FortiGate 2200E Series Data Sheet

2y ago
40 Views
3 Downloads
728.43 KB
6 Pages
Last View : Today
Last Download : 5m ago
Upload by : Amalia Wilborn
Transcription

DATA SHEETNext Generation FirewallSegmentationSecure Web GatewayIPSMobile SecurityFortiGate 2200E Series FG-2200E and 2201EThe FortiGate 2200E series delivers high performance next generation firewall (NGFW) capabilitiesfor large enterprises and service providers. With multiple high-speed interfaces, high-port density, andhigh-throughput, ideal deployments are at the enterprise edge, hybrid data center core, and across internalsegments. Leverage industry-leading IPS, SSL inspection, and advanced threat protection to optimizeyour network’s performance.Fortinet’s Security-Driven Networking approach provides tight integration ofthe network to the new generation of security.Security§ Identifies thousands of applications inside network traffic fordeep inspection and granular policy enforcement§ Protects against malware, exploits, and malicious websites inboth encrypted and non-encrypted traffic§ Prevents and detects against known attacks using continuousthreat intelligence from AI-powered FortiGuard Labs securityservices§ Proactively blocks unknown sophisticated attacks in realtime with the Fortinet Security Fabric integrated AI-poweredFortiSandboxPerformance§ Engineered for Innovation using Fortinet’s purpose-built securityprocessors (SPU) to deliver the industry’s best threat protectionperformance and ultra-low latency§ Provides industry-leading performance and protection for SSLencrypted traffic including the first firewall vendor to provideTLS 1.3 deep inspectionCertification§ Independently tested and validated best security effectivenessand performance§ Received unparalleled third-party certifications from NSS Labs,ICSA, Virus Bulletin, and AV ComparativesNetworking§ Application aware routing with in-built SD-WAN capabilities toachieve consistent application performance and the best userexperience§ Built-in advanced routing capabilities to deliver highperformance with encrypted IPSEC tunnels at scaleManagement§ Includes a management console that is effective and simple touse, which provides a comprehensive network of automation &visibility§ Provides Zero Touch Provisioning leveraging Single Paneof Glass Management powered by the Fabric ManagementCenter§ Predefined compliance checklists analyze the deployment andhighlight best practices to improve the overall security postureSecurity Fabric§ Enables Fortinet and Fabric-ready partners’ products to providebroader visibility, integrated end-to-end detection, threatintelligence sharing, and automated remediation§ Automatically builds Network Topology visualizations whichdiscover IoT devices and provide complete visibility into Fortinetand Fabric-ready partner productsFirewallIPSNGFWThreat ProtectionInterfaces158 Gbps16.5 Gbps13.5 Gbps11 GbpsMultiple GE RJ45, 10 GE SFP , 25 GE SFP28, and40 GE QSFP slotsRefer to the specifications table for details

DATA SHEET FortiGate 2200E SeriesDeploymentNext Generation Firewall (NGFW)§ Reduce the complexity and maximize your ROI by integratingthreat protection security capabilities into a single highperformance network security appliance, powered by Fortinet’sSecurity Processing Unit (SPU)§ Full visibility into users, devices, applications across the entireattack surface and consistent security policy enforcementirrespective of asset location§ Protect against network exploitable vulnerabilities with Industryvalidated IPS security effectiveness, low latency and optimizednetwork performance§ Automatically block threats on decrypted traffic using theIPS§ Purpose-built security processors delivering industry validatedIPS performance with high throughput and low latency§ Deploy virtual patches at the network level to protect againstnetwork exploitable vulnerabilities and optimize networkprotection time§ Deep packet inspection at wire speeds offers unparalleled threatvisibility into network traffic including traffic encrypted with thelatest TLS 1.3§ Proactively block newly discovered sophisticated attacks in realtime with advanced threat protection provided by the intelligenceservices of the Fortinet Security FabricIndustry’s highest SSL inspection performance, includingthe latest TLS 1.3 standard with mandated ciphers§ Proactively block newly discovered sophisticated attacks inreal-time with AI-powered FortiGuard Labs and advanced threatprotection services included in the Fortinet Security FabricMobile Security for 4G, 5G, and IOT§ SPU accelerated, high performance CGNAT and IPv6 migrationoption including: NAT44, NAT444, NAT64/DNS64, NAT46 for 4GGi/sGi and 5G N6 connectivity and securitySegmentation§ Segmentation that adapts to any network topology, deliveringend-to-end security from the branch level to data centers andextending to multiple clouds§ Reduce security risks by improving network visibility from thecomponents of the Fortinet Security Fabric, which adapt access§ RAN Access Security with highly scalable and best performingIPsec aggregation and control security gateway (SecGW)§ User plane security enabled by full Threat Protection and visibilityinto GTP-U inspection§ 4G and 5G security for user and data plane traffic includingSCTP, GTP-U and SIP that provides protection against attacks§ High-speed interfaces to enable deployment flexibilitypermissions to current levels of trust and enforce access controleffectively and efficiently§ Delivers defense in depth security powered by high-performanceL7 inspection and remediation by Fortinet’s SPU, while deliveringthird party validated TCO of per protected Mbps§ Protects critical business applications and helps implement anycompliance requirements without network redesignsSecure Web Gateway (SWG)§ Secure web access from both internal and external risks, evenFortiClientVPN ClientDATACENTERFortiGateIPS, SegmentationFortiGateNGFWfor encrypted traffic at high performance§ Enhanced user experience with dynamic web and video caching§ Block and control web access based on user or user groupsacross URL’s and domains§ Prevent data loss and discover user activity to known andFortiManagerAutomation-DrivenNetwork ManagementFortiAnalyzerAnalytics-poweredSecurity & Log Managementunknown cloud applications§ Block DNS requests against malicious domains§ Multi-layered advanced protection against zero-day malwarethreats delivered over the web2FortiGate 2200E deployment in data center(NGFW, IPS, and Intent-based Segmentation)

