FortiGate 40F, 60F, 70G and 90G Compared: Which Model for Which Office?
FortiGate 60F vs 70G comparison, with the 40F and 90G placed on the same table, comes down to how much traffic you will inspect rather than how many users you have: according to Fortinet data sheets, the 40F fits a 5–10 user micro office, the 60F a 10–30 user small office, the 70G a 20–50 user branch, and the 90G a busy 100–150 user site. The real differences are SSL inspection, session capacity and port layout.
Four models at a glance: what separates the F-series from the G-series?
The F-series (40F, 60F) runs on Fortinet's SoC4 system-on-a-chip, while the G-series (70G, 90G) uses the newer SP5 Secure SD-WAN ASIC. According to the data sheets, the G-series brings firewall throughput that does not drop with small packets, at least double the session capacity, a TPM and a signed-firmware switch; the F-series remains valid for micro and small offices thanks to fanless design and lower power draw.
The table below lines up the four models using values from the official Fortinet data sheets. Throughput figures are "up to" values measured under lab conditions. For sizing, the binding rows are Threat Protection (all profiles including antivirus enabled) and, if you intend to open all encrypted traffic, SSL Inspection.
| Metric (Fortinet data sheet) | FortiGate 40F | FortiGate 60F | FortiGate 70G | FortiGate 90G |
|---|---|---|---|---|
| Target scale (our field experience) | 5–10 users | 10–30 users | 20–50 users | 100–150 users |
| ASIC | SoC4 | SoC4 | SP5 | SP5 |
| IPv4 firewall (1518 / 64 byte UDP) | 5 / 5 Gbps | 10 / 6 Gbps | 10 / 10 Gbps | 28 / 27.9 Gbps |
| IPS throughput | 1 Gbps | 1.4 Gbps | 2.5 Gbps | 4.5 Gbps |
| NGFW throughput | 800 Mbps | 1 Gbps | 1.5 Gbps | 2.5 Gbps |
| Threat Protection throughput | 600 Mbps | 700 Mbps | 1.3 Gbps | 2.2 Gbps |
| SSL Inspection throughput | 310 Mbps | 630 Mbps | 1.4 Gbps | 2.6 Gbps |
| IPsec VPN (512 byte, AES256-SHA256) | 4.4 Gbps | 6.5 Gbps | 7.1 Gbps | 25 Gbps |
| Concurrent sessions (TCP) | 700,000 | 700,000 | 1.4 million | 3 million |
| New sessions/second (TCP) | 35,000 | 35,000 | 100,000 | 124,000 |
| Firewall policies | 2,000 | 2,000 | 5,000 | 5,000 |
| Port layout | 5x GE RJ45 | 10x GE RJ45 (2 WAN) | 10x GE RJ45 (2 WAN) | 2x shared media pairs (10GE SFP+ / RJ45) + 8x GE RJ45 |
| Max FortiAP (tunnel) / FortiSwitch | 16 (8) / 8 | 64 (32) / 24 | 96 (48) / 24 | 128 (64) / 24 |
| PoE / built-in Wi-Fi variant | No / No | No / No | 70G-POE 60 W / FortiWiFi 70G (Wi-Fi 6) | No / No |
| SSD variant | — | FG-61F 128 GB | FG-71G 64 GB | FG-91G 120 GB |
| TPM | No | No | Yes | Yes |
| Average power draw | 7.74 W (fanless) | 10.17 W (fanless) | 12.3 W | 19.9 W |
| SSL VPN / Agentless VPN (FortiOS 7.6) | 7.6.0+: no web or tunnel mode; 7.6.3+: no Agentless VPN | 7.6.0+: no web or tunnel mode; 7.6.3+: no Agentless VPN | 7.6.3+: no tunnel mode (all models); verify Agentless VPN in current release notes | 7.6.1+: no web or tunnel mode; 7.6.3+: no Agentless VPN |
One common misreading needs clearing up first: IPS throughput and Threat Protection throughput are not the same thing. The IPS value is measured with only the intrusion prevention engine active; the Threat Protection value applies with firewall, IPS, application control and antivirus all enabled together. If a branch link will run under "full protection", the second row is the one to compare. How these values interact with the license bundle is covered separately in our article on the factors that determine FortiGate pricing.
Which office is the FortiGate 40F right for?
The FortiGate 40F is a fanless desktop model with five GE RJ45 ports that, according to the Fortinet data sheet, delivers 5 Gbps IPv4 firewall, 600 Mbps Threat Protection and 310 Mbps SSL Inspection throughput. It is the right size for a 5–10 user single-site office, a home office, a small clinic or a point of sale without a wired line; the 40F-3G4G variant carries an embedded LTE modem and two nano SIM slots.
