Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 1100E

An NP6 generation 2 RU data center firewall; 80 Gbps IPv4 firewall, 8 million concurrent sessions and parts commonality with an existing E-series fleet.

Quick answer

The FortiGate 1100E is an NP6 generation data center firewall that offers 80 / 80 / 45 Gbps IPv4 firewall throughput, 7.11 Gbps Threat Protection and 8 million concurrent TCP sessions in a 2 RU chassis. Its fastest interfaces are two 40GE QSFP+ slots. It is chosen when extending existing E-series deployments and in cabinets that require -48V DC power.

The FortiGate 1100E is an NP6 generation data center firewall that offers 80 / 80 / 45 Gbps IPv4 firewall throughput (1518 / 512 / 64-byte UDP), 12.5 Gbps IPS, 9.8 Gbps NGFW and 7.11 Gbps Threat Protection throughput in a 2 RU chassis. It carries 8 million concurrent TCP sessions, opens 500,000 new sessions per second, and its fastest interfaces are two 40GE QSFP+ slots.

The most widespread piece of misinformation about this model is that it is "the FortiGate 1000F with increased session capacity". The official data sheets do not support that: the 1100E supports 8 million and the 1000F 7.5 million concurrent sessions — a difference of only about 7% — whereas on firewall throughput the 1000F leads by a factor of 2.5. The FortiGate 1100E is not a higher model but the previous NP6 generation; the 1000F comes with NP7. What the two models share is the CP9 content processor; according to Fortinet's documentation the CP9 provides more than 10 Gbps of pattern matching acceleration in flow-based inspection (Fortinet Document Library, 2026), and the SSL inspection throughput of both models sits at the same 10 Gbps level.

Which organizations is the FortiGate 1100E suitable for?

The only concrete rationale that makes the FortiGate 1100E defensible today is operational commonality with an existing E-series fleet: the 1100E shares the same power supply SKU (SP-FG300E-PS) with the FG-300/301E, FG-400/401E, FG-500/501E and FG-600/601E, so the spare parts pool and the field replacement procedure stay unchanged. The other two rationales often put forward are weakened by the official data sheets. -48V DC power: the FG-1100E-DC really is a DC input model and the 1000F data sheet has no DC option — but Fortinet also lists the FG-900G-DC with dual DC power supplies (48–60 VDC), and in 1 RU at that. Copper port density: the 1100E has sixteen GE RJ45 ports, but the 900G also offers 16 switch ports plus 1 management port. In other words, neither DC power nor copper density on its own points to the 1100E. On the capacity side it supports 10 default / 250 maximum VDOMs, 100,000 firewall policies, 20,000 gateway-to-gateway and 100,000 client-to-gateway IPsec tunnels. For the full model family and the selection criteria, take a look at our FortiGate product page.

What is the real difference between the FortiGate 1100E and the FortiGate 1000F?

Metric (official data sheet)FortiGate 1100EFortiGate 1000F
IPv4 Firewall Throughput (1518 / 512 / 64-byte UDP)80 / 80 / 45 Gbps198 / 196 / 134 Gbps
IPS Throughput12.5 Gbps19 Gbps
NGFW Throughput9.8 Gbps15 Gbps
Threat Protection Throughput7.11 Gbps13 Gbps
SSL Inspection Throughput10 Gbps10 Gbps
Concurrent SSL Inspection sessions780,000600,000
SSL-VPN Throughput8.4 Gbps5.3 Gbps
IPsec VPN Throughput (512-byte)48 Gbps55 Gbps
Concurrent sessions (TCP)8 million7.5 million
New sessions per second (TCP)500,000650,000
Firewall latency (64-byte UDP)2.76 µs3.45 µs
Hardware accelerationSPU NP6 + CP9SPU NP7 + CP9
Fastest interface2x 40GE QSFP+2x 100GE QSFP28 / 40GE QSFP+
Power consumption (average / maximum)217 W / 336 W210 W / 408 W
DC power optionFG-1100E-DC (-48V DC)Not listed in the data sheet

The one-sentence summary of the table is this: the FortiGate 1100E leads the 1000F only on concurrent sessions, concurrent SSL inspection sessions, SSL-VPN throughput, latency and the DC power option. On firewall, IPS, NGFW, Threat Protection, IPsec VPN, new sessions per second and interface speed, the 1000F is markedly ahead. That is why our default choice in a new data center project is the FortiGate 1000F. If traffic is inspection-heavy, the FortiGate 900G, which delivers 30 Gbps Threat Protection and 28 million sessions in a 1 RU chassis, is more efficient; if session and IPS capacity are critical, the FortiGate 1800F, with 12 million sessions and four 100GE QSFP28 slots, is the one to evaluate.

