Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 100F

A 1U mid-branch model for organizations that need port density, with 22 gigabit copper ports; its successor is the FortiGate 120G.

Quick answer

The FortiGate 100F is a 1U rack-mounted NGFW for port-dense mid-sized branches and small headquarters. IPv4 firewall throughput is 20 Gbps, Threat Protection throughput is 1 Gbps and IPsec VPN throughput is 11.5 Gbps. It offers 22 gigabit copper ports and dual power supplies; for new projects, its successor the FortiGate 120G should be evaluated.

The FortiGate 100F is a 1U rack-mounted next-generation firewall designed for mid-sized branches and small headquarters where the number of wired ports is the deciding factor. According to the official data sheet, IPv4 firewall throughput is 20 / 18 / 10 Gbps with 1518 / 512 / 64 byte UDP packets, IPS throughput is 2.6 Gbps and Threat Protection throughput is 1 Gbps. These three figures come from separate tests; quoting the 2.6 Gbps number as the threat prevention capacity is a frequent mistake.

The 1 Gbps Threat Protection and 1 Gbps SSL inspection ceilings define the appliance's real limit. CyberRatings.org reports that more than 95% of global web traffic is encrypted (CyberRatings.org, 2025); in other words, once full TLS inspection is switched on, the 100F's effective capacity settles at around 1 Gbps. In a branch with 100-250 users this is usually sufficient, but if the circuit exceeds 1 Gbit/s the inspection policy must be defined selectively by category, or you should move up to the next model.

What size of organization is the FortiGate 100F suited to?

The appliance holds 1.5 million concurrent TCP sessions, opens 56,000 new sessions per second and supports 10,000 firewall policies; the VDOM count is 10 by default and 10 at maximum. On the IPsec side it can terminate 2,000 gateway-to-gateway and 16,000 client-to-gateway tunnels. The built-in controller scales to 128 FortiAPs (64 of them in tunnel mode) and 32 FortiSwitches. It comes in a 1U rack form factor (44 x 432 x 254 mm, 3.29 kg), generates 40.4 dBA of noise and draws 35.1 W on average; the FG-101F variant ships with a 480 GB internal SSD.

What is the port layout and 10GE capacity of the FortiGate 100F?

The 100F product code description defines the port layout precisely: 22 GE RJ45 ports (2 WAN, 1 DMZ, 1 management, 2 HA and 16 switch ports, four of which are shared with SFP), 4 GE SFP slots and 2 10GE SFP+ FortiLink slots. In other words, the number of 10 Gigabit interfaces on the device is two, not four, and these are primarily reserved for FortiSwitch connectivity. This detail is critical in uplink design: aggregation plans built on the assumption of four 10GE uplinks cannot be implemented on the 100F.

What is the difference between the FortiGate 100F and the 120G?

Metric (official data sheet)FortiGate 100FFortiGate 120G
IPv4 Firewall Throughput (1518/512/64 byte UDP)20 / 18 / 10 Gbps39 / 39 / 28 Gbps
IPS Throughput2.6 Gbps5.3 Gbps
NGFW Throughput1.6 Gbps3.1 Gbps
Threat Protection Throughput1 Gbps2.8 Gbps
SSL Inspection Throughput1 Gbps3 Gbps
IPsec VPN Throughput (512 byte)11.5 Gbps35 Gbps
Concurrent sessions / new sessions per second (TCP)1.5 million / 56,0003 million / 140,000
10GE SFP+ slots2 (FortiLink)4 (FortiLink)
GE RJ45 / GE SFP22 / 418 / 8
ASICFortiSoC4Secure SD-WAN ASIC SP5

The only exception in the table is the port count: the 100F offers four more copper ports than the 120G. Apart from that, the FortiGate 120G leads on every metric; the gap is 2.8x in threat prevention and 3x in IPsec VPN. If the copper port count is not the deciding factor and the missing ports can be covered by a FortiSwitch, the 120G should be preferred in new deployments.

Is the FortiGate 100F still the right choice for new projects?

