FortiGate 601E: Next-Generation Firewall
Enterprise-Grade Protection for Mid-Sized to Large Enterprises
The FortiGate 601E delivers next-generation firewall (NGFW) capabilities for mid-sized to large enterprises, with the flexibility to be deployed at the campus or enterprise branch. It protects against cyber threats with security processor-powered high performance, security efficacy, and deep visibility.
Figure 1: Front view of FG-601E
Interfaces
Features & Capabilities
Security
- Protects against known exploits, malware, and malicious websites using continuous threat intelligence provided by FortiGuard Labs security services.
- Identifies thousands of applications, including cloud applications, for deep inspection into network traffic.
- Protects against unknown attacks using dynamic analysis and provides automated mitigation to stop targeted attacks.
Performance
- Delivers industry’s best threat protection performance and ultra-low latency using purpose-built security processor (SPU) technology.
- Provides industry-leading performance and protection for SSL encrypted traffic.
Certification
- Independently tested and validated best security effectiveness and performance.
- Received unparalleled third-party certifications from NSS Labs, ICSA, Virus Bulletin, and AV Comparatives.
Networking
- Delivers extensive routing, switching, wireless controller, and high-performance IPsec VPN capabilities to consolidate networking and security functionality.
- Enables flexible deployment such as Next Generation Firewall and Secure SD-WAN.
Management
- Single Pane of Glass with Network Operations Center (NOC) view provides 360° visibility to identify issues quickly and intuitively.
- Predefined compliance checklist analyzes the deployment and highlights best practices to improve overall security posture.
Security Fabric
- Enables Fortinet and Fabric-ready partners’ products to collaboratively integrate and provide end-to-end security across the entire attack surface.
- Automatically builds Network Topology visualizations which discover IoT devices and provide complete visibility into Fortinet and Fabric-ready partner products.
Specifications & Performance Indicators
| Metric | FG-601E |
|---|---|
| Interfaces and Modules | |
| Hardware Accelerated 10 GE SFP+ Slots | 2 |
| Hardware Accelerated GE RJ45 Interfaces | 8 |
| Hardware Accelerated GE SFP Slots | 8 |
| GE RJ45 Management Ports | 2 |
| USB Ports | 2 |
| RJ45 Console Port | 1 |
| Onboard Storage | 2 x 240 GB SSD |
| Included Transceivers | 2x SFP (SX 1 GE) |
| System Performance — Enterprise Traffic Mix | |
| IPS Throughput | 10 Gbps |
| NGFW Throughput | 9.5 Gbps |
| Threat Protection Throughput | 7 Gbps |
| System Performance and Capacity | |
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 36 / 36 / 27 Gbps |
| IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 36 / 36 / 27 Gbps |
| Firewall Latency (64 byte, UDP) | 2 μs |
| Firewall Throughput (Packet per Second) | 40.5 Mpps |
| Concurrent Sessions (TCP) | 8 Million |
| New Sessions/Second (TCP) | 450,000 |
| Firewall Policies | 10,000 |
| IPsec VPN Throughput (512 byte) | 20 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 2,000 |
| Client-to-Gateway IPsec VPN Tunnels | 50,000 |
| SSL-VPN Throughput | 7 Gbps |
| Concurrent SSL-VPN Users (Tunnel Mode) | 5,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 8 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 5,500 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 800,000 |
| Application Control Throughput (HTTP 64K) | 15 Gbps |
| CAPWAP Throughput (HTTP 64K) | 18 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 10 |
| Maximum Number of FortiSwitches Supported | 64 |
| Maximum Number of FortiAPs (Total / Tunnel) | 1,024 / 512 |
| Maximum Number of FortiTokens | 1,000 |
| Maximum Number of Registered Endpoints | 2,000 |
| High Availability Configurations | Active-Active, Active-Passive, Clustering |
