Especificaciones Técnicas Equipos de Red

Download as pdf or txt
Download as pdf or txt
You are on page 1of 7

DATASHEET

FortiGate -5000 Series ®

10-Gigabit Ready FortiGate Consolidated


Security Systems
Unmatched Performance, Scalability, and Security
FortiGate-5000 series chassis-based security systems offer unmatched
performance, reliability, and scalability for your high-speed service provider,
large enterprise or telecommunications carrier network. Native 10-GbE support
and a highly-flexible AdvancedTCA™ (ATCA)-compliant architecture enable the FortiOS™ 4.0 Software
FortiGate-5000 series to protect complex, multi-tenant cloud-based security-as- Redefines Networks Security
a-service and infrastructure-as-a-service environments. Purpose-built by Fortinet, FortiOS 4.0 is a purpose-built
the FortiGate-5000 series integrates modular carrier-class hardware components operating system that leverages
the power of specialized FortiASIC
with advanced FortiASIC™ acceleration and consolidated security from the hardware to offer increased levels
FortiOS™ operating system. of security and performance.
Fortinet developed FortiOS 4.0
Carrier-Class High-Performance Hardware software solely for FortiGate
consolidated security platforms.
By adding modular blades, a FortiGate-5000 series system can scale to deliver FortiOS software enables a
up to 480 Gbps of firewall throughput, the fastest throughput available, and up comprehensive suite of security
to 132 million concurrent sessions. Advanced networking blades such as the services – firewall, VPN, intrusion
FortiSwitch-5003B and FortiSwitch-5203B distribute traffic to multiple FortiGate prevention, anti-malware,
antispam, web filtering, application
security blades, enabling wire-speed firewall performance at 10-Gigabit Ethernet control, data loss prevention,
(10-GbE), GbE, and 10/100 link speeds. vulnerability management, and
endpoint network access control.
Modular Scalability
Since the FortiGate-5000 series hardware is composed of multiple security and The FortiASIC™ Advantage
networking blades, scalability for future growth comes standard. In addition, select FortiASIC processors power
FortiGate security blades feature Advanced Mezzanine Card (AMC) expansion bays FortiGate platforms. With exclusive
hardware, the purpose built, high-
for additional hardware-accelerated network interfaces, local disk-based storage, and performance network, security, and
security processing offloading to specialized hardware. With four chassis models and an content processors use intelligent
array of network and security options to choose from, FortiGate-5000 series systems and proprietary digital engines
scale easily with your business plans and security requirements into the future. to accelerate resource-intensive
security services.

Features Benefits
Hardware Accelerated Performance FortiASIC processors provide assurance that the
security device will not become a bottleneck in
the network

FortiGate-5020 System Additional Capacity on Demand Fortinet expansion slots provide greater flexibility
by supporting additional hardware-accelerated
ports and localized storage of event data

Unified Security Architecture FortiGate consolidated security provides better


FortiGate-5050 System protection and lowered costs over multiple point
security products

FortiGate-5140 System Centralized Management FortiManager and FortiAnalyzer centralized


management and reporting appliances simplify
the deployment, monitoring, and maintenance of
FortiGate-5060 System
your security infrastructure
Secure large enterprise, service provider, and carrier networks.
CENTRALIZED MANAGEMENT

CENTRALIZED REPORTING
Next-Generation Perimeter Security
VoI
Firewalls alone aren’t enough to block today’s P
VO
IP
MA CAL
blended threats. When single packets are CORPORATE NA L
GER
examined by point products with no concern LAN
for multi-vector attacks, blended threats often R&D

pass undetected. Combining content inspection


firewall technology with gateway antivirus SAL
ES
and intrusion prevention allows packet flows
to be tracked. Fortinet multi-layered security WE
SER B / EM
VER AI
S L
technologies examine entire packet flows,
from content inspection through reassembly, MULTI-THREAT SECURITY

stopping threats at the perimeter before


corporate resources are compromised.

