FortiGate NGFW is Fortinet's next-generation firewall family, built on the FortiOS operating system and FortiASIC hardware acceleration. Firewall, IPS, antivirus, application control, SSL/TLS inspection, SD-WAN and ZTNA are consolidated into a single appliance, and the same policy model runs unchanged across 20 models, from the desktop FortiGate 40F to the 12U chassis-based FortiGate 7081F. The right model is chosen according to inspected traffic requirements rather than user count.
Independent data shows why this layer has become so critical. In Verizon's 2025 Data Breach Investigations Report, vulnerability exploitation rose to 20% as an initial access vector, and 22% of those exploitation actions directly targeted edge devices and VPNs — in the previous report that share was only 3% (Verizon DBIR, 2025). The same report measures that organizations were able to fully close only around 54% of their edge device vulnerabilities during the year, and that doing so took a median of 32 days (Verizon DBIR, 2025). Fortinet's official product page, for its part, describes FortiGate as "the most deployed network firewall, with more than 50% of global market share" (Fortinet, 2026). In other words, the layer attackers probe most and the most widespread device family in the field meet at the same point; sizing and patch discipline are therefore not negotiable.
Which security functions does FortiGate NGFW combine in a single appliance?
FortiGate runs stateful firewall, intrusion prevention (IPS), antivirus, application control, web and DNS filtering, SSL/TLS inspection, IPsec VPN, SD-WAN and a ZTNA access gateway within a single FortiOS instance. These are not separate boxes but security profiles attached to the same policy engine: when you bind an IPS and antivirus profile to a firewall rule, traffic is not diverted to a second appliance — it is inspected within the same session.
The operational counterpart of that is clear. Instead of keeping a separate VPN concentrator, a separate web proxy and a separate SD-WAN box at the branch, you deploy a single appliance. Because the same FortiOS also runs at headquarters, a policy written at the branch is valid with identical syntax on the large model in the data center. Configuration portability is the most overlooked property in a 20-model family, and yet the one that most reduces total cost of ownership; a device upgrade stops being a migration project and becomes a configuration transfer.
Separating which capability comes with the appliance and which comes with a subscription is the first step in budget planning:
- Included with the appliance, no additional subscription required: firewall policies, NAT, VLAN, dynamic routing, IPsec VPN, SD-WAN routing and SLA measurement, HA clustering, VDOMs up to the model limit, the built-in WLAN controller and FortiSwitch management through FortiLink.
- Included with a FortiGuard subscription: IPS signatures, antivirus definitions, web and DNS filtering categories, the application control signature database, IoT/OT device recognition, botnet and poor-reputation IP lists.
- Included with FortiCare: hardware replacement, technical support and access to FortiOS releases; Long-Term Supported releases are unlocked only with a FortiCare Elite contract.
On the FortiLink side, a FortiGate can manage between 8 and 300 FortiSwitches as its own logical extension depending on the model, and provides basic NAC functions such as profiling connected devices, IoT segmentation and quarantine in the event of a breach at no extra cost (Fortinet FortiSwitch data sheet, 2026). On the ZTNA side the architecture has three parts: the FortiClient ZTNA agent on the endpoint, FortiClient EMS holding identity and posture information, and the FortiGate ZTNA application gateway enforcing the access decision. Fortinet introduced this model with FortiOS 7.0 (Fortinet Docs, 2026) and has since positioned it as the primary remote access method to replace SSL-VPN; indeed, the FortiGate 40F and 60F data sheets state explicitly that SSL-VPN is not supported on FortiOS 7.6.0 and later (FortiGate 60F data sheet, 2026).
Which FortiGate model should I choose?
The decisive figure in the selection is not raw firewall throughput but Threat Protection throughput. Fortinet measures this metric on Enterprise Mix traffic with firewall, IPS, application control and malware protection all enabled simultaneously and logging running; the result stays between just 5% and 19% of the raw firewall figure across the 18 models in the table below. For example, the FortiGate 600F's IPv4 firewall figure is 139 Gbps while its Threat Protection figure is 10.5 Gbps (FortiGate 600F data sheet, 2026). Choosing a device on the basis of 139 Gbps and then running into a reality of 10.5 Gbps is the sizing mistake we see most often in the field.
