Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · Network Security

FortiGate NGFW

A 20-model NGFW family: from the 40F to the 7081F, a single FortiOS policy, built-in SD-WAN and ZTNA.

Quick answer

FortiGate NGFW is Fortinet's next-generation firewall family, built on the FortiOS operating system and the NP7 network and CP9 content processors. The same software and the same policy model run across 20 models, from the desktop FortiGate 40F to the 12U chassis-based 7081F; firewall, IPS, antivirus, SSL inspection, SD-WAN and ZTNA are consolidated into a single appliance.

FortiGate NGFW is Fortinet's next-generation firewall family, built on the FortiOS operating system and FortiASIC hardware acceleration. Firewall, IPS, antivirus, application control, SSL/TLS inspection, SD-WAN and ZTNA are consolidated into a single appliance, and the same policy model runs unchanged across 20 models, from the desktop FortiGate 40F to the 12U chassis-based FortiGate 7081F. The right model is chosen according to inspected traffic requirements rather than user count.

Independent data shows why this layer has become so critical. In Verizon's 2025 Data Breach Investigations Report, vulnerability exploitation rose to 20% as an initial access vector, and 22% of those exploitation actions directly targeted edge devices and VPNs — in the previous report that share was only 3% (Verizon DBIR, 2025). The same report measures that organizations were able to fully close only around 54% of their edge device vulnerabilities during the year, and that doing so took a median of 32 days (Verizon DBIR, 2025). Fortinet's official product page, for its part, describes FortiGate as "the most deployed network firewall, with more than 50% of global market share" (Fortinet, 2026). In other words, the layer attackers probe most and the most widespread device family in the field meet at the same point; sizing and patch discipline are therefore not negotiable.

Which security functions does FortiGate NGFW combine in a single appliance?

FortiGate runs stateful firewall, intrusion prevention (IPS), antivirus, application control, web and DNS filtering, SSL/TLS inspection, IPsec VPN, SD-WAN and a ZTNA access gateway within a single FortiOS instance. These are not separate boxes but security profiles attached to the same policy engine: when you bind an IPS and antivirus profile to a firewall rule, traffic is not diverted to a second appliance — it is inspected within the same session.

The operational counterpart of that is clear. Instead of keeping a separate VPN concentrator, a separate web proxy and a separate SD-WAN box at the branch, you deploy a single appliance. Because the same FortiOS also runs at headquarters, a policy written at the branch is valid with identical syntax on the large model in the data center. Configuration portability is the most overlooked property in a 20-model family, and yet the one that most reduces total cost of ownership; a device upgrade stops being a migration project and becomes a configuration transfer.

Separating which capability comes with the appliance and which comes with a subscription is the first step in budget planning:

  • Included with the appliance, no additional subscription required: firewall policies, NAT, VLAN, dynamic routing, IPsec VPN, SD-WAN routing and SLA measurement, HA clustering, VDOMs up to the model limit, the built-in WLAN controller and FortiSwitch management through FortiLink.
  • Included with a FortiGuard subscription: IPS signatures, antivirus definitions, web and DNS filtering categories, the application control signature database, IoT/OT device recognition, botnet and poor-reputation IP lists.
  • Included with FortiCare: hardware replacement, technical support and access to FortiOS releases; Long-Term Supported releases are unlocked only with a FortiCare Elite contract.

On the FortiLink side, a FortiGate can manage between 8 and 300 FortiSwitches as its own logical extension depending on the model, and provides basic NAC functions such as profiling connected devices, IoT segmentation and quarantine in the event of a breach at no extra cost (Fortinet FortiSwitch data sheet, 2026). On the ZTNA side the architecture has three parts: the FortiClient ZTNA agent on the endpoint, FortiClient EMS holding identity and posture information, and the FortiGate ZTNA application gateway enforcing the access decision. Fortinet introduced this model with FortiOS 7.0 (Fortinet Docs, 2026) and has since positioned it as the primary remote access method to replace SSL-VPN; indeed, the FortiGate 40F and 60F data sheets state explicitly that SSL-VPN is not supported on FortiOS 7.6.0 and later (FortiGate 60F data sheet, 2026).

Which FortiGate model should I choose?