AIL
EM S
E B / RVER
AIL W SE
EM S
B / RVER
E
W SE MSSP Core Security
The FortiGate-5000 Series delivers
AIL AIL
EM S
B / ER
WE SERV
EM S
B / ER
comprehensive security for Managed Security
WE SERV
GEM
ENT
G
Service Providers (MSSPs). The full suite of
NA
RTIN
TER ALIZED
MA
E DR
EPO ASIC-accelerated security modules allows for
CEN CEN
TR LIZ
DA
TA CEN
TRA
customizable features for specific customers,
while virtualization features like Virtual Domains
AIL
EM S
B / ER
WE SERV
(VDOMs) provides up to 3,000 separate security
domains. Finally, the full suite of Fortinet
Y
integrated management applications—including
RIT
ECU
REA
TS granular reporting features—offer unprecedented
I-TH
ULT
M visibility into the security posture of customers
while illustrating their highest risks.

Secure Messaging CENTRALIZED MANAGEMENT

Email is an essential corporate communication CENTRALIZED REPORTING

tool. Malware has adapted to this trend and


email is now a primary vector of transmission VO
IP
MA CAL
NA L
for malware threats. Instant messaging and CORPORATE GER
LAN
other social media are also quickly becoming
Vo
IP

a primary propagation vector as adoption


rates increase. As with any new technology,
Em
ai
l

IM introduces security risks in the form of


P2
IM

a new generation of malware that could


W SER
EB V

potentially infect corporate resources. By


/ E ERS
M
AI
L

combining Fortinet antispam technology, IM MULTI-THREAT SECURITY

and P2P controls, antivirus scanning, and Web


filtering, customers can secure email and other
messaging, preventing costly data breaches.
Technical Specifications FortiGate-5020 FortiGate-5050 FortiGate-5060 FortiGate-5140
ATCA Chassis
Available Slots 2 5 6 14
High Availability Backplane Fabric Built-in Built-in Built-in Built-in
Dual Switch Module Support No Yes Yes Yes
Firewall Throughput (Max) Up to 44 Gbps Up to 110 Gbps Up to 240 Gbps Up to 480 Gbps
IPSec VPN Throughput (Max) Up to 17 Gbps Up to 42.5 Gbps Up to 102 Gbps Up to 204 Gbps
Concurrent Firewall Sessions (Max) Up to 4 Million Up to 10 Million Up to 66 Million Up to 132 Million
Dimensions
Height 5.25 in (13.3 cm) 8.75 in 8.86 in (22 cm) 21 in (53.3 cm)
Width 17 in (43.2 cm) 17 in (43.2 cm) 17.64 in (44.8 cm) 19 in (48.3 cm)
Length 15.5 in (39.4 cm) 15.5 in (39.4 cm) 18.82 in (47.8 cm) 19 in (48.3 cm)
Weight 35.5 lb (16.1 Kg) 17.3 lb (7.85 Kg) 38 (17.3 Kg) 64.5 lb (29.3 Kg)
Environment
Power Required AC DC/AC1 DC DC/AC1
Power Consumption (AVG) - - 350 W 531 W
Heat Dissipation - - 1194 BTU/h 1812 BTU/h
Operating Temperature 32 – 104 deg F (0 – 40 deg C) 32 – 104 deg F (0 – 40 deg C) 41 – 104 deg F (5 – 40 deg C) 32 – 104 deg F (0 – 40 deg C)
Storage Temperature -13 – 158 deg F (-35 – 70 deg C) -13 – 158 deg F (-35 – 70 deg C) 23 – 131 deg F (-5 – 55 deg C) -13 – 158 deg F (-35 – 70 deg C)
Humidity 5 to 90% non-condensing 5 to 90% non-condensing 5 to 85% non-condensing 5 to 90% non-condensing
Compliance
FCC Class A Part 15, UL/CUL, C FCC Class A Part 15, UL/CUL, C FCC Class A Part 15, UL/CUL, C
Certifications -
Tick, VCCI Tick, VCCI Tick, VCCI
Note: All performance values are “up to” and vary depending on system configuration.
1
Optional FortiGate-5053 Power Supply Shelf used to provide AC power to the FortiGate-5050 or FortiGate-5140 chassis.

