Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 3700F

400 Gigabit class data center firewall: 589 Gbps IPv4 firewall, 4x 400GE QSFP-DD and 140 million sessions, in 2 RU.

Quick answer

The FortiGate 3700F is a 2U data center firewall that, according to its official datasheet, delivers 589 Gbps IPv4 Firewall, 86 Gbps IPS, 75 Gbps Threat Protection and 55 Gbps SSL Inspection throughput. With four 400GE QSFP-DD ports, 140 million concurrent sessions and 1.45 µs latency on Ultra Low Latency ports, it targets hyperscale data centers and carrier backbones.

The FortiGate 3700F is a 2U data center firewall listed on its official datasheet with 589 / 589 / 420 Gbps IPv4 Firewall throughput (1518 / 512 / 64 byte UDP) — and the same 589 / 589 / 420 Gbps on the IPv6 side (1518 / 512 / 86 byte UDP) — along with 86 Gbps IPS, 80 Gbps NGFW, 75 Gbps Threat Protection and 55 Gbps SSL Inspection throughput. With four 400GE QSFP-DD ports, 160 Gbps IPsec VPN throughput and 140 million concurrent TCP sessions, it targets hyperscale data centers, carrier backbones and financial trading networks that require low latency (FortiGate 3700F Series Data Sheet, 2026). The model sits in the data center group of the FortiGate NGFW family, on the tier between the 2600F and the 4400F.

What separates the 3700F from its predecessors is that the increase in scale happens across every heading at once, not only in bandwidth. Compared with the FortiGate 2600F one tier below, firewall throughput rises roughly 3x (198 → 589 Gbps), Threat Protection 3x (25 → 75 Gbps), SSL Inspection 2.75x (20 → 55 Gbps), IPsec VPN roughly 3x (55 → 160 Gbps) and concurrent session capacity roughly 6x (24 → 140 million). That means the two models address different classes of requirement; the 3700F is not "a slightly bigger 2600F".

What size of data center is the FortiGate 3700F right for?

The FortiGate 3700F suits environments that carry 400 Gigabit in the backbone, generate more than 50 Gbps of inspected traffic and whose session table is measured in tens of millions. Typical profiles are: the north-south boundary of hyperscale and regional cloud operators, the subscriber backbone of internet service providers, large content and CDN nodes, national-scale e-government or banking data centers, and financial networks that operate at microsecond precision such as exchange or payment settlement platforms.

On the capacity side, the appliance supports 200,000 firewall policies, 40,000 site-to-site and 200,000 client-to-site IPsec tunnels, 10 default / 500 maximum VDOMs, and management of 300 FortiSwitch and 4,096 FortiAP units. The inspection load should be assessed together with the reality CyberRatings.org reports: more than 95% of global web traffic is encrypted, and some products suffer a marked performance drop while inspecting encrypted traffic (CyberRatings.org, 2025). The 55 Gbps SSL Inspection throughput and 15 million concurrent SSL sessions of the 3700F leave room for a meaningful share of that encrypted volume to actually be decrypted and examined.

What do the 400GE QSFP-DD ports and the Ultra Low Latency ports deliver in practice?

The interface layout of the 3700F is the most flexible in the family: 4x 400GE QSFP-DD / 200GE QSFP56 / 100GE QSFP28 / 40GE QSFP+, 18x 50GE SFP56 / 25GE SFP28 / 10GE SFP+, 4x 25GE SFP28 / 10GE SFP+ / GE SFP Ultra Low Latency ports, 2x 50/25/10/1GE HA ports and 2x 10GE / GE RJ45 management ports. Because the same QSFP-DD cage can be used at 400, 200, 100 and 40 Gigabit, the appliance can connect to a 100 GE backbone today and move to 400 GE later without a hardware change. On the upgrade path, 400GE and 200GE appear for the first time at this tier; the fastest interface on the 2600F is 100GE QSFP28.

The Ultra Low Latency ports open a separate use case. While the standard firewall latency of the appliance is 3.56 µs with 64 byte UDP packets, over the ULL ports that figure drops to 1.45 µs. Flows where latency translates directly into cost — algorithmic trading, order routing and real-time settlement — can be moved onto these ports while other segments on the same chassis continue to run with full inspection. Packet processing capacity is 630 Mpps and application control throughput is 190 Gbps.