The decisive figure in the selection is not raw firewall throughput but Threat Protection throughput. Fortinet measures this metric on Enterprise Mix traffic with firewall, IPS, application control and malware protection all enabled simultaneously and logging running; the result stays between just 5% and 19% of the raw firewall figure across the 18 models in the table below. For example, the FortiGate 600F's IPv4 firewall figure is 139 Gbps while its Threat Protection figure is 10.5 Gbps (FortiGate 600F data sheet, 2026). Choosing a device on the basis of 139 Gbps and then running into a reality of 10.5 Gbps is the sizing mistake we see most often in the field.

The user scenarios in the table below are not Fortinet data sheet values — Fortinet does not publish a user count per model. The scenario column is a starting point drawn from our own deployment experience; the throughput column is the Threat Protection row from the relevant model's official data sheet. When the binding constraint is SSL inspection rather than Threat Protection, the ordering changes: the FortiGate 900G delivers 16.7 Gbps, the FortiGate 2600F 20 Gbps and the FortiGate 3700F 55 Gbps of SSL Inspection; in that case the SSL Inspection row should be consulted directly instead of the tier in the table. The final decision should always be made on the real traffic measured at your current internet egress plus a three-year growth allowance.

ScenarioThreat Protection throughput requiredStarting modelOne tier up
Micro office, checkout/POS point, single internet lineup to 600 MbpsFortiGate 40FFortiGate 60F
Small branch, limited SSL inspection700 Mbps – 1.3 GbpsFortiGate 60F / FortiGate 70GFortiGate 80F
Mid-sized branch powering phones and APs over PoE900 Mbps – 2.2 GbpsFortiGate 80F / FortiGate 90GFortiGate 120G
Head office, 1U rack, heavy application control2.8 – 3 GbpsFortiGate 120G / FortiGate 200FFortiGate 400F
Campus or regional headquarters, multiple VLANs and 10GE uplink9 – 10.5 GbpsFortiGate 400F / FortiGate 600FFortiGate 900G
Enterprise headquarters where full SSL inspection is mandatoryup to 30 GbpsFortiGate 900GFortiGate 3700F
Data center edge, 100GE uplink13 – 25 GbpsFortiGate 1000F / FortiGate 1800F / FortiGate 2600FFortiGate 3700F
Hyperscale, carrier and large service provider75 Gbps and aboveFortiGate 3700F / FortiGate 4400FFortiGate 7081F
Cloud and virtualization environmentDepends on host hardwareFortiGate-VMFortiGate CNF (SaaS)

Entry level (SMB and branch). The FortiGate 40F is a fanless desktop appliance drawing an average of 7.74 W and generating 0 dBA of noise; it is designed for places where mechanical cooling is a problem, such as behind a checkout counter or in a small stockroom (FortiGate 40F data sheet, 2026). The FortiGate 60F, with ten GE RJ45 ports and 700,000 concurrent sessions, is the classic branch appliance. The FortiGate 70G, despite appearing to sit in the same class, delivers 10 Gbps on 64 byte packets (6 Gbps on the 60F), 100,000 new sessions per second (35,000 on the 60F) and 1.4 Gbps of SSL inspection (630 Mbps on the 60F) (FortiGate 70G data sheet, 2026); in new branch projects it is these three rows that make the difference. The FortiGate 90G stands out with 25 Gbps of IPsec VPN in a desktop form factor (FortiGate 90G data sheet, 2026), while the FortiGate 120G sits on the head office boundary with 2.8 Gbps of Threat Protection and 35 Gbps of IPsec VPN in a 1U body (FortiGate 120G data sheet, 2026).

Mid-range (campus and regional headquarters). The FortiGate 400F delivers 79.5 Gbps of IPv4 firewall, 9 Gbps of Threat Protection and 8 Gbps of SSL inspection; its fastest interfaces are eight 10GE SFP+ ports, four of them ultra-low latency (FortiGate 400F data sheet, 2026). In this family the 25GE SFP28 interface first appears on the FortiGate 600F (a 4x 25GE SFP28/10GE SFP+ ultra-low latency slot) (FortiGate 600F data sheet, 2026). The FortiGate 900G is this group's performance leap: 164 Gbps of firewall, 30 Gbps of Threat Protection, 16.7 Gbps of SSL inspection and 28 million concurrent sessions (FortiGate 900G data sheet, 2026). The FortiGate 1000F, by contrast, has a higher firewall figure (198 Gbps) yet stops at 13 Gbps on the Threat Protection side (FortiGate 1000F data sheet, 2026) — the two models should be separated not as "big/small" but by port requirements and inspection intensity.