Which designs do two 40GE QSFP+ uplinks cover?

The FortiGate 1100E's interface layout is listed in the data sheet as follows: 2x 40GE QSFP+, 4x 25GE SFP28 / 10GE SFP+ / GE SFP, 4x 10GE SFP+ / GE SFP, 8x GE SFP, 16x GE RJ45 and 2x GE RJ45 management/HA ports. This means direct connectivity in existing data centers with a 40 Gigabit core. In an environment that has moved to a 100 Gigabit core, by contrast, the 1100E requires an intermediate conversion layer; the device does not have a 100GE slot. In deployments with high copper port requirements, the sixteen GE RJ45 ports outnumber the 1000F's eight RJ45 ports; however, the 1000F's RJ45 ports support 10GE / 5GE / 2.5GE / GE / 100M speeds, while those on the 1100E are limited to GE. On the VPN side, with 48 Gbps of IPsec throughput (512-byte, AES256-SHA256) and 20,000 gateway-to-gateway tunnels it can take on the role of a branch aggregation point; for remote access the data sheet lists 8.4 Gbps SSL-VPN throughput and a recommended maximum of 10,000 concurrent tunnel mode users. The 2.76 µs firewall latency with 64-byte UDP packets and 67.5 Mpps of packet capacity are notable figures in latency-sensitive internal segmentation scenarios.

How should the FortiOS and lifecycle plan for the FortiGate 1100E be built?

Fortinet data sheets do not state the FortiOS release on which performance figures were measured; the release decision is therefore made purely according to the support calendar. The CSB-260330-1 bulletin (March 2026) sets the calendar for the two lines as follows: on FortiOS 7.4 engineering support ends on 11 May 2027 and full support on 11 November 2028; on FortiOS 7.6 these dates are 25 July 2028 and 25 January 2030 (Fortinet Community, 2026). The lifecycle rule is fixed: a major release receives 36 months of engineering support followed by 18 months of "Must Fix" support; on the LTS line the total extends to 72 months and that access is tied to a FortiCare Elite contract (Fortinet Community, 2026). On a mature hardware platform such as the FortiGate 1100E the real question is the lifecycle of the hardware itself. Let us be clear here: we do not give a date unless we have seen a verified, published EOS date for this model. Before purchase we check Fortinet's official Product Life Cycle record together with you. If you are targeting a depreciation window longer than five years, the F and G series models are a safer choice.

In Turkey the FortiGate 1100E is usually positioned not at the center of a greenfield design but on top of an existing deployment. For the log retention obligation under KVKK (Turkey's data protection law), PCI-DSS segmentation requirements and the log integrity required in BDDK (Turkish banking regulator) audits, we deploy the device together with FortiAnalyzer, and we consolidate multi-device policy management in FortiManager. The data sheet lists active-active, active-passive and clustering HA options; in 1100E refresh projects, leaving the existing device as the HA peer and bringing the new node into active service is the least disruptive migration path. The data sheet states a 2 RU chassis, hot-swappable dual power supplies delivering 1+1 redundancy (80Plus) and 217 W average / 336 W maximum power consumption. As a Fortinet authorized channel partner, Sora Yazılım provides licensing, installation, migration from the legacy firewall and the managed service layer; before commissioning we move the existing policy set across with the FortiConverter service.

Do you already run a FortiGate 1100E and are considering a refresh? We profile the existing device's session, IPS and SSL inspection usage and prepare a comparative sizing report against the 1000F, 900G and 1800F; if you have constraints such as a DC-powered cabinet or copper port density, we factor those in as well. Reach us through our contact page and let us clarify the licensing, procurement and migration plan. We do not publish pricing on the page; quotes are prepared specifically for the project according to capacity and license scope.