How do you choose between the FortiGate 3700F and the 4400F?

The distinction between the two models is misreported in most sources. The reality is that 400 Gigabit ports exist only on the 3700F; the fastest interfaces on the 4400F are twelve 100GE QSFP28 / 40GE QSFP+ slots. In exchange, the 4400F is clearly ahead in raw forwarding, SSL inspection, IPsec and session scale — but it demands 4 RU of space and roughly 2.6x the power. The table below compares the three tiers using official datasheet figures.

Metric (official datasheet)FortiGate 2600FFortiGate 3700FFortiGate 4400F
IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)198 / 196 / 140 Gbps589 / 589 / 420 Gbps1.15 / 1.14 / 0.50 Tbps
Firewall Throughput (pps)210 Mpps630 Mpps750 Mpps
IPS Throughput31 Gbps86 Gbps94 Gbps
NGFW Throughput27 Gbps80 Gbps82 Gbps
Threat Protection Throughput25 Gbps75 Gbps75 Gbps
SSL Inspection Throughput20 Gbps55 Gbps86 Gbps
IPsec VPN Throughput (512 byte)55 Gbps160 Gbps310 Gbps
Concurrent Sessions (TCP)24 million140 million210 million (700 million with Hyperscale)
New Sessions/Second (TCP)1 million930,0001 million (10 million with Hyperscale)
Fastest interface4x 100GE QSFP284x 400GE QSFP-DD12x 100GE QSFP28
Form factor / average power2 RU / 416 W2 RU / 590 W4 RU / 1533 W

The decision rule can be simplified. If your backbone requires 400 Gigabit ports, or if rack space and power budget are constrained, choose the 3700F: 589 Gbps and 590 W average consumption in 2 RU deliver far higher density per data center than the FortiGate 4400F, which asks for 4 RU and 1533 W. Conversely, if you need SSL inspection above 86 Gbps, IPsec aggregation above 160 Gbps or hundreds of millions of sessions, the 4400F is the right step. It is worth noting that Threat Protection throughput is 75 Gbps on both models: moving to the 4400F purely for threat prevention capacity buys you nothing.

How should 140 million sessions, 500 VDOMs and FortiOS planning be handled?

The 140 million concurrent TCP session capacity of the 3700F is delivered in the standard configuration and carries no asterisked Hyperscale Firewall license condition on the datasheet; on the 1800F and 2600F that extra license is required to reach 40 million sessions. On the other hand, the new session setup rate is 930,000 per second, slightly below the 1 million of the 2600F. For environments whose bottleneck is the number of long-lived sessions the 3700F is ideal; for environments whose bottleneck is connection setup rate per second, a capacity measurement is essential. On the hardware side the SPU NP7 network processor and the CP9 content processor are at work; according to Fortinet documentation a single NP7 supports a maximum of 200 Gbps across two 100 Gigabit interfaces and up to 12 million sessions (Fortinet Document Library, 2026), while the CP9 provides more than 10 Gbps of pattern-matching acceleration in flow-based inspection (Fortinet Document Library, 2026).

A maximum of 500 VDOMs makes it possible to build isolated policy domains per tenant, scope area or business unit on a single chassis. Because appliance lifetimes at this scale usually exceed five years, the FortiOS lifecycle must be planned from the outset: bulletin CSB-260330-1 of March 2026 extended engineering support for the 7.6 branch to July 25, 2028 and full support to January 25, 2030 (Fortinet Community, 2026). At this scale log volume is an architectural problem in its own right; the 2x 1.92 TB SSDs on the FG-3701F variant provide local buffering, while FortiAnalyzer should be positioned for central archiving, correlation and reporting.

The physical requirements are clear: 2 RU of height, 21.4 kg of weight, average 590 W and maximum 1140 W consumption, 70.4 dBA of noise, front-to-back forced airflow and dual hot-swap 80Plus AC power supplies for 1+1 redundancy. The HA cluster is built as active-active, active-passive or clustering over the two dedicated 50/25/10/1GE HA ports on the chassis. In Turkey, appliances in this class are typically deployed on platforms that process large volumes of personal data under KVKK (Turkey's data protection law), in financial data centers subject to BDDK (Turkish banking regulator) audits and in payment infrastructures that require PCI-DSS segmentation. As a Fortinet authorized channel partner, Sora Yazılım runs capacity validation based on traffic measurement, 400GE optics and transceiver planning, HA cluster and VDOM design, configuration migration from existing appliances, log retention architecture and managed service processes. To clarify whether the 3700F is the right tier for your environment and to request a quotation, reach us through our contact page.

