bg_image

FortiGate® 601E

FortiGate 601E: Next-Generation Firewall

Enterprise-Grade Protection for Mid-Sized to Large Enterprises

The FortiGate 601E delivers next-generation firewall (NGFW) capabilities for mid-sized to large enterprises, with the flexibility to be deployed at the campus or enterprise branch. It protects against cyber threats with security processor-powered high performance, security efficacy, and deep visibility.

Figure 1: Front view of FG-601E

Interfaces

1. 1x USB Port
2. 1x Console Port
3. 2x GE RJ45 MGMT/HA Ports
4. 8x GE RJ45 Ports
5. 8x GE SFP Slots
6. 2x 10 GE SFP+ Slots

Features & Capabilities

Security

  • Protects against known exploits, malware, and malicious websites using continuous threat intelligence provided by FortiGuard Labs security services.
  • Identifies thousands of applications, including cloud applications, for deep inspection into network traffic.
  • Protects against unknown attacks using dynamic analysis and provides automated mitigation to stop targeted attacks.

Performance

  • Delivers industry’s best threat protection performance and ultra-low latency using purpose-built security processor (SPU) technology.
  • Provides industry-leading performance and protection for SSL encrypted traffic.

Certification

  • Independently tested and validated best security effectiveness and performance.
  • Received unparalleled third-party certifications from NSS Labs, ICSA, Virus Bulletin, and AV Comparatives.

Networking

  • Delivers extensive routing, switching, wireless controller, and high-performance IPsec VPN capabilities to consolidate networking and security functionality.
  • Enables flexible deployment such as Next Generation Firewall and Secure SD-WAN.

Management

  • Single Pane of Glass with Network Operations Center (NOC) view provides 360° visibility to identify issues quickly and intuitively.
  • Predefined compliance checklist analyzes the deployment and highlights best practices to improve overall security posture.

Security Fabric

  • Enables Fortinet and Fabric-ready partners’ products to collaboratively integrate and provide end-to-end security across the entire attack surface.
  • Automatically builds Network Topology visualizations which discover IoT devices and provide complete visibility into Fortinet and Fabric-ready partner products.

Specifications & Performance Indicators

MetricFG-601E
Interfaces and Modules
Hardware Accelerated 10 GE SFP+ Slots2
Hardware Accelerated GE RJ45 Interfaces8
Hardware Accelerated GE SFP Slots8
GE RJ45 Management Ports2
USB Ports2
RJ45 Console Port1
Onboard Storage2 x 240 GB SSD
Included Transceivers2x SFP (SX 1 GE)
System Performance — Enterprise Traffic Mix
IPS Throughput10 Gbps
NGFW Throughput9.5 Gbps
Threat Protection Throughput7 Gbps
System Performance and Capacity
IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP)36 / 36 / 27 Gbps
IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP)36 / 36 / 27 Gbps
Firewall Latency (64 byte, UDP)2 μs
Firewall Throughput (Packet per Second)40.5 Mpps
Concurrent Sessions (TCP)8 Million
New Sessions/Second (TCP)450,000
Firewall Policies10,000
IPsec VPN Throughput (512 byte)20 Gbps
Gateway-to-Gateway IPsec VPN Tunnels2,000
Client-to-Gateway IPsec VPN Tunnels50,000
SSL-VPN Throughput7 Gbps
Concurrent SSL-VPN Users (Tunnel Mode)5,000
SSL Inspection Throughput (IPS, avg. HTTPS)8 Gbps
SSL Inspection CPS (IPS, avg. HTTPS)5,500
SSL Inspection Concurrent Session (IPS, avg. HTTPS)800,000
Application Control Throughput (HTTP 64K)15 Gbps
CAPWAP Throughput (HTTP 64K)18 Gbps
Virtual Domains (Default / Maximum)10 / 10
Maximum Number of FortiSwitches Supported64
Maximum Number of FortiAPs (Total / Tunnel)1,024 / 512
Maximum Number of FortiTokens1,000
Maximum Number of Registered Endpoints2,000
High Availability ConfigurationsActive-Active, Active-Passive, Clustering