  • 80 Gbps IPv4 firewall (1518-byte UDP)
  • 8 million concurrent TCP sessions
  • 2x 40GE QSFP+ slots, 16x GE RJ45 ports
  • SPU NP6 + CP9 hardware acceleration
  • -48V DC power option (FG-1100E-DC)
Key features

What this model offers

  • IPv4 firewall throughput 80 / 80 / 45 Gbps (1518 / 512 / 64-byte UDP)
  • IPS throughput 12.5 Gbps, NGFW throughput 9.8 Gbps (Enterprise Mix, logging enabled)
  • Threat Protection throughput 7.11 Gbps (firewall + IPS + application control + malware protection)
  • SSL inspection throughput 10 Gbps; 6,500 CPS and 780,000 concurrent inspection sessions
  • IPsec VPN throughput 48 Gbps (512-byte, AES256-SHA256)
  • SSL-VPN throughput 8.4 Gbps; recommended maximum of 10,000 concurrent tunnel mode users
  • 8 million concurrent TCP sessions, 500,000 new sessions per second
  • 2.76 µs firewall latency with 64-byte UDP packets, 67.5 Mpps packet capacity
  • 2x 40GE QSFP+ and 4x 25GE SFP28 / 10GE SFP+ / GE SFP slots
  • 16x GE RJ45, 8x GE SFP, 4x 10GE SFP+ and 2x GE RJ45 management/HA ports
  • SPU NP6 and CP9 hardware acceleration
  • 100,000 firewall policies, multi-tenant isolation with up to 250 VDOMs
  • 20,000 gateway-to-gateway and 100,000 client-to-gateway IPsec tunnels
  • AC or -48V DC power option; 1+1 redundancy with hot-swappable dual PSUs
Tech Summary

Technical data

IPv4 Firewall Throughput (1518 / 512 / 64-byte UDP)
80 / 80 / 45 Gbps
IPS Throughput (Enterprise Mix, logging enabled)
12.5 Gbps
NGFW Throughput (Firewall + IPS + Application Control)
9.8 Gbps
Threat Protection Throughput (FW + IPS + AppCtrl + Malware Protection)
7.11 Gbps
SSL Inspection Throughput (IPS, average HTTPS)
10 Gbps
Concurrent SSL Inspection sessions
780,000
IPsec VPN Throughput (512-byte, AES256-SHA256)
48 Gbps
SSL-VPN Throughput / concurrent users
8.4 Gbps / 10,000
Concurrent sessions (TCP)
8 million
New sessions per second (TCP)
500,000
Firewall latency (64-byte UDP)
2.76 µs
Interfaces
2x 40GE QSFP+, 4x 25GE SFP28/10GE SFP+/GE SFP, 4x 10GE SFP+/GE SFP, 8x GE SFP, 16x GE RJ45, 2x GE RJ45 MGMT/HA
Hardware acceleration
SPU NP6 + CP9
VDOMs (default / maximum)
10 / 250
Form factor and power consumption
Rack Mount 2 RU; 217 W average / 336 W maximum; AC or -48V DC
Use Cases

At what scale is this model preferred?

Telecom and colocation

Capacity matching in a DC-powered cabinet

In operator cabinets already running an FG-1100E-DC in the field, completing the second node with the same model allows an HA pair to be built without changing the -48V DC power and rack depth plan. A 2 RU chassis, 217 W average consumption and 1+1 redundant power supplies simplify the calculation in colocation spaces with tight energy budgets. In a greenfield DC cabinet design, however, we also bring the FG-900G-DC into the comparison.

Finance

Extending an existing E-series fleet

Because it uses the same power supply SKU as FG-300E, FG-400E, FG-500E and FG-600E devices, it pools the spare parts inventory and field replacement procedures. Added to the same FortiManager policy tree, capacity is increased without changing the operating model.

Public sector

Site-to-site VPN aggregation point

48 Gbps of IPsec VPN throughput and 20,000 gateway-to-gateway tunnel capacity make it possible to terminate the provincial connections of multi-location public institutions at a single center. The 100,000 client-to-gateway tunnels leave additional capacity for field teams.

Healthcare

Copper-dense data center layer

Sixteen GE RJ45 ports allow a large number of copper connections to be terminated directly without fiber conversion; the ports are limited to GE speed, so if 10GE copper is required you move to the 1000F's RJ45 ports. The 2.76 µs firewall latency with 64-byte UDP packets preserves the latency budget in internal segmentation between clinical systems.

