The FortiGate 1000F is a 2 RU next-generation firewall (NGFW) positioned at the data center north-south layer and in large enterprise cores. With the figures from the official data sheet, its IPv4 firewall throughput is 198 / 196 / 134 Gbps with 1518 / 512 / 64-byte UDP packets, IPS throughput is 19 Gbps, NGFW throughput is 15 Gbps and Threat Protection throughput is 13 Gbps. The device carries 7.5 million concurrent TCP sessions and opens 650,000 new sessions per second.
These six metrics are not interchangeable; to size a firewall correctly you need to know which inspections will be enabled. CyberRatings.org reports that more than 95% of global web traffic is encrypted and that some enterprise firewalls suffer a marked performance loss when inspecting encrypted traffic (CyberRatings.org, 2025). That is why, in FortiGate 1000F projects, we treat the 10 Gbps SSL inspection and 13 Gbps Threat Protection figures as binding rather than the raw 198 Gbps firewall number.
What size of organization is the FortiGate 1000F suited to?
The FortiGate 1000F is for organizations whose inspected traffic does not exceed the 10 Gbps band but which need 100 Gigabit interfaces and high raw packet capacity in the core: data center entry layers, large campus cores, regional hosting providers and multi-tenant public sector networks. On the capacity side it supports 10 default / 250 maximum VDOMs, 100,000 firewall policies, 20,000 gateway-to-gateway and 100,000 client-to-gateway IPsec tunnels. In raw packet processing it reaches 201 Mpps and produces 3.45 µs of latency with 64-byte UDP packets. On the Security Fabric side a single device can manage 196 FortiSwitches and 4,096 FortiAPs (2,048 of them in tunnel mode), so the campus switching and wireless layers are handled from the same policy tree. You can reach the full model family and the selection criteria on our FortiGate product page.
What is the difference between the FortiGate 1000F, the 900G and the 1800F?
| Metric (official data sheet) | FortiGate 900G | FortiGate 1000F | FortiGate 1800F |
|---|
| IPv4 Firewall Throughput (1518-byte UDP) | 164 Gbps | 198 Gbps | 198 Gbps |
| IPS Throughput | 42 Gbps | 19 Gbps | 22 Gbps |
| NGFW Throughput | 31 Gbps | 15 Gbps | 17 Gbps |
| Threat Protection Throughput | 30 Gbps | 13 Gbps | 15 Gbps |
| SSL Inspection Throughput | 16.7 Gbps | 10 Gbps | 12 Gbps |
| IPsec VPN Throughput (512-byte) | 55 Gbps | 55 Gbps | 55 Gbps |
| Concurrent sessions (TCP) | 28 million | 7.5 million | 12 million |
| New sessions per second (TCP) | 720,000 | 650,000 | 750,000 |
| Fastest interface | 4x 25GE SFP28 (ULL) | 2x 100GE QSFP28 | 4x 100GE QSFP28 |
| Form factor | 1 RU | 2 RU | 2 RU |
The table shows the real rationale for choosing the FortiGate 1000F: raw firewall throughput and 100 Gigabit interfaces. If your traffic is inspection-heavy, the table flips — the FortiGate 900G offers 30 Gbps Threat Protection and 28 million concurrent sessions in a 1 RU chassis, which puts it ahead of the 1000F in environments with a high IPS and malware load. What makes the case for the 1000F is its two 100GE QSFP28 slots and 198 Gbps of raw capacity. When session count or IPS becomes the constraint in its own right, the upgrade path is the FortiGate 1800F: the same 198 Gbps firewall figure, 15 Gbps Threat Protection, 12 million sessions and four 100GE QSFP28 slots. The FortiGate 1100E in the same 2 RU class, by contrast, is the previous NP6 generation; with its 80 Gbps firewall figure it sits alongside the 1000F rather than above it.
What do two 100GE QSFP28 slots deliver in practice?