High end (data center and hyperscale). The FortiGate 1800F and 2600F share the same 198 Gbps firewall figure; the real difference between them lies in Threat Protection (15 Gbps versus 25 Gbps), SSL inspection (12 Gbps versus 20 Gbps) and session capacity (12 million versus 24 million) (FortiGate 2600F data sheet, 2026). The FortiGate 3700F offers four 400GE QSFP-DD ports and 1.45 µs of firewall latency on ultra-low latency ports (FortiGate 3700F data sheet, 2026). The FortiGate 4400F reaches 1.15 Tbps of firewall throughput on 1518 byte packets and 210 million concurrent sessions; with the Hyperscale Firewall license, session capacity rises to 700 million and the new session rate to 10 million per second (FortiGate 4400F data sheet, 2026). At the top of the family, the 7081F is a 12U eight-slot chassis that produces 1.89 Tbps of firewall and 312 Gbps of Threat Protection with six FPM modules (FortiGate 7000F data sheet, 2026).

One caveat: although the FortiGate 100F and 200F are still very widespread in the field, Fortinet no longer publishes an English data sheet for these two models; they have been succeeded by the 120G and the 200G. We recommend moving to the G series on new projects and, for an existing 100F/200F fleet, planning the refresh calendar together with the FortiOS support dates.

What are the official performance figures for the FortiGate models?

The table below is taken from each model's own official Fortinet data sheet. The firewall column is the IPv4 figure measured with 1518 byte UDP packets; on the same row Fortinet also publishes 512 and 64 byte figures, and the number falls as the packet gets smaller. IPsec VPN figures are measured with AES256-SHA256 encryption and 512 byte packets (Fortinet Product Matrix, 2026). Fortinet prefixes all of these values with "up to": they are laboratory upper limits, not production guarantees. Current English data sheets have been used for 16 of the models in the table; the FortiGate 100F and 200F rows are taken from the last official data sheet Fortinet published for those models (the 2023-dated Korean localization, FG-100F-DAT-R30 and FG-200F-DAT-R17) — Fortinet no longer publishes a current English data sheet for these two models.

ModelClassIPv4 Firewall (1518 byte UDP)Threat ProtectionSSL InspectionIPsec VPN (512 byte)Concurrent sessions (TCP)Form factor
FortiGate 40FEntry5 Gbps600 Mbps310 Mbps4.4 Gbps700,000Desktop, fanless
FortiGate 60FEntry10 Gbps700 Mbps630 Mbps6.5 Gbps700,000Desktop, fanless
FortiGate 70GEntry10 Gbps1.3 Gbps1.4 Gbps7.1 Gbps1.4 millionDesktop
FortiGate 80FEntry10 Gbps900 Mbps715 Mbps6.5 Gbps1.5 millionDesktop
FortiGate 90GEntry28 Gbps2.2 Gbps2.6 Gbps25 Gbps3 millionDesktop
FortiGate 100FEntry20 Gbps1 Gbps1 Gbps11.5 Gbps1.5 million1U rack
FortiGate 120GEntry39 Gbps2.8 Gbps3 Gbps35 Gbps3 million1U rack
FortiGate 200FMid27 Gbps3 Gbps4 Gbps13 Gbps3 million1U rack
FortiGate 400FMid79.5 Gbps9 Gbps8 Gbps55 Gbps7.8 million1U rack
FortiGate 600FMid139 Gbps10.5 Gbps9 Gbps55 Gbps8 million1U rack
FortiGate 900GMid164 Gbps30 Gbps16.7 Gbps55 Gbps28 million1U rack
FortiGate 1000FMid198 Gbps13 Gbps10 Gbps55 Gbps7.5 million2U rack
FortiGate 1100EMid80 Gbps7.11 Gbps10 Gbps48 Gbps8 million2U rack
FortiGate 1800FHigh198 Gbps15 Gbps12 Gbps55 Gbps12 million (40 million with Hyperscale)2U rack
FortiGate 2600FHigh198 Gbps25 Gbps20 Gbps55 Gbps24 million (40 million with Hyperscale)2U rack
FortiGate 3700FHigh589 Gbps75 Gbps55 Gbps160 Gbps140 million2U rack
FortiGate 4400FHigh1.15 Tbps75 Gbps86 Gbps310 Gbps210 million (700 million with Hyperscale)4U rack
FortiGate 7081FHigh1.89 Tbps312 Gbps324 Gbps378 Gbps600 million12U, 8-slot chassis

Why do these metrics differ so widely from one another?

