Description
Fortinet FortiGate-6500F/FortiGate-6501F Nairobi
Digital enterprises are processing vast amounts of encrypted traffic and content rich data along with an increased emphasis on optimized user experiences. The digital attack surface has spawned new, complex forms of attacks that require advanced protection to be applied at anytime, anywhere the threat is discovered. Today’s next-generation firewalls (NGFWs) must reliably handle large volumes of network and cloud traffic, provide consolidated advanced security in a smaller, more efficient physical footprint, and accommodate new security requirements such as extensive inspection of encrypted traffic for sophisticated malware without impacting performance.
The new Fortinet firewall FortiGate 6000 NGFW appliances feature the latest Fortinet innovation, to deliver leading edge security, performance, and connectivity for the most demanding network needs. The 6000 series combines unprecedented threat protection and SSL inspection performance in an easy to manage, compact appliance.
Fortinet firewall FortiGate-6500F in Nairobi identifies thousands of applications inside network traffic for deep inspection and granular policy enforcement. It not only protects your network system against malware, exploits, and malicious websites in both encrypted and non-encrypted traffic, but also prevents and detects against known attacks using continuous threat intelligence from AI-powered FortiGuard Labs security services. It also proactively blocks unknown sophisticated attacks in real-time with the Fortinet Security Fabric integrated AI-powered FortiSandbox.
Fortinet FG-6500F/FG-6501F Features :
-
Security :
- Fortinet FG-6500F/ FG-6501F identifies thousands of applications inside network traffic for deep inspection and granular policy enforcement, then protects the network system against malware, exploits, and malicious websites in both encrypted and non-encrypted traffic. It also detects known attacks using continuous threat intelligence from AI-powered FortiGuard Labs security services. The Fortinet FG-6500F/ FG-6501F proactively blocks unknown sophisticated attacks in real-time with the Fortinet Security Fabric integrated AI-powered FortiSandbox.
-
Performance
- Fortinet FG-6500F/ FG-6501F is built for Innovation using Fortinet’s purpose-built security processors (SPU) to deliver the industry’s best threat protection performance and ultra-low latency. It provides industry-leading performance and protection for SSL encrypted traffic including the first firewall vendor to provide TLS 1.3 deep inspection.
-
Certification
- Fortinet FG-6500F/ FG-6501F has been independently tested and validated for best security effectiveness and performance. It has received unparalleled third-party certifications from NSS Labs, ICSA, Virus Bulletin, and AV Comparatives.
-
Networking
- Fortinet FG-6500/ FG-6501F incorporates Application aware routing with in-built SD-WAN capabilities to achieve consistent application performance and the best user experience. It has built-in advanced routing capabilities which deliver high performance with encrypted IPSEC tunnels at scale.
-
Management
- Fortinet FG-6500/ FG-6501F includes a management console that is effective and simple to use, which provides a comprehensive network of automation & visibility. It provides Zero Touch Provisioning leveraging Single Pane of Glass Management powered by the Fabric Management Center, and uses a set of predefined compliance checklists analyze the deployment and highlight best practices to improve the overall security posture.
-
Security Fabric
- Fortinet FG-6500/ FG-6501F enables Fortinet and Fabric-ready partners’ products to provide broader visibility, integrated end-to-end detection, threat intelligence sharing, and automated remediation. It automatically builds Network Topology visualizations which discover IoT devices and provide complete visibility into Fortinet and Fabric-ready partner products.
-
Next Generation Firewall (NGFW)
- Fortinet FG-6500/ FG-6501F reduces complexity and maximizes your ROI by integrating threat protection security capabilities into a single high performance network security appliance, powered by Fortinet’s Security Processing Unit (SPU). It offers full visibility into users, devices, applications across the entire attack surface and consistent security policy enforcement irrespective of asset location. The robust firewall protects your network system against network exploitable vulnerabilities with Industry validated IPS , resulting in security effectiveness, low latency and optimized network performance. It automatically block threats on decrypted traffic using the Industry’s highest SSL inspection performance, including the latest TLS 1.3 standard with mandated ciphers, and also proactively block newly discovered sophisticated attacks in real-time with AI-powered FortiGuard Labs and advanced threat protection services included in the Fortinet Security Fabric.
-
IPS
- Fortinet FG-6500F/ FG- 6501F uses its purpose-built security processors delivering industry validated IPS performance with high throughput and low latency. It deploys virtual patches at the network level to protect against network exploitable vulnerabilities and optimize network protection time. Deep packet inspection at wire speeds offers unparalleled threat visibility into network traffic including traffic encrypted with the latest TLS 1.3.
-
Segmentation
- Fortinet FG – 6500F/ FG-6501F boasts of a segmentation feature that adapts to any network topology, delivering end-to-end security from the branch level to data centers and extending to multiple clouds. Segmentation reduces security risks by improving network visibility from the components of the Fortinet Security Fabric, which adapt access permissions to current levels of trust and enforce access control effectively and efficiently. It also delivers defense in depth security powered by high-performance L7 inspection and remediation by Fortinet’s SPU, while delivering third party validated TCO of per protected Mbps, and also protects critical business applications and helps implement any compliance requirements without network redesigns.
