Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 400F

A 1U enterprise NGFW with NP7 + CP9 acceleration for campuses and medium-to-large headquarters with 500–1000 users.

Quick answer

The FortiGate 400F is a 1U enterprise NGFW designed for campuses and medium-to-large headquarters with 500–1000 users. According to the official data sheet, IPv4 firewall throughput is 79.5/78.5/70 Gbps, IPS throughput is 12 Gbps, Threat Protection throughput is 9 Gbps and SSL inspection throughput is 8 Gbps. It offers NP7 + CP9 acceleration, 7.8 million sessions and 8 10GE SFP+ ports.

The FortiGate 400F is a 1U enterprise next-generation firewall positioned for campuses and medium-to-large headquarters with 500–1000 users. According to the official Fortinet data sheet, IPv4 and IPv6 firewall throughput is 79.5 / 78.5 / 70 Gbps with 1518/512/64 byte UDP packets, IPS throughput is 12 Gbps, NGFW throughput is 10 Gbps, Threat Protection throughput is 9 Gbps and SSL inspection throughput is 8 Gbps. The appliance carries 7.8 million concurrent TCP sessions and can open 500,000 new sessions per second. This profile takes the 400F out of the branch appliance category and places it at the inspection point between the campus backbone and the data centre.

At this scale, what really matters is not raw speed but the speed that remains under inspection. According to FortiGuard Labs' 2026 Global Threat Landscape report, the number of confirmed ransomware victims reached 7,831 in 2025 and the time to exploitation for critical vulnerabilities dropped to 24–48 hours (Fortinet, 2026). At this tempo, gaining throughput by switching off IPS and malware protection is not a realistic option. That is why, when sizing the 400F, we look not at the 79.5 Gbps firewall figure but at the 9 Gbps Threat Protection and 8 Gbps SSL inspection values that apply with all profiles enabled.

What size of organization is the FortiGate 400F suited to?

The 400F is for organizations expected to carry 500–1000 active users, intra-campus server traffic and centrally terminated branch VPNs together at a single inspection point. The data sheet gives 500,000 new sessions per second and 7.8 million concurrent sessions; this is the critical metric in campus environments where student or employee density spikes suddenly in the morning hours — it is almost twice the 280,000 new sessions per second of the FortiGate 200F. On the IPsec VPN side there is 55 Gbps of throughput with AES256-SHA256 at 512 byte packets, plus 2,000 gateway-to-gateway and 50,000 client-to-gateway tunnel capacity; on the SSL-VPN side the recommended maximum number of concurrent users is 5,000. The 400F can also manage 512 FortiAPs (256 of them in tunnel mode) and, on the FortiSwitch side, 96 switches; support for 96 switches requires FortiOS 7.6.1 or later, while earlier releases go up to 72 switches.

Does the FortiGate 400F have 25GE SFP28 ports?

No. This is the most frequent piece of misinformation we encounter in the field and it directly affects the purchasing decision. The fastest interfaces on the FortiGate 400F are 10GE SFP+ slots: 4 standard 10GE SFP+ and 4 10GE SFP+ Ultra Low Latency, 8 in total. Alongside them are 16 hardware-accelerated GE RJ45 ports, 8 GE SFP slots and 2 GE RJ45 management ports; 2 SFP (SX 1 GE) transceivers ship in the box. In this lineup the closest higher model offering 25GE SFP28 is the FortiGate 600F (4 25GE SFP28 Ultra Low Latency slots). If your backbone side is 25GE, you should plan directly for the 600F rather than the 400F; there is no way to establish a 25GE connection with a 400F. Likewise, the 400F has no 40GE QSFP+ or 100GE QSFP28 ports.

What are the Ultra Low Latency ports for?

Four of the 400F's 10GE SFP+ slots are defined as Ultra Low Latency (ULL). The difference is measurable in the data sheet: firewall latency for 64 byte UDP packets is 4.19 µs on standard ports, dropping to 2.5 µs on ULL ports. Total packet processing capacity is 105 Mpps. When latency-sensitive workloads — financial transaction flows, real-time production telemetry, storage or cluster traffic requiring low latency — are routed through these ports, the latency the firewall adds stays at the microsecond level. At the design stage we recommend allocating the ULL ports to the segments with the tightest latency budget rather than distributing them at random; the remaining traffic is carried over the standard 10GE SFP+ and GE ports.

