Fortinet today introduced its latest custom ASIC to power its next generation of entry and mid-range FortiGate firewalls. The vendor touted the new chip as offering better firewall performance, faster encryption for zero-trust and secure access service edge (SASE) use cases, while enabling it to build better systems for the network edge.
The security giant plans to roll out the first set of FortiGate firewall products based on the new 7-nanometer chip, dubbed FortiSP5, in the second half of this year, Fortinet CMO and EVP of Product John Maddison told SDxCentral.
Maddison claimed the new chip delivers 17-times faster firewall performances, 32-times faster encryption, and 88% less power consumption than standard CPUs, while offering hardware supply chain and price advantages. It also provides FortiGate next-generation firewall (NGFW) products with 3.5-times faster performance to support 14 different firewall applications, including zero trust, SD-WAN, secure sockets layer (SSL) inspection, access point, and Wi-Fi network access control.
“These numbers are pretty staggering when you think about it. It's not 10% better, it's 3,200% better," Maddison said. “The ability to do encryption, run things very fast from a network perspective, to do content matching, all that allows all the applications to run such as zero trust, and SD-WAN, and next-gen firewall."
He highlighted the use case for edge computing that allows Fortinet to build NGFW systems running faster at the network edge with more applications and low power consumption.
As more functionality and computing shift to the network edge to improve efficiency and cost control, traditional products don’t offer enough processing power to deliver new capabilities and applications. Plus, the firewalls for those locations have to be hardware form factors and require different designs from those for data centers or in the cloud, Maddison explained.
Fortinet's entry-level FortiGate firewalls are targeting this large appliance marketplace at the network edge and are designed to secure operational technology infrastructure and IoT devices, he added.
Fortinet claims the new ASIC also accelerates and runs twice as many applications, including zero-trust network access (ZTNA), SD-WAN, and SSL inspection compared to the previous iteration. And ZTNA, SD-WAN, and firewalls are key components of SASE.
Those security features rely on encryption technologies, so they are “really hard to run on low-end CPU-based systems,” Maddison said.
Comments