
Just bought 5 of these bad boys
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
its set to auto update
yet it hasent loaded.. interesting..
i will load it tonight..
funny thing that i noticed.. i have it configured like so:
and with ~15 clients, and 4 VPN tunnels open, its eating 80% of the on board mem... and i mean the traffic is about ~15/ksec and its simple SQL or HTTP transactions going through the thing..
Meh, Lets see what the new firmware has in store for me..
thanks for the heads up, and have fun with your new toys.

yet it hasent loaded.. interesting..
i will load it tonight..
funny thing that i noticed.. i have it configured like so:
Code: Select all
SDSL-> Forti - ( 3 lines ) -> 3 Servers
|_->Unmanaged Switch -> Clients
Meh, Lets see what the new firmware has in store for me..

thanks for the heads up, and have fun with your new toys.
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 4108
- Joined: Sat Dec 14, 2002 8:00 am
-
- Posts: 4755
- Joined: Mon Oct 22, 2001 7:00 am
nice package... not really a fan of subscriptions, but it seems you can't stray from them these days. What happens if it lapses? Do you manage your own content filters or does the feature become disabled? I like the deep packet inspectionish filtering too.
Oooh, 100 MBPS throughput with 40 3DES for a sub 2000 tag? hmm not bad...
Oooh, 100 MBPS throughput with 40 3DES for a sub 2000 tag? hmm not bad...
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
thus far, i have not had a hiccup fro mthe thing.. then again the most stressfull thing that it has to do is VPN tunnel's
it gives quite a bit of configurability, it also allows AutoFirmware update, Auto Virii updates ( for routers and clients.. it will store it in its cach ), etc etc..
it bascially a we'll managed Micro Unix box.

it gives quite a bit of configurability, it also allows AutoFirmware update, Auto Virii updates ( for routers and clients.. it will store it in its cach ), etc etc..
it bascially a we'll managed Micro Unix box.
-
- Posts: 4108
- Joined: Sat Dec 14, 2002 8:00 am
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
btw, you dont need to do anything really to get the filters working, no routing process's, No nothing, they are pritty much ready to go in the box and they watch the traffic that pass's through it and catches it..
it also gives the option to not allow certan file Extentions to be blocked. ( I.E .BAT, .EXE, .ZIP, .torrent etc
)
if you guys have any more q's or anything, i can log in ( through the pwn ass remote web interface ) and take some screenies
it also gives the option to not allow certan file Extentions to be blocked. ( I.E .BAT, .EXE, .ZIP, .torrent etc

if you guys have any more q's or anything, i can log in ( through the pwn ass remote web interface ) and take some screenies

-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 4755
- Joined: Mon Oct 22, 2001 7:00 am
right on amidy, ups for you guys sharing this, I'm getting ready to toss my Pix 515e because of hardware issues and am more interested the further I dig into this thing. Both seem to have enterprise-level protection for a low-budget system. Amidy, what's a yearly subscription cost for the whole 9 yards on a 60 and how many vpn client licenses do you get? Looks like it's unlimited IKE peers (remote vpn gateways) as well as internal clients, have you tried setting up off-brand peer tunnels, or just the vpn portion?
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 4755
- Joined: Mon Oct 22, 2001 7:00 am
thanks :icon14: that got me what I needed.AmIdYfReAk wrote:all the cost's are here mang
http://www.fortiwall.com/productcart/pc ... tegory=666
-
- Posts: 4755
- Joined: Mon Oct 22, 2001 7:00 am
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 6926
- Joined: Thu Feb 10, 2000 8:00 am
-
- Posts: 4755
- Joined: Mon Oct 22, 2001 7:00 am
very happy with the 60 overall.. some observations:
keyword/url filtering should not implicitly override 'allow all from host' rules (which by the way have no effect if there's a deny from all hosts below it--very different from checkpoint or cisco).
In 3.0 I hope they tweak the spam filters, and maybe include pop3s and imaps proxy filters, as well.
other than that, with dumped syslog data every day, it's every bit as effective as any solution I've used short of ssl-based proxy/vpn aggregators.
and the firmware upload via https is brilliant.
keyword/url filtering should not implicitly override 'allow all from host' rules (which by the way have no effect if there's a deny from all hosts below it--very different from checkpoint or cisco).
In 3.0 I hope they tweak the spam filters, and maybe include pop3s and imaps proxy filters, as well.
other than that, with dumped syslog data every day, it's every bit as effective as any solution I've used short of ssl-based proxy/vpn aggregators.
and the firmware upload via https is brilliant.
-
- Posts: 4755
- Joined: Mon Oct 22, 2001 7:00 am