Two values set the practical ceiling of the 40F. The first is its 310 Mbps SSL Inspection capacity: with most web traffic encrypted today, an "open and inspect all HTTPS" policy quickly becomes a bottleneck on this model. The second is the limit of 2,000 firewall policies and 700,000 concurrent sessions; in multi-VLAN deployments with a busy guest network, this table fills up earlier than expected. Average consumption of 7.74 W and a 0 dBA noise level mean the unit can sit in a meeting room or on a desk.
On the access layer, the data sheet defines management of 16 FortiAPs (8 in tunnel mode) and 8 FortiSwitches, which is enough for a single-floor small office. A footnote in the subscription table states that Content Disarm and Reconstruct, Video Filtering and Inline CASB are not available on the 40F series from FortiOS 7.4.4 onward. If a compliance requirement depends on one of these three services, look at the 70G from the start rather than the 40F. The full specification is on our FortiGate 40F product page.
Is the FortiGate 60F still the right choice in 2026?
The FortiGate 60F, with ten GE RJ45 ports (2 WAN + 1 DMZ + 5 internal + 2 FortiLink), 10 Gbps IPv4 firewall, 700 Mbps Threat Protection and 630 Mbps SSL Inspection, has long been the standard model for 10–30 user small offices and branches. Fortinet has not published an end-of-order date for it; for new multi-year purchases, however, the SSL-VPN restriction and session capacity mean it should be evaluated alongside the 70G.
The real strength of the 60F is port density and access-layer capacity. Two separate Ethernet WAN ports, which many alternatives in the same class lack, allow SD-WAN to run across two links without an extra license; management of 64 FortiAPs (32 tunnel) and 24 FortiSwitches brings the wired and wireless infrastructure of a multi-floor small office under one policy engine. The FG-61F variant adds a 128 GB internal SSD for limited local log storage; organizations that need long-term retention should still plan on FortiAnalyzer.
Its limits are equally clear. At 64 byte UDP, firewall throughput drops to 6 Gbps, concurrent sessions stay at 700,000 and new sessions per second at 35,000; in environments that generate many short-lived connections, such as POS terminals, IoT sensors and crowded guest networks, these numbers trail the 70G's 1.4 million / 100,000. The data sheet footnote also states that SSL-VPN is not supported on FortiOS 7.6.0 and later. An existing 60F fleet does not need urgent replacement; for a new purchase, we recommend applying the criteria in our firewall selection guide for SMBs. Detailed values are on the FortiGate 60F product page.
Does the FortiGate 70G really replace the 60F?
The FortiGate 70G delivers, on the SP5 ASIC, 10 Gbps firewall throughput at both 1518 and 64 byte packets, 1.3 Gbps Threat Protection, 1.4 Gbps SSL Inspection, 1.4 million concurrent sessions and 100,000 new sessions per second. Fortinet's current ordering guide lists the 70G among the latest available models for each series; that is why we position it as the refresh path for the 60F in 20–50 user branches.
The claim that "the 70G is twice as fast as the 60F" does not match the data sheets; large-packet firewall capacity is 10 Gbps on both. The real gain is in three places: small-packet performance (10 Gbps vs 6 Gbps), the session table (1.4 million vs 700,000) and inspected traffic (1.4 Gbps vs 630 Mbps SSL Inspection, roughly 2.2x). The firewall policy limit rises from 2,000 to 5,000, which gives room in branches with detailed segmentation. Average draw is 12.3 W, so the capacity increase does not show up on the electricity bill.
The operational advantage of the 70G family is variant choice: the FG-70G-POE powers IP phones, cameras or a FortiAP without a separate switch through four GE RJ45 PoE/+ ports and a 60 W budget; the FortiWiFi 70G carries a built-in dual-band Wi-Fi 6 access point; the FG-71G adds a 64 GB SSD. All are managed from a single configuration template, so hardware varies by store type while the central policy set stays the same. On hardware security, the 70G introduces a TPM and a physical signed-firmware switch that the 40F and 60F lack, a tangible layer at field sites where physical access is not fully controlled. One important caveat: the data sheet lists SSL-VPN throughput as "N/A" for the 70G, and FortiOS 7.6.3 replaced SSL VPN tunnel mode with IPsec on all models; because the 70G is not named in Fortinet's Agentless VPN removal list, verify that feature's status in the current release notes. Design remote access on IPsec (7.1 Gbps) or ZTNA from day one. Source: FortiGate FortiWiFi 70G Series Data Sheet. For variant selection see our FortiGate 70G product page.
