Catalog   /   Computing   /   Networking   /   Routers & Firewalls

Comparison Fortinet FortiGate 101E vs Fortinet FortiGate 101F

Add to comparison
Fortinet FortiGate 101E
Fortinet FortiGate 101F
Fortinet FortiGate 101EFortinet FortiGate 101F
Compare prices 1Compare prices 4
TOP sellers
Equipped with a built-in 480 GB SSD drive.
There is a modification without an SSD drive: Fortinet FortiGate 100E
This modification is equipped with a built-in 480 GB SSD drive.
The firewall has 34 ports in total: 1xUSB, 1xRJ45(console), 2xRJ45 (DMZ/Managment), 2xGE WAN, 2xGE (HA), 12xGE, 2xSFP+ FortiLink, 4xSFP, 4xGE/SFP (combo). Modification without drive Fortinet FortiGate 100F
TypeFirewallFirewall
Mountrack-mountdesktop
Ports
Connections
Ethernet
Ethernet
optics (SFP/SFP+)
Gigabit Ethernet21 pcs21 pcs
SFP (optics)2 pcs
SFP+ (optics)10 pcs
Of which dedicated WANs2 pcs2 pcs
USB ports11
Console port
Features
Control
SSH
Telnet
Web interface
SNMP
SSH
Telnet
Web interface
SNMP
Basic features
DHCP server
load balancing
channel reservation
port forwarding
VPN
DDNS
DHCP server
load balancing
channel reservation
port forwarding
VPN
DDNS
Hardware
SSD drive480 GB
Security
Security
MAC address filtering
DoS protection
web content filtering
antivirus
antispam
DMZ
MAC address filtering
DoS protection
web content filtering
antivirus
antispam
DMZ
Firewall performance7400 Mbps20000 Mbps
Intrusion prevention1900 Mbps2600 Mbps
VPN performance4000 Mbps11500 Mbps
VPN tunnels1000016000
General
PSUbuilt-inexternal
Operating temperature0 °C ~ +40 °C
Dimensions (WxDxH)445x432x254 mm
Weight3300 g
Added to E-Catalogmay 2020may 2020
Compare Fortinet FortiGate 101E and FortiGate 101F
Fortinet FortiGate 101F often compared
Glossary

Mount

Desktop. Desktop routers include routers that do not use special rack mounts and are suitable for placement on any suitable surface — a table, shelf, etc. Although there are quite advanced models among desktop devices, however, most of them have relatively simple functionality and are designed for use in small networks where an abundance of equipment is not required.

Rack mounted. Routers that are standard installed in a telecommunications rack are usually 19 "standard (although technically many of them can also be used as desktop ones, albeit with less convenience). Racks are used in extensive networks that require a large amount of equipment; accordingly, routers of this type in general, more powerful and advanced than the desktop, and are designed primarily for professional use.

To the mast. Installation on a mast or other vertical structure — a tower, a pole, etc. Quite a rare form factor; It is mainly used in waterproof models designed for the possibility of working outdoors. Mobile network capable devices in this category may have a directional antenna to improve connectivity.

Connections

How the router connects to the Internet or other external network.

Almost all modern routers have ethernet network connectors for this purpose, however, in addition to them, other connection options can be provided — both wired ( ADSL, SFP / SFP + optics) and wireless (mobile access via 3G / 4G modem or SIM card). Here are the features of each option:

— Ethernet. A standard LAN network cable connector (“twisted pair”) is the most popular modern wired connection format in computer networks. Widely used both in "local" and to provide access to the Internet. This standard is somewhat inferior to SFP / SFP + (see below) in terms of speed and noise immunity, but it is much cheaper. The speed of work in modern versions of Ethernet can reach 10 Gbps (see "Connection speed of WAN ports"), theoretically, a further increase in throughput is possible.

