ethernet ports | 1 x 5GE, 1GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 2 x GE | 1 x GE | 1 x GE | 4 x GE | 4 x GE |
PoE (802.3xx) | 2at/bt (30W) | at | at | bt | at | af | af | at | at |
Hardware | FAP-831F-suffix* | FAP-431F-suffix* | FAP-433F-suffix* | FAP-432F-suffix* | FAP-231F-suffix* | FAP-221E-suffix* | FAP-223E-suffix* | FAP-C24JE-suffix* | FAP-23JF-suffix* |
NB - no license required for FortiGate management | - | - | - | - | - | - | - | - | - |
FortiLAN Cloud Management (when NOT managed by FortiGate) | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD |
FortiCare is only applicable when used with FortiLAN Cloud | |||||||||
FortiCare Premium | FC-10-F831F-247-02-DD | FC-10-F431F-247-02-DD | FC-10-F433F-247-02-DD | FC-10-PF432-247-02-DD | FC-10-PF231-247-02-DD | FC-10-PE221-247-02-DD | FC-10-PE223-247-02-DD | FC-10-PC24E-247-02-DD | FC-10-P23JF-247-02-DD |
FortiCare Elite | FC-10-P831F-284-02-DD | FC-10-F431F-284-02-DD | FC-10-F433F-284-02-DD | FC-10-PF432-284-02-DD | FC-10-PF231-284-02-DD | FC-10-PE221-284-02-DD | FC-10-PE223-284-02-DD | FC-10-AP024-284-02-DD | FC-10-P23JF-284-02-DD |
FortiAP (UTP)
FORTIAP UTP | FAP-U431F | FAP-U433F | FAP-U432F | FAP-U231F | FAP-U234F | FAP-U422EV |
---|---|---|---|---|---|---|
Wi-Fi Generation | 6 | 6 | 6 | 6 | 6 | 5 |
MIMO/Antennas | 4x4, Internal | 4x4 External | 2x2, External | 2x2, Internal | 2x2, Internal | 4x4 External |
Use | Indoor | Indoor | Outdoor | Indoor | Outdoor | Outdoor |
Majority of clients | Laptops, all | Laptops, all | All | All | All | All |
Radios | 3 | 3 | 3 | 2 | 2 | 2 |
Ethernet ports | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 1 x 2.5GE, 1GE | 2GE | 1 x 2.5GE, 1GE | 2GE |
PoE (802.3xx) | 1at or 2af | 1at or 2af | bt (injector included) | at | bt (injector included) | at |
Hardware | FAP-U431F-suffix* | FAP-U433F-suffix* | FAP-U433F-suffix* | FAP-U433F-suffix* | FAP-U433F-suffix* | FAP-U422EV-suffix* |
UTP Subscription | FC-10-90APU-443-02-DD | FC-10-90APU-443-02-DD | FC-10-90APU-443-02-DD | FC-10-90APU-443-02-DD | FC-10-90APU-443-02-DD | FC-10-90APU-443-02-DD |
NB - no license required for FortiGate management | - | - | - | - | - | - |
FortiLAN Cloud Management (when NOT managed by FortiGate) | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD | FC-10-90AP1-639-02-DD |
FortiCare is only applicable when used with FortiLAN Cloud | ||||||
FortiCare Premium | FC-10-P431F-247-02-DD | FC-10-P433F-247-02-DD | FC-10-PU432-247-02-DD | FC-10-P231-247-02-DD | FC-10-PU234-247-02-DD | FC-10-P0422-247-02-DD |
FortiCare Elite | FC-10-P431F-284-02-DD | FC-10-P433F-284-02-DD | FC-10-PU432-284-02-DD | FC-10-PF231-284-02-DD | FC-10-PU234-284-02-DD | FC-10-P0422-284-02-DD |
For additional FortiAP details, external antennas and accessories, please see https://www.fortinet.com/products/wireless-access-points.