It pays to be clear on this point: Fortinet no longer publishes an English data sheet for the 100F; the most current official document available to us is the company's own Korean localization (document code FG-100F-DAT-R30-20230227). The model is being superseded by the 120G. Fortinet's product life cycle policy defines 36 months of engineering support from general availability of a FortiOS major release, followed by 18 months of "Must Fix" support (Fortinet Community, 2026). No urgent replacement is required for an existing 100F fleet; however, for new purchases we recommend factoring the appliance's remaining life into the investment decision and comparing it against the 120G. For smaller branches the desktop FortiGate 90G, and for headquarters that need a higher session setup rate the FortiGate 200F, are the alternatives.

How does the FortiOS support calendar affect a 100F investment?

With bulletin CSB-260330-1, Fortinet extended end of support for FortiOS 7.4 to 11 November 2028 and for FortiOS 7.6 to 25 January 2030 (Fortinet Community, 2026). Hardware lifetime and software lifetime must be planned separately: even though the FortiOS support calendar has been extended, the appliance's own life cycle advances independently. The data sheet also does not state which FortiOS version the performance figures were measured on, and qualifies all values as "up to".

As a Fortinet authorized channel partner, Sora Yazılım provides licensing and managed services across the FortiGate firewall family; we also take on configuration migration and successor-model transition projects for 100F fleets in the field. Whether refreshing your existing FortiGate 100F or moving to the successor model is the better call is something we can assess together, based on your current policy count, circuit capacity and port requirements. Get in touch through our contact page for a quote.

  • IPv4 firewall throughput 20 / 18 / 10 Gbps
  • Threat Protection throughput 1 Gbps
  • 22x GE RJ45 + 4x GE SFP + 2x 10GE SFP+ FortiLink
  • Dual internal AC power supplies (1+1 redundancy, 80Plus)
  • 1U rack mount, 35.1 W average consumption
Key features

What this model offers

  • IPv4 firewall throughput 20 / 18 / 10 Gbps (1518 / 512 / 64 byte UDP), 15 Mpps
  • Threat Protection throughput 1 Gbps, NGFW 1.6 Gbps, IPS 2.6 Gbps
  • SSL inspection throughput 1 Gbps, 135,000 concurrent inspected sessions, 1,800 CPS
  • IPsec VPN throughput 11.5 Gbps (AES256-SHA256, 512 byte)
  • 2,000 gateway-to-gateway and 16,000 client-to-gateway IPsec tunnels
  • 1.5 million concurrent TCP sessions, 56,000 new sessions per second
  • 10,000 firewall policies and 10 VDOMs
  • 22x GE RJ45 (2 WAN, 1 DMZ, 1 MGMT, 2 HA, 16 switch ports — 4 shared with SFP)
  • 4x GE SFP slots and 2x 10GE SFP+ FortiLink slots
  • FortiSoC4 ASIC hardware acceleration
  • Built-in controller for up to 128 FortiAPs (64 in tunnel mode) and 32 FortiSwitches
  • Dual internal AC power supplies, 1+1 redundancy, 80Plus efficiency class
  • 480 GB internal SSD on the FG-101F variant
  • Active-active, active-passive and clustering HA configurations
Tech Summary

Technical data

IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)
20 / 18 / 10 Gbps
Firewall Throughput (packets per second)
15 Mpps
Firewall Latency (64 byte UDP)
4.97 µs
IPS Throughput
2.6 Gbps
NGFW Throughput
1.6 Gbps
Threat Protection Throughput
1 Gbps
SSL Inspection Throughput
1 Gbps
IPsec VPN Throughput (512 byte, AES256-SHA256)
11.5 Gbps
Concurrent sessions (TCP)
1.5 million
New sessions per second (TCP)
56,000
Firewall policies / VDOMs
10,000 / 10
Interface layout
22x GE RJ45 (2 WAN, 1 DMZ, 1 MGMT, 2 HA, 16 switch — 4 shared with SFP), 4x GE SFP, 2x 10GE SFP+ FortiLink
Maximum FortiAPs / FortiSwitches
128 (64 tunnel) / 32
Form factor and noise
Rack mount 1U, 44 x 432 x 254 mm, 3.29 kg; 40.4 dBA
Power supply and consumption
Dual internal AC PSU (not hot-swappable), 1+1 redundancy, 80Plus; 35.1 W / 38.7 W
Use Cases

At what scale is this model preferred?