Because each one turns on a different number of security engines. IPv4 Firewall throughput measures stateful packet forwarding only. IPS throughput is measured with the intrusion prevention engine enabled. NGFW throughput is the figure with firewall, IPS and application control running together. Threat Protection throughput adds malware protection on top of those and is measured with logging enabled. SSL Inspection throughput, meanwhile, is the average across HTTPS sessions using different cipher suites. The most common mistake on websites and in quotations is presenting the IPS or NGFW figure as "threat protection"; on some models the gap is more than double. In the table on this page the metric names are used exactly as they appear in the data sheets.

How do the NP7 and CP9 processors change performance?

What sets FortiGate apart from its competitors is that it hands part of the security processing off from general-purpose CPUs to dedicated ASICs. The NP7 network processor offloads sessions from the CPU to deliver "fastpath" acceleration; each NP7 supports a maximum data rate of 200 Gbps across two 100 Gigabit interfaces, and a single NP7 processor can carry up to 12 million concurrent sessions (Fortinet Docs — NP7 acceleration, 2026). On appliances with a Hyperscale license, the NP7 additionally takes on session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection (Fortinet Docs, 2026); that is the answer to why the session table can grow so large in carrier and large service provider scenarios.

The CP9 content processor, for its part, delivers more than 10 Gbps of pattern-matching acceleration in flow-based inspection — that is, in IPS and application control (Fortinet Docs — CP9 capabilities, 2026). The CP9's VPN bulk data engine processes DES/3DES and AES-128/192/256 together with the MD5/SHA-1/SHA-256/384/512 algorithms in hardware; its key exchange processor handles public key operations of up to 8K with CRT for RSA and generally up to 4096 bits, along with ECC (P-256) support for NSA Suite B (Fortinet Docs, 2026). Current FortiGate devices use the CP10, CP9, CP9Lite and CP9XLite content processors; CP4, CP5, CP6 and CP8 belong to earlier generations (Fortinet Docs — Content processors, 2026). The first thing to check when evaluating a device from the second-hand market is which content processor generation the model belongs to.

How do independent tests and analysts rate FortiGate NGFW?

The short answer: strong in analyst reports, and dependent on signature currency in independent laboratory tests. Fortinet was positioned as a Leader in the 2025 Gartner Magic Quadrant for Hybrid Mesh Firewall and placed highest on the "Ability to Execute" axis (Fortinet, 2025); this MQ was the first edition to replace Gartner's classic Network Firewalls MQ and it brought the total number of Gartner MQ reports Fortinet appears in to 12 (Fortinet, 2025). On the Forrester side it was named a Leader in The Forrester Wave™: Enterprise Firewall Solutions, Q4 2024 and received 5/5, the highest possible score, in 10 criteria including automation effectiveness, DNS security, performance, SD-WAN, traffic decryption and ZTE/SASE (Fortinet, 2024).

The picture on the independent testing side is more instructive. In CyberRatings.org's fourth-quarter 2025 Enterprise Firewall test, run with NSS Labs, seven enterprise firewalls were assessed using Enterprise Firewall Test Methodology v3.0 and security effectiveness ranged from 46.37% to 99.59% (CyberRatings.org, 2025). Under encrypted workloads the devices were put through 3,326 exploits, 11,311 malware samples, 5,752 evasion techniques spread across 53 categories, 6,481 false-positive samples and 55 performance tests (CyberRatings.org, 2025). CyberRatings also reported that more than 95% of global web traffic is encrypted and that some products suffer a marked loss of performance while inspecting encrypted traffic (CyberRatings.org, 2025) — there is no better piece of data to explain why the SSL Inspection row sits at the center of model selection.

