FortiGate 1000D
Interfaces
- USB Management Port
- USB Port
- Console Port
- 2x GE RJ45 Management Ports
- 16x GE SFP Slots
- 16x GE RJ45 Ports
- 2x 10 GE SFP+ Slots
NP Direct
By removing the Internal Switch Fabric, the NP Direct architecture provides direct access to the SPU-NP for the lowest latency forwarding. NGFW deployments require some attention to network design to ensure optimal use of this technology.
Powered by SPU
- Custom SPU processors deliver the power you need to detect malicious content at multi-Gigabit speeds
- Other security technologies cannot protect against today's wide range of content- and connection-based threats because they rely on general-purpose CPUs, causing a dangerous performance gap
- SPU processors provide the performance needed to block emerging threats, meet rigorous third-party certifications, and ensure that your network security solution does not become a network bottleneck
Network Processor
Fortinet's new, breakthrough SPU NP6 network processor works inline with FortiOS functions delivering:
- Superior firewall performance for IPv4/IPv6, SCTP and multicast traffic with ultra-low latency down to 2 microseconds
- VPN, CAPWAP and IP tunnel acceleration
- Anomaly-based intrusion prevention, checksum offload and packet defragmentation
- Traffic shaping and priority queuing
Content Processor
The SPU CP8 content processor works outside of the direct flow of traffic, providing high-speed cryptography and content inspection services including:
- Signature-based content inspection acceleration
- Encryption and decryption offloading
10 GE Connectivity
High speed connectivity is essential for network security segmentation. The FortiGate 1000D provides 10 GE slots that simplify network designs without relying on additional devices to bridge desired connectivityFortiGate 1000D Specifications | |
---|---|
Interfaces and modules | |
Hardware Accelerated GE/10 GE SFP/SFP+ Slots | 2 |
Hardware Accelerated GE SFP Slots | 16 |
Hardware Accelerated GE RJ45 Ports | 16 |
GE RJ45 Management / HA Ports | 2 |
USB Ports (Client / Server) | 1 / 2 |
Console Port | 1 |
Onboard Storage | 256 GB |
Included Transceivers | 0 |
System performance and capacity | |
IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 52 / 52 / 33 Gbps |
IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) | 52 / 52 / 33 Gbps |
Firewall Latency (64 byte, UDP) | 3 μs |
Firewall Throughput (Packet per Second) | 49.5 Mpps |
Concurrent Sessions (TCP) | 11 Mil |
New Sessions per Second (TCP) | 280,000 |
Firewall Policies | 100,000 |
IPsec VPN Throughput (512 byte) | 25 Gbps |
Gateway-to-Gateway IPsec VPN Tunnels | 20,000 |
Client-to-Gateway IPsec VPN Tunnels | 50,000 |
SSL-VPN Throughput | 3.6 Gbps |
Concurrent SSL-VPN Users (Recommended Maximum) | 10,000 |
IPS Throughput (HTTP / Enterprise Mix) 1 | 8 / 4.2 Gbps |
SSL Inspection Throughput 2 | 4 Gbps |
Application Control Throughput 3 | 8 Gbps |
NGFW Throughput 4 | 5 Gbps |
Threat Protection Throughput 5 | 3 Gbps |
CAPWAP Throughput 6 | 11 Gbps |
Virtual Domains (Default / Maximum) | 10 / 250 |
Maximum Number of FortiAPs (Total / Tunnel) | 4,096 / 1,024 |
Maximum Number of FortiTokens | 5,000 |
Maximum Number of Registered Endpoints | 8,000 |
High Availability Configurations | Active-Active, Active-Passive, Clustering |
Dimensions and power | |
Height x Width x Length (inches) | 3.48 x 17.20 x 17.95 |
Height x Width x Length (mm) | 88.5 x 437 x 456 |
Weight | 24.70 lbs (11.20 kg) |
Form Factor | Rack Mount, 2 RU |
AC Power Supply | 100–240V AC, 50–60 Hz |
Power Consumption (Average / Maximum) | 153 W / 220.8 W |
Current (Maximum) | 100V / 5A, 240V / 3A |
Heat Dissipation | 753.40 BTU/h |
Redundant Power Supplies | Yes, Hot swappable |
Operating environment and certifications | |
Operating Temperature | 32–104°F (0–40°C) |
Storage Temperature | -31–158°F (-35–70°C) |
Humidity | 20–90% non-condensing |
Operating Altitude | Up to 7,400 ft (2,250 m) |
Compliance | FCC Part 15 Class A, C-Tick, VCCI, CE, UL/cUL, CB |
Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 |
Note: All performance values are "up to" and vary depending on system configuration. IPsec VPN performance is based on 512 byte UDP packets using AES-256+SHA1.
1. IPS performance is measured using 1 Mbyte HTTP and Enterprise Traffic Mix.
2. SSL Inspection is measured with IPS enabled and HTTP traffic, using TLS v1.2 with AES256-SHA.
3. Application Control performance is measured with 64 Kbytes HTTP traffic.
4. NGFW performance is measured with IPS and Application Control enabled, based on Enterprise Traffic Mix.
5. Threat Protection performance is measured with IPS and Application Control and Malware protection enabled, based on Enterprise Traffic Mix.
6. CAPWAP performance is based on 1444 byte UDP packets.
* Maximum loading on each PoE/+ port is 30 W (802.3at).