FortiGate-5020 Security System

The FortiGate-5000 series of consolidated FortiGate-5050 Security System


security systems also include
Multiple Deployment Modes (Transparent/Routing)
Backplane Switch Fabric
Advanced Layer-2/3 Routing Capabilities
High Availability (Active/Active, Active/Passive, Clustering)
Virtual Domains (VDOMs)
Data Center Traffic Optimization
Traffic Shaping and Prioritization FortiGate-5060 Security System FortiGate-5140 Security System
WAN Optimization
Multiple Device Authentication Options
Technical Specifications RTM-XD2 RTM-XB2
Management Options Rear Transition Modules
Wire-speed
Local Web-Based Management Interface Application 10-GbE backplane fabric
10-GbE backplane fabric
Command Line Management Interface (CLI) FortiASIC Hardware Acceleration FortiASIC NP4 FortiASIC NP2
Local Event Logging (Memory / Disk if available)
Compatible Chassis Models FortiGate-5140 and FortiGate-5050
Centralized Management (FortiManager Appliance Required)
Centralized Event Logging (FortiAnalyzer Appliance Required) Compatible Networking Blade FortiSwitch-5003A and FortiSwitch-5003B
Compatible Security Blades FortiGate-5001A-SW and FortiGate-5001A-DW
1 RTM-XD2 module per 1 RTM-XB2 module per
Configuration Notes
FortiGate security blade FortiGate security blade
Performance
RTM-XB2 Rear Transition Module Firewall Performance
20 Gbps 11 Gbps
(64, 512, 1518 byte UDP packets)
IPSec VPN 8 Gbps 8 Gbps
Environment
Power Consumption (AVG) 148 W
RTM-XD2 Rear Transition Module
Operating Temperature 32 – 104 deg F (0 – 40 deg C)
Rear Transition Modules Storage Temperature -13 – 158 deg F (-35 – 70 deg C)
Humidity 5 to 90% non-condensing
Provide enhanced 10-Gigabit Ethernet (10-GbE)
Compliance
backplane fabric connectivity to FortiGate systems. Certifications FCC Class A Part 15, UL/CUL, C Tick, VCCI
They include FortiASIC Network Processors for secure Note: All performance values are “up to” and vary depending on system configuration.
and low-latency communications.
FortiGate-5000 Series Security Blades
Provide core FortiOS-based security services to FortiGate systems.

FortiGate-5001SX Security Blade FortiGate-5001-DW Security Blade


(shown with optional ADM-XB2 Module)

FortiGate-5001FA2 Security Blade FortiGate-5001-SW Security Blade

FortiGate-5005FA2 Security Blade FortiGate-5001B Security Blade

Technical Specifications FortiGate-5001B FortiGate-5001A-DW FortiGate-5001A-SW FortiGate-5001SX FortiGate-5001FA2 FortiGate-5005FA2


Security Blades
SFP Ports 0 Requires AMC Module Requires AMC Module 4 4 8
SFP+ Ports (10-GbE) 8 Requires AMC Module Requires AMC Module 0 0 0
10/100/1000 Base-T Ports 2 2 2 4 4 0
Maximum Ports 10 10 6 4 4 8
FortiASIC Network Processor
8 Requires AMC Module Requires AMC Module - 2 2
Accelerated Ports
Local Storage 64 GB SSD - Requires AMC Module - - -
AMC-Based Expansion Slot - 1 Double-Width 1 Single-Width - - -
Performance
Firewall Throughput 40 Gbps 2 - 22 Gbps 1 2 - 13 Gbps 1 4 Gbps 4 Gbps 5 Gbps
IPSec VPN Throughput 17 Gbps 800 Mbps - 8.5 Gbps 1 800 Mbps - 7 Gbps 1 600 Mbps 600 Mbps 800 Mbps
IPS Throughput 5 Gbps 3.5 Gbps 3.5 Gbps 2 Gbps (UDP) 2 Gbps (UDP) 1.5 Gbps
Proxy Antivirus HTTP Throughput 1.5 Gbps 500 Mbps 500 Mbps 250 Mbps 250 Mbps 300 Mbps
Gateway-to-Gateway IPSec VPN Tunnels
10,000 / 5,000
(System / VDOM)
Client-to-Gateway IPSec VPN Tunnels 64,000 64,000 64,000 10,000 10,000 64,000
Concurrent Sessions (Max) 11 M 2M 2M 1M 1M 1M
New Sessions / Sec 96,000 50,000 50,000 20,000 20,000 30,000
SSL-VPN Users (Max) 25,000 5,000 5,000 2,000 2,000 3,000
SSL-VPN Throughput 530 Mbps 480 Mbps 480 Mbps 111 Mbps 119 Mbps 346 Mbps
Firewall Policies (Max) 100,000
Virtual Domains (Standard/Optional) 10 / 250
Unlimited User Licenses Yes
Environment
Power Consumption (AVG) 187 W 148 W 148 W 132 W 132 W 187 W
Heat Dissipation 639 BTU/h 505 BTU/h 505 BTU/h 451 BTU/h 451 BTU/h 639 BTU/h
Operating Temperature 32 – 104 deg F (0 – 40 deg C)
Storage Temperature -13 – 158 deg F (-35 – 70 deg C)
Humidity 5 to 90% non-condensing
Compliance
Certifications FCC Class A Part 15, UL/CUL, C Tick, VCCI
Note: All performance values are “up to” and vary depending on system configuration. Antivirus performance is benchmarked using HTTP traffic (32 Kbyte objects).
1 Higher performance number combines performance provided by AMC modules.
FortiGate-5000 Series Networking Blades
Provide advanced switching and load-balancing functions to FortiGate systems.