Fortinet's result in this test came in two stages, and conveying the whole of it is necessary for an honest assessment. In the first round the FortiGate-200G (FortiOS 7.6.4, IPS v7.01154) proved vulnerable to Layer 4 TCP evasion techniques; security effectiveness measured 79.24%, exploit evasion resistance 60%, and the product received a "Caution" rating (CyberRatings.org, 2025). Fortinet released an updated IPS package within days; on retest, exploit evasion resistance rose to 100% and overall security effectiveness to 99.24%, and the rating was raised to "Recommended" (CyberRatings.org, 2025). In the same round the Palo Alto Networks PA-1410 scored 46.37% on the first measurement and rose to 96.07% on retest (CyberRatings.org, 2025). The lesson to draw concerns operational discipline far more than product selection: an NGFW without a current signature package delivers twenty points less protection on exactly the same hardware.

For the sake of balance: Fortinet is not a Leader in every category. Among the current positions listed on the company's own Gartner MQ page are Challenger placements in the 2026 SASE Platforms, 2025 SIEM, 2025 email security and 2026 CPS protection platforms Magic Quadrants (Fortinet, 2026). This means that choosing Fortinet at the firewall layer does not oblige you to reach the same conclusion automatically at the other layers; evaluating the product family layer by layer is sounder than buying it as a whole. On corporate scale, Fortinet reports more than 1 million customers; as of June 30, 2026 the number of devices shipped reaches 17.2 million and the global patent count 1,448 (Fortinet, 2026).

How should the FortiOS version, license and support calendar be planned?

The rule is this: every FortiGate in production should be on a FortiOS release that is still under engineering support. For a standard major/interim release, Fortinet provides 36 months of engineering support from the general availability date, followed by 18 months of "Must Fix" support; on Long-Term Supported releases that period stretches to a total of 72 months including an 18-month Urgent Fix phase, and LTS access is possible only with a FortiCare Elite contract (Fortinet Community — Product Life Cycle, 2026).

The current calendar was pushed back by one year with bulletin CSB-260330-1 published in March 2026. The end of engineering support for FortiOS 7.4 moved to May 11, 2027 and the end of full support to November 11, 2028; for FortiOS 7.6, the end of engineering support became July 25, 2028 and the end of support January 25, 2030 (Fortinet Community — CSB-260330-1, 2026). The practical reading: there is no emergency for a fleet running on 7.4 today, but a move to 7.6 should be planned during 2027. Fortinet also announced FortiOS 8.0 on March 10, 2026; the release brings FortiView for shadow-AI detection, AI-aware application control, Model Context Protocol visibility, OCR-supported DLP and quantum-safe cryptography controls with post-quantum cryptography certificates (Fortinet, 2026). For teams that want to govern enterprise AI usage, 8.0 is not a release to skip but a roadmap item to plan for.

FortiGuard Labs' 2026 Global Threat Landscape Report shows why patch discipline matters this much: time to exploitation on critical advisories has dropped to 24–48 hours and global exploitation attempts rose 25.49% year over year (Fortinet, 2026). The same report states that the number of confirmed ransomware victims in 2025 reached 7,831, a 389% increase over the previous report (Fortinet, 2026). FortiGuard Labs produces this intelligence by processing more than 100 billion events every day with artificial intelligence and machine learning systems (Fortinet, 2026). However powerful the appliance, a FortiGate whose subscription has expired sits outside that intelligence stream.

How are KVKK, PCI DSS and Turkey's compliance requirements met with FortiGate?

The official Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) writes explicitly that "the priority measures are the firewall and the gateway" in protecting information technology systems containing personal data against unauthorized access threats arriving over the internet, and that these form the first line of defense (KVKK Personal Data Security Guide, 2018). The summary table of technical measures in the same guide lists network security, intrusion detection and prevention systems, log records and penetration testing as separate items (KVKK, 2018). Of those items, FortiGate directly covers the network security and intrusion prevention part; for the log records and reporting side it needs to be positioned together with FortiAnalyzer.

