Fortinet has long been known in the industry for providing you bang for your buck, which is generally viewed at a FortiGate level as performance/throughput vs cost. The numbers stack up nicely for the end customers and when that end customer is a Service Provider (SP) who is constantly looking at ARPU (Average Revenue Per User) it's a key criteria but not the only criteria to consider.
Read On
In a recent project for one of our customers in the SP space, Fortinet was a clear choice for a solution to deploy CGNAT. Below summarises some of the reasons why, yet there are a number of others that could be included.
Why Fortinet?
Scale
The FortiGate Clustering Protocol (FGCP) provides failover protection, meaning that a cluster can provide FortiGate services even when one of the devices in the cluster encounters a problem that would result in the complete loss of connectivity for a stand-alone FortiGate unit. Failover protection provides a backup mechanism that can be used to reduce the risk of unexpected downtime, especially in mission-critical environments.
FGCP supports failover protection in four ways:
If a link fails.
If a device loses power.
If an SSD fails.
If memory utilization exceeds the threshold for a specified amount of time.
When session-pickup is enabled in the HA settings, existing TCP sessions are kept, and users on the network are not impacted by downtime as the traffic can be passed without reestablishing the sessions.
Synchronizing sessions between FGCP clusters is useful when data centers in different locations are used for load balancing, and traffic must be shared and flow freely based on demand.
Hyperscale Licence/FortiOS One of the added benefits for the cost point of view is the ability to use FortiOS instead of the Hyperscale licence depending on your requirements. (See Helpful Links) section for Hyperscale comparison to FortiOS.
Port Block Allocation
This type of IP pool is also a type of port address translation (PAT). It gives users a more flexible way to control the way external IPs and ports are allocated. Users need to define Block Size/Block Per User and external IP range. Block Size means how many ports each Block contains. Block per User means how many blocks each user (internal IP) can use.
Future Proof
If there were to be changes to the The Telecommunications (Interception and Access) Act 1979 for something like a logging requirement or a change to web browsing histories which aren’t currently logged. The performance of the FortiGates would not be affected by adding URL Filtering or additional logging based on the customers current solution.
Adding VPN’s.
Cost
Performance/Throughput this is well known throughout the industry when considering Fortinet.
Power is a huge challenge currently and into the future. The throughput to watts usage of the Fortinet makes them very economical and resource efficient.
Our view at ICT Networks is that using FortiGates for the purpose of CGNAT delivers upon the right balance of performance and cost. Any Service Provider can consider it for their future requirements when deploying CGNAT.
Fortinet has long been known in the industry for providing you bang for your buck, which is generally viewed at a FortiGate level as performance/throughput vs cost. The numbers stack up nicely for the end customers and when that end customer is a Service Provider (SP) who is constantly looking at...
One of the things I first thought about when HPE announced its plans to acquire Juniper Networks was how will this benefit our customers? We were a long term Juniper Partner with great expertise and a proven track record of supporting our customers across Juniper products and services.