When do you need the FortiGate 90G?
The FortiGate 90G is built for busy 100–150 user branches and small head offices that want near-1U performance in a desktop form factor: 28 Gbps IPv4 firewall, 4.5 Gbps IPS, 2.2 Gbps Threat Protection, 2.6 Gbps SSL Inspection, 25 Gbps IPsec VPN and 3 million concurrent sessions. Its two shared media pairs can be used as 10GE SFP+; there is no PoE and no built-in Wi-Fi.
The figure that sets the 90G apart from the other three is its 25 Gbps IPsec VPN throughput, against 7.1 Gbps on the 70G and 6.5 Gbps on the 60F. In practice, when SD-WAN builds a separate overlay tunnel per WAN link, or when a regional hub aggregates the tunnels of downstream branches, the encryption load grows fast; the 90G handles it without pushing it onto the CPU and terminates 200 gateway-to-gateway and 2,500 client-to-gateway tunnels. The 2.6 Gbps SSL Inspection capacity allows all HTTPS traffic on a 1 Gbit/s class link to be inspected, which is decisive in finance branches under PCI-DSS.
The port design differs from the other three models: two shared media pairs (10/5/2.5/GE RJ45 or 10GE/GE SFP+) plus eight GE RJ45 internal ports. RJ45 and SFP+ cannot be used simultaneously on the same pair, which must be reflected in the design. For software offices or production sites connecting to a 10GE backbone, this is the only option in the desktop class. Wireless is handled by separate FortiAPs (up to 128, 64 in tunnel mode) and PoE by a FortiSwitch PoE model placed in between. The unit produces 21.73 dBA, so it is not silent like the F-series. A detailed comparison with the 80F and 120G is in our FortiGate 90G article, and the full specification on the FortiGate 90G product page.
Which five criteria decide the model?
In our field experience, five criteria decide between the four models: the amount of encrypted traffic to inspect (the SSL Inspection row), the session profile (density of short-lived connections such as POS and IoT), port and uplink needs (whether 10GE is required), the size of the access layer (how many FortiAPs and FortiSwitches will be managed) and PoE/Wi-Fi requirements. User count is only the starting point.
The decision matrix below maps typical office types to these criteria. The values are from Fortinet data sheets; the office types are the scenarios we meet most often in projects.
| Office type | Deciding criterion | Recommended model | Why |
|---|---|---|---|
| Home office, 5–10 person micro office, clinic | Silence, low power, single WAN | FortiGate 40F | Fanless 0 dBA, 7.74 W; 310 Mbps SSL inspection is enough at this scale |
| Temporary point of sale with no wired line | Cellular WAN | FortiGate 40F-3G4G | Embedded LTE modem, 2 nano SIMs, no external dongle |
| 10–30 person office, accounting or law firm | Port count, dual WAN, wireless layer | FortiGate 60F | 10 ports, 2 WAN, 64 FortiAPs; 630 Mbps SSL inspection |
| POS/IoT-heavy store, 20–50 person branch | Session setup rate, full SSL inspection | FortiGate 70G | 100,000 new sessions/s, 1.4 Gbps SSL Inspection, 5,000 policies |
| Small branch wanting firewall + Wi-Fi + PoE in one box | Hardware consolidation | FortiWiFi 70G-POE | Built-in Wi-Fi 6 and 60 W PoE budget in a single chassis |
| Remote branch, warehouse, uncontrolled physical access | Hardware security | FortiGate 70G / 90G | TPM and signed-firmware switch only on the G-series |
| 100–150 person busy branch, VPN-aggregating regional hub | IPsec capacity, 10GE uplink | FortiGate 90G | 25 Gbps IPsec, 3 million sessions, 10GE SFP+ media pairs |
| Rack mount, dual PSU, 150+ users | Resilience, port density | Higher model (120G and up) | Outside the scope of these four; evaluate the 1U series |
Make the access layer part of the same decision: all four models manage FortiSwitches over FortiLink, but there is a growth-margin difference between the 40F's limit of 8 switches and the 24-switch limit of the 60F/70G/90G. What FortiLink provides and which switch model pairs with which FortiGate is explained in our FortiSwitch and FortiLink selection guide. If wired ports are running short, adding a FortiSwitch on the FortiLink port is usually a better spend than moving up a firewall model.
How do SSL-VPN and FortiOS version limits affect the decision?
On current FortiOS 7.6 releases none of the four models keeps SSL VPN tunnel mode: according to Fortinet release notes, web and tunnel mode were removed from the 40F and 60F in 7.6.0, the 90G does not offer them from 7.6.1, and 7.6.3 replaced tunnel mode with IPsec on all models. Agentless VPN, the successor to web mode, is not available on the 40F, 60F or 90G; for the 70G, verify the current release notes.