In PCI DSS v4.0 the terminology has changed: Network Security Controls (NSC) has taken the place of the term "firewall", and Requirement 1 is now titled "Install and Maintain Network Security Controls". The standard requires NSC configurations to be reviewed at least once every six months to verify their effectiveness (1.2.7), traffic entering and leaving the cardholder data environment to be restricted to what is necessary with all other traffic explicitly denied (1.3.1 and 1.3.2), NSCs to be placed between trusted and untrusted networks (1.4.1), and, where segmentation is used, penetration testing to be carried out at least every twelve months and after every segmentation change (11.4.5) (PCI DSS v4.0, PCI SSC). On the FortiGate side the counterparts of these are logical separation with VDOMs, policy-based explicit deny rules, and a six-monthly policy review record kept through FortiManager.

In organizations supervised by the BDDK (Turkey's banking regulator), the headline topics are network segmentation, recording of privileged access, change management and log retention. None of these is closed out by a firewall product alone; the segmentation and traffic recording layer, however, can be built with the FortiGate + FortiAnalyzer pairing. The FortiAnalyzer hardware family ingests between 100 GB and 8,300 GB of logs per day, manages between 180 and 10,000 devices/VDOMs, and supports an HA cluster of up to four nodes (FortiAnalyzer data sheet, 2026); ready-made compliance reports such as PCI-DSS and HIPAA also come out of the same product (Fortinet, 2026). The European threat picture supports this investment as well: ENISA's Threat Landscape 2025 report, covering July 1, 2024 – June 30, 2025, examined 4,875 incidents and measured vulnerability exploitation at 21.3% of initial access and phishing at 60% (ENISA Threat Landscape, 2025).

How do you choose between physical FortiGate, FortiGate-VM and FortiGate CNF?

The decision is made by looking at where the traffic terminates. At physical network edges such as internet egress, branch WAN and the OT/IT boundary, a hardware FortiGate is the fit; in a virtualized data center and in VPC/VNet architectures within a single cloud account, FortiGate-VM; and in multi-account, multi-region cloud environments, FortiGate CNF suits teams that want to hand off the management burden entirely. All three options carry the same FortiGate NGFW policy model and the same FortiGuard intelligence stream; the only thing that changes is the delivery and operating model.

The current FortiGate-VM license tiers are the S series: there are seven levels, from VM-01S to VM-32S and the VM-ULS that supports unlimited vCPU (FortiGate Virtual Appliances data sheet, 2025). A maximum of 24 network interfaces can be defined per instance (FortiOS 6.4.0 and later; 18 in earlier releases) (Fortinet, 2025), and the product is offered on the AWS (including GovCloud and AWS China), Azure, Google Cloud, Oracle OCI, Alibaba Cloud and IBM Cloud marketplaces (Fortinet, 2025). One point to watch: Fortinet does not publish throughput or session figures for FortiGate-VM, because performance depends directly on the underlying host hardware and the number of vCPUs. If you see the phrase "FortiGate-VM does X Gbps" in a quotation, ask where the figure comes from.

FortiGate CNF is, in Fortinet's own words, a software-as-a-service cloud network security service, and it removes the need to configure, provision and maintain firewall software infrastructure. The service is in production support on both AWS and Azure; a single CNF instance can protect multiple VPCs/VNets, availability zones and accounts within a region under one shared policy (FortiGate CNF Administration Guide, 2025). Fortinet first made the service generally available on AWS Marketplace on November 28, 2022 (Fortinet, 2022); Azure support was added later. No fixed throughput figure is published for CNF either, because the service scales automatically.

As a Fortinet authorized channel partner, Sora Yazılım provides sizing, licensing, installation, migration from an existing firewall and managed services on FortiGate NGFW projects. We measure the real traffic at your current internet egress, derive your Threat Protection requirement, recommend a model with a three-year growth allowance, and prepare a refresh plan aligned with the FortiOS support calendar. For the whole Fortinet product family see our Fortinet solutions page, and for our deployment approach on the cloud and automation side see our DevOps and infrastructure service. For model selection, refreshing your existing appliance or a multi-branch SD-WAN design, request a quotation from our contact page — we carry out the measurement and architecture recommendation work before the quotation.

