Skip to content

About

Documentation repository for licensed-firewall

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

176 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

copyright
years
2026
lastupdated 2026-10-08
keywords firewall, license plans, vsi profiles, instance sizing, deployment sizes, pricing, firewall pricing, license plan pricing
subcollection licensed-firewall

{{site.data.keyword.attribute-definition-list}}

About firewall license plans, instance profiles, and pricing

{: #about-firewall-license-plans-and-instance-profiles}

When you provision a licensed firewall, the system automatically assigns a virtual server instance profile based on the license plan that you select. {: shortdesc}

The license plan determines:

  • The instance profile family
  • The supported deployment sizes
  • The performance and scaling characteristics

The license plan and virtual server profile are linked at deployment time.

Planning considerations

{: #considerations}

Review the following considerations before you select your license plan and deployment size:

  • Larger deployment sizes provide higher throughput and session capacity.
  • The selected license plan determines the available sizing options and scaling limits.
  • Some instance configurations might be less suitable for high availability or hub-and-spoke architectures. Review network design requirements before you select a deployment.
  • All deployments include FortiCare Premium support.
  • All license plans, including ATP, are available in all supported regions.

The license plan cannot be changed after deployment. You can resize the virtual server instance to a different profile without changing the license plan. For more information, see Resizing a firewall virtual server instance. {: important}

Choosing a deployment topology

{: #choosing-a-deployment-topology}

Select a deployment topology based on your availability requirements and tolerance for downtime. All three topologies are available as separate catalog tiles and are deployed by using IBM Cloud Schematics.

Topology Catalog Tile Firewall Instances Availability Zones Automatic Failover Best For
Single VM Fortinet FortiGate VM NGFW - Single (IBM reseller){: external} 1 1 No Development, testing, or noncritical workloads
Active/Passive HA - Single Zone Fortinet FortiGate VM NGFW - A/P HA (IBM reseller){: external} 2 1 Yes Production workloads requiring zone-level redundancy
Active/Passive HA - Cross Zone Fortinet FortiGate VM NGFW - Cross Zone A/P HA (IBM reseller){: external} 2 2 Yes Production workloads requiring the highest availability
{: caption="Deployment topology comparison" caption-side="bottom"}

Key differences between the topologies:

  • Single VM — Deploys one FortiGate-VM instance with a public interface (port1) and a private interface (port2). There is no redundancy. If the instance fails, traffic is interrupted until it is restarted or replaced.
  • Active/Passive HA - Single Zone — Deploys two FortiGate-VM instances in the same availability zone as an active-passive cluster. The IBM Cloud SDN connector enables automatic failover between nodes. If the active node fails, the passive node takes over without manual intervention.
  • Active/Passive HA - Cross Zone — Extends the single-zone HA topology across two availability zones. In addition to automatic failover, a public address range enables the floating IP to move between zones, providing resilience against a full zone outage. This is the highest-availability configuration.

For details on what IBM applies to each topology at provisioning time, see Understanding the default firewall configuration.

Choosing a license plan

{: #choosing-a-license-plan}

Select a license plan based on your workload requirements, performance needs, and scale. For more information about FortiGate Security Bundle features, see the FortiGate Security Bundles page{: external}.

License Plan Best For Supported Sizes Profile Family Key Characteristics
ATP (Advanced Threat Protection) Entry-level deployments Small, Medium gen2-cx Lower cost, limited scale
UTP (Unified Threat Protection) General-purpose security Small, Medium, Large gen3-cx Balanced cost and performance
Enterprise High-performance environments Medium, Large, X-large gen3-cx Highest scalability and throughput
{: caption="License plan comparison" caption-side="bottom"}

VDOM support is available only with the Enterprise license plan at the X-large (32 vCPU) deployment size. {: note}

License plan pricing

{: #pricing}

The following table lists estimated prices for each license plan and deployment size. Prices are in US dollars and apply per vCPU per hour.

License plan Deployment size vCPU Per vCPU/hour Est. monthly Est. annual
ATP Small 2 $0.17 $248.20 $2,978.40
ATP Medium 8 $0.17 $992.80 $11,913.60
UTP Small 2 $0.44 $642.40 $7,708.80
UTP Medium 8 $0.20 $1,168.00 $14,016.00
UTP Large 16 $0.21 $2,401.70 $28,820.40
Enterprise Medium 8 $0.24 $1,401.60 $16,819.20
Enterprise Large 16 $0.24 $2,803.20 $33,638.40
Enterprise X-large (8 VDOM) 32 $0.24 $5,606.40 $67,276.80
{: caption="Licensed firewall list prices by license plan and deployment size" caption-side="bottom"}

Monthly and annual estimates are based on 730 hours per month. Prices shown are list prices and do not include applicable taxes or discounts. {: note}

License plan feature entitlements

{: #license-plan-features}

The following table shows the security services and features that are included in each license plan.

