Advertisement


Home Networking Fortinet FortiGate FG-60F Review A Bigger Gateway Firewall

Fortinet FortiGate FG-60F Review A Bigger Gateway Firewall

8

Fortinet FortiGate FG-60F Internal Hardware Overview

Removing the cover reveals a neat custom board.

Fortinet FortiGate 60F Inside 1
Fortinet FortiGate 60F Inside 1

First, we can see a large heatsink.

Fortinet FortiGate 60F Heat Sink 1
Fortinet FortiGate 60F Heat Sink 1

Under that one is the Fortinet FortiSOC4. Fortinet makes its own ASIC to accelerate its networking, which is just neat. We could not find real photos of these before we did the FG-40F review.

Fortinet FortiGate 60F FortiSOC4 CPU 1
Fortinet FortiGate 60F FortiSOC4 CPU 1

Next, there is another big heatsink that hides something fascinating underneath.

Fortinet FortiGate 60F Heat Sink 2
Fortinet FortiGate 60F Heat Sink 2

Pulling this off, we get a Broadcom PHY.

Fortinet FortiGate 60F Chip 3
Fortinet FortiGate 60F Chip 3

You can also see Broadcom chips next to it. The reason this is so interesting because the FG-40F used Marvell chipsets.

Fortinet FortiGate 60F Inside 3
Fortinet FortiGate 60F Inside 3

There are a few more components we are not going to go through, but figured we would show.

Fortinet FortiGate 60F Inside 4
Fortinet FortiGate 60F Inside 4

There are missing components likely for a WiFi version.

Fortinet FortiGate 60F Chip 2
Fortinet FortiGate 60F Chip 2

Here is the board with the two big heatsinks off.

Fortinet FortiGate 60F Inside 10
Fortinet FortiGate 60F Inside 10

Since we had the board out, here is the other side.

Fortinet FortiGate 60F Inside 8
Fortinet FortiGate 60F Inside 8

If you were wondering where the battery is, it is on the other side of the PCB.

Fortinet FortiGate 60F Battery 1
Fortinet FortiGate 60F Battery 1

Next, let us get to the software experience.

8 COMMENTS

  1. Speaking of updates, fortigates can’t be directly updated to every version – you have to go in their required sequence. The ideal use case for the 60F might be, in addition to the extra ports, the ability to do a couple more things unlicensed than the 40F does. If you maintain a license, it matters less, of course. But then if you’re buying new, maybe you’ll be considering the G series anyway. And for other purposes you might jump directly to a used 100F or something depending on what you want. BTW the connector these and the sonicwalls use is a known standard which I’ve forgotten, but while YMMV I have found it to be cross compatible. Saves cost if you’re buying used ones and running unlicensed.

  2. It’s rough timing for this review when every other security news article is about the Fortibleed campaign happening against the Fortigate firewalls out in the world.

  3. really appreciate the high resolution photographs of the unit’s internals.
    Thank you for including them in your reviews of these units.

  4. I use a Fortigate 60F at home, and kept it licensed for 4 years until it didn’t seem to be worth paying the money anymore. It’s a very capable unit and the “NGFW” (app control + IPS) feature set is well worth it over any enthusiast self-built homelab firewall. The selling point for me was the ASIC – turning on those features didn’t slow things down much, like your performance tests show. Those features slow down any general-purpose appliance that uses a standard x86/ARM CPU.

    Like the graphs show, though, the perimeter antivirus feature is not worth it. And deep-packet inspection for TLS seems necessary to catch botnet/malware but it is hard to use without installing root certs on every endpoint. So in the end I gave up on even trying to use those in a home environment.

  5. Why are you reviewing outdated models? These have been out for over 6 years now and there are updated G series that have replaced them such as the 30G, and 50G.

  6. I am also curious as to why the review of such older models. Also, having spent a considerable portion of my career performance testing firewalls from all of the major enterprise vendors, including Fortinet, I’d be very curious to see more about your testing methodology including the firewall policy and logging configs. FWIW I also use a fortigate at home and have been happy with it. To the person who gave up on home TLS inspection, what do you imagine the point of having such a robust and feature rich firewall is when you’re not looking at over 90% of the traffic?

  7. Excellent review with plenty of real-world testing instead of just listing specifications. I really appreciated the detailed performance benchmarks and hardware teardown, which make it much easier to understand where the FG-60F fits in different network environments. This is a valuable resource for anyone considering a FortiGate firewall for their business.

  8. It’s a pity that the state of open support for specialized network accelerator hardware is comparatively weak. It’s very attractive to tick on some of the more sophisticated traffic munging options without beating the CPU to death or taking a massive hit to speed; but from a security perspective the idea of running a fortinet firmware on an internet-exposed device is absolutely terrifying. They aren’t alone there(Hey Ivanti, how’s it going? Citrix Netscaler! So good to see you!); but the state of things in fancy edge network widget land is frankly terrifying vs. relatively normal linux or BSD systems.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.