Fortinet announced a new security blade: the FortiGate-5001C. The blade provides large data centers as well as private and hybrid cloud deployments with consolidated security capabilities. Its security features, throughput and low latency make it good for large Internet gateways as well as centralized Managed Security Services Providers (MSSPs).
The FortiGate 5001C blade, running on FortiGate-5000 series chassis, combined with Fortinet’s line of virtual machine security technologies, offers a complete core-to-perimeter data center and cloud security solution.
It runs the company’s network-security operating system FortiOS 5. The blade integrates native 10-Gigabit Ethernet (GbE) support for FortiGate-5000 chassis-based platforms. Delivering up to 40 Gbps of firewall throughput and up to 17 Gbps of IPSec throughput, the FortiGate-5001C integrates essential security functions in an Advanced Telecom Computing Architecture (ATCA)-compliant blade form factor. This includes firewall, virtual private network, application control, intrusion prevention, antimalware and Web filtering.
Fortinet’s virtual domain (VDOM) and administrative domain (ADOM) technologies enable granular control over the deployment of the new security blade to partition networks on the basis of individual customers, groups of subscribers and/or business units.
Each blade features four 10-GbE ports to enable scalability. The blades feature the latest FortiASIC processors that optimize session rates and accelerated IPS performance. Fortinet develops its own customized processors.
Fortinet provides single-pane-of-glass management with the FortiManager family of physical and virtual management devices. The FortiManager centralized management allows security administrators to configure and manage thousands of physical appliances and virtual machines.
The FortiAnalyzer family of physical and virtual devices provides centralized logging and reporting, which enables administrators to analyze, report and archive security event, network traffic, Web content and messaging data to measure policy compliance.
The newest version of Fortinet’s operating system includes more than 150 new security features designed to protect against modern Advanced Persistent Threats (APTs) and targeted attacks. These enhancements include four key elements:
- Advanced Malware Detection: The malware engine helps reduce the size and increase the performance of the malware signature database. An inline sandbox applies behavior models against a sample file to determine if it is a threat. Cloud-based inspection can then provide a more detailed analysis of suspicious files.
- Exploit Discovery and Protection: FortiOS 5 can scan and identify vulnerabilities via a network or agent scan. The intrusion protection system function can then be deployed to protect vulnerable assets until the normal patching cycle remediates the vulnerability.
- Cloud-Based Reputation Systems: A new advanced anti-malware detection system adds an on-device, behavior-based heuristic engine and cloud-based AV services that includes an operating system sandbox and botnet IP reputation database.
- Multi-Vector Policy Engine: Although traditional policy can be applied based on source (IP address), FortiOS 5 also has the ability to apply policy based on the user and device identity. This is an important attribute for distributed, virtual and cloud networks.