Key features

What it offers

  • A single FortiOS operating system — the same policy model and portable configuration from the 40F to the 7081F
  • NP7 network processor: fastpath acceleration of up to 200 Gbps across two 100 GbE interfaces
  • Capacity to carry up to 12 million concurrent sessions per NP7
  • CP9 content processor: over 10 Gbps of pattern-matching acceleration in flow-based inspection
  • Hardware crypto processing for RSA (up to 8K with CRT), AES-128/192/256 and ECC P-256
  • Built-in SD-WAN — no separate appliance or additional SD-WAN license required
  • ZTNA application gateway (with FortiClient + FortiClient EMS), since FortiOS 7.0
  • IPS, antivirus, application control, web and DNS filtering and SSL/TLS inspection in a single policy
  • Session capacity expansion on the 1800F, 2600F and 4400F with the Hyperscale Firewall license
  • HA clustering (active-passive / active-active) and logical separation with VDOMs
  • 8–300 FortiSwitches per model via FortiLink and FortiAP management through the integrated WLAN controller
  • Central logging, compliance reporting and policy management with FortiAnalyzer and FortiManager
  • FortiGate-VM (AWS, Azure, GCP, OCI, Alibaba, IBM) and SaaS FortiGate CNF (AWS + Azure) options
  • Shadow-AI visibility, OCR-supported DLP and post-quantum cryptography controls with FortiOS 8.0
Model Family

Models and segments

Choose the right model from the segments below — Sora handles sizing and quoting.

Entry-Level (KOBİ / Şube)

5–250 kullanıcı, küçük ofis ve şube için.

Mid-Range (Orta Ofis / Kampüs)

250–3000 kullanıcı, merkez ofis ve kampüs.

High-End (Veri Merkezi / Hyperscale)

3000+ kullanıcı, veri merkezi north-south, ISP omurgası.

Tech Summary

Important technical data

Operating system
FortiOS; 7.4 (end of support November 11, 2028) and 7.6 (end of support January 25, 2030) active, 8.0 announced in March 2026
Hardware acceleration
NP7 network processor + CP10 / CP9 / CP9Lite / CP9XLite content processors
NP7 capacity
200 Gbps per processor (2 x 100 GbE) and up to 12 million sessions
CP9 capacity
Over 10 Gbps of pattern matching in flow-based inspection
IPv4 firewall range (1518 byte UDP)
5 Gbps (40F) – 1.89 Tbps (7081F, 6 FPM)
Threat Protection range
600 Mbps (40F) – 312 Gbps (7081F)
SSL Inspection range
310 Mbps (40F) – 324 Gbps (7081F)
IPsec VPN range (AES256-SHA256, 512 byte)
4.4 Gbps (40F) – 378 Gbps (7081F)
Concurrent session range (TCP)
700,000 (40F) – 600 million (7081F)
Form factor
Desktop (including fanless models), 1U, 2U, 4U and a 12U 8-slot chassis
Virtual and cloud
FortiGate-VM S series (VM-01S…VM-32S, VM-ULS) and FortiGate CNF (AWS + Azure SaaS)
FortiOS support duration
36 months engineering + 18 months Must Fix; 72 months in total on LTS releases (FortiCare Elite required)
Use Cases

When would you choose this product?

Retail

SD-WAN and central policy across a multi-branch chain

FortiGate 60F/80F class appliances at the branches and a 400F/600F class hub at headquarters; because SD-WAN management is built into FortiOS, no additional SD-WAN license or separate box is needed. Policy is distributed from FortiManager using a single template.

Finance

PCI DSS scope reduction and CDE segmentation

The cardholder data environment is separated out with VDOMs; as required by PCI DSS v4.0 clauses 1.3.1/1.3.2, CDE traffic is restricted to what is necessary and all other traffic is explicitly denied. Segmentation controls are verified with penetration testing at least once a year in line with 11.4.5.

Manufacturing

Segmentation at the OT/IT boundary

Placed between the factory network and the corporate network, the FortiGate keeps the ICS/SCADA segment in a separate VDOM. Unmanaged devices are profiled using FortiGuard's IoT/OT device recognition signatures and quarantined through FortiLink in the event of a breach.

Public sector and healthcare

KVKK technical measures and log records

The network security, intrusion detection/prevention and log records items of the KVKK guide are built with the FortiGate + FortiAnalyzer pairing; access and policy changes are recorded, and compliance reports are produced through FortiAnalyzer.

Cloud

Central inspection in a multi-account AWS/Azure environment

FortiGate-VM is chosen in single-account, single-VPC scenarios, and FortiGate CNF when multiple VPCs/VNets and accounts within a region need to be protected under one shared policy; with CNF, installing and maintaining the firewall software infrastructure is not the customer's responsibility.