What do NP7 and CP9 hardware acceleration deliver?

The FortiGate 400F uses Fortinet's NP7 network processor together with the CP9 content processor; it also includes a TPM module that generates and stores cryptographic keys in hardware. The NP7 provides "fastpath" acceleration that takes packet processing for established sessions off the FortiGate CPU and runs it on the ASIC; according to Fortinet documentation, the NP7 can also take over session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection from the CPU, depending on platform and license (Fortinet Document Library, 2026). Sizing must be based not on the general capability of the ASIC but on the appliance's own data sheet values: for the 400F, 7.8 million concurrent sessions and 79.5 Gbps firewall throughput. The CP9, for its part, provides more than 10 Gbps of pattern matching acceleration in flow-based inspection. The practical result of this pairing is visible in the data sheet: workloads that can be offloaded to the ASIC stay high — Application Control throughput of 28 Gbps, CAPWAP throughput of 65 Gbps, IPsec VPN of 55 Gbps — while full content inspection balances out at 9 Gbps. Compared with the 200F's NP6XLite + CP9 combination, this is precisely where the most pronounced leap occurs.

What is the difference between the FortiGate 400F, the 200F and the 600F?

To map the upgrade path correctly, the official data sheet values of the three models need to be placed side by side. Looking at a single "throughput" figure hides where the difference between these three appliances actually arises.

Metric (official data sheet)FortiGate 200FFortiGate 400FFortiGate 600F
IPv4 Firewall Throughput (1518/512/64 byte UDP)27 / 27 / 11 Gbps79.5 / 78.5 / 70 Gbps139 / 137.5 / 70 Gbps
IPS Throughput (Enterprise Mix)5 Gbps12 Gbps14 Gbps
NGFW Throughput3.5 Gbps10 Gbps11.5 Gbps
Threat Protection Throughput3 Gbps9 Gbps10.5 Gbps
SSL Inspection Throughput4 Gbps8 Gbps9 Gbps
IPsec VPN Throughput (512 byte)13 Gbps55 Gbps55 Gbps
Concurrent sessions (TCP)3 million7.8 million8 million
New sessions per second (TCP)280,000500,000550,000
Firewall policies10,00010,00030,000
VDOMs (default / maximum)10 / 1010 / 2510 / 50
Fastest interface4x 10GE SFP+8x 10GE SFP+ (4 of them ULL)4x 25GE SFP28 ULL + 4x 10GE SFP+
ASICNP6XLite + CP9NP7 + CP9NP7 + CP9

The break in the table lies between the 200F and the 400F, not between the 400F and the 600F. Moving from the 200F to the 400F increases firewall throughput roughly 2.9x, Threat Protection 3x, SSL inspection 2x, IPsec VPN 4.2x and concurrent sessions 2.6x — and the ASIC generation moves from NP6XLite to NP7. Moving from the 400F to the 600F, by contrast, brings a relatively small increase in security inspection metrics (IPS 17%, Threat Protection 17%, SSL inspection 13%); the 600F's real difference is its raw firewall throughput (139 Gbps), its 25GE SFP28 interfaces, a policy base three times larger (30,000) and a VDOM ceiling twice as high. The decision therefore simplifies as follows: you move from the 200F to the 400F for security inspection capacity; you move from the 400F to the 600F for backbone speed, port type, policy count and tenant count. You can find all the models and their positioning compared side by side on our FortiGate product page.

How many VDOMs, and what power and rack planning, are required?