DATA SHEET FortiGate 2200E SeriesHardwareFortiGate 18202223252729HA13124262830HA23233FortiGate 2200ESTATUSALARMHAPOWERUSBCONSOLE1 2345SFP 6QSFP 347CAUTION/ATTENTIONFAN1FAN2FAN3FAN4SHOCK HAZARD. DISCONNECTALL POWER SOURCES.RISQUE D’ÉLECTROCUTION.DÉBRANCHEZ TOUTES LESSOURCES es1.2.3.4.USB PortConsole Port2x GE RJ45 MGMT Ports12x GE RJ45 Ports5. 18x 25 GE SFP28 / 10 GE SFP Slots6. 2x 25 GE SFP28 / 10 GE SFP HA Slots7. 4x 40 GE QSFP SlotsNetwork ProcessorPowered by SPUFortinet’s new, breakthrough SPU NP6 network processor works§ Custom SPU processors deliver the§ Superior firewall performance for IPv4/IPv6, SCTP, and multicastpower you need to detect maliciouscontent at multi-Gigabit speeds§ Other security technologies cannot protect againsttoday’s wide range of content- and connection-basedthreats because they rely on general-purpose CPUs,causing a dangerous performance gap§ SPU processors provide the performance neededto block emerging threats, meet rigorous third-partycertifications, and ensure that your network securitysolution does not become a network bottleneckinline with FortiOS functions delivering:traffic with ultra-low latency down to 2 microseconds§ VPN, CAPWAP, and IP tunnel acceleration§ Anomaly-based intrusion prevention, checksum offload, andpacket defragmentation§ Traffic shaping and priority queuingContent ProcessorFortinet’s new, breakthrough SPU CP9 content processor worksoutside of the direct flow of traffic and accelerates the inspection ofcomputationally intensive security features:§ Enhanced IPS performance with the unique capability of fullsignature matching at SPU§ SSL Inspection capabilities based on the latest industrymandated cipher suites§ Encryption and decryption offloadingHigh-Speed ConnectivityHigh-speed connectivity is essential for network securitysegmentation at the core of data networks. The FortiGate 2200Eseries provides 40 GE and 25 GE interfaces, simplifying networkdesigns without relying on additional devices to bridge desiredconnectivity.3

