Advertisement


Home Networking Fortinet FortiGate FG-60F Review A Bigger Gateway Firewall

Fortinet FortiGate FG-60F Review A Bigger Gateway Firewall

8

Fortinet FortiGate FG-60F Software Experience

The software experience is largely the same as the FG-40F. Logging in, Fortinet’s default IP is 192.168.1.99, and the default username is admin with no password. You are immediately required to change the password.

Fortinet FortiGate Login Screen
Fortinet FortiGate Login Screen

We logged into our unit and saw the FortiOS 7.6.6 dashboard. This looks a lot like the same version on the FG-40F, which is expected.

Fortinet FortiGate 60F FG 60F Dashboard V7.6.6
Fortinet FortiGate 60F FG 60F Dashboard V7.6.6

Just a quick note: we ended up having issues with updating this box, which meant we needed to hook up a console cable and screw around with recovery.

Once you are set up and have registered your device, there are UIs and wizards for a ton of features. The interface setup is relatively intuitive, and Fortinet has the gateway diagram with port labels and connection status on top. If you configure hundreds of these, you probably do not notice little features like this.

Fortinet FortiGate 60F FG 60F Network Interfaces
Fortinet FortiGate 60F FG 60F Network Interfaces

In the FG-40F review, we went into more detail around the FortiLink interfaces and so forth, but since the boxes are fairly similar

VPNs are a big deal for Fortinet and this entire segment. It turns out that both CyPerf and IxNetwork, which we use, have great VPN testing tools, but we are going to add that into future reviews.

Fortinet FortiGate 60F FG 60F VPN Wizard
Fortinet FortiGate 60F FG 60F VPN Wizard

On the security side, Fortinet is well known for its security features, including its IPS.

Fortinet FortiGate 60F FG 60F Security Intrusion Prevention
Fortinet FortiGate 60F FG 60F Security Intrusion Prevention

With a subscription, you have access to a great default set of IPS signatures. We will look at the performance of turning many of the security features on in our performance testing section.

Fortinet FortiGate 60F FG 60F Security IPS Signatures
Fortinet FortiGate 60F FG 60F Security IPS Signatures

There is an application sensor feature as well. Here is a quick look at the signatures for that:

Fortinet FortiGate 60F FG 60F Security Application Signatures
Fortinet FortiGate 60F FG 60F Security Application Signatures

Fortinet also has SSL and SSH inspection features.

Fortinet FortiGate 60F FG 60F Security SSL SSH Inspection
Fortinet FortiGate 60F FG 60F Security SSL SSH Inspection

There are, of course, web filters, antivirus features, and more that we looked at in the FG-40F piece. Something we wanted to show here is the logs of traffic being blocked. When we ran our Keysight CyPerf tool through the gateway, it is not just uniform packets, so the logs look fairly neat.

Fortinet FortiGate 60F FG 60F Log Traffic Blocked
Fortinet FortiGate 60F FG 60F Log Traffic Blocked

There is a CLI for Fortinet, which is how we did most of the configuration of these units. On both the FG-30G (both units) and FG-60F we ended up having to use the console port to fix firmware updates or to fix an update gone poorly. Since we did all the performance testing for these boxes back-to-back, we ended up using console access on three of the four boxes on hand just to update firmware, so it is an important feature.

Next, let us talk about onboarding.

A Word on Onboarding

To do this review, we purchased the FG-60F-BDL-809-12 bundle. The FG-60F is the hardware. 12 is for the duration. The 809 means we have 1 Year FortiCare Premium and FortiGuard Enterprise Protection. These boxes have a ton of features and various license levels. We were doing a batch of four of these at the same time, but needless to say, onboarding is focused on ensuring you have licenses and that data is captured for sales operations to correctly attribute your purchase to a Fortinet partner. We had both Patrick and Rohit do this, and the SonicWall back-to-back, and SonicWall felt much easier from an onboarding perspective since the workflow was basically sign up for MySonicWall and then register products. If you are coming from a solution like pfSense, OPNsense, or even Ubiquiti, both will feel very rough from a customer experience side.

Now, let us get to the performance.

8 COMMENTS

  1. Speaking of updates, fortigates can’t be directly updated to every version – you have to go in their required sequence. The ideal use case for the 60F might be, in addition to the extra ports, the ability to do a couple more things unlicensed than the 40F does. If you maintain a license, it matters less, of course. But then if you’re buying new, maybe you’ll be considering the G series anyway. And for other purposes you might jump directly to a used 100F or something depending on what you want. BTW the connector these and the sonicwalls use is a known standard which I’ve forgotten, but while YMMV I have found it to be cross compatible. Saves cost if you’re buying used ones and running unlicensed.

  2. It’s rough timing for this review when every other security news article is about the Fortibleed campaign happening against the Fortigate firewalls out in the world.

  3. really appreciate the high resolution photographs of the unit’s internals.
    Thank you for including them in your reviews of these units.

  4. I use a Fortigate 60F at home, and kept it licensed for 4 years until it didn’t seem to be worth paying the money anymore. It’s a very capable unit and the “NGFW” (app control + IPS) feature set is well worth it over any enthusiast self-built homelab firewall. The selling point for me was the ASIC – turning on those features didn’t slow things down much, like your performance tests show. Those features slow down any general-purpose appliance that uses a standard x86/ARM CPU.

    Like the graphs show, though, the perimeter antivirus feature is not worth it. And deep-packet inspection for TLS seems necessary to catch botnet/malware but it is hard to use without installing root certs on every endpoint. So in the end I gave up on even trying to use those in a home environment.

  5. Why are you reviewing outdated models? These have been out for over 6 years now and there are updated G series that have replaced them such as the 30G, and 50G.

  6. I am also curious as to why the review of such older models. Also, having spent a considerable portion of my career performance testing firewalls from all of the major enterprise vendors, including Fortinet, I’d be very curious to see more about your testing methodology including the firewall policy and logging configs. FWIW I also use a fortigate at home and have been happy with it. To the person who gave up on home TLS inspection, what do you imagine the point of having such a robust and feature rich firewall is when you’re not looking at over 90% of the traffic?

  7. Excellent review with plenty of real-world testing instead of just listing specifications. I really appreciated the detailed performance benchmarks and hardware teardown, which make it much easier to understand where the FG-60F fits in different network environments. This is a valuable resource for anyone considering a FortiGate firewall for their business.

  8. It’s a pity that the state of open support for specialized network accelerator hardware is comparatively weak. It’s very attractive to tick on some of the more sophisticated traffic munging options without beating the CPU to death or taking a massive hit to speed; but from a security perspective the idea of running a fortinet firmware on an internet-exposed device is absolutely terrifying. They aren’t alone there(Hey Ivanti, how’s it going? Citrix Netscaler! So good to see you!); but the state of things in fancy edge network widget land is frankly terrifying vs. relatively normal linux or BSD systems.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.