FortiSwitch-5203B Network Blade FortiSwitch-5003A Network Blade

FortiSwitch-5003B Network Blade

Technical Specifications FortiSwitch-5003A FortiSwitch-5003B FortiSwitch-5203B


Networking Blades
Fabric Channel Interfaces 8x 10-GbE SFP+ 8x 10-GbE SFP+ 8x 10-GbE SFP+
1x 10-GbE SFP+ 2x 10-GbE SFP+ 2x 10-GbE SFP+
Base Channel Interfaces
2x 10/100/1000 1x 10/100/1000 1x 10/100/1000
Transceivers Included 2x 10-GbE SFP+ SR 2x 10-GbE SFP+ SR 2x 10-GbE SFP+ SR
Total Switching Throughput 225 Gbps 225 Gbps 225 Gbps
Yes
10-GbE Backplane Fabric Support Yes Yes
(Requires RTM-XB2/RTM-XD2)
GbE Backplane Fabric Support Yes Yes Yes
Environment
Power Consumption (AVG) 148 W 150 W 210 W
Operating Temperature 32 – 104 deg F (0 – 40 deg C)
Storage Temperature -13 – 158 deg F (-35 – 70 deg C)
Humidity 5 to 90% non-condensing
Compliance
Certifications FCC Class A Part 15, UL/CUL, C Tick, VCCI

Security Processing Modules Bypass Modules Accelerated Interface Modules


Accelerate Intrusion Prevention and Provide power-failure bypass operation to Accelerate Firewall and VPN
Multicast applications. FortiGate system. applications.

ADM-XE2 Module ASM-CX4 Module ASM-FX2 Module ADM-XD4 Module

Storage Modules
ASM-CE4 Module
Enable FortiOS security and administration
ADM-XB2 Module
functions that require local storage.