The user scenarios in the table below are not Fortinet data sheet values — Fortinet does not publish a user count per model. The scenario column is a starting point drawn from our own deployment experience; the throughput column is the Threat Protection row from the relevant model's official data sheet. When the binding constraint is SSL inspection rather than Threat Protection, the ordering changes: the FortiGate 900G delivers 16.7 Gbps, the FortiGate 2600F 20 Gbps and the FortiGate 3700F 55 Gbps of SSL Inspection; in that case the SSL Inspection row should be consulted directly instead of the tier in the table. The final decision should always be made on the real traffic measured at your current internet egress plus a three-year growth allowance.
| Scenario | Threat Protection throughput required | Starting model | One tier up |
|---|
| Micro office, checkout/POS point, single internet line | up to 600 Mbps | FortiGate 40F | FortiGate 60F |
| Small branch, limited SSL inspection | 700 Mbps – 1.3 Gbps | FortiGate 60F / FortiGate 70G | FortiGate 80F |
| Mid-sized branch powering phones and APs over PoE | 900 Mbps – 2.2 Gbps | FortiGate 80F / FortiGate 90G | FortiGate 120G |
| Head office, 1U rack, heavy application control | 2.8 – 3 Gbps | FortiGate 120G / FortiGate 200F | FortiGate 400F |
| Campus or regional headquarters, multiple VLANs and 10GE uplink | 9 – 10.5 Gbps | FortiGate 400F / FortiGate 600F | FortiGate 900G |
| Enterprise headquarters where full SSL inspection is mandatory | up to 30 Gbps | FortiGate 900G | FortiGate 3700F |
| Data center edge, 100GE uplink | 13 – 25 Gbps | FortiGate 1000F / FortiGate 1800F / FortiGate 2600F | FortiGate 3700F |
| Hyperscale, carrier and large service provider | 75 Gbps and above | FortiGate 3700F / FortiGate 4400F | FortiGate 7081F |
| Cloud and virtualization environment | Depends on host hardware | FortiGate-VM | FortiGate CNF (SaaS) |
Entry level (SMB and branch). The FortiGate 40F is a fanless desktop appliance drawing an average of 7.74 W and generating 0 dBA of noise; it is designed for places where mechanical cooling is a problem, such as behind a checkout counter or in a small stockroom (FortiGate 40F data sheet, 2026). The FortiGate 60F, with ten GE RJ45 ports and 700,000 concurrent sessions, is the classic branch appliance. The FortiGate 70G, despite appearing to sit in the same class, delivers 10 Gbps on 64 byte packets (6 Gbps on the 60F), 100,000 new sessions per second (35,000 on the 60F) and 1.4 Gbps of SSL inspection (630 Mbps on the 60F) (FortiGate 70G data sheet, 2026); in new branch projects it is these three rows that make the difference. The FortiGate 90G stands out with 25 Gbps of IPsec VPN in a desktop form factor (FortiGate 90G data sheet, 2026), while the FortiGate 120G sits on the head office boundary with 2.8 Gbps of Threat Protection and 35 Gbps of IPsec VPN in a 1U body (FortiGate 120G data sheet, 2026).
Mid-range (campus and regional headquarters). The FortiGate 400F delivers 79.5 Gbps of IPv4 firewall, 9 Gbps of Threat Protection and 8 Gbps of SSL inspection; its fastest interfaces are eight 10GE SFP+ ports, four of them ultra-low latency (FortiGate 400F data sheet, 2026). In this family the 25GE SFP28 interface first appears on the FortiGate 600F (a 4x 25GE SFP28/10GE SFP+ ultra-low latency slot) (FortiGate 600F data sheet, 2026). The FortiGate 900G is this group's performance leap: 164 Gbps of firewall, 30 Gbps of Threat Protection, 16.7 Gbps of SSL inspection and 28 million concurrent sessions (FortiGate 900G data sheet, 2026). The FortiGate 1000F, by contrast, has a higher firewall figure (198 Gbps) yet stops at 13 Gbps on the Threat Protection side (FortiGate 1000F data sheet, 2026) — the two models should be separated not as "big/small" but by port requirements and inspection intensity.