  • 589 / 589 / 420 Gbps IPv4 Firewall throughput
  • 75 Gbps Threat Protection, 55 Gbps SSL Inspection
  • 4x 400GE QSFP-DD (200GE / 100GE / 40GE compatible)
  • 140 million concurrent sessions, 160 Gbps IPsec VPN
  • 1.45 µs latency on ULL ports, 2 RU
Key features

What this model offers

  • 589 / 589 / 420 Gbps IPv4 Firewall throughput (1518 / 512 / 64 byte UDP) and identical IPv6 Firewall throughput (1518 / 512 / 86 byte UDP), 630 Mpps packet processing
  • 86 Gbps IPS, 80 Gbps NGFW and 75 Gbps Threat Protection throughput (Enterprise Mix, logging enabled)
  • 55 Gbps SSL Inspection throughput; 57,000 SSL CPS and 15 million concurrent SSL sessions
  • 160 Gbps IPsec VPN throughput (AES256-SHA256, 512 byte packets)
  • 190 Gbps Application Control throughput
  • 3.56 µs firewall latency with 64 byte UDP packets; 1.45 µs on Ultra Low Latency ports
  • 4x 400GE QSFP-DD / 200GE QSFP56 / 100GE QSFP28 / 40GE QSFP+ ports — the same cage can be used at four different speeds
  • 18x 50GE SFP56 / 25GE SFP28 / 10GE SFP+ and 4x 25GE SFP28 / 10GE SFP+ / GE SFP Ultra Low Latency slots
  • 140 million concurrent TCP sessions (no Hyperscale license required) and 930,000 new sessions per second
  • 200,000 firewall policies, 40,000 site-to-site and 200,000 client-to-site IPsec tunnels
  • 10 default / 500 maximum VDOMs; management of 300 FortiSwitch and 4,096 FortiAP units
  • Hardware acceleration through the SPU NP7 network processor and CP9 content processor, with hardware-accelerated VXLAN segmentation
  • Active-active, active-passive and clustering HA; 2x 50/25/10/1GE dedicated HA ports
  • 2 RU chassis, dual hot-swap 80Plus AC power supplies (1+1); 2x 1.92 TB SSD on the FG-3701F
Tech Summary

Technical data

IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)
589 / 589 / 420 Gbps
Firewall Throughput (pps)
630 Mpps
Firewall Latency (64 byte UDP)
3.56 µs (1.45 µs on Ultra Low Latency ports)
IPS Throughput
86 Gbps
NGFW Throughput
80 Gbps
Threat Protection Throughput
75 Gbps
SSL Inspection Throughput
55 Gbps
IPsec VPN Throughput (512 byte, AES256-SHA256)
160 Gbps
Application Control Throughput
190 Gbps
Concurrent Sessions (TCP)
140 million
New Sessions/Second (TCP)
930,000
Firewall Policies / VDOM
200,000 policies; 10 default / 500 maximum VDOMs
Interfaces
4x 400GE QSFP-DD/200GE QSFP56/100GE QSFP28/40GE QSFP+, 18x 50GE SFP56/25GE SFP28/10GE SFP+, 4x 25GE SFP28/10GE SFP+/GE SFP Ultra Low Latency, 2x 50/25/10/1GE HA, 2x 10GE/GE RJ45 MGMT
Form factor / power consumption (avg. / max.)
Rack Mount 2 RU, 21.4 kg, 70.4 dBA; 590 W / 1140 W
Use Cases

At what scale is this model preferred?

Cloud and hyperscale hosting

North-south boundary on a 400 Gigabit backbone

An edge firewall that connects to the cloud operator's spine layer over 400GE QSFP-DD and carries 589 Gbps of raw forwarding and 75 Gbps of inspected traffic. Because the same QSFP-DD cage can also be used at 100GE, it can connect to the existing backbone today and move to 400GE later without a hardware change.

Telecommunications and ISPs

Session-heavy inspection on the subscriber backbone

A broad subscriber base is carried on a single chassis with 140 million concurrent session capacity. Eighteen 50GE SFP56 ports connect to the aggregation layer while 160 Gbps IPsec VPN throughput serves carrier VPN services.