Feature ATP UTP Enterprise
Intrusion Prevention System (IPS) Checkmark icon Checkmark icon Checkmark icon
Application control Checkmark icon Checkmark icon
Geo IP updates Checkmark icon Checkmark icon Checkmark icon
Advanced Malware Protection (AMP) Checkmark icon Checkmark icon Checkmark icon
Antivirus Checkmark icon Checkmark icon Checkmark icon
Botnet protection Checkmark icon Checkmark icon Checkmark icon
Device and OS detection Checkmark icon Checkmark icon Checkmark icon
Internet Service (SaaS) database Checkmark icon Checkmark icon Checkmark icon
Web and content filtering Checkmark icon Checkmark icon
Secure DNS filtering Checkmark icon Checkmark icon
Video filtering Checkmark icon Checkmark icon
AntiSpam Checkmark icon Checkmark icon
IoT query service Checkmark icon
OT protocol service Checkmark icon
Security Fabric rating and compliance monitoring Checkmark icon
AI-based inline malware prevention Checkmark icon
{: caption="License plan feature entitlements" caption-side="bottom"}

AI-based inline malware prevention is included with the Enterprise license and can be configured, used, and logged. However, access to FortiGate Cloud and FortiCloud is not available because the license is managed through the IBM Fortinet account. {: note}

Sizing and scaling characteristics

{: #sizing-and-scaling-characteristics}

Understanding the sizing and scaling characteristics helps you select the appropriate deployment size for your workload requirements.

Deployment sizes

{: #deployment-size-definitions}

Deployment sizes are mapped to vCPU allocations.

Deployment Size vCPU
Small 2
Medium 8
Large 16
X-large 32
{: caption="Deployment size vCPU allocations" caption-side="bottom"}

Larger deployment sizes include increased memory, which improves session handling and overall scalability. {: note}

Supported sizes by license plan

{: #supported-deployment-sizes-by-license-plan}

The available deployment sizes vary by license plan.

License Plan Small (2 vCPU) Medium (8 vCPU) Large (16 vCPU) X-large (32 vCPU)
Enterprise Not available Supported Supported Supported
UTP Supported Supported Supported Not available
ATP Supported Supported Not available Not available
{: caption="Supported deployment sizes by license plan" caption-side="bottom"}

VDOM support is available only with the Enterprise license plan at the X-large (32 vCPU) deployment size. {: note}

Session scaling

{: #session-scaling}

Connection capacity increases with deployment size and available memory.

  • Smaller deployments support fewer concurrent sessions.
  • Larger deployments support significantly higher connection volumes and session tables.

Instance profile details

{: #instance-profile-details}

Instance profiles define the compute resources that are allocated to your firewall deployment.

Each license plan includes a specific number of vCPUs for your FortiGate-VM. Based on the selected license plan and deployment size, IBM automatically assigns a virtual server instance profile that provides the required vCPUs and throughput. Because available profiles vary by region, IBM manages profile selection and you cannot choose or override the assigned profile.

Virtual server profiles are automatically assigned during provisioning based on the selected license plan and deployment size. You cannot manually select or override the instance profile during deployment. {: note}

Enterprise profile mappings

{: #enterprise-profile-mappings}

This license plan uses gen3-cx profiles and supports Medium, Large, and X-large deployment sizes.

Deployment Size vCPU Instance Profile Profile Family
Medium 8 cx3d-8x20 gen3-cx
Large 16 cx3d-16x40 gen3-cx
X-large 32 cx3d-32x80 gen3-cx
{: caption="Enterprise license plan virtual server profile mappings" caption-side="bottom"}

The X-large (32 vCPU) Enterprise deployment is the only configuration that supports virtual domains (VDOMs) and includes 8 VDOMs. {: note}

UTP profile mappings

{: #utp-profile-mappings}

This license plan uses gen3-cx profiles and supports Small, Medium, and Large deployment sizes.

Deployment Size vCPU Instance Profile Profile Family
Small 2 cx3d-2x5 gen3-cx
Medium 8 cx3d-8x20 gen3-cx
Large 16 cx3d-16x40 gen3-cx
{: caption="Unified Threat Protection (UTP) license plan virtual server profile mappings" caption-side="bottom"}

ATP profile mappings

{: #atp-profile-mappings}

This license plan uses gen2-cx profiles and supports Small and Medium deployment sizes. In some regions, IBM automatically assigns an equivalent alternative profile where the standard gen2-cx profile is unavailable.

Deployment Size vCPU Instance Profile Profile Family
Small 2 cx2-2x4 gen2-cx
Medium 8 cx2-8x16 gen2-cx
{: caption="Advanced Threat Protection (ATP) license plan virtual server profile mappings" caption-side="bottom"}

In a few regions, IBM automatically assigns an alternate gen3-cx profile where the standard gen2-cx profile is unavailable. The deployment size and entitlement remain equivalent. {: note}

Profile considerations

{: #instance-profile-considerations}

Consider the following factors when you evaluate instance profiles for your deployment:

  • cx profiles provide a balanced cost-to-performance ratio and are suitable for most workloads.
  • Profiles with higher memory ratios can benefit environments with high session counts.
  • Profiles with -d include additional instance storage, which can increase cost.
  • Profile selection impacts both performance characteristics and pricing.
  • Gen3 profiles use newer infrastructure and are recommended for most deployments.
  • Gen2 profiles are typically used for smaller or entry-level workloads.

Related links

{: #license-plans-related-links}

About

Documentation repository for licensed-firewall

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors