| copyright |
|
||
|---|---|---|---|
| lastupdated | 2026-09-03 | ||
| keywords | explore, firewalls, fsa, fortigate, juniper, vsrx, vra, vfsa, virtual router appliance, security, vyatta, comparison, features | ||
| subcollection | fortigate-10g |
{{site.data.keyword.attribute-definition-list}}
{: #exploring-firewalls}
Effective 17 December 2025, Fortigate Security Appliance 10 Gbps and IBM Shared Hardware Firewall on IBM Cloud have reached End of Marketing (EOM) and no longer accept new orders. Additionally, both these services will reach End of Support (EOS) on 31 December 2026. After this date, they will no longer be supported or available for use on IBM Cloud. {: deprecated}
{{site.data.keyword.cloud}} offers several firewalls to choose from. The following table compares the firewall solutions to help you choose the most suitable one. To learn more about the individual offering, click its name in the table. {: shortdesc}
These offerings are not managed services. When using them, you must understand the shared responsibilities between the client (or their managed services provider) and IBM. For more information, refer to Roles and responsibilities for IBM Cloud gateways and firewalls. {: important}
{: #migration-options-fortigate-10g-ibm-shared-firewall}
FortiGate Security Appliance 10Gbps and Shared Hardware Firewall are expected to reach end of support on 31 December 2026. To keep your network secure and avoid any business disruptions, we recommend planning your migration well before the end of support date.
The following alternatives help you migrate to a suitable firewall offering:
- Recommended option:
- Migrate to virtual firewall in IBM Cloud VPC. For more information see, IBM Cloud VPC firewall options.
- Migrate to the Fortinet Virtual Firewall (vFSA). See Getting started with vFSA and license types.
- Use Forti-Converter Service that is included in the enterprise license to migrate security policies and configurations from Fortinet hardware to the Fortinet virtual appliance.
- Register an account in the FortiConverter Service{: external} for customer self-managed service.
- For help with creating a migration ticket, see the Forti-Converter Service Ticket Guide{: external}.
- Other virtual firewall options:
- Virtual Router Appliance (VRA 5600): Enterprise router with firewall, VPN, traffic shaping, and policy-based routing. See Getting started with Virtual Router Appliance.
- Juniper vSRX with Content Security Bundle: Enhanced security features, VLAN protection, HA configurations, IPS/IDS/UTM capabilities. See Getting started with Juniper vSRX.
Contact IBM Cloud Support{: external} for any guidance or to know more about the migration process.
| Feature | Security Groups (VSI only) | IBM Cloud Juniper vSRX Standard | Virtual Router Appliance | FortiGate Security Appliance 10 Gbps | Hardware Firewall | Cloud Internet Services | Virtual FortiGate Security Appliance |
|---|---|---|---|---|---|---|---|
| Stateful Packet Inspection | IP Firewall only | ||||||
| Public Network Protection | |||||||
| Private Network Protection | |||||||
| Ingress Rules | IP Firewall only | ||||||
| Egress Rules | |||||||
| Single Tenant Appliance | |||||||
| VLAN Protection | |||||||
| Multi-VLAN Support | |||||||
| NAT Support | |||||||
| SSL/IPsec VPN Termination | |||||||
| OpenVPN Termination | Only with single port on TCP/UDP | ||||||
| HA Option | N/A | Using ranges and load balancers | |||||
| Manage from API & Portal | Yes | Appliance GUI | Appliance GUI | Appliance GUI | Yes | Cloud console | Appliance GUI |
| 10 Gbps Support | N/A | ||||||
| NGFW Add-ons (IPS, AV, WF) | TLS encryption, IP firewall rules, and Proxy Protocol v1 | ||||||
| Remote Access VPN | |||||||
| {: row-headers} | |||||||
| {: caption="A comparison of IBM's firewall offerings" caption-side="bottom"} | |||||||
| {: class="comparison-table"} | |||||||
| {: summary="This table shows IBM's firewall offerings and links to their documentation."} |