Finance and capital markets

Low-latency trading network segmentation

Order routing and settlement flows are moved onto Ultra Low Latency ports and carried at 1.45 µs of latency, while corporate and DMZ segments on the same chassis continue to run with full inspection. VDOM separation simplifies BDDK (Turkish banking regulator) audit records.

Public sector and national data centers

Tenant separation in a multi-agency data center

A maximum of 500 VDOMs allows an isolated policy domain to be defined per ministry, agency or business unit. Capacity for 200,000 firewall policies and 200,000 client-to-site IPsec tunnels carries large-scale remote access scenarios.

Content delivery and media

CDN node and broadcast infrastructure edge

High-volume egress traffic is carried over the 400GE ports and inspected at protocol level with 190 Gbps of application control capacity. The 630 Mpps packet processing capacity is the principal advantage in small-packet-heavy flows.

Who is it for?

Architecture and network security teams managing hyperscale and regional cloud operations, internet service providers, national-scale public sector and banking data centers, CDN and media broadcast infrastructures, and capital market trading networks that require Ultra Low Latency.

Frequently Asked Questions

Common questions about this model

What is the firewall throughput of the FortiGate 3700F?
The official datasheet states IPv4 Firewall throughput as 589 / 589 / 420 Gbps for 1518 / 512 / 64 byte UDP packets; on the IPv6 side the same trio is measured with 1518 / 512 / 86 byte packets. Packet processing capacity is 630 Mpps. The 818 Gbps figure quoted in some sources has no counterpart in the Fortinet datasheet.
How much threat prevention capacity does the FortiGate 3700F have?
Threat Protection throughput (firewall + IPS + application control + malware protection) is 75 Gbps. NGFW throughput is 80 Gbps and IPS throughput is 86 Gbps; these three metrics measure different feature sets and are not interchangeable.
Does the 3700F really offer 400GE ports?
Yes. The appliance has four 400GE QSFP-DD ports, and those cages can also be used as 200GE QSFP56, 100GE QSFP28 or 40GE QSFP+. Among the models compared on this page the 3700F is the only one offering 400GE; the fastest interfaces on the 4400F one tier above are twelve 100GE QSFP28 / 40GE QSFP+ slots.
How much latency do the Ultra Low Latency ports deliver?
While standard firewall latency is 3.56 µs with 64 byte UDP packets, over the four Ultra Low Latency 25GE SFP28 / 10GE SFP+ ports that figure drops to 1.45 µs. Latency-sensitive transaction flows can be moved onto these ports.
How do you choose between the FortiGate 3700F and the 4400F?
If 400 Gigabit ports are required, or if rack space and power are constrained, the 3700F (2 RU, 590 W average). If you need SSL inspection above 86 Gbps, IPsec above 160 Gbps or hundreds of millions of sessions, the 4400F (4 RU, 1533 W average, 1.15 Tbps firewall). Threat Protection is 75 Gbps on both models.
How many concurrent sessions does the 3700F support?
140 million concurrent TCP sessions and 930,000 new sessions per second. That session capacity is delivered in the standard configuration and does not require a separate Hyperscale Firewall license.
Why can the 2600F open more new sessions per second?
According to the datasheets, the 2600F establishes 1 million new TCP sessions per second and the 3700F 930,000. Concurrent session capacity and new session setup rate are different metrics; if your bottleneck is connection setup rate, moving to a higher model without a capacity measurement may bring no benefit.
How many VDOMs and how many firewall policies can be defined?
10 default and 500 maximum VDOMs and 200,000 firewall policies are supported. In addition, 40,000 site-to-site and 200,000 client-to-site IPsec tunnels can be defined.
How much space, power and cooling does it require in the data center?
2 RU of height, 21.4 kg of weight; average 590 W and maximum 1140 W consumption, 70.4 dBA of noise and front-to-back forced airflow. Dual hot-swap 80Plus AC power supplies provide 1+1 redundancy.
Which services does Sora Yazılım provide for the FortiGate 3700F?
As a Fortinet authorized channel partner we provide capacity validation based on traffic measurement, 400GE optics and transceiver planning, licensing, HA cluster and VDOM design, configuration migration, log architecture with FortiAnalyzer and managed services. For a scoping study and quotation request, write to us through our contact page.

FortiGate 3700F — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support