ASM-S08 Module ADM-FB8 Module

ASM-FB4 Module

Note: See the respective module datasheet for complete technical specifications for AMC Modules.
Ordering Info
Chassis SKU Description
FortiGate-5020 Chassis FG-5020AC 2-slot chassis with fan and dual AC power supplies
FortiGate-5020 Fan Tray FG-5020FA Spare, Fan tray for FG-5020 chassis
FortiGate-5020/5050 Power Supply FG-5020PS FortiGate-5020/5050 power supply
FortiGate-5050 Chassis FG-5050-DC 5-slot chassis with fan, 1 shelf manager card, DC powered
FortiGate-5050 Fan Tray FG-5050FA Fan tray for FG-5050 chassis
FortiGate-5050 Shelf Manager FG-5050SM Shelf manager for FG-5050 chassis
FortiGate-5050 Shelf Alarm Panel FG-5050SAP Shelf alarm panel for FG-5050 chassis
FortiGate-5060 Chassis FG-5060-DC 6-slot chassis, 1 fan tray, 1 shelf manager, DC powered
FortiGate-5140 Chassis FG-5140-DC 14-slot chassis with fan, 1 shelf manager card, no power supply included, DC powered
FortiGate-5140 Power Supply FG-5140PS FortiGate-5140 power supply
FortiGate-5140 Shelf Manager FG-5140SM-12 Shelf manager for FG-5140 chassis
FortiGate-5140 SAP FG-5140SAP Self alarm panel for FG-5140 chassis
FortiGate-5140 Fan Tray FG-5140FA Spare, Fan Tray for FG-5140 Chassis
FortiGate-5053 Power Converter Tray FG-5053 Power converter shelf for FG-5000 series, no power supplies inlcuded
Security Blades SKU Description
FortiGate-5001 SX FG-5001SX Security blade with 4 10/100/1000 ports and 4 SFP ports (4 SX-type transceivers included)
Security blade with 4 10/100/1000 ports, 2 FortiASIC accelerated SFP ports (2 SX-type transceivers included), and 2
FortiGate-5001FA2 FG-5001FA2
non-accelerated SFP ports
Security blade with 2 FortiASIC-accelerated SFP ports (2 SX-type transceivers included) and 6 non-accelerated SFP
FortiGate-5005FA2 FG-5005FA2
ports
FortiGate-5001A-DW FG-5001A-DW Security blade with 2 10/100/1000 ports and 1 double-width AMC slot
FortiGate-5001A-SW FG-5001A-SW Security blade with 2 10/100/1000 ports and 1 single-width AMC slot
Security blade with 8 FortiASIC-accellerated SFP+ ports (2 SR-type SFP+ transceivers included) and onboard 64GB
FortiGate-5001B FG-5001B
SSD
Networking Blades SKU Description
Networking blade for FortiGate-5000 series with 8 SFP+ fabric ports, 1 SFP+ base port, 2 10/100/1000
FortiSwitch-5003A Network Blade FS-5003A
base ports
Networking blade for FortiGate-5000 series with 8 SFP+ fabric ports, 2 SFP+ base ports, 1 10/100/1000 management
FortiSwitch-5003B Network Blade FS-5003B
port, includes 2 SR SFP+ transceivers
Networking blade for FortiGate-5000 series with 8 SFP+ Fabric ports, 2 SFP+ base ports, 1 10/100/1000 management
FortiSwitch-5203B Network Blade FS-5203B
port, includes 2 SR SFP+ transceivers
Modules SKU Description
ASM-FB4 Module ASM-FB4 AMC Accelerated Interface Module, single-width, 4-port SFP, includes 4 SX SFP transceivers (Accelerated FW/VPN)
ASM-S08 Module ASM-S08 AMC Storage Module, single-width, 80 GB hard disk drive (Local Disk-Based Storage)
ASM-CX4 Module ASM-CX4 AMC Bypass Module, single-width, 4-port 10/100/1000 (Power Failure Bypass)
ASM-FX2 Module ASM-FX2 AMC Bypass Module, single-width, 2-port fiber bypass module, LC-type Connectors (Power Failure Bypass)
ASM-CE4 Module ASM-CE4 AMC Security Processing Module, single-width, 4-port 10/100/1000, (Accelerated IPS / Multicast)
ADM-FB8 Module ADM-FB8 AMC Accelerated Interface Module, double-width, 8-port SFP, includes 4 SX SFP transceivers (Accelerated FW/VPN)
AMC Accelerated Interface Module, double-width, two port 10-GbE XFP, includes 2 SR XFP transceivers (Accelerated
ADM-XB2 Module ADM-XB2
FW/VPN)
AMC Accelerated Interface Module, double-width, 4 port 10-GbE SFP+, includes 2 SR SFP+ transceivers (Accelerated
ADM-XD4 Module ADM-XD4
FW/VPN)
AMC Security Processing Module, double-width, 2 port 10-GbE XFP, accelerated IPS, includes 2 SR XFP transceivers
ADM-XE2 Module ADM-XE2
(Accelerated FW/VPN)
RTM-XB2 Module RTM-XB2 Rear Transition Module for FG-5000 series, 2 10-GbE internal ports for backplane fabric
RTM-XD2 Module RTM-XD2 Rear transition module for FG-5000 series, 2 10-GbE internal ports for backplane fabric
Other Accessories SKU Description
LX Transceiver Module FG-TRAN-LX Transceiver LX module for all FortiGate models with SFP interfaces
TX Transceiver Module FG-TRAN-GC Transceiver Base-T (Copper) module for all FortiGate models with SFP interfaces, supports 10/100/1000 operation
SX Transceiver Module FG-TRAN-SX Transceiver SX module for all FortiGate models with SFP interfaces
SFP+ Transceiver Module FG-TRAN-SFP+SR 10-GbE transceiver, short range SFP+ module for all FortiGate models with SFP+ interfaces
XFP Transceiver Module FG-TRAN-XFPSR 10-GbE transceiver, short range XFP module for all FortiGate models with XFP interfaces
SFP+ Long Range Transceiver Module FG-TRAN-SFP+LR 10-GbE transceiver, SFP+, Long Range
XFP Long Range Transceiver Module FG-TRAN-XFPLR 10-GbE transceiver, XFP, Long Range