FortiSwitch
FORTISWITCH | 100 SERIES | 200 SERIES | 400 SERIES | 500 SERIES | 1000 SERIES | 3000 SERIES |
---|---|---|---|---|---|---|
Main Port Speed | 1 Gbps | 1 Gbps | 1 Gbps | 1 Gbps | 10/40 Gbps | 40/100 Gbps |
Main Port Count Options | 8, 24, 48 | 24, 48 | 24, 48 | 24, 48 | 24, 48 | 32 |
Uplink Port Speed | 1 or 10 Gbps | 1 Gbps | 10 Gbps | 10 Gbps | 40 or 100 Gbps | n/a |
Redundant Power Supplieas | n/a | Some Models | Some Models | Optional RSU | Yes | Yes |
PoE Options | Yes | Yes | Yes | Yes | n/a | n/a |
Examples Full PoE FortiSwitches | ||||||
8-port FPoE Hardware Bundle | FS-108F-FPOE | |||||
Renewal | FC-10-F108F-247-02-DD | |||||
24-port FPoE Hardware Bundle | FS-124F-FPOE | FS-224D-FPOE | FS-M426E-FPOE | FS-524D-FPOE | ||
Renewal | FC-10-S124FP-247-02-DD | FC-10-W0226-247-02-DD | FC-10-M426E-247-02-DD | FC-10-W0505-247-02-DD | ||
48-port FPoE Hardware Bundle | FS-248E-FPOE | FS-448E-FPOE | FS-548D-FPOE | |||
Renewal | FC-10-W248E-247-02-DD | FC-10-S448F-247-02-DD | FC-10-W0501-247-02-DD | |||
NB - no license required for FortiGate management | - | - | - | - | - | - |
FortiLAN Cloud Management (when not managed by FortiGate) | FC-10-FSW00-628-02-DD | FC-10-FSW10-628-02-DD | FC-10-FSW10-628-02-DD | FC-10-FSW20-628-02-DD | FC-10-FSW30-628-02-DD | n/a |
FortiCare is only applicable when used with FortiLAN Cloud |
For additional models, accessories, advanced licenses, etc, please see the FortiSwitch Ordering Guide: https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/og-fortiswitch.pdf.
Additional Wireless Management Products
PRODUCT | DESCRIPTION | SKU LICENSE |
---|---|---|
FortiGate Cloud / FortiLAN Cloud - Multi Tenancy Account | FortiGate Cloud or FortiLAN Cloud Multi Tenancy service for a Managed Service Provider (MSP) to create and manage multiple SubAccounts. | FCLE-10-FCLD0-161-02-DD |
FortiAIOps | Base license for FortiAIOps MEA for FortiManager (Includes management of 10 FortiGate devices). | LIC-AIO-BASE |
Stackable upgrade license for adding 10 FortiGate devices. | LIC-AIO-10 | |
Stackable upgrade license for adding 100 FortiGate devices. | LIC-AIO-100 | |
Stackable upgrade license for adding 1000 FortiGate devices. | LIC-AIO-1000 | |
Stackable upgrade license for adding 5000 FortiGate devices. | LIC-AIO-5000 | |
FortiAIOps Support | 24x7FortiCareContract (1 - 10 devices). | FC1-10-AIOPS-248-02-DD |
24x7FortiCareContract (1 - 110 devices). | FC2-10-AIOPS-248-02-DD | |
24x7FortiCareContract (1 - 310 devices). | FC3-10-AIOPS-248-02-DD | |
24x7FortiCareContract (1 - 1010 devices). | FC4-10-AIOPS-248-02-DD | |
24x7FortiCareContract (1 - 5010 devices). | FC5-10-AIOPS-248-02-DD | |
24x7FortiCareContract (1 - 10010 devices). | FC6-10-AIOPS-248-02-DD | |
24x7FortiCareContract (1 - Unlimited). | FC7-10-AIOPS-248-02-DD | |
FortiWLM-VM | FortiWLM Wireless LAN Management Virtual Appliance. Utilizes FWM licenses and can support up to 20,000 APs. Comes with 50 AP license included when purchased (30-day trial for demo). Supports Docker in FortiManager, VMware, Hyper-V, and KVM hypervisors. | FWM-VM |
FortiWLM VM, FortiWLM 100D, and FortiWLM 1000D 50 AP Software License. Enables all features and functionality. | FWM-NM-50-A | |
FortiWLM VM, FortiWLM 100D, and FortiWLM 1000D 250 AP Software License. Enables all features and functionality. | FWM-NM-250-A | |
FortiWLM VM, FortiWLM 100D, and FortiWLM 1000D 2500 AP Software License. Enables all features and functionality. | FWM-NM-2500-A | |
24x7 FortiCare Contract | FC-10-WLMVM-248-02-DD | |
FortiPresence-VM | FortiPresence Analytics VM version. Consists of 2 VMs for installation. Per AP Licenses sold separately. | LIC-FPA-VM |
Per AP Perpetual License for FortiPresence-VM. | LIC-FPA-AP | |
50 AP Perpetual License for FortiPresence-VM | LIC-FPA-AP-50 | |
250 AP Perpetual License for FortiPresence-VM | LIC-FPA-AP-250 | |
500 AP Perpetual License for FortiPresence-VM | LIC-FPA-AP-500 | |
1000 AP Perpetual License for FortiPresence-VM | LIC-FPA-AP-1000 | |
24x7 FortiCare Contract | FC-10-FPAVM-248-02-DD | |
Training Services | NSE 6/Secure Wireless LAN (FortiWiFi, FortiGate, FortiAP) | FT-FWF |
NSE 6 Exam Voucher | NSE-EX-SPL6 | |
NSE 6 Exam Bundle | NSE-EX-BUN6 |
Additional Ordering Guides
- All: https://www.fortinet.com/resources/ordering-guides
- NGFW: https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/og-next-generation-firewall.pdf
- FortiAP: https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/og-wireless.pdf
- FortiSwitch: https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/og-fortiswitch.pdf
Frequently Asked Questions
What makes a FortiGate a LAN Edge Controller?