High end (data center and hyperscale). The FortiGate 1800F and 2600F share the same 198 Gbps firewall figure; the real difference between them lies in Threat Protection (15 Gbps versus 25 Gbps), SSL inspection (12 Gbps versus 20 Gbps) and session capacity (12 million versus 24 million) (FortiGate 2600F data sheet, 2026). The FortiGate 3700F offers four 400GE QSFP-DD ports and 1.45 µs of firewall latency on ultra-low latency ports (FortiGate 3700F data sheet, 2026). The FortiGate 4400F reaches 1.15 Tbps of firewall throughput on 1518 byte packets and 210 million concurrent sessions; with the Hyperscale Firewall license, session capacity rises to 700 million and the new session rate to 10 million per second (FortiGate 4400F data sheet, 2026). At the top of the family, the 7081F is a 12U eight-slot chassis that produces 1.89 Tbps of firewall and 312 Gbps of Threat Protection with six FPM modules (FortiGate 7000F data sheet, 2026).
One caveat: although the FortiGate 100F and 200F are still very widespread in the field, Fortinet no longer publishes an English data sheet for these two models; they have been succeeded by the 120G and the 200G. We recommend moving to the G series on new projects and, for an existing 100F/200F fleet, planning the refresh calendar together with the FortiOS support dates.
What are the official performance figures for the FortiGate models?
The table below is taken from each model's own official Fortinet data sheet. The firewall column is the IPv4 figure measured with 1518 byte UDP packets; on the same row Fortinet also publishes 512 and 64 byte figures, and the number falls as the packet gets smaller. IPsec VPN figures are measured with AES256-SHA256 encryption and 512 byte packets (Fortinet Product Matrix, 2026). Fortinet prefixes all of these values with "up to": they are laboratory upper limits, not production guarantees. Current English data sheets have been used for 16 of the models in the table; the FortiGate 100F and 200F rows are taken from the last official data sheet Fortinet published for those models (the 2023-dated Korean localization, FG-100F-DAT-R30 and FG-200F-DAT-R17) — Fortinet no longer publishes a current English data sheet for these two models.
| Model | Class | IPv4 Firewall (1518 byte UDP) | Threat Protection | SSL Inspection | IPsec VPN (512 byte) | Concurrent sessions (TCP) | Form factor |
|---|
| FortiGate 40F | Entry | 5 Gbps | 600 Mbps | 310 Mbps | 4.4 Gbps | 700,000 | Desktop, fanless |
| FortiGate 60F | Entry | 10 Gbps | 700 Mbps | 630 Mbps | 6.5 Gbps | 700,000 | Desktop, fanless |
| FortiGate 70G | Entry | 10 Gbps | 1.3 Gbps | 1.4 Gbps | 7.1 Gbps | 1.4 million | Desktop |
| FortiGate 80F | Entry | 10 Gbps | 900 Mbps | 715 Mbps | 6.5 Gbps | 1.5 million | Desktop |
| FortiGate 90G | Entry | 28 Gbps | 2.2 Gbps | 2.6 Gbps | 25 Gbps | 3 million | Desktop |
| FortiGate 100F | Entry | 20 Gbps | 1 Gbps | 1 Gbps | 11.5 Gbps | 1.5 million | 1U rack |
| FortiGate 120G | Entry | 39 Gbps | 2.8 Gbps | 3 Gbps | 35 Gbps | 3 million | 1U rack |
| FortiGate 200F | Mid | 27 Gbps | 3 Gbps | 4 Gbps | 13 Gbps | 3 million | 1U rack |
| FortiGate 400F | Mid | 79.5 Gbps | 9 Gbps | 8 Gbps | 55 Gbps | 7.8 million | 1U rack |
| FortiGate 600F | Mid | 139 Gbps | 10.5 Gbps | 9 Gbps | 55 Gbps | 8 million | 1U rack |
| FortiGate 900G | Mid | 164 Gbps | 30 Gbps | 16.7 Gbps | 55 Gbps | 28 million | 1U rack |
| FortiGate 1000F | Mid | 198 Gbps | 13 Gbps | 10 Gbps | 55 Gbps | 7.5 million | 2U rack |
| FortiGate 1100E | Mid | 80 Gbps | 7.11 Gbps | 10 Gbps | 48 Gbps | 8 million | 2U rack |
| FortiGate 1800F | High | 198 Gbps | 15 Gbps | 12 Gbps | 55 Gbps | 12 million (40 million with Hyperscale) | 2U rack |
| FortiGate 2600F | High | 198 Gbps | 25 Gbps | 20 Gbps | 55 Gbps | 24 million (40 million with Hyperscale) | 2U rack |
| FortiGate 3700F | High | 589 Gbps | 75 Gbps | 55 Gbps | 160 Gbps | 140 million | 2U rack |
| FortiGate 4400F | High | 1.15 Tbps | 75 Gbps | 86 Gbps | 310 Gbps | 210 million (700 million with Hyperscale) | 4U rack |
| FortiGate 7081F | High | 1.89 Tbps | 312 Gbps | 324 Gbps | 378 Gbps | 600 million | 12U, 8-slot chassis |
Why do these metrics differ so widely from one another?
