The FortiGate 3700F is a 2U data center firewall listed on its official datasheet with 589 / 589 / 420 Gbps IPv4 Firewall throughput (1518 / 512 / 64 byte UDP) — and the same 589 / 589 / 420 Gbps on the IPv6 side (1518 / 512 / 86 byte UDP) — along with 86 Gbps IPS, 80 Gbps NGFW, 75 Gbps Threat Protection and 55 Gbps SSL Inspection throughput. With four 400GE QSFP-DD ports, 160 Gbps IPsec VPN throughput and 140 million concurrent TCP sessions, it targets hyperscale data centers, carrier backbones and financial trading networks that require low latency (FortiGate 3700F Series Data Sheet, 2026). The model sits in the data center group of the FortiGate NGFW family, on the tier between the 2600F and the 4400F.
What separates the 3700F from its predecessors is that the increase in scale happens across every heading at once, not only in bandwidth. Compared with the FortiGate 2600F one tier below, firewall throughput rises roughly 3x (198 → 589 Gbps), Threat Protection 3x (25 → 75 Gbps), SSL Inspection 2.75x (20 → 55 Gbps), IPsec VPN roughly 3x (55 → 160 Gbps) and concurrent session capacity roughly 6x (24 → 140 million). That means the two models address different classes of requirement; the 3700F is not "a slightly bigger 2600F".
What size of data center is the FortiGate 3700F right for?
The FortiGate 3700F suits environments that carry 400 Gigabit in the backbone, generate more than 50 Gbps of inspected traffic and whose session table is measured in tens of millions. Typical profiles are: the north-south boundary of hyperscale and regional cloud operators, the subscriber backbone of internet service providers, large content and CDN nodes, national-scale e-government or banking data centers, and financial networks that operate at microsecond precision such as exchange or payment settlement platforms.
On the capacity side, the appliance supports 200,000 firewall policies, 40,000 site-to-site and 200,000 client-to-site IPsec tunnels, 10 default / 500 maximum VDOMs, and management of 300 FortiSwitch and 4,096 FortiAP units. The inspection load should be assessed together with the reality CyberRatings.org reports: more than 95% of global web traffic is encrypted, and some products suffer a marked performance drop while inspecting encrypted traffic (CyberRatings.org, 2025). The 55 Gbps SSL Inspection throughput and 15 million concurrent SSL sessions of the 3700F leave room for a meaningful share of that encrypted volume to actually be decrypted and examined.
What do the 400GE QSFP-DD ports and the Ultra Low Latency ports deliver in practice?
The interface layout of the 3700F is the most flexible in the family: 4x 400GE QSFP-DD / 200GE QSFP56 / 100GE QSFP28 / 40GE QSFP+, 18x 50GE SFP56 / 25GE SFP28 / 10GE SFP+, 4x 25GE SFP28 / 10GE SFP+ / GE SFP Ultra Low Latency ports, 2x 50/25/10/1GE HA ports and 2x 10GE / GE RJ45 management ports. Because the same QSFP-DD cage can be used at 400, 200, 100 and 40 Gigabit, the appliance can connect to a 100 GE backbone today and move to 400 GE later without a hardware change. On the upgrade path, 400GE and 200GE appear for the first time at this tier; the fastest interface on the 2600F is 100GE QSFP28.
The Ultra Low Latency ports open a separate use case. While the standard firewall latency of the appliance is 3.56 µs with 64 byte UDP packets, over the ULL ports that figure drops to 1.45 µs. Flows where latency translates directly into cost — algorithmic trading, order routing and real-time settlement — can be moved onto these ports while other segments on the same chassis continue to run with full inspection. Packet processing capacity is 630 Mpps and application control throughput is 190 Gbps.
How do you choose between the FortiGate 3700F and the 4400F?