The virtual domain capacity of the 400F is 10 by default, 25 at maximum. This is a genuine expansion over the 200F's 10/10 ceiling: for holding companies and campus structures that segment by subsidiary or tenant beyond basic divisions such as production, test, OT, DMZ and guest network, 25 VDOMs are sufficient in most scenarios. On the physical planning side, the 400F comes in a 1 RU rack mount form factor (44.45 x 432 x 380 mm, 6.4 kg), consumes 154.8 W on average and 189.2 W at maximum, and generates 48 dBA of noise. The power supplies come as hot-swappable dual AC PSUs providing 1+1 redundancy; there is also a DC variant for environments requiring a 48–60 VDC supply. This is an important operational difference compared with the 200F's non-hot-swappable internal dual power supplies: a PSU failure can be addressed without opening a maintenance window. Onboard storage is not present on the standard 400F; for organizations needing local logging and archiving, the FG-401F variant ships with 2 480 GB SSDs.

High availability and version planning: According to the data sheet, the 400F supports Active-Active, Active-Passive and clustering configurations. Two points specific to the 400F stand out when building an HA pair. First, you should not spend Ultra Low Latency ports on heartbeat and session synchronization; the value of those four ports lies in latency-sensitive production traffic, and the HA link should be built over standard 10GE SFP+ or GE ports. Second, because the 400F's power supplies are hot-swappable, PSU maintenance does not require removing the appliance from HA — on the 200F, the same operation requires a planned maintenance window. Fortinet publishes no metric for failover time; since takeover duration depends on the heartbeat interval, the scope of synchronized sessions and the convergence behaviour of neighbouring switches, it must be measured and recorded during commissioning. On the version side, capacity-to-version dependencies such as 96 FortiSwitch support requiring FortiOS 7.6.1+ must be evaluated together with the targeted access layer scale.

Turkey context and compliance: The 400F's 25 VDOM capacity produces a concrete payoff on the compliance side. The access restriction expectation of KVKK (Turkey's data protection law), the need to narrow PCI-DSS scope for segments carrying card data and the segment-level traceability required in BDDK (Turkey's banking regulator) audits can all be met on a single appliance by defining a separate VDOM per unit or subsidiary; each VDOM forms a distinct audit boundary with its own policy base and administrator role. Since the standard 400F has no onboard storage — local retention is possible only with the FG-401F's 2x 480 GB SSDs — forwarding the log stream to a central collector is mandatory; in our deployments we define a separate log stream and report template per VDOM so that each unit's audit output is kept distinct. As a Fortinet authorized channel partner, Sora Yazılım provides licensing, deployment, migration from an existing NGFW, HA clustering, SD-WAN orchestration and managed services for the FortiGate 400F.

If you share your campus topology, your backbone port type (10GE or 25GE), the security profiles you plan to enable and your VDOM requirements, we will compare the 400F's data sheet capacity against your real load and produce a sizing note; if the result points to a lower model (200F) or a higher one (600F), we will say so plainly. Get in touch through our contact page for scoping, a deployment plan and a quote.

  • 79.5 / 78.5 / 70 Gbps IPv4 firewall throughput
  • 9 Gbps Threat Protection, 8 Gbps SSL inspection
  • 8x 10GE SFP+ (4 of them Ultra Low Latency, 2.5 µs)
  • NP7 + CP9 hardware acceleration and TPM
  • 7.8 million sessions, 500,000 new sessions per second, 25 VDOMs
Key features

What this model offers

  • IPv4 and IPv6 firewall throughput 79.5/78.5/70 Gbps (1518/512/64 byte UDP)
  • IPS throughput 12 Gbps, NGFW throughput 10 Gbps, Threat Protection 9 Gbps
  • SSL inspection throughput 8 Gbps; 6,000 CPS, 800,000 concurrent SSL sessions
  • IPsec VPN 55 Gbps (512 byte, AES256-SHA256); 2,000 G2G + 50,000 C2G tunnels
  • SSL-VPN throughput 3.6 Gbps, recommended maximum of 5,000 concurrent users
  • 16x hardware-accelerated GE RJ45 + 8x GE SFP + 2x GE RJ45 management ports
  • 4x 10GE SFP+ and 4x 10GE SFP+ Ultra Low Latency slots (ULL latency 2.5 µs)
  • FortiASIC NP7 + CP9 hardware acceleration and Trusted Platform Module
  • 105 Mpps packet processing, 7.8 million concurrent sessions, 500,000 new sessions per second
  • Hot-swappable dual AC power supplies, 1+1 redundancy, 80Plus; DC variant 48–60 VDC
  • Multi-tenant segmentation with 10 default / 25 maximum VDOMs
  • Active-Active, Active-Passive and clustering HA configurations
  • Management of 96 FortiSwitches (FortiOS 7.6.1+) and 512 FortiAPs (256 tunnel)
  • 2x 480 GB onboard SSDs on the FG-401F variant; 2x SFP (SX 1 GE) transceivers in the box
Tech Summary