A FortiGate combines security enforcement, FortiAP management, FortiSwitch management and secure network fabric traffic into a unified whole — Security Driven Networking. Security is enforced not only at the perimeter, but extended out to the edge of the network — where the clients connect, or the LAN Edge of FortiAPs and FortiSwitches.
What is the difference between FortiGate Cloud and FortiLAN Cloud?
With FortiGate as a LAN Edge controller it manages the on-site FortiAPs and FortiSwitches, so FortiGate Cloud manages the LAN Edge devices via the managed FortiGate. For locations that need Fortinet LAN Edge devices that are not associated with a FortiGate (for whatever reason), FortiLAN Cloud can directly manage the FortiAPs and FortiSwitches.
How can an MSSP use FortiGate or FortiLAN Cloud with multiple customers?
They can add a multi-tenancy license to either, which will enable the creation of sub-accounts with full data isolation.
What are typical licenses for customer deployments with NGFW with FortiGates?
The Unified Threat Protection (UTP) and the Enterprise bundles, which provide extensive coverage for device-, content-, and web-based threats, comprehensively cover most customer use cases, or the SMB bundles for site requiring the smaller FortiGate models. See FortiGuard Security Services here.
What does the Enterprise bundle include?
The Enterprise bundle includes IPS, Advanced Malware Protection, Application Control, URL, DNS and Video Filtering, Antispam, Security Rating, IoT Detection, Industrial Security, FortiConverter Service, and FortiCare Premium. FortiGate cloud must be added when purchasing enterprise bundle.
What does the SMB Bundle include?
The SMB Protection bundle includes IPS, Advanced Malware Protection, Application Control, URL, DNS and Video Filtering, Antispam, plus FortiGate Cloud subscription and FortiCare Premium. FortiGate Cloud does not need to be added.
What does the UTP license include?
The UTP license includes IPS, advanced malware protection, application control, botnet DB, mobile malware, outbreak prevention, web and video filtering, Cloud Sandbox, secure DNS filtering, antispam service, and 24x7 support. For more information click here. FortiGate Cloud would need to be added.
Why the difference between "Tunnel vs Total" FortiAPs?
On a per SSID basis, FortiAPs can tunnel traffic back to the FortiGate for a full security stack inspection – the default behavior. However, some customer environments may have a need for local-only Wi-Fi or low inspection guest traffic. Under such circumstances, more FortiAPs.
How do I license FortiAPs and FortiSwitches on the FortiGate?
No need. There are no licensing limits for on any FortiGate for LAN Edge devices. Each one comes out of the box able to manage the full number of FortiAPs and FortiSwitches, with only the hardware-based limits above.
How many FortiAPs does my customer need?
Every physical site is different. Any FortiAP deployment should have a site survey and a wireless deployment plan from a capable Wi-fi engioneer to insure good coverage and performance over a site. As an estimate for planning purposes, most sites require approximately one for FortiAP for 1500 sq ft (150 sq m) and about 60 active devices per FortiAP (30 devices per service radio).
What is the difference between 4x4 vs 2x2?
MIMO is a feature of Wi-Fi that uses multiple antennas to send simultaneous signals and so increase throughput. However, the number of antennas must align on both the client and the FortiAP to maximize the potential benefits. Phones and tablets normally have one antenna, at most two, and so cannot take significant advantage of a 4x4 FortiAP vs a 2x2, while laptops, which usually have three antennas, get a significant boost from a 4x4 FortiAP. Of course, all FortiAPs work with all Wi-Fi client devices, so sometimes budget is the deciding factor or 2x2 performance is plenty. The FAP-831F is an 8x8 FortiAP that supports Multi-User MIMO, able to divide its multiple traffic streams among clients simultaneous, boosting total Wi-Fi performance and is meant for high density environments such as auditoriums and stadiums.