An IDMZ - an industrial demilitarised zone - is the buffer between a plant's control system
network and the business network. The reason it exists is that the two networks have opposite
requirements. The control network must not be exposed to the internet, cannot usually be patched
on anyone else's schedule, and often runs equipment that predates modern security entirely. The
business network needs the data that control system produces. An IDMZ resolves that by allowing
no direct traffic between the two: data is handed across through brokers and replicated
services inside the zone, and the firewall on each side enforces that nothing bypasses it. This
segmentation is what IEC 62443 and the Purdue reference model are describing, and it is now
routinely required by asset owners and insurers alike.
The firewall is the component that makes that boundary real, and FortiGate is a common choice
for it. Fortinet describe the 80F series as integrating firewalling, SD-WAN and security in one
appliance, powered by FortiOS - which they position as the industry's first converged networking
and security operating system. That convergence is the practical argument: an IDMZ needs
segmentation, inspection and often a wide-area link in the same place, and doing all three in one
appliance means one configuration, one policy set and one thing to audit.
The hardware approach is worth noting because it is unusual. The 80F family is built on
Fortinet's patented SD-WAN ASIC - a purpose-designed chip rather than a general-purpose
processor - which Fortinet state delivers performance beyond traditional CPUs at lower cost and
reduced power consumption. An embedded multi-core processor works alongside it. For a firewall
this matters when inspection is switched on: deep inspection is computationally expensive, and
appliances sized on marketing throughput figures frequently disappoint once the features the
firewall was bought for are actually enabled. Dedicated silicon is how that gap is narrowed.
Both models sit in the same Fortinet Security Fabric, working with FortiGuard AI-Powered
Security Services for what Fortinet describe as coordinated, automated, end-to-end threat
protection in real time. The practical value of the Fabric in an industrial context is that the
IDMZ firewalls, the site firewall and any branch appliances share threat intelligence and are
managed together rather than as separate boxes with separate rule sets that drift apart.
On choosing between the two: Fortinet position the 80F series for distributed enterprise
sites and for transforming WAN architecture, which is the profile of a remote facility, a branch
or a small plant. The 400F is the substantially larger appliance, appropriate where the boundary
carries more traffic or more concurrent sessions - a main site, a data centre edge or a busy
IDMZ. Sizing it correctly means working from the actual traffic to be inspected and the features
to be enabled, so we quote throughput figures from Fortinet's current datasheet for the specific
model and configuration rather than reproducing numbers here that a firmware release or a
feature change would invalidate.