The distinction between the two models is misreported in most sources. The reality is that 400 Gigabit ports exist only on the 3700F; the fastest interfaces on the 4400F are twelve 100GE QSFP28 / 40GE QSFP+ slots. In exchange, the 4400F is clearly ahead in raw forwarding, SSL inspection, IPsec and session scale — but it demands 4 RU of space and roughly 2.6x the power. The table below compares the three tiers using official datasheet figures.
| Metric (official datasheet) | FortiGate 2600F | FortiGate 3700F | FortiGate 4400F |
|---|
| IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP) | 198 / 196 / 140 Gbps | 589 / 589 / 420 Gbps | 1.15 / 1.14 / 0.50 Tbps |
| Firewall Throughput (pps) | 210 Mpps | 630 Mpps | 750 Mpps |
| IPS Throughput | 31 Gbps | 86 Gbps | 94 Gbps |
| NGFW Throughput | 27 Gbps | 80 Gbps | 82 Gbps |
| Threat Protection Throughput | 25 Gbps | 75 Gbps | 75 Gbps |
| SSL Inspection Throughput | 20 Gbps | 55 Gbps | 86 Gbps |
| IPsec VPN Throughput (512 byte) | 55 Gbps | 160 Gbps | 310 Gbps |
| Concurrent Sessions (TCP) | 24 million | 140 million | 210 million (700 million with Hyperscale) |
| New Sessions/Second (TCP) | 1 million | 930,000 | 1 million (10 million with Hyperscale) |
| Fastest interface | 4x 100GE QSFP28 | 4x 400GE QSFP-DD | 12x 100GE QSFP28 |
| Form factor / average power | 2 RU / 416 W | 2 RU / 590 W | 4 RU / 1533 W |
The decision rule can be simplified. If your backbone requires 400 Gigabit ports, or if rack space and power budget are constrained, choose the 3700F: 589 Gbps and 590 W average consumption in 2 RU deliver far higher density per data center than the FortiGate 4400F, which asks for 4 RU and 1533 W. Conversely, if you need SSL inspection above 86 Gbps, IPsec aggregation above 160 Gbps or hundreds of millions of sessions, the 4400F is the right step. It is worth noting that Threat Protection throughput is 75 Gbps on both models: moving to the 4400F purely for threat prevention capacity buys you nothing.
How should 140 million sessions, 500 VDOMs and FortiOS planning be handled?
The 140 million concurrent TCP session capacity of the 3700F is delivered in the standard configuration and carries no asterisked Hyperscale Firewall license condition on the datasheet; on the 1800F and 2600F that extra license is required to reach 40 million sessions. On the other hand, the new session setup rate is 930,000 per second, slightly below the 1 million of the 2600F. For environments whose bottleneck is the number of long-lived sessions the 3700F is ideal; for environments whose bottleneck is connection setup rate per second, a capacity measurement is essential. On the hardware side the SPU NP7 network processor and the CP9 content processor are at work; according to Fortinet documentation a single NP7 supports a maximum of 200 Gbps across two 100 Gigabit interfaces and up to 12 million sessions (Fortinet Document Library, 2026), while the CP9 provides more than 10 Gbps of pattern-matching acceleration in flow-based inspection (Fortinet Document Library, 2026).
A maximum of 500 VDOMs makes it possible to build isolated policy domains per tenant, scope area or business unit on a single chassis. Because appliance lifetimes at this scale usually exceed five years, the FortiOS lifecycle must be planned from the outset: bulletin CSB-260330-1 of March 2026 extended engineering support for the 7.6 branch to July 25, 2028 and full support to January 25, 2030 (Fortinet Community, 2026). At this scale log volume is an architectural problem in its own right; the 2x 1.92 TB SSDs on the FG-3701F variant provide local buffering, while FortiAnalyzer should be positioned for central archiving, correlation and reporting.
The physical requirements are clear: 2 RU of height, 21.4 kg of weight, average 590 W and maximum 1140 W consumption, 70.4 dBA of noise, front-to-back forced airflow and dual hot-swap 80Plus AC power supplies for 1+1 redundancy. The HA cluster is built as active-active, active-passive or clustering over the two dedicated 50/25/10/1GE HA ports on the chassis. In Turkey, appliances in this class are typically deployed on platforms that process large volumes of personal data under KVKK (Turkey's data protection law), in financial data centers subject to BDDK (Turkish banking regulator) audits and in payment infrastructures that require PCI-DSS segmentation. As a Fortinet authorized channel partner, Sora Yazılım runs capacity validation based on traffic measurement, 400GE optics and transceiver planning, HA cluster and VDOM design, configuration migration from existing appliances, log retention architecture and managed service processes. To clarify whether the 3700F is the right tier for your environment and to request a quotation, reach us through our contact page.