The FortiGate 2600F is a 2U data center firewall listed on its official datasheet with 198 / 196 / 140 Gbps IPv4 Firewall throughput (1518 / 512 / 64 byte UDP), 31 Gbps IPS, 27 Gbps NGFW, 25 Gbps Threat Protection and 20 Gbps SSL Inspection throughput. With 24 million concurrent TCP sessions, 1 million new sessions per second and a maximum of 500 VDOMs, it targets inspection-heavy, multi-tenant data centers (FortiGate 2600F Series Data Sheet, 2026). The appliance belongs to the data center group of the FortiGate NGFW family.
Positioning the 2600F correctly starts with correcting a common error: this model does not offer higher raw firewall throughput than the 1800F. Both models are rated at 198 Gbps IPv4 Firewall throughput at 1518 bytes, 210 Mpps packet processing and 55 Gbps IPsec VPN throughput. Everything that separates the 2600F is concentrated under inspection, and that is the decisive heading in a world dominated by encrypted traffic: CyberRatings.org reports that more than 95% of global web traffic is encrypted (CyberRatings.org, 2025).
When should the FortiGate 2600F be chosen over the 1800F?
The short answer: when inspected traffic, the session table or the number of tenants presses against the ceiling of the 1800F. At 25 Gbps, the Threat Protection throughput of the 2600F is roughly 67% above the 15 Gbps of the 1800F; SSL Inspection throughput is 20 Gbps versus 12 Gbps, SSL inspection concurrent session capacity is 2.7 million versus 1.3 million, and SSL CPS is 16,000 versus 9,500. The gap in application control is larger still: 64 Gbps versus 34 Gbps.
The second decisive factor is the session table. The 2600F supports 24 million concurrent TCP sessions and 1 million new sessions per second; on the FortiGate 1800F those figures are 12 million and 750,000. Because microservice architectures, API gateways, CDN front ends and heavy IoT traffic multiply short-lived sessions rapidly, cost per session is a more critical bottleneck than Gbps in most data centers. The third difference is multi-tenancy: the 2600F supports 500 VDOMs, the 1800F 250.
How does the interface layout of the FortiGate 2600F differ from the 1800F?
The port layout of the 2600F consists of 4x 100GE QSFP28 / 40GE QSFP+, 16x 25GE SFP28 / 10GE SFP+ / GE SFP, 16x 10GE / GE RJ45, 2x 10GE SFP+ / GE SFP HA and 2x GE RJ45 management ports. The fastest interface class is the same as on the 1800F (4x 100GE QSFP28; this model has no 200GE ports either), but there are two practical differences. First, the number of 25GE SFP28 slots rises from 12 to 16. Second, and more importantly, the copper ports: while the 1800F offers 16 1 Gigabit RJ45 ports, the 16 RJ45 ports on the 2600F run at 10GE / GE.
For organizations that want to terminate campus distribution layers that have not moved to optical infrastructure, or management and backup networks, directly over 10 Gigabit copper, that detail alone can change the model choice. The FG-2601F variant additionally adds two 960 GB NVMe SSDs for local log buffering; for central archiving and reporting we recommend pairing it with FortiAnalyzer. In the data center, a FortiWeb layer can also be positioned in front of web applications.
What do 24 million sessions, 500 VDOMs and the Hyperscale license mean in practice?
500 VDOMs means that up to 500 mutually isolated virtual firewalls can be defined on a single chassis. For hosting and managed service providers that translates into separate policies, a separate routing table and separate administrator rights per customer; on the enterprise side it is used to separate production, test, DMZ, OT and PCI-DSS scope domains in an auditable way. The appliance carries that tenant density with 100,000 firewall policies and 20,000 site-to-site plus 100,000 client-to-site IPsec tunnels.
On the session side, standard capacity is 24 million. The values shown with an asterisk on the datasheet require the Hyperscale Firewall license: with it, concurrent sessions rise to 40 million, the new session rate to 2 million per second, and CGNAT functions run in hardware on the SPU NP7 network processor. According to Fortinet documentation, in this mode the NP7 takes over session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection from the CPU (Fortinet Document Library, 2026). The same Hyperscale license family covers the 1800F and 2600F series together. The CP9 content processor, meanwhile, handles pattern matching in flow-based inspection at more than 10 Gbps, which is what makes the model's 31 Gbps IPS and 64 Gbps application control figures possible (Fortinet Document Library, 2026).
When is it time to move to the FortiGate 3700F?
The jump between the 2600F and the 3700F is far larger than the one between the 1800F and the 2600F, and it includes raw forwarding as well. The table below places the official datasheet figures of the three models side by side.
| Metric (official datasheet) | FortiGate 1800F | FortiGate 2600F | FortiGate 3700F |
|---|
| IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP) | 198 / 197 / 140 Gbps | 198 / 196 / 140 Gbps | 589 / 589 / 420 Gbps |
| IPS Throughput | 22 Gbps | 31 Gbps | 86 Gbps |
| NGFW Throughput | 17 Gbps | 27 Gbps | 80 Gbps |
| Threat Protection Throughput | 15 Gbps | 25 Gbps | 75 Gbps |
| SSL Inspection Throughput | 12 Gbps | 20 Gbps | 55 Gbps |
| IPsec VPN Throughput (512 byte) | 55 Gbps | 55 Gbps | 160 Gbps |
| Concurrent Sessions (TCP) | 12 million | 24 million | 140 million |
| New Sessions/Second (TCP) | 750,000 | 1 million | 930,000 |
| Fastest interface | 4x 100GE QSFP28 | 4x 100GE QSFP28 | 4x 400GE QSFP-DD |
| VDOMs (default / maximum) | 10 / 250 | 10 / 500 | 10 / 500 |
| Power consumption (avg. / max.) | 410.9 W / 459.1 W | 416 W / 510 W | 590 W / 1140 W |
One striking detail in the table is the new sessions per second row: although the FortiGate 3700F carries 140 million concurrent sessions, its new session setup rate of 930,000 sits slightly below the 1 million of the 2600F. In other words, if your bottleneck is the number of long-lived sessions, 400 Gigabit uplinks or SSL inspection above 55 Gbps, the 3700F is the right step; if your bottleneck is connection setup rate per second, the 2600F may be the better match. This is a concrete example of why no model should be chosen without a capacity measurement.
Physically, the 2600F is 2 RU high and weighs 13.9 kg; it draws 416 W on average and 510 W at maximum and produces 71.72 dBA of noise. Dual hot-swap power supplies provide 1+1 redundancy, the DC option is offered at -48…-60 VDC, and the PSUs are in the 80Plus efficiency class. Active-active, active-passive and clustering HA configurations are supported. For release planning we recommend the FortiOS 7.6 branch; in bulletin CSB-260330-1 of March 2026, Fortinet extended the end of engineering support for 7.6 to July 25, 2028 and its end of full support to January 25, 2030 (Fortinet Community, 2026).
In Turkey the FortiGate 2600F is typically deployed in the primary data centers of financial institutions subject to BDDK (Turkish banking regulator) audits, in hosting platforms that process large volumes of personal data under KVKK (Turkey's data protection law), and in payment infrastructures that require PCI-DSS segmentation. As a Fortinet authorized channel partner, Sora Yazılım carries out capacity validation based on your actual traffic, VDOM and HA design, configuration migration from legacy appliances, log retention architecture and managed service processes. To clarify which of the 1800F, 2600F and 3700F is right for your environment and to request a quotation, reach us through our contact page.