DATA SHEET FortiGate 2200E SeriesFortinet Security FabricSecurity FabricThe Security Fabric is the cybersecurity platform that enables digitalinnovations. It delivers broad visibility of the entire attack surface tobetter manage risk. Its unified and integrated solution reduces thecomplexity of supporting multiple-point products, while automatedworkflows increase operational speeds and reduce response timesacross the Fortinet deployment ecosystem. The Fortinet SecurityFabric overs the following key areas under a single managementcenter:§ Security-Driven Networking that secures, accelerates, andunifies the network and user experience§ Zero Trust Network Access that identifies and secures usersand devices in real-time, on and off of the network§ Dynamic Cloud Security that protects and controls cloudinfrastructures and applications§ AI-Driven Security Operations that automatically prevents,detects, isolates, and responds to cyber threatsFortiOSFortiGates are the foundation of the Fortinet Security Fabric—the§ Control thousands of applications, block the latest exploits, andcore is FortiOS. All security and networking capabilities across thefilter web traffic based on millions of real-time URL ratings inentire FortiGate platform are controlled with one intuitive operatingaddition to true TLS 1.3 support.system. FortiOS reduces complexity, costs, and response times by§ Automatically prevent, detect, and mitigate advanced attackstruly consolidating next-generation security products and serviceswithin minutes with an integrated AI-driven security and advancedinto one platform.§ A truly consolidated platform with a single OS and pane-of-glassfor across the entire digital attack surface.§ Industry-leading protection: NSS Labs Recommended, VB100,AV Comparatives, and ICSA validated security and performance.§ Leverage the latest technologies such as deception-basedthreat protection.§ Improve and unify the user experience with innovative SD-WANcapabilities with the ability to detect, contain, and isolate threatswith automated segmentation.§ Utilize SPU hardware acceleration to boost network securityperformance.security.ServicesFortiGuard Security ServicesFortiCare Support ServicesFortiGuard Labs offer real-time intelligence on the threat landscape,Our FortiCare customer support team provides global technicaldelivering comprehensive security updates across the full rangesupport for all Fortinet products. With support staff in the Americas,of Fortinet’s solutions. Comprised of security threat researchers,Europe, Middle East, and Asia, FortiCare offers services to meet theengineers, and forensic specialists, the team collaborates with theneeds of enterprises of all sizes.world’s leading threat monitoring organizations and other networkand security vendors, as well as law enforcement agencies.4For more information, please refer to forti.net/fortiguardand forti.net/forticare

DATA SHEET FortiGate 2200E SeriesSpecificationsFORTIGATE 2200EFORTIGATE 2201EInterfaces and ModulesFORTIGATE 2200EHardware Accelerated 40 GE QSFP Slots4Height x Width x Length (inches)Hardware Accelerated 25 GE SFP28 /10 GE SFP HA Slots2Height x Width x Length (mm)Hardware Accelerated 25 GE SFP28 /10 GE SFP Slots18Hardware Accelerated GE RJ45 Ports12GE RJ45 Management Ports2USB Port1Console Port1Onboard StorageIncluded TransceiversWeight–Form Factor (supports EIA/non-EIA standards)Power InputPower Consumption (Average / Maximum)Current (Maximum)Heat Dissipation2x 1 TB SSD2x SFP (SR 10 GE)System Performance — Enterprise Traffic MixIPS Throughput2NGFW Throughput 2, 4Threat Protection Throughput 2, 516.5 Gbps13.5 Gbps11 GbpsSystem Performance and CapacityIPv4 Firewall Throughput(1518 / 512 / 64 byte, UDP)158 / 155 / 100 GbpsIPv6 Firewall Throughput(1518 / 512 / 86 byte, UDP)158 / 155 / 100 GbpsFirewall Latency (64 byte, UDP)150 MppsConcurrent Sessions (TCP)24 MillionNew Sessions/Second (TCP)500,000Firewall Policies100,000IPsec VPN Throughput (512 byte) 198 GbpsGateway-to-Gateway IPsec VPN Tunnels20,000Client-to-Gateway IPsec VPN Tunnels100,000SSL-VPN Throughput10 GbpsConcurrent SSL-VPN Users(Recommended Maximum, Tunnel Mode)30,000SSL Inspection Throughput (IPS, avg. HTTPS) 317 Gbps2.5 MillionApplication Control Throughput (HTTP 64K) 252 GbpsCAPWAP Throughput (HTTP 64K)60 GbpsVirtual Domains (Default / Maximum)10 / 500Maximum Number of FortiSwitches Supported196Maximum Number of FortiAPs (Total / Tunnel)4,096 / 2,048High Availability Configurations88.9 x 443 x 55640.0 lbs (18.2 kg)41.4 lbs (18.8 kg)Rack Mount, 2 RU100–240V AC, 50–60 Hz408 W / 571 W412 W / 577 W12A@100V, 9A@240V1948 BTU/h1968 BTU/hYes, Hot swappableOperating Environment and CertificationsOperating Temperature32–104 F (0–40 C)Storage Temperature-31–158 F (-35–70 C)Humidity10–90% non-condensingNoise LevelOperating Altitude70 dBAUp to 7,400 ft (2,250 m)ComplianceFCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CBCertificationsICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN;USGv6/IPv69,500SSL Inspection Concurrent Session(IPS, avg. HTTPS) 3Maximum Number of FortiTokensRedundant Power Supplies3.5 x 17.44 x 21.894 μsFirewall Throughput (Packet per Second)SSL Inspection CPS (IPS, avg. HTTPS) 3FORTIGATE 2201EDimensions and Power20,000Active-Active, Active-Passive, ClusteringNote: All performance values are “up to” and vary depending on system configuration.1. IPsec VPN performance test uses AES256-SHA256.2. IPS (Enterprise Mix), Application Control, NGFW, and Threat Protection are measured with Logging enabled.3. SSL Inspection performance values use an average of HTTPS sessions of different cipher suites.4. NGFW performance is measured with Firewall, IPS, and Application Control enabled.5. Threat Protection performance is measured with Firewall, IPS, Application Control, and MalwareProtection enabled.5