Because each one turns on a different number of security engines. IPv4 Firewall throughput measures stateful packet forwarding only. IPS throughput is measured with the intrusion prevention engine enabled. NGFW throughput is the figure with firewall, IPS and application control running together. Threat Protection throughput adds malware protection on top of those and is measured with logging enabled. SSL Inspection throughput, meanwhile, is the average across HTTPS sessions using different cipher suites. The most common mistake on websites and in quotations is presenting the IPS or NGFW figure as "threat protection"; on some models the gap is more than double. In the table on this page the metric names are used exactly as they appear in the data sheets.
How do the NP7 and CP9 processors change performance?
What sets FortiGate apart from its competitors is that it hands part of the security processing off from general-purpose CPUs to dedicated ASICs. The NP7 network processor offloads sessions from the CPU to deliver "fastpath" acceleration; each NP7 supports a maximum data rate of 200 Gbps across two 100 Gigabit interfaces, and a single NP7 processor can carry up to 12 million concurrent sessions (Fortinet Docs — NP7 acceleration, 2026). On appliances with a Hyperscale license, the NP7 additionally takes on session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection (Fortinet Docs, 2026); that is the answer to why the session table can grow so large in carrier and large service provider scenarios.
The CP9 content processor, for its part, delivers more than 10 Gbps of pattern-matching acceleration in flow-based inspection — that is, in IPS and application control (Fortinet Docs — CP9 capabilities, 2026). The CP9's VPN bulk data engine processes DES/3DES and AES-128/192/256 together with the MD5/SHA-1/SHA-256/384/512 algorithms in hardware; its key exchange processor handles public key operations of up to 8K with CRT for RSA and generally up to 4096 bits, along with ECC (P-256) support for NSA Suite B (Fortinet Docs, 2026). Current FortiGate devices use the CP10, CP9, CP9Lite and CP9XLite content processors; CP4, CP5, CP6 and CP8 belong to earlier generations (Fortinet Docs — Content processors, 2026). The first thing to check when evaluating a device from the second-hand market is which content processor generation the model belongs to.
How do independent tests and analysts rate FortiGate NGFW?
The short answer: strong in analyst reports, and dependent on signature currency in independent laboratory tests. Fortinet was positioned as a Leader in the 2025 Gartner Magic Quadrant for Hybrid Mesh Firewall and placed highest on the "Ability to Execute" axis (Fortinet, 2025); this MQ was the first edition to replace Gartner's classic Network Firewalls MQ and it brought the total number of Gartner MQ reports Fortinet appears in to 12 (Fortinet, 2025). On the Forrester side it was named a Leader in The Forrester Wave™: Enterprise Firewall Solutions, Q4 2024 and received 5/5, the highest possible score, in 10 criteria including automation effectiveness, DNS security, performance, SD-WAN, traffic decryption and ZTE/SASE (Fortinet, 2024).
The picture on the independent testing side is more instructive. In CyberRatings.org's fourth-quarter 2025 Enterprise Firewall test, run with NSS Labs, seven enterprise firewalls were assessed using Enterprise Firewall Test Methodology v3.0 and security effectiveness ranged from 46.37% to 99.59% (CyberRatings.org, 2025). Under encrypted workloads the devices were put through 3,326 exploits, 11,311 malware samples, 5,752 evasion techniques spread across 53 categories, 6,481 false-positive samples and 55 performance tests (CyberRatings.org, 2025). CyberRatings also reported that more than 95% of global web traffic is encrypted and that some products suffer a marked loss of performance while inspecting encrypted traffic (CyberRatings.org, 2025) — there is no better piece of data to explain why the SSL Inspection row sits at the center of model selection.