Who is it for?

Every segment, from SMBs running a branch network to enterprise IT teams operating campuses and data centers, finance and healthcare organizations within PCI DSS and KVKK scope, and service providers seeking hyperscale capacity.

Frequently Asked Questions

Frequently asked questions

What is the real difference between the FortiGate 70G and the FortiGate 60F?
On 1518 byte packets both deliver 10 Gbps of IPv4 firewall; the difference is in the other rows. The 70G does 10 Gbps on 64 byte packets while the 60F stops at 6 Gbps. Threat Protection is 1.3 Gbps versus 700 Mbps, SSL Inspection 1.4 Gbps versus 630 Mbps, concurrent sessions 1.4 million versus 700,000, and new sessions per second 100,000 versus 35,000. The 70G is recommended for new branch projects.
How many users can a FortiGate 200F handle?
Fortinet does not publish a user count for any model; the right question is a traffic question. The 200F's official figures are 27 Gbps IPv4 firewall, 3 Gbps Threat Protection, 4 Gbps SSL Inspection, 3 million concurrent sessions and 280,000 new sessions per second. Sizing should be based on the inspected traffic measured at your current egress plus a three-year growth allowance.
How much does performance drop when SSL inspection is enabled?
The drop varies by model and is published as a separate row in the data sheet. For example: the FortiGate 600F does 139 Gbps of IPv4 firewall while its SSL Inspection figure is 9 Gbps; on the FortiGate 900G that pair is 164 Gbps and 16.7 Gbps. Because CyberRatings reports that more than 95% of global web traffic is encrypted, realistic sizing should be done from the SSL Inspection row.
How does FortiGate HA (redundancy) work?
Two or more appliances form an active-passive or active-active cluster; session state is synchronized between members. On NP7-based models with a Hyperscale license, HA hardware session synchronization is also handled by the NP7 and offloaded from the CPU. All members of the cluster must be on the same FortiOS release.
Which FortiGate features do not require a license?
Firewall policies, NAT, VLAN, dynamic routing, IPsec VPN, SD-WAN routing and SLA measurement, HA, VDOMs up to the model limit and FortiSwitch management through FortiLink come with the appliance. IPS signatures, antivirus, web/DNS filtering, the application control signature database and IoT recognition depend on a FortiGuard subscription; hardware replacement and release access depend on FortiCare.
Which FortiOS version should I stay on?
One that is still under engineering support. With bulletin CSB-260330-1 in March 2026, the end of engineering support for FortiOS 7.4 became May 11, 2027 and end of support November 11, 2028; for FortiOS 7.6, end of engineering support is July 25, 2028 and end of support January 25, 2030. FortiOS 8.0, meanwhile, was announced on March 10, 2026. Access to Long-Term Supported releases requires a FortiCare Elite contract.
What does the Hyperscale Firewall license do?
It expands the session table and the session setup rate. On the FortiGate 1800F concurrent sessions rise from 12 million to 40 million, on the 2600F from 24 million to 40 million, on the 4400F from 210 million to 700 million, and new sessions per second from 1 million to 10 million. The license also hands session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection over to the NP7.
Can FortiGate replace a WAF?
No. Application control and IPS signatures provide a basic layer of protection, but OWASP Top 10 coverage, machine learning-driven API discovery, schema validation and payment page script protection reside in the FortiWeb product. In organizations that publish web applications, FortiGate and FortiWeb complement each other; neither takes the place of the other.
Why is no throughput figure given for FortiGate-VM?
Fortinet does not publish firewall, IPS or Threat Protection throughput, nor concurrent session values, in the FortiGate-VM data sheet; performance depends on the underlying host hardware and the number of vCPUs assigned. The data sheet gives capacity values only: license tiers from VM-01S to VM-ULS, a maximum of 24 network interfaces per instance, and 10,000–200,000 firewall policies depending on the tier.
What does a FortiGate cost?
Price varies with the model, the FortiGuard subscription bundle, the contract term and the project scope; we do not publish prices on this page. For a quotation covering the model recommendation, license scope and installation line items, reach us through our contact page — before the quotation we measure your current traffic and carry out a sizing study.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

FortinetFortiGate NGFW
Related Services

Services we deliver alongside this product

FortiGate NGFW licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support