What is our primary use case?
Our company uses the solution for various clients.
For one customer, we use the solution for global load balancing, GSLB, and sending DNS requests to the primary DNS.
For another customer, we use the solution as the ADC for data centers to protect all websites and use Layer 7 to provide DDos protection and load balancing for web traffic.
For a third customer, we use the solution as a GSLB but rented a data center rack to deploy as a virtual machine with all DNS requests going to the cloud and then to the customer.
How has it helped my organization?
Our company provides WAF and complicated applications to customers. If we do not use the solution, we have issues because it protects the web server from SQL injections, XSS, DDoS, and HTTP attacks. Competitors such as Palo Alto, Check Point, and even FortiGate cannot provide a WAF.
Link load balancing also helps us to reduce our linked and internal traffic.
What is most valuable?
The solution provides high-level services such as availability, redundancy, and load balancing between servers.
Routing protocols are better than those in FortiWeb.
For example, CNN has one website but a lot of web traffic so we need more than one server for high availability and load sharing. The solution allows for load sharing across multiple servers or even multiple data centers where they run as active/active or active/passive. If we lose the primary data center due to natural disaster or a high global load, we can manipulate DNS traffic to the secondary data center.
What needs improvement?
The solution's WAF needs an upgrade because it is not as good as FortiWeb, VMware, F5, or Imperva.
The solution should be migrated to a software-defined network like Imperva and VMware.
For how long have I used the solution?
I have been using the solution for ten years.
What do I think about the stability of the solution?
The solution is stable. We use version 6.2.4 to provide better stability than the newer versions which have more bugs.
What do I think about the scalability of the solution?
The scalability is limited to 200 gigabit throughput on the best version of the solution which is the 5000F series.
We can use the solution as an HA in active/active mode which allows us to increase throughput by 50%.
For one customer, we used the 1200F series with a 40 gigabit throughput and usage was less than 70% with one million users.
How are customer service and support?
I have not used technical support for the solution but have used it for other Fortinet products.
Colleagues work for the company so I can get quick solutions for issues.
For one particular issue, technical support was not able to resolve our issue so they sent us a new version of the solution and that solved the problem.
How was the initial setup?
The initial setup and configuration are very easy because the solution includes a simple OS. Initial configuration takes about ten minutes for simple environments.
It is important to assess the environment and decide what services, servers, and web applications are needed.
The solution can be configured in router mode or one-arm mode which uses source NAT as destination NAT to send traffic to the firewall. One-arm mode is more complex and requires discussions with our engineers.
For example, you have a website with Node.js for your programming language, Amazon S3 for your CDN, NGINX for your web server, and you use both React and reCAPTCHA. Our team meets with your developer to learn your website and OS through a multi-step process and then we configure the solution to protect everything.
What about the implementation team?
Depending on the complexity of the project, we implement the solution ourselves or sometimes we rely on third-party teams to assist us.
What's my experience with pricing, setup cost, and licensing?
The solution is less expensive than F5 or Imperva and is the most reasonably priced option available.
Which other solutions did I evaluate?
We use different solutions based on a customer's needs and budget.
Imperva is the best solution, F5 is the best for on-premises, and we also like Magic Quadrant.
VMware has all the features of FortiADC such as GSLB, load balancer, and WAF. It can be used for your data center or as a software-defined network with a single point of management that does not have 200 gigabit limitations.
What other advice do I have?
It is important to know your network and load share needs before deciding on a solution. This assessment will help you decide if a certain model of the solution will meet your needs or if you should look at another product such as F5, Imperva, or VMware.
I currently use version 6.2.4 of the solution because we will not update to 7.0 or 7.1 until they are in the market for a year and all bugs have been worked out.
Fortinet equipment can have bugs and some exist in the version we use but the there are more bugs in the newer versions.
I rate the solution a six out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other