Fortinet's result in this test came in two stages, and conveying the whole of it is necessary for an honest assessment. In the first round the FortiGate-200G (FortiOS 7.6.4, IPS v7.01154) proved vulnerable to Layer 4 TCP evasion techniques; security effectiveness measured 79.24%, exploit evasion resistance 60%, and the product received a "Caution" rating (CyberRatings.org, 2025). Fortinet released an updated IPS package within days; on retest, exploit evasion resistance rose to 100% and overall security effectiveness to 99.24%, and the rating was raised to "Recommended" (CyberRatings.org, 2025). In the same round the Palo Alto Networks PA-1410 scored 46.37% on the first measurement and rose to 96.07% on retest (CyberRatings.org, 2025). The lesson to draw concerns operational discipline far more than product selection: an NGFW without a current signature package delivers twenty points less protection on exactly the same hardware.
For the sake of balance: Fortinet is not a Leader in every category. Among the current positions listed on the company's own Gartner MQ page are Challenger placements in the 2026 SASE Platforms, 2025 SIEM, 2025 email security and 2026 CPS protection platforms Magic Quadrants (Fortinet, 2026). This means that choosing Fortinet at the firewall layer does not oblige you to reach the same conclusion automatically at the other layers; evaluating the product family layer by layer is sounder than buying it as a whole. On corporate scale, Fortinet reports more than 1 million customers; as of June 30, 2026 the number of devices shipped reaches 17.2 million and the global patent count 1,448 (Fortinet, 2026).
How should the FortiOS version, license and support calendar be planned?
The rule is this: every FortiGate in production should be on a FortiOS release that is still under engineering support. For a standard major/interim release, Fortinet provides 36 months of engineering support from the general availability date, followed by 18 months of "Must Fix" support; on Long-Term Supported releases that period stretches to a total of 72 months including an 18-month Urgent Fix phase, and LTS access is possible only with a FortiCare Elite contract (Fortinet Community — Product Life Cycle, 2026).
The current calendar was pushed back by one year with bulletin CSB-260330-1 published in March 2026. The end of engineering support for FortiOS 7.4 moved to May 11, 2027 and the end of full support to November 11, 2028; for FortiOS 7.6, the end of engineering support became July 25, 2028 and the end of support January 25, 2030 (Fortinet Community — CSB-260330-1, 2026). The practical reading: there is no emergency for a fleet running on 7.4 today, but a move to 7.6 should be planned during 2027. Fortinet also announced FortiOS 8.0 on March 10, 2026; the release brings FortiView for shadow-AI detection, AI-aware application control, Model Context Protocol visibility, OCR-supported DLP and quantum-safe cryptography controls with post-quantum cryptography certificates (Fortinet, 2026). For teams that want to govern enterprise AI usage, 8.0 is not a release to skip but a roadmap item to plan for.
FortiGuard Labs' 2026 Global Threat Landscape Report shows why patch discipline matters this much: time to exploitation on critical advisories has dropped to 24–48 hours and global exploitation attempts rose 25.49% year over year (Fortinet, 2026). The same report states that the number of confirmed ransomware victims in 2025 reached 7,831, a 389% increase over the previous report (Fortinet, 2026). FortiGuard Labs produces this intelligence by processing more than 100 billion events every day with artificial intelligence and machine learning systems (Fortinet, 2026). However powerful the appliance, a FortiGate whose subscription has expired sits outside that intelligence stream.
How are KVKK, PCI DSS and Turkey's compliance requirements met with FortiGate?
The official Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) writes explicitly that "the priority measures are the firewall and the gateway" in protecting information technology systems containing personal data against unauthorized access threats arriving over the internet, and that these form the first line of defense (KVKK Personal Data Security Guide, 2018). The summary table of technical measures in the same guide lists network security, intrusion detection and prevention systems, log records and penetration testing as separate items (KVKK, 2018). Of those items, FortiGate directly covers the network security and intrusion prevention part; for the log records and reporting side it needs to be positioned together with FortiAnalyzer.
