Overview:
UTM Evolution:
The evolution of network security threats has driven the expansion of security products to include multiple threat recognition systems within a single appliance. Unified Threat Management systems from Fortinet include firewall, VPN, intrusion prevention, antivirus, antimalware, antispam and web content filtering to identify numerous types of threats from a single device. While the ease of use of UTM products has created a prolific adoption trend, administrators still struggle with limited physical deployment options due to the available throughput and port density of mid-range devices.
Perimeter Dissemination:
Over time, as network devices and user habits have evolved, networks experienced a dissemination of the classic perimeter that had previously surrounded and protected their networks. The mobility offered by laptops and more recently, WiFi-enabled smart phones, have introduced security threats from the access layer, where LAN-side users connect to the network. The ideal network security solution would offer line rate throughput on numerous ports to facilitate the segmentation of the LAN into individual security zones, offering granular security policies, the isolation of security events, and increased visibility into network traffic and events.
ASIC-Accelerated Multi-Threat Security Solution:
The FortiGate-620B answers the call of growing enterprise networks by integrating a purpose-built security processing ASIC, known as the FortiASIC Network Processor, designed to deliver security throughput at switching speeds. Sixteen hardware accelerated interfaces (expandable to 20) allow networks to enforce firewall policy between network segmentation points for layered security with switch-like performance. An additional purpose-built ASIC, known as the FortiASIC Content Processor, provides additional acceleration for content intensive security technologies such as intrusion prevention and antivirus scanning for dangerous traffic streams. The inclusion of an Advanced Mezzanine Card (AMC) expansion slot allows for even more flexibility, offering additional ASIC-accelerated ports for additional throughput or disk-based storage for local logging and content archiving. With numerous accelerated multi-threat security interfaces, organizations can create multiple security zones for various departments, users, access methods, and even devices to enforce network security at accelerated speeds.
Features & Benefits:
Hardware Acceleration: Up to 20 Gbps FW & 15 Gbps VPN combined with 1Gbps IPS and 250 Mbps AV acceleration ensures security is never a bottleneck
Twenty 10/100/1000 interfaces (expandable to 24): Facilitates numerous internal segmentation points throughout the network
Modular Expansion: Flexible expansion options for fouradditional NP-accelerated ports or HDD for local logging and archiving
Unified Security Architecture: Multi-threat protection from a single device increases security and lowers costs
Technical Specifications:
| 620B Base Unit | 620B with Optional ASM-FB4 |
| Hardware Specifications |
| Total 10/100/1000 Interfaces | 20 | 24 |
| Internal Switch or Security Zone Ports | 20 | 24 |
| AMC Expansion Slot | 1 Single Width | N/A |
| System Performance |
| Firewall Throughput– Avg Size Packets (512 byte) | 16 Gbps | 20 Gbps |
| Firewall Throughput– Small Size Packets (64 byte) | 16 Gbps | 20 Gbps |
| IPSec VPN Throughput | 12 Gbps | 15 Gbps |
| Antivirus Throughput* | 250 Mbps |
| IPS Throughput* | 1 Gbps |
| Dedicated IPSec VPN Tunnels | 20,000 |
| Concurrent Sessions | 600,000 |
| New Sessions/Sec | 25,000 |
| Policies | 100,000 |
| Unlimited User Licenses | Yes |
| Dimensions |
| Height | 1.77 inches (4.5 cm) |
| Width | 17 inches (43.2 cm) |
| Length | 15. 5 inches (39.4 cm) |
| Weight | 20 lbs (9.1 kg) |
| Rack Mountable | Yes |
| AC Power Required | 110 - 240 VAC, 50 - 60 Hz, 8.0 Amp (Max) |
| Power Consumption (AVG) | 225W |
| Environmental |
| Operating Temperature | 32 to 104°F (0 to 40°C) |
| Storage Temperature | -31 to 158°F (-35 to 70°C) |
Humidity (non-condensing) | 20 to 90% |
| Compliance |
| Compliance | FCC Class A Part 15, UL/CUL, C Tick, VCCI |
| Certifications | ICSA Labs: Firewall, IPSec, Antivirus, IPS, Antispyware |
| * Antivirus performance is measured based on HTTP traffic with 32Kbyte file attachments and IPS performance is measured based on UDP traffic with 512byte packet size. Actual performance may vary depending on network traffic and environments. |