DATA SHEET FortiGate 2200E SeriesOrder InformationProductSKUDescriptionFortiGate 2200EFG-2200E4x 40 GE QSFP slots, 20x 25 GE SFP28 slots (including 18x ports, 2x HA ports), 14x GE RJ45 ports(including 12x ports, 2x management ports), SPU NP6 and CP9 hardware accelerated, and dual AC power supplies.FortiGate 2201EFG-2201E4x 40 GE QSFP slots, 20x 25 GE SFP28 slots (including 18x ports, 2x HA ports), 14x GE RJ45 ports(including 12x ports, 2x management ports), SPU NP6 and CP9 hardware accelerated, and dual AC power supplies,with 2x 1 TB SSD onboard storage.Optional Accessories/SparesSKUDescription10 GE SFP Transceiver Module, Short RangeFG-TRAN-SFP SR10 GE SFP transceiver module, short range for all systems with SFP and SFP/SFP slots.10 GE SFP Transceiver Module, Long RangeFG-TRAN-SFP LR10 GE SFP transceiver module, long range for all systems with SFP and SFP/SFP slots.10 GE SFP Active Direct Attach Cable, 10m / 32.8 ftSP-CABLE-ADASFP 10 GE SFP active direct attach cable, 10m / 32.8 ft for all systems with SFP and SFP/SFP slots.25 GE SFP28 Transceiver Module, Long RangeFG-TRAN-SFP28-LR25 GE SFP28 transceiver module, long range for all systems with SFP28 slots.25 GE/10 GE Dual Rate SFP28 Transceiver Module, Short RangeFG-TRAN-SFP28-SR25 GE/10 GE dual rate SFP28 transceiver module, short range for all systems with SFP28/SFP slots.40 GE QSFP Transceivers, Short RangeFG-TRAN-QSFP SR40 GE QSFP transceivers, short range for all systems with QSFP slots.40 GE QSFP Transceivers, Short Range, BiDiFG-TRAN-QSFP SR-BIDI40 GE QSFP transceivers, short range BiDi for systems with QSFP slots.40 GE QSFP Transceivers, Long RangeFG-TRAN-QSFP LR40 GE QSFP transceivers, long range for all systems with QSFP slots.40 GE QSFP to 4x 10GE SFP Optical BreakoutFG-TRAN-QSFP 4XSFP40GE QSFP Parallel Breakout Active Optical Cable with 1m length for all systems with QSFP slots.QSFP to 4xSFP Optical breakout 5mFG-TRAN-QSFP 4SFP-540G QSFP Parallel Breakout MPO to 4xLC connectors, 5m reach, transceivers not included.Rack Mount Sliding RailsSP-FG3040B-RAILRack mount sliding rails for FG-1000C/-DC, FG-1100/1101E, FG-1200D, FG-1500D/-DC, FG-2000E,FG-2200E/2201E, FG-2500E, FG-3040B/-DC, FG-3140B/-DC, FG-3240C/-DC, FG-3000D/-DC, FG-3100D/-DC,FG-3200D/-DC, FG-3300E/3301E, FG-3400/3401E, FG-3600/3601E, FG-3700D/-DC, FG-3700DX, FG-3810D/-DCand FG-3950B/-DC.AC Power SupplySP-FG3800D-PSAC power supply for FG-2200/2201E, FG-3300/3301E, FG-3400/3401E, FG-3600/3601E, FG-3700D,FG-3700D-NEBS, FG-3700DX, FG-3810D and FG-3815D.BundlesFortiGuardBundleFortiGuard Labs delivers anumber of security intelligenceservices to augment theFortiGate firewall platform.You can easily optimize theprotection capabilities of yourFortiGate with one of theseFortiGuard ified ThreatProtectionThreatProtectionFortiCare24x7ASE 124x724x7FortiGuard App Control Service FortiGuard IPS Service FortiGuard Advanced Malware Protection (AMP) — Antivirus, Mobile Malware,Botnet, CDR, Virus Outbreak Protection and FortiSandbox Cloud Service FortiGuard Web Filtering Service FortiGuard Antispam Service FortiGuard Security Rating Service FortiGuard Industrial Service FortiGuard IoT Detection Service 2 FortiConverter Service IPAM Cloud 2 SD-WAN Orchestrator Entitlement 2 SD-WAN Cloud Assisted Monitoring SD-WAN Overlay Controller VPN Service FortiAnalyzer Cloud FortiManager Cloud 1. 24x7 plus Advanced Services Ticket Handling2. Available when running FortiOS 6.4