— SFP / SFP + (optics). A connector for transmitting network traffic over a fiber optic cable. The main advantage of such a cable is complete insensitivity to electromagnetic interference. And data transfer rates can reach 2.7 Gbps in the original SFP and 16 Gbps in SFP+. At the same time, maintaining this standard is not cheap, and the benefits mentioned are not often needed in fact. Therefore, SFP / SFP + is found mainly in mid-range a...nd top-level routers.

— ADSL. Connecting to the Internet through a fixed telephone network using ADSL technology. The key advantage of this connection is the ability to use existing networks without laying additional wires; at the same time, Internet access is completely separated from telephone communication and traffic does not interfere with voice calls. On the other hand, the bandwidth of ADSL is very low by modern standards (less than 24 Mbps), moreover, the data transmission speed is noticeably lower than the reception speed. This can create problems for video communication and some other specific tasks. So nowadays ADSL is used less and less.

— 3G/4G modem (USB). Internet connection via mobile network using a separate 3G or 4G modem connected to the USB port. This feature can be useful where there is no full-fledged wired connection (for example, in rural areas), and also as a fallback option in case the main communication channel fails. And the type of network supported depends mainly on the modem used (the compatibility of the router with different models needs to be specified separately, but most often there are no problems with this). As for specific types of networks, most 3G modems work in UMTS networks (the same ones that are massively used by mobile phones); the data transfer rate in such networks can reach 75 Mbit / s (however, usually it is much lower). Less common are 3G modems for EV-DO networks based on CDMA — this standard has lower speeds (up to 14.7 Mbps) and not as extensive coverage as UMTS, however, both the equipment and the connection itself can be cheaper. And the designation "4G" means only one type of networks — LTE; it provides speeds up to 173 Mbps, but is not as widespread as 3G.

— SIM card. Another option for connecting to the Internet via mobile networks is its own SIM card slot provided in the design of the router. This option is convenient because you do not need to buy an additional device (modem) for mobile Internet — you just need to purchase an operator's SIM card. On the other hand, due to the built-in mobile communication modules, such routers themselves are more expensive than analogues for USB modems. In addition, the connectivity options in them are limited by the characteristics of the module: for example, a router for 3G networks will not be able to fully use 4G networks (whereas a USB modem can usually be changed to a more advanced one). As a result, this option is relatively rare in modern equipment.

SFP (optics)

The number of optical network ports of the SFP standard provided in the design of the device. We emphasize that we are talking about "ordinary" SFPs; SFP+ data is usually listed separately.

Specifically, in switches, the marking “SFP” usually means a connector for fiber with a connection speed of 1 Gbps. Technically, this is not much compared to RJ-45 speeds; however, this connection format has a number of advantages. One of the main ones is a greater effective range: the mentioned gigabit standard works with a cable length of up to 550 m, and by the standards of optical fiber, this is still very little. True, the cable itself is sensitive to kinks and requires quite delicate handling; on the other hand, it is completely immune to electromagnetic interference. On the other hand, in general, the SFP format is noticeably less popular in network equipment than RJ-45; therefore, there are few ports of this type even in advanced devices ( 1 port or 2 ports, less often more). It is also worth considering that there may be so-called combo connectors that combine SFP and RJ-45; the presence of such ports is specified in the notes, they are taken into account both in the calculation of RJ-45 and in the calculation of SFP.

SFP+ (optics)

The number of SFP+ optical ports provided in the device design.

The general advantages of fiber optics over regular Ethernet cables are longer communication ranges and insensitivity to electromagnetic interference. Specifically, SFP+ is a development of the original SFP standard; Such connectors operate at a speed of 10 Gbit/s as standard. As for the number of such ports, despite all its advantages, optical fiber in network equipment is still used quite rarely and most often there is only 1 port(less often 2 ports or more). It is also worth considering that there may be so-called combo connectors that combine SFP+ and RJ-45; the presence of such ports is specified in the notes; they are taken into account both when calculating RJ-45 and when calculating SFP+.

