---
name: fortigate-10g-explore-firewalls
title: Exploring firewalls
description: IBM Cloud&reg; offers several firewalls to choose from. The following table compares the firewall solutions to help you choose the most suitable one. To learn more about the individual offering, click its name in the table.
last-updated: 2026-04-13
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/fortigate-10g?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Exploring firewalls
{: #exploring-firewalls}

Effective 17 December 2025, [Fortigate Security Appliance 10 Gbps](https://cloud.ibm.com/docs/fortigate-10g?topic=fortigate-10g-getting-started&format=markdown) and [IBM Shared Hardware Firewall](https://cloud.ibm.com/docs/hardware-firewall-shared?topic=hardware-firewall-shared-getting-started&format=markdown) on IBM Cloud have reached End of Marketing (EOM) and no longer accept new orders. Additionally, both these services will reach End of Support (EOS) on 31 December 2026. After this date, they will no longer be supported or available for use on IBM Cloud.
{: deprecated}

IBM Cloud&reg; offers several firewalls to choose from. The following table compares the firewall solutions to help you choose the most suitable one. To learn more about the individual offering, click its name in the table.
{: shortdesc}

These offerings are not managed services. When using them, you must understand the shared responsibilities between the client (or their managed services provider) and IBM. For more information, refer to [Roles and responsibilities for IBM Cloud gateways and firewalls](https://cloud.ibm.com/docs/hardware-firewall-shared?topic=hardware-firewall-shared-ga-raci&format=markdown).
{: important}

## Migration options for FSA 10Gbps and IBM shared hardware firewall
{: #migration-options-fortigate-10g-ibm-shared-firewall}

FortiGate Security Appliance 10Gbps and Shared Hardware Firewall are expected to reach end of support on 31 December 2026. To keep your network secure and avoid any business disruptions, we recommend planning your migration well before the end of support date.

The following alternatives help you migrate to a suitable firewall offering:

1. Recommended option:
   * Migrate to the Fortinet Virtual Firewall (vFSA). See [Getting started with vFSA](https://cloud.ibm.com/docs/vfsa?topic=vfsa-getting-started-vfsa&format=markdown) and [license types](https://cloud.ibm.com/docs/vfsa?topic=vfsa-getting-started-vfsa&format=markdown#choosing-vfsa-license).
   * Use Forti-Converter Service that is included in the enterprise license to migrate security policies and configurations from Fortinet hardware to the Fortinet virtual appliance.
      * Register an account in the [FortiConverter Service](https://service.forticonverter.com/){: external} for customer self-managed service.
      * For help with creating a migration ticket, see the [Forti-Converter Service Ticket Guide](https://docs.fortinet.com/document/forticonverter-service/25.1.0/online-help/783478/create-forticonverter-service-ticket){: external}.
1. Other virtual firewall options:
   * Virtual Router Appliance (VRA 5600): Enterprise router with firewall, VPN, traffic shaping, and policy-based    routing. See [Getting started with Virtual Router Appliance](https://cloud.ibm.com/docs/virtual-router-appliance?topic=virtual-router-appliance-getting-started-vra&format=markdown).
   * Juniper vSRX with Content Security Bundle: Enhanced security features, VLAN protection, HA configurations, IPS/IDS/UTM capabilities. See [Getting started with Juniper vSRX](https://cloud.ibm.com/docs/vsrx?topic=vsrx-getting-started-vsrx&format=markdown).

Contact [IBM Cloud Support](https://www.ibm.com/products/cloud/support){: external} for any guidance or to know more about the migration process.

| Feature | [Security Groups](https://cloud.ibm.com/docs/security-groups?topic=security-groups-getting-started&format=markdown) (VSI only) | [IBM Cloud Juniper vSRX Standard](https://cloud.ibm.com/docs/vsrx?topic=vsrx-getting-started-vsrx&format=markdown) | [Virtual Router Appliance](https://cloud.ibm.com/docs/virtual-router-appliance?topic=virtual-router-appliance-getting-started-vra&format=markdown) | [FortiGate Security Appliance 10 Gbps](https://cloud.ibm.com/docs/fortigate-10g?topic=fortigate-10g-getting-started&format=markdown) | [Hardware Firewall](https://cloud.ibm.com/docs/hardware-firewall-shared?topic=hardware-firewall-shared-getting-started&format=markdown) | [Cloud Internet Services](https://cloud.ibm.com/docs/cis?topic=cis-getting-started&format=markdown) | [Virtual FortiGate Security Appliance](https://cloud.ibm.com/docs/vfsa?topic=vfsa-getting-started-vfsa&format=markdown) |
| ------ | ------ | ------ | ------ | ------ | ------ | ------ | ------ |
| **Stateful Packet Inspection** | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | IP Firewall only | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Public Network Protection** | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Private Network Protection** | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Ingress Rules** | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | IP Firewall only | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Egress Rules** | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Single Tenant Appliance** | | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **VLAN Protection** | | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Multi-VLAN Support** | | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **NAT Support** | | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **SSL/IPsec VPN Termination** | | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **OpenVPN Termination** | | | ![Checkmark icon](../icons/checkmark-icon.svg) | | | Only with single port on TCP/UDP | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **HA Option** | N/A | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | Using ranges and load balancers | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Manage from API & Portal** | Yes | Appliance GUI | Appliance GUI | Appliance GUI | Yes | Cloud console | Appliance GUI |
| **10 Gbps Support** | N/A | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) | | | ![Checkmark icon](../icons/checkmark-icon.svg) | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **NGFW Add-ons (IPS, AV, WF)** | | ![Checkmark icon](../icons/checkmark-icon.svg) | | ![Checkmark icon](../icons/checkmark-icon.svg) | | TLS encryption, IP firewall rules, and Proxy Protocol v1 | ![Checkmark icon](../icons/checkmark-icon.svg) |
| **Remote Access VPN** | | ![Checkmark icon](../icons/checkmark-icon.svg) | | | | | ![Checkmark icon](../icons/checkmark-icon.svg) |
{: row-headers}
{: caption="A comparison of IBM's firewall offerings" caption-side="bottom"}
{: class="comparison-table"}
{: summary="This table shows IBM's firewall offerings and links to their documentation."}