▲ 11 r/sophos

moving from fortinet to sophos

Sizing a perimeter firewall for a university campus edge and looking for model suggestions before we run a PoC.

Requirements:

  • Users: ~3,500–4,000 concurrent
  • Total edge/WAN capacity: current pipe scaling up to 10 Gbps (all traffic)
  • SSL deep-inspection (decrypt) load: ~2 Gbps baseline today — this is my binding constraint (full IPS/AV/app-control/logging, everything decrypted)
  • ~1,200–1,500 managed devices in decrypt scope; ~2,300 BYOD endpoints bypass decryption
  • Active-standby HA — each appliance must independently carry the full load
  • 7-year horizon, 15% expected / 25% stress growth; 80% utilization as capacity-review trigger
reddit.com
u/tkr_2020 — 1 day ago

Pa 3410 sizing

Is a Palo Alto PA-3410 sufficient for 7–8 Gbps with Full Threat Prevention and ~80% SSL Decryption?
Hi everyone,
We’re evaluating a Palo Alto PA-3410 as our internet edge firewall and would appreciate feedback from anyone running one in production.
Our requirements:
7–8 Gbps sustained internet throughput
Full security profile enabled (Threat Prevention, Antivirus, Anti-Spyware, URL Filtering, WildFire, DNS Security, etc.)
Approximately 80% of traffic requires SSL/TLS decryption
Enterprise environment with several thousand users
Mix of Microsoft 365, web browsing, video conferencing, and general business applications
I know the datasheet provides benchmark numbers, but I’m more interested in real-world performance.
A few questions:
Can the PA-3410 realistically handle 7–8 Gbps with full security profiles and around 80% SSL decryption enabled?
What CPU and dataplane utilization do you typically see at those traffic levels?
Have you experienced any bottlenecks or limitations?
If you were purchasing today, would you still choose the PA-3410, or would you recommend moving to a larger model (e.g., PA-5410 or PA-5410/5420 series) for additional headroom and future growth?
Any real-world deployment experiences or recommendations would be greatly appreciated.

reddit.com
u/tkr_2020 — 12 days ago

**FortiGate 401G for a 4000-user university campus — realistic or undersized?**

Hi all, sizing a perimeter firewall refresh for a university campus and would appreciate real-world input from anyone running the new G-series (or similar loads on 600F/700G class boxes).

**Environment:**

- ~4000 students + 500 staff

- Traffic profile: general browsing, M365/Teams, LMS, and a lot of video streaming (YouTube/Netflix, incl. 4K) at peak hours

- Datasheet numbers I'm weighing: 401G = 13 Gbps Threat Protection / 25 Gbps IPS / 11.5 Gbps SSL inspection vs 701G = 26 Gbps TP / 38 Gbps IPS

- Full UTM at the edge: IPS, AV, app control, web filtering; partial SSL deep inspection

- IPsec remote access VPN (FortiClient + RADIUS MFA), a few hundred concurrent users

- 25G uplinks available toward the core

**My back-of-envelope:** peak concurrency with heavy streaming puts me around 1 to 2.5 Gbps inspected — i.e. right at the 401G's TP ceiling on day one, with 5 years of growth ahead.

**Questions:**

  1. Anyone running a 401G (or 600F/401F) at a campus/EDU with 3–5k users? What does your real peak inspected throughput look like vs the datasheet?
  2. How badly do the TP numbers degrade in practice with logging + SSL inspection enabled on real enterprise-mix traffic?
  3. Is the jump to the 701G worth it for the headroom, or is per-user QoS/traffic shaping on streaming the smarter play?
  4. Any gotchas on the new G-series (CP10) I should know before committing?

Thanks in advance — happy to share config/traffic stats if useful.

reddit.com
u/tkr_2020 — 1 month ago

onedrive sync issue

We use OneDrive for Business and need a solution for sharing files and folders among a team while maintaining proper access permissions.

Currently, each team member's Desktop and Documents folders are synced with their own personal OneDrive for Business account. In addition, we have a separate shared OneDrive account that all team members use to collaborate. Users create folders and work directly within this shared account, but this frequently results in synchronization conflicts and sync issues across different users.

What is the best Microsoft-recommended approach for team file sharing in this scenario? Should we continue using a shared OneDrive account, or would another solution (such as a SharePoint document library with permission management) be more appropriate for collaborative work while avoiding sync conflicts?

reddit.com
u/tkr_2020 — 2 months ago

ems cloud

Using FortiClient EMS Cloud, which requires Entra ID integration for user-based installer invitations. Can VPN authentication still be handled by on-prem AD with FortiAuthenticator/FortiToken MFA, or does it make more sense to move VPN authentication to Entra SAML as well? Any impact on EMS tags or posture checks if authentication remains on-prem?

thanks

reddit.com
u/tkr_2020 — 2 months ago

EMS /ZTNA-CLOUD Clound license deployment

Hi

We are currently using FortiGate SSL-VPN with on-prem Active Directory authentication integrated through on-prem FortiAuthenticator and FortiToken MFA.

Current environment:

  • Mixed endpoint environment
    • Corporate devices joined to on-prem AD
    • Contractor/BYOD devices not domain joined
  • VPN authentication currently:
    • AD authentication via FortiAuthenticator
    • MFA using on-prem FortiToken
  • Planning to deploy:
    • FortiClient EMS Cloud
    • ZTNA
    • SAML authentication against Microsoft Entra ID

Our goal is to implement device posture-based access using EMS/ZTNA tags while supporting both corporate and contractor devices.

Questions:

  1. In this type of hybrid environment, is it better to keep VPN authentication on-prem via FortiAuthenticator + AD + FortiToken, or migrate VPN authentication fully to SAML with Microsoft Entra ID?
  2. How do EMS/ZTNA tags work when authentication is done through Entra ID SAML instead of on-prem AD?
  3. Can FortiGate combine:
    • User identity from Entra ID SAML
    • EMS/ZTNA posture tags from EMS Cloud in the same SSL-VPN policy?
  4. For contractor/BYOD devices that are not domain joined:
    • Can EMS still assign posture tags properly?
    • What is the recommended onboarding approach?
  5. Any best-practice architecture recommendations for:
    • Corporate domain-joined devices
    • Contractor unmanaged devices
    • EMS Cloud
    • ZTNA
    • SSL-VPN
    • Entra ID SAML
    • FortiAuthenticator/FortiToken coexistence

Would appreciate guidance from anyone running a similar deployment in production.

reddit.com
u/tkr_2020 — 2 months ago