FortiOS Security Services


FIREWALL ANTIVIRUS / ANTISPYWARE INTRUSION PREVENTION SYSTEM (IPS)
ICSA Labs Certified (Enterprise Firewall) ICSA Labs Certified (Gateway Antivirus) ICSA Labs Certified (NIPS)
NAT, PAT, Transparent (Bridge) Includes Antispyware and Worm Prevention: Protection From Over 3000 Threats
Routing Mode (RIP, OSPF, BGP, Multicast) HTTP/HTTPS SMTP/SMTPS Protocol Anomaly Support
Policy-Based NAT POP3/POP3S IMAP/IMAPS Custom Signature Support
Virtual Domains (NAT/Transparent mode) FTP IM Protocols Automatic Attack Database Update
VLAN Tagging (802.1Q) Flow-Based Antivirus Scanning Mode IPv6 Support
Group-Based Authentication & Scheduling Automatic “Push” Content Updates
SIP/H.323 /SCCP NAT Traversal File Quarantine Support APPLICATION CONTROL
WINS Support Databases: Standard, Extended, Extreme, Flow Identify and Control Over 1400 Applications
Explicit Proxy Support (Citrix/TS etc.) IPv6 Support Control Popular Apps Regardless of Port/Protocol:
VoIP Security (SIP Firewall/RTP Pinholing) AOL-IM Yahoo MSN KaZaa
Granular Per-Policy Protection Profiles ICQ Gnutella BitTorrent MySpace
Identity/Application-Based Policy WinNY Skype eDonkey Facebook
Vulnerability Management
IPv6 Support (NAT/Transparent mode)
FortiOS Security Services (cont.)
VIRTUAL PRIVATE NETWORK (VPN) WEB FILTERING DATA LOSS PREVENTION (DLP)
ICSA Labs Certified (IPSec) 76 Unique Categories Identification and Control Over Sensitive Data in Motion
PPTP, IPSec, and SSL Dedicated Tunnels FortiGuard Web Filtering Service Categorizes over 2 Billion Web Built-in Pattern Database
SSL-VPN Concentrator (incl. iPhone client support) pages RegEx-based Matching Engine for Customized Patterns
DES, 3DES, and AES Encryption Support HTTP/HTTPS Filtering Configurable Actions (block/log)
SHA-1/MD5 Authentication Web Filtering Time-Based Quota Supports IM, HTTP/HTTPS, and More
PPTP, L2TP, VPN Client Pass Through URL/Keyword/Phrase Block Many Popular File Types Supported
Hub and Spoke VPN Support URL Exempt List International Character Sets Supported
IKE Certificate Authentication (v1 & v2) Content Profiles
IPSec NAT Traversal Blocks Java Applet, Cookies, Active X ANTISPAM
Automatic IPSec Configuration MIME Content Header Filtering Support for SMTP/SMTPS, POP3/POP3S, IMAP/IMAPS
Dead Peer Detection IPv6 Support Real-Time Blacklist/Open Relay Database Server
RSA SecurID Support MIME Header Check
SSL Single Sign-On Bookmarks HIGH AVAILABILITY (HA) Keyword/Phrase Filtering
SSL Two-Factor Authentication Active-Active, Active-Passive IP Address Blacklist/Exempt List
LDAP Group Authentication (SSL) Stateful Failover (FW and VPN) Automatic Real-Time Updates From FortiGuard Network
Device Failure Detection and Notification
NETWORKING/ROUTING Link Status Monitor ENDPOINT COMPLIANCE AND CONTROL
Multiple WAN Link Support Link failover Monitor & Control Hosts Running FortiClient Endpoint Security
PPPoE Support Server Load Balancing
DHCP Client/Server LOGGING/MONITORING/VULNERABILITY
Policy-Based Routing WAN OPTIMIZATION Local Event Logging
Dynamic Routing for IPv4 and IPv6 (RIP, OSPF, BGP, & Multi- Bi-directional / Gateway to Client/Gateway Log to Remote Syslog/WELF Server
cast for IPv4) Integrated Caching and Protocol Optimization Graphical Real-Time and Historical Monitoring
Multi-Zone Support Accelerates CIFS/FTP/MAPI/HTTP/HTTPS/Generic TCP SNMP Support
Route Between Zones Email Notification of Viruses And Attacks
Route Between Virtual LANs (VDOMS) VIRTUAL DOMAINS (VDOMs) VPN Tunnel Monitor
Multi-Link Aggregation (802.3ad) Separate Firewall/Routing Domains Optional FortiAnalyzer Logging / Reporting
IPv6 Support (Firewall, DNS, Transparent Mode, SIP, Dynamic Separate Administrative Domains Optional FortiGuard Analysis and Management Service
Routing, Admin Access, Management) Separate VLAN Interfaces
VRRP and Link Failure Control 10 VDOM License Std. (more can be added) MANAGEMENT/ADMINISTRATION
sFlow Client
Console Interface (RS-232)
TRAFFIC SHAPING WebUI (HTTP/HTTPS)
USER AUTHENTICATION OPTIONS Policy-based Traffic Shaping Telnet / Secure Command Shell (SSH)
Local Database Application-based and Per-IP Traffic Shaping Command Line Interface
Windows Active Directory (AD) Integration Differentiated Services (DiffServ) Support Role-Based Administration
External RADIUS/LDAP Integration Guarantee/Max/Priority Bandwidth Multi-language Support: English, Japanese, Korean, Spanish,
Xauth over RADIUS for IPSEC VPN Shaping via Accounting, Traffic Quotas Chinese (Simplified & Traditional), French
RSA SecurID Support Multiple Administrators and User Levels
LDAP Group Support Upgrades and Changes via TFTP and WebUI
WIRELESS CONTROLLER
Unified WiFi and Access Point Management System Software Rollback
DATA CENTER OPTIMIZATION Automatic Provisioning of APs Configurable Password Policy
Web Server Caching Optional FortiManager Central Management
On-wire Detection and Blocking of Rogue APs
TCP Multiplexing
Virtual APs with Different SSIDs
HTTPS Offloading
Multiple Authentication Methods
WCCP Support