Higher education

Remote-access-heavy campus

The data sheet lists 8.4 Gbps SSL-VPN throughput and a recommended maximum of 10,000 concurrent tunnel mode users; 780,000 concurrent SSL inspection sessions are also supported. During periods with large numbers of remote academic and administrative staff, these two figures become decisive.

Who is it for?

Organizations that already operate an E-series FortiGate fleet and are expanding capacity without changing their spare parts pool; enterprises completing an existing 1100E deployment with an HA peer or drawing up a refresh schedule; teams running a 2 RU device as an SSL-VPN and site-to-site IPsec aggregation point.

Frequently Asked Questions

Common questions about this model

How many Gbps is the FortiGate 1100E firewall throughput?
According to the official data sheet the IPv4 firewall throughput is 80 / 80 / 45 Gbps (with 1518, 512 and 64-byte UDP packets respectively). The 198 Gbps figure that appears in some sources belongs not to this model but to the FortiGate 1000F and 1800F. With inspections enabled, the binding figures are 12.5 Gbps IPS and 7.11 Gbps Threat Protection throughput.
How many concurrent sessions does the FortiGate 1100E support?
The data sheet figure is 8 million concurrent TCP sessions and 500,000 new sessions per second. The frequently repeated claim of 30 million sessions does not match the official data sheet. If more than 20 million sessions are required, you should look at the 900G class with 28 million sessions or the 2600F with 24 million.
Is the FortiGate 1100E a high-session version of the 1000F?
No. The 1100E supports 8 million and the 1000F 7.5 million sessions; the difference is about 7% and is not large enough to serve as a positioning rationale. The 1100E is the previous NP6 generation platform, while the 1000F is the NP7 generation. On firewall throughput the 1000F leads by roughly 2.5x and on Threat Protection by roughly 1.8x.
Does the FortiGate 1100E have 100GE ports?
No. The fastest interfaces on the device are two 40GE QSFP+ slots. If direct connectivity to a 100 Gigabit core is required, the 1000F with two 100GE QSFP28 slots or the 1800F with four should be chosen.
Are Threat Protection throughput and IPS throughput the same thing?
No; these two metrics measure different inspection combinations. On the 1100E, IPS throughput is 12.5 Gbps, NGFW throughput is 9.8 Gbps (firewall + IPS + application control) and Threat Protection throughput is 7.11 Gbps (with malware protection enabled on top of those). In sizing, the lowest figure — Threat Protection — is taken as the basis.
Is there a DC-powered model of the FortiGate 1100E?
Yes. The FG-1100E-DC variant runs on -48V DC input and draws a maximum of 11.5 A. Standard AC models are powered by 100-240V AC and ship by default with dual PSUs providing 1+1 redundancy. The FortiGate 1000F data sheet does not list a DC power option. However, DC power alone is not a rationale for the 1100E: Fortinet also lists the FG-900G-DC with dual DC power supplies (48–60 VDC), and the 900G does the same job in 1 RU with markedly higher performance.
How many VDOMs does the FortiGate 1100E support?
The data sheet states 10 VDOMs by default and 250 VDOMs at maximum; this figure is in the same class as the 1000F and 1800F. VDOM count is not an item where the 1100E falls short — the constraint is on the throughput side. In holding group, public sector and hosting scenarios that require a separate policy set and routing table per tenant, this capacity is sufficient.
What is the SSL inspection capacity of the FortiGate 1100E?
The data sheet states 10 Gbps SSL inspection throughput, 6,500 new SSL inspection connections per second (CPS) and 780,000 concurrent inspection sessions. These figures are averages across HTTPS sessions with different cipher suites. On the concurrent inspection session item the 1100E is above the 1000F's figure of 600,000.
When will the FortiGate 1100E reach EOS?
We do not give a date because we cannot confirm a verified EOS date published by Fortinet for this model. The estimated dates circulating online are unsourced. Before purchase or refresh we check Fortinet's official Product Life Cycle record together with you, using the device's serial number.
Should I buy a FortiGate 1100E for a new project?
As a rule, no. The only defensible rationale is parts and procedure commonality with an existing E-series fleet. DC power and copper port density are two frequently used arguments, but the FG-900G-DC covers both. For new projects the 1000F, which delivers 2.5x the firewall throughput in the same 2 RU class, is the better choice; the 900G if traffic is inspection-heavy, and the 1800F if session and IPS capacity are critical.

FortiGate 1100E — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support