The FortiGate 1000F's interface layout is listed in the data sheet as follows: 2x 100GE QSFP28 / 40GE QSFP+, 8x 25GE SFP28 / 10GE SFP+ / GE SFP, 16x 10GE SFP+ / GE SFP, 8x 10GE / 5GE / 2.5GE / GE / 100M RJ45, 1x 2.5GE HA port and 1x GE management port. This layout makes it possible to connect directly at 100 Gigabit to the core switches without an intermediate aggregation layer; the 25GE and 10GE slots are reserved for server and DMZ segments, and the RJ45 ports for management and out-of-band networks. On the acceleration side, the device comes with SPU NP7 and CP9 processors. According to Fortinet's documentation, a single NP7 supports up to 200 Gbps of data throughput over two 100 Gigabit interfaces and up to 12 million sessions (Fortinet Document Library, 2026) — the 1000F's 198 Gbps figure and its two 100GE slots are consistent with this architecture. The device also contains a Trusted Platform Module (TPM) that generates and stores cryptographic keys in hardware.
Which FortiOS release is supported and how long is the support window?
An important detail: Fortinet data sheets do not state the FortiOS release on which performance figures were measured. Claims of the form "this much on that release" should therefore not be trusted; the release decision is made according to the support calendar. With the CSB-260330-1 bulletin published in March 2026, end of engineering support for FortiOS 7.4 was extended to 11 May 2027 and end of full support to 11 November 2028, while for FortiOS 7.6 end of engineering support moved to 25 July 2028 and end of full support to 25 January 2030 (Fortinet Community, 2026). Fortinet also announced FortiOS 8.0 on 10 March 2026 (Fortinet Newsroom, 2026). The lifecycle rule works like this: a standard major release receives 36 months of engineering support from its release date, followed by 18 months of "Must Fix" support; on Long-Term Supported releases the total rises to 72 months and LTS access requires a FortiCare Elite contract (Fortinet Community, 2026). On data center devices we build the release plan around a maintenance window of at least three years, not around the moment of purchase.
In Turkey there are three issues that a device of the FortiGate 1000F class does not solve on its own: inspection and log retention for personal data traffic under KVKK (Turkey's data protection law), segmentation of the cardholder environment under PCI-DSS, and the log integrity required in BDDK (Turkish banking regulator) audits. In practice we position the 1000F together with FortiAnalyzer: audit reports and the log archive are collected in FortiAnalyzer, and multi-device policy management in FortiManager. The device supports active-active, active-passive and cluster HA configurations; in production environments a two-device HA pair is our standard. The data sheet states a 2 RU chassis, hot-swappable dual power supplies (two PSUs by default, 80Plus) and 210 W average / 408 W maximum power consumption; cabinet planning, heat calculations (1,211 BTU/h) and UPS sizing are done against these values. As a Fortinet authorized channel partner, Sora Yazılım delivers licensing, installation, migration from your existing firewall and the managed service layer as a package.
Is the FortiGate 1000F the right model for your traffic? Let us measure your inspected traffic volume, concurrent session profile and 100 Gigabit requirement together, and, if needed, produce a comparative sizing report against the 900G and 1800F. Reach us through our contact page and let our engineers clarify the deployment, licensing and HA scenario. Price quotes are always prepared specifically for the project.
Tech SummaryTechnical data
- IPv4 Firewall Throughput (1518 / 512 / 64-byte UDP)
- 198 / 196 / 134 Gbps
- IPS Throughput (Enterprise Mix, logging enabled)
- 19 Gbps
- NGFW Throughput (Firewall + IPS + Application Control)
- 15 Gbps
- Threat Protection Throughput (FW + IPS + AppCtrl + Malware Protection)
- 13 Gbps
- SSL Inspection Throughput (IPS, average HTTPS)
- 10 Gbps
- IPsec VPN Throughput (512-byte, AES256-SHA256)
- 55 Gbps
- Concurrent sessions (TCP)
- 7.5 million
- New sessions per second (TCP)
- 650,000
- Firewall latency (64-byte UDP)
- 3.45 µs
- Firewall policies
- 100,000
- Interfaces
- 2x 100GE QSFP28/40GE QSFP+, 8x 25GE SFP28, 16x 10GE SFP+, 8x 10GE RJ45, 1x 2.5GE HA, 1x GE MGMT
- Hardware acceleration
- SPU NP7 + CP9, Trusted Platform Module (TPM)
- VDOMs (default / maximum)
- 10 / 250
- Form factor and power consumption
- Rack Mount 2 RU; 210 W average / 408 W maximum