Mid-sized business

Headquarters with 150-250 users

In offices where a large number of copper links running to floor switches terminate directly on the firewall, the 22 GE RJ45 ports become the deciding factor; the need for an intermediate switching layer is reduced.

Healthcare

Central site of a clinic chain

IPsec tunnels from branch clinics are aggregated at the central site. The 2,000 gateway-to-gateway tunnel capacity is sufficient for a mid-sized chain; patient data is carried encrypted under KVKK (Turkey's data protection law).

Education

Small campus network

With support for 128 FortiAPs and 32 FortiSwitches, the campus wired and wireless access layer is managed from a single interface; student and staff networks are placed under separate policy sets.

Manufacturing

Separating the plant office and production networks

The office and production networks are placed in separate VDOMs and the traffic between them is controlled by policy. The dual internal power supplies reduce the risk of supply-related outages in facilities running shift work.

Public sector

Refreshing an existing 100F fleet

When deciding on a refresh for 100F appliances in the field, the remaining life cycle and the performance gap versus the 120G are evaluated together; the configuration can be migrated via FortiManager.

Who is it for?

Mid-sized branches and small headquarters with 100-250 users; campus and factory locations requiring a large number of copper ports; organizations with a 100F fleet in the field that are planning a refresh.

Frequently Asked Questions

Common questions about this model

How many Gbps is the FortiGate 100F firewall throughput?
IPv4 firewall throughput is 20 / 18 / 10 Gbps with 1518 / 512 / 64 byte UDP packets; the packets-per-second figure is 15 Mpps and 64 byte latency is 4.97 µs. A single "32 Gbps" value does not appear in the official data sheet.
Is the threat prevention capacity of the 100F 2.6 Gbps?
No. 2.6 Gbps is the IPS throughput of the 100F. Threat Protection throughput — with firewall, IPS, application control and antivirus enabled together — is 1 Gbps. NGFW throughput is 1.6 Gbps.
How many 10 Gigabit ports does the FortiGate 100F have?
There are two 10GE SFP+ FortiLink slots. All other interfaces are gigabit class: 22 GE RJ45 ports and 4 GE SFP slots. Designs that assume four 10GE uplinks cannot be implemented on the 100F.
How many concurrent sessions does the 100F support?
1.5 million concurrent TCP sessions and 56,000 new sessions per second. Up to 10,000 firewall policies can be defined; on the IPsec side, 2,000 gateway-to-gateway and 16,000 client-to-gateway tunnels are supported.
Should I buy the 120G instead of the 100F?
If the copper port count is not the deciding factor, yes. The 120G leads by 2.8x in threat prevention, 3x in IPsec VPN and 2.5x in session setup rate, and it offers four 10GE SFP+ slots. The 100F's only advantage is its GE RJ45 port count of 22 versus 18.
Is the 100F power supply redundant?
Yes. The appliance has dual internal AC power supplies providing 1+1 redundancy, in the 80Plus efficiency class. However, these supplies are not hot-swappable; in the event of a failure the appliance must be powered down.
How many VDOMs does the 100F support?
The default and maximum VDOM count is 10; the 120G and 200F share the same limit. It is sufficient for separating the office, server and guest networks of a single branch. Multi-tenant service provider scenarios require 1000F-class models, which can scale to a maximum of 250 VDOMs.
Why is the official 100F data sheet no longer published in English?
The model is being superseded by the 120G and there is no current English data sheet on fortinet.com. The figures on this page are taken from Fortinet's own official Korean localization (document code FG-100F-DAT-R30-20230227).
How many FortiAPs and FortiSwitches can the 100F manage?
A total of 128 FortiAPs (64 of them in tunnel mode) and 32 FortiSwitches. Access points are managed by the built-in wireless controller, and switches through the two 10GE SFP+ FortiLink slots.
Does the 100F support high availability (HA)?
Yes. The data sheet lists active-active, active-passive and clustering modes. What sets the 100F apart in this class is its two dedicated GE RJ45 HA ports; cluster synchronization traffic can be kept entirely separate from production ports.

FortiGate 100F — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support