-
Mobile Security for 4G, 5G, and IOT
- Fortinet FG-6500F/ FG-6501F is equipped with standard features including SPU acceleration, high performance CGNAT and IPv6 migration option including: NAT44, NAT444, NAT64/DNS64, NAT46 for 4G Gi/sGi and 5G N6 connectivity and security. It also boasts of RAN Access Security with highly scalable and best performing IPsec aggregation and control security gateway (SecGW). It has user plane security enabled by full Threat Protection and visibility into GTP-U inspection, and supports 4G and 5G security for user and data plane traffic including SCTP, GTP-U and SIP that provides protection against attacks. It is also packed with high-speed interfaces to enable deployment flexibility.
-
Secure Web Gateway (SWG)
- Fortinet FG- 6500F/FG -6501F allows for secure web access from both internal and external risks, even for encrypted traffic at high performance, thus offering enhanced user experience with dynamic web and video caching. It also blocks and controls web access based on user or user groups across URL’s and domains. The Firewall prevents data loss and discovers user activity to known and unknown cloud applications. In addition, it blocks DNS requests against malicious domains using multi-layered advanced protection against zero-day malware threats delivered over the web.
Fortinet FG-6500F/FG-6501F Specifications :
FG-6300F/6301F | FG-6500F/6501F | |
---|---|---|
Interfaces and Modules | ||
40/100 GE QSFP28 Slots | 4 | |
1/10/25 GE SFP28 Slots | 24 | |
10 GE SFP+ Slots | 3 | |
GE RJ45 Management Ports | 2 | |
USB Ports | 1 | |
Console Port | 1 | |
Internal Storage | 2 TB NVMe (for 6301F and 6501F only) | |
Included Transceivers | 2x SFP+ (SR 10 GE) | |
System Performance and Capacity | ||
Firewall Throughput (1518 / 512 / 64 byte, UDP) |
239 / 238 / 135 Gbps | 239 / 238 / 135 Gbps |
Firewall Latency (64 byte, UDP) | 5 μs | 5 μs |
Firewall Throughput (Packet per Second) | 202.5 Mpps | 202.5 Mpps |
Concurrent Sessions (TCP) | 120 Million | 200 Million |
New Sessions/Sec (TCP) | 2 Million | 3 Million |
Firewall Policies | 200,000 | 200,000 |
IPsec VPN Throughput (512 byte) | 130 Gbps | 160 Gbps |
Gateway-to-Gateway IPsec VPN Tunnels | 16,000 | 16,000 |
Client-to-Gateway IPsec VPN Tunnels | 90,000 | 90,000 |
SSL-VPN Throughput | TBA | TBA |
Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) |
30,000 | 30,000 |
SSL Inspection Throughput (IPS, HTTP) | 90 Gbps | 130 Gbps |
Application Control Throughput (HTTP 64K) | 150 Gbps | 220 Gbps |
CAPWAP Throughput (1444 byte, UDP) | N/A | N/A |
Virtual Domains (Default / Maximum) | 10 / 500 | |
Maximum Number of Switches Supported | N/A | |
Maximum Number of FortiAPs (Total / Tunnel Mode) |
N/A | |
Maximum Number of FortiTokens | 20,000 | |
Maximum Number of Registered FortiClients | 100,000 | |
High Availability Configurations | Supported | |
System Performance — Optimal Traffic Mix | ||
IPS Throughput | 212 Gbps | 230 Gbps |
System Performance — Enterprise Traffic Mix | ||
IPS Throughput | 110 Gbps | 170 Gbps |
NGFW Throughput | 90 Gbps | 150 Gbps |
Threat Protection Throughput | 60 Gbps | 100 Gbps |
Dimensions and Power | ||
Height x Width x Length (inches) | 5.20 x 17.20 x 26.18 | 5.3 x 17.2 x 27.3 |
Height x Width x Length (mm) | 132 x 437 x 665 | 133 x 437 x 694 |
Weight | 67.68 lbs (30.7 kg) / 69.00 lbs (31.3 kg) |
78.26 lbs (35.5 kg) / 79.59 lbs (36.1 kg) |
Form Factor | 3 RU | |
AC Power Supply | 100–240V AC, 50–60 Hz | |
Power Consumption (Average / Maximum) | (977 / 1,217 W) / (977 / 1,237 W) |
(1,308 / 1,548 W) / (1,328 / 1,568 W) |
Current (Maximum) | 30A@100VAC, 20A@240VAC | |
Heat Dissipation | 4,153 / 4,221 BTU/h | 5,282 / 5,350 BTU/h |
Redundant Power Supplies | 2+1 Redundant, Hot Swappable | |
Operating Environment and Certifications | ||
Operating Temperature | 32–104°F (0–40°C) | |
Storage Temperature | -31–158°F (-35–70°C) | |
Humidity | 10–90% non-condensing | |
Noise Level | 57.43 dBA | |
Operating Altitude | Up to 7,400 ft (2,250 m) | |
Compliance |
Interfaces
- Console Port
- USB Port
- 2x GE RJ45, 1x 1/10 GE SFP Management Ports
- 2x 10 GE SFP HA Slots
- 24x 1/10/25 GE SFP28 Slots
- 4x 40/100 GE QSFP28 Slots