Note: The list above is comprehensive and may contain FortiOS features which are not available on all FortiGate appliances.
Consult FortiGate system documentation to determine feature availability.

FortiGuard® Security Subscription Services deliver dynamic, automated updates for Fortinet products. The Fortinet Global Security
Research Team creates these updates to ensure up-to-date protection against sophisticated threats. Subscriptions include antivirus,
intrusion prevention, web filtering, antispam, vulnerability and compliance management, application control, and database security services.

FortiCare™ Support Services provide global support for all Fortinet products and services. FortiCare support enables your Fortinet products
to perform optimally. Support plans start with 8x5 Enhanced Support with return and replace hardware support or 24x7 Comprehensive
Support with advanced hardware replacement. Options include Premium Support, Premium RMA, and Professional Services. All hardware
products include a 1-year limited hardware warranty and a 90-day limited software warranty.

COMMON CRITERIA
EAL 4+ CERTIFIED

GLOBAL HEADQUARTERS EMEA SALES OFFICE – FRANCE APAC SALES OFFICE – SINGAPORE
Fortinet Incorporated Fortinet Incorporated Fortinet Incorporated
1090 Kifer Road, Sunnyvale, CA 94086 USA 120 rue Albert Caquot 300 Beach Road #20-01
Tel +1.408.235.7700 06560, Sophia Antipolis, France The Concourse, Singapore 199555
Fax +1.408.235.7737 Tel +33.4.8987.0510 Tel: +65-6513-3734
www.fortinet.com/sales Fax +33.4.8987.0501 Fax: +65-6295-0015

Copyright© 2011 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, and FortiGuard®, are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be trademarks of Fortinet. All other product or company names may be trademarks of
their respective owners. Performance metrics contained herein were attained in internal lab tests under ideal conditions, and performance may vary. Network variables, different network environments and other conditions may affect performance results. Nothing
herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser that expressly warrants
that the identified product will perform according to the performance metrics herein. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any guarantees. Fortinet
reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable. Certain Fortinet products are licensed under U.S. Patent No. 5,623,600.
FG-5000-DAT-R8-201109

You might also like