SSD drive

The amount of SSD installed in the router.

Such a drive performs a service function: it is intended for storing logs, as well as for caching some data, which allows you to significantly speed up access to them. The more capacious the SSD, the wider the router's capabilities for working with these tasks; on the other hand, the volume of the drive significantly affects the cost. Thus, manufacturers usually select SSD modules taking into account the general class and functionality of a particular device, so this parameter plays a secondary role when choosing — first of all, you should focus on the characteristics directly related to the operation of the router (number of ports, basic functions, security, performance, etc.).

Firewall performance

Performance of a Firewall type device (see "Type") in intrusion prevention mode.

Intrusion protection is carried out on the same principle as the general processing of traffic by a firewall — by checking the received and transmitted data. However, the principles of filtering are somewhat different: Firewall cuts off certain types of traffic, preventing them from reaching network devices, while intrusion protection allows all traffic, but checks it for suspicious activity. Actions upon detection of such activity can be different: in some models, protection only notifies the administrator about the attack, in others, it independently takes retaliatory measures. Anyway, fine-grained traffic inspection is more resource-intensive than running a firewall in normal mode, which is why the performance in intrusion prevention mode is inevitably lower than the overall performance of the Firewall.

Note that this parameter is specified for optimal conditions — in particular, for those types of traffic that do not require a large amount of resources for scanning. So the real throughput of the firewall will inevitably be lower than the claimed one, and when choosing according to this indicator, it is worth taking a certain margin — at least 10 – 15%.

Intrusion prevention

Performance of a Firewall type device (see "Type") in intrusion prevention mode.

Intrusion protection is carried out on the same principle as the general processing of traffic by a firewall — by checking the received and transmitted data. However, the principles of filtering are somewhat different: Firewall cuts off certain types of traffic, preventing them from reaching network devices, while intrusion protection allows all traffic, but checks it for suspicious activity. Actions upon detection of such activity can be different: in some models, protection only notifies the administrator about the attack, in others, it independently takes retaliatory measures. Anyway, fine-grained traffic inspection requires more resources than running a firewall in normal mode, which is why the performance in intrusion prevention mode is inevitably lower than the overall performance of the Firewall.

Note that this parameter is specified for optimal conditions — in particular, for those types of traffic that do not require a large amount of resources for verification. So the real throughput of the firewall will inevitably be lower than the claimed one, and when choosing according to this indicator, it is worth taking a certain margin — at least 10 – 15%.

VPN performance

The performance of a device of the Firewall type (see "Type") when operating in VPN mode — namely, when building a virtual private network using a firewall as a VPN server. It is indicated by the maximum volume of traffic that the device can process per second with such a connection.

For more information about VPN in general, see "Basic Features". Here we note that in this format of operation, the Firewall must additionally encrypt the transmitted traffic and decrypt the received, which creates an additional load on the device. Therefore, throughput in VPN mode is inevitably less than the overall performance of the Firewall (see above). It is worth choosing according to this indicator with a certain margin — at least 10 – 15%; this will give an additional guarantee in case of abnormal loads.

As for specific figures, VPN bandwidth up to 1 Gbps is considered relatively small, more than 1 Gbps is considered high.

PSU

Built -in. The built-in power supply does not take up space on the outside, but can significantly increase the size and weight of the entire router. Because of this, this option is quite rare — mainly among rack-mount models (see "Form factor"), where an external unit can create significant inconvenience, as well as among the most powerful desktop routers, for which dimensions and weight is not critical.

— External. Theoretically, the external placement of the power supply requires additional space, and therefore is not as convenient as the internal one. In fact, most blocks of this type are quite compact in size and are equipped with “plugs” for sockets right on the case — in other words, the block is installed on a socket, and from there the wire stretches to the router. And the absence of power circuits and transformers inside the routers has a positive effect on their compactness. Thanks to all this, this option is very popular among desktop models (see "Form factor"), primarily entry-level and mid-level.