In PCI DSS v4.0 the terminology has changed: Network Security Controls (NSC) has taken the place of the term "firewall", and Requirement 1 is now titled "Install and Maintain Network Security Controls". The standard requires NSC configurations to be reviewed at least once every six months to verify their effectiveness (1.2.7), traffic entering and leaving the cardholder data environment to be restricted to what is necessary with all other traffic explicitly denied (1.3.1 and 1.3.2), NSCs to be placed between trusted and untrusted networks (1.4.1), and, where segmentation is used, penetration testing to be carried out at least every twelve months and after every segmentation change (11.4.5) (PCI DSS v4.0, PCI SSC). On the FortiGate side the counterparts of these are logical separation with VDOMs, policy-based explicit deny rules, and a six-monthly policy review record kept through FortiManager.
In organizations supervised by the BDDK (Turkey's banking regulator), the headline topics are network segmentation, recording of privileged access, change management and log retention. None of these is closed out by a firewall product alone; the segmentation and traffic recording layer, however, can be built with the FortiGate + FortiAnalyzer pairing. The FortiAnalyzer hardware family ingests between 100 GB and 8,300 GB of logs per day, manages between 180 and 10,000 devices/VDOMs, and supports an HA cluster of up to four nodes (FortiAnalyzer data sheet, 2026); ready-made compliance reports such as PCI-DSS and HIPAA also come out of the same product (Fortinet, 2026). The European threat picture supports this investment as well: ENISA's Threat Landscape 2025 report, covering July 1, 2024 – June 30, 2025, examined 4,875 incidents and measured vulnerability exploitation at 21.3% of initial access and phishing at 60% (ENISA Threat Landscape, 2025).
How do you choose between physical FortiGate, FortiGate-VM and FortiGate CNF?
The decision is made by looking at where the traffic terminates. At physical network edges such as internet egress, branch WAN and the OT/IT boundary, a hardware FortiGate is the fit; in a virtualized data center and in VPC/VNet architectures within a single cloud account, FortiGate-VM; and in multi-account, multi-region cloud environments, FortiGate CNF suits teams that want to hand off the management burden entirely. All three options carry the same FortiGate NGFW policy model and the same FortiGuard intelligence stream; the only thing that changes is the delivery and operating model.
The current FortiGate-VM license tiers are the S series: there are seven levels, from VM-01S to VM-32S and the VM-ULS that supports unlimited vCPU (FortiGate Virtual Appliances data sheet, 2025). A maximum of 24 network interfaces can be defined per instance (FortiOS 6.4.0 and later; 18 in earlier releases) (Fortinet, 2025), and the product is offered on the AWS (including GovCloud and AWS China), Azure, Google Cloud, Oracle OCI, Alibaba Cloud and IBM Cloud marketplaces (Fortinet, 2025). One point to watch: Fortinet does not publish throughput or session figures for FortiGate-VM, because performance depends directly on the underlying host hardware and the number of vCPUs. If you see the phrase "FortiGate-VM does X Gbps" in a quotation, ask where the figure comes from.
FortiGate CNF is, in Fortinet's own words, a software-as-a-service cloud network security service, and it removes the need to configure, provision and maintain firewall software infrastructure. The service is in production support on both AWS and Azure; a single CNF instance can protect multiple VPCs/VNets, availability zones and accounts within a region under one shared policy (FortiGate CNF Administration Guide, 2025). Fortinet first made the service generally available on AWS Marketplace on November 28, 2022 (Fortinet, 2022); Azure support was added later. No fixed throughput figure is published for CNF either, because the service scales automatically.
As a Fortinet authorized channel partner, Sora Yazılım provides sizing, licensing, installation, migration from an existing firewall and managed services on FortiGate NGFW projects. We measure the real traffic at your current internet egress, derive your Threat Protection requirement, recommend a model with a three-year growth allowance, and prepare a refresh plan aligned with the FortiOS support calendar. For the whole Fortinet product family see our Fortinet solutions page, and for our deployment approach on the cloud and automation side see our DevOps and infrastructure service. For model selection, refreshing your existing appliance or a multi-branch SD-WAN design, request a quotation from our contact page — we carry out the measurement and architecture recommendation work before the quotation.