This restriction is the most expensive detail overlooked in model selection. If FortiClient profiles remain on SSL-VPN while a 60F is swapped for a 70G, remote workers cannot connect on installation day. The correct order is to move client profiles to IPsec or the ZTNA application gateway first, then replace the hardware. Version-level details and what was removed in which FortiOS release are covered in our FortiOS 7.6 SSL-VPN migration plan; verify the Fortinet release notes for definitive information. According to Fortinet's FortiOS 7.6.3 release notes, SSL VPN tunnel mode is replaced by IPsec VPN on all models from that release onward, so tunnel configurations must be migrated before upgrading.
The second version restriction sits on the subscription side. The footnote in the 40F and 60F data sheets states that Content Disarm and Reconstruct, Video Filtering and Inline CASB are not available on these series from FortiOS 7.4.4 onward; the 70G and 90G do not appear in that footnote. If one of these three services is part of your compliance requirement, the discussion is about hardware, not versions. Under Fortinet's product life cycle policy, standard FortiOS releases receive 36 months of engineering support followed by 18 months of "Must Fix" support; since release-specific end dates can be revised, we check the current calendar together before every purchase. Source: FortiGate 60F Series Data Sheet.
Frequently Asked Questions
What is the difference between the FortiGate 60F and 70G?
Large-packet firewall throughput is 10 Gbps on both. The difference shows at small packets (10 Gbps vs 6 Gbps), in concurrent sessions (1.4 million vs 700,000), in new sessions per second (100,000 vs 35,000) and in SSL Inspection (1.4 Gbps vs 630 Mbps). The 70G also offers a TPM plus PoE and Wi-Fi 6 variants.
How many users does the FortiGate 40F support?
Fortinet does not publish user counts; scale is derived from capacity values. 700,000 concurrent sessions, 35,000 new sessions per second and a 2,000 policy limit typically correspond to a 5–10 user single-site office. The deciding limit is usually the 310 Mbps SSL Inspection capacity.
Is the FortiGate 70G twice as fast as the 60F?
No. This common claim does not match the data sheets; at 1518 byte packets both models deliver 10 Gbps. The real gain is in small-packet performance, session capacity and inspected traffic. The SSL Inspection ratio is roughly 2.2x (1.4 Gbps / 630 Mbps), not two times and certainly not five.
Does the FortiGate 90G have built-in Wi-Fi or PoE?
No. The hardware table in the data sheet lists no wireless interface and no PoE port for the FG-90G and FG-91G. Wireless is provided by separate FortiAPs (up to 128), and a FortiSwitch PoE model is placed in between for PoE. If Wi-Fi and PoE are wanted in one device, consider the FortiWiFi 70G-POE.
Which of these four models supports SSL-VPN?
None of them has SSL VPN tunnel mode on FortiOS 7.6.3 or later; tunnel mode was replaced with IPsec VPN on all models. The 40F, 60F and 90G also lack Agentless VPN, the successor to web mode; for the 70G, verify the current release notes. New deployments should design remote access on IPsec dial-up tunnels or ZTNA.
Should a new purchase in 2026 be F-series or G-series?
For new multi-year purchases we put the 70G and 90G first: SP5 ASIC, TPM, a larger session table and no restrictions in the version footnotes. The 40F and 60F remain valid options for micro and small offices, since Fortinet has not published an end-of-order date; an existing fleet does not need urgent replacement.
Can all four models manage FortiSwitch and FortiAP?
Yes, all four manage FortiSwitches over FortiLink and FortiAPs through the built-in wireless controller. Capacity differs: 40F 8 switches / 16 APs, 60F 24 switches / 64 APs, 70G 24 switches / 96 APs, 90G 24 switches / 128 APs. Offices with growth plans should factor these limits into the model decision.
Conclusion
Choosing between the FortiGate 40F, 60F, 70G and 90G is not a speed race but a profile match. The quiet, low-power 40F fits the micro office, the 60F the small office that needs port density, the 70G the branch carrying session and SSL inspection load, and the 90G the busy site that aggregates VPNs or connects to a 10GE backbone. Before deciding, clarify your SSL-VPN dependency, the share of encrypted traffic you will inspect and your access-layer growth plan; all data sheet values are compared side by side on our FortiGate product family page.
As a project, procurement and deployment partner for Fortinet solutions, we plan the migration from your current device, the license bundle and the access-layer design together with you. To clarify which model is the right size for your office profile, request a free discovery call through our contact page.