IPsec VPN Throughput (512 byte) 1 98 Gbps Gateway-to-Gateway IPsec VPN Tunnels 20,000 Client-to-Gateway IPsec VPN Tunnels 100,000 SSL-VPN Throughput 10 Gbps Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) 30,000 SSL Inspection Throughput (IPS, avg. HTTPS) 3 17 Gbps SSL Inspection CPS (IPS, avg. HTTPS) 3 9,500 SSL Inspection .

Related Documents:

Expected Life Span 3-5 years License cost Perpetual License for life. Fortinet Confidential Initial Setup. Fortinet Confidential . FortiGate-50B FortiGate-50B 20 FortiGate- 60B/C FortiGate-80C 500 FortiGate -110C/111C FortiGate-200B FortiGate-310 FortiGate-620 FortiGate-800 1000 FortiGate-1240 FortiGate-3016B

Mar 14, 2021 · Datasheet Fortigate-60D CP0 FortiSOC2 1 1839 3879 n/a Fortigate 60D datasheet FortiWiFi-60E SOC3 ARMv7 4 1863 3662 (EMMC) n/a Fortigate 60E datasheet Fortigate-60E SOC3 ARMv7 4 1866 3662 (EMMC) n/a Fortigate 60E datasheet FortiGate-61E SOC3 ARMv7 4 1866 3662 (EMMC) 122104 Fortigate

FortiGate-100D FortiGate-3700D/DX FortiGate-100E/EF FortiGate-3810D FortiGate-101E FortiGate-3815D FortiGate-140D FortiGate-3950D . Manual Bootdevice AESencrypted UsedtogenerateIKE protocolkeys ByerasingtheBoot deviceandpower cyclingthemodule

FortiGate Rugged 30D FortiGate Rugged 35D FortiGate Rugged 60D FortiGate Rugged 90D Product SKU Description FortiGate Rugged 30D FGR-30D Ruggedized, 4x GE RJ45 ports, 2x GE SFP slots, 2x DB9 Serial. Maximum managed FortiAPs (Total / Tunnel) 2 / 2. FortiGate Rugged 35D FGR-35D Ruggedized,

FortiGate Rugged 30D FortiGate Rugged 35D FortiGate Rugged 60D FortiGate Rugged 90D Product SKU Description FortiGate Rugged 30D FGR-30D Ruggedized, 4x GE RJ45 ports, 2x GE SFP slots, 2x DB9 Serial. Maximum managed FortiAPs (Total / Tunnel) 2 / 2. FortiGate Rugged 35D FGR-35D Ruggedized, IP67 rating for outdoor environment, 3x GE RJ45 Switch ports.

The information in this guide applies to all FortiGate un its. All FortiGate models except the FortiGate-30B model support VDOMs, and all FortiGate models support VLANs. By default, your FortiGate unit supports a maximum of 10 VDOMs in any combination of NAT/Route and Transparent operating modes. For FortiGate models numbered

FORTIGATE 200D FORTIGATE 200D-POE FORTIGATE 240D FORTIGATE 240D-POE FORTIGATE 280D-POE Hardware Specifications GE RJ45 WAN Interfaces 2 2 2 2 2 GE RJ45 LAN Interfaces 16 8 40 16 52 GE RJ45 PoE LAN Interfaces – 8 – 24 32 GE SFP DMZ Interfaces 2 2

FortiGate 2 5 SPECIFICATIONS FORTIGATE 200D-POE FORTIGATE 240D FORTIGATE 240D-POE FORTIGATE 280D-POE Hardware Specifications GE RJ45 WAN Interfaces 2 2 2 2 GE RJ45 LAN Interfaces 8 40 16 52 . FG-400D, FG-500D, FG-600D, FHV-500D, FDD-