Technical data

IPv4 / IPv6 Firewall Throughput (1518/512/64 byte UDP)
79.5 / 78.5 / 70 Gbps
Firewall Throughput (packets per second)
105 Mpps
Firewall Latency (64 byte UDP)
4.19 µs (2.5 µs on Ultra Low Latency ports)
IPS Throughput (Enterprise Mix)
12 Gbps
NGFW Throughput (FW + IPS + Application Control)
10 Gbps
Threat Protection Throughput (FW + IPS + AppCtrl + AV)
9 Gbps
SSL Inspection Throughput (IPS, average HTTPS)
8 Gbps
IPsec VPN Throughput (512 byte, AES256-SHA256)
55 Gbps
Concurrent Sessions (TCP)
7.8 million
New Sessions/Second (TCP)
500,000
Interface layout
16x GE RJ45, 8x GE SFP, 4x 10GE SFP+, 4x 10GE SFP+ Ultra Low Latency, 2x GE RJ45 MGMT, 1x USB, 1x console
Virtual domains (VDOM, default / maximum)
10 / 25
Form factor
Rack Mount, 1 RU (44.45 x 432 x 380 mm, 6.4 kg), 48 dBA
Power consumption (average / maximum)
154.8 W / 189.2 W
Use Cases

At what scale is this model preferred?

Higher education

Campus internet edge and student network

Typical positioning: a 400F HA pair between the campus backbone and the internet edge. Session setup rate spikes suddenly in the morning hours when classes begin; the 500,000 new sessions per second figure absorbs this peak load. Student, academic staff, laboratory and guest networks run in separate VDOMs, and the wireless access layer is managed from the same appliance.

Healthcare

Fully inspected internet edge in a city hospital network

Typical positioning: a 400F HA pair on the backbone of a city hospital where the HIS, imaging (PACS), laboratory and administrative networks are separated. Large image transfers to PACS workstations are moved onto the Ultra Low Latency 10GE SFP+ ports; the 105 Mpps packet processing capacity keeps this traffic under inspection. Capacity is calculated from the 8 Gbps SSL inspection and 9 Gbps Threat Protection values, not from the raw firewall figure.

Holding / multi-company group

Subsidiary-based VDOM separation at head office

Typical positioning: at the head office of a holding company hosting several subsidiaries in the same building, the 400F creates logical firewalls with a separate VDOM per subsidiary. The 25 VDOM ceiling meets a need that the 200F's 10 VDOM limit cannot address in this scenario; each subsidiary gets its own policy base, routing table and administrator role.

Manufacturing

Plant backbone and low-latency OT traffic

Typical positioning: production line telemetry and SCADA traffic are routed through the Ultra Low Latency 10GE SFP+ ports, where firewall latency is 2.5 µs with 64 byte packets. IT and OT segments are kept in separate VDOMs, and traffic into OT is restricted to defined protocols and destinations only.

Finance / service provider

Terminating branch VPNs aggregated at the centre

Typical positioning: with 55 Gbps IPsec VPN throughput and 50,000 client-to-gateway tunnel capacity, the 400F terminates both branch-to-centre site-to-site tunnels and remote worker access on the same appliance. On the SSL-VPN side the recommended maximum number of concurrent users is 5,000; for larger remote access populations the load is moved to a separate appliance.

Who is it for?

Campuses and medium-to-large headquarters with 500–1000 users; structures where branch VPNs terminate centrally; university, hospital, holding company, manufacturing and finance organizations requiring tenant- or subsidiary-based segmentation of up to 25 VDOMs.

Frequently Asked Questions

Common questions about this model

What are the verified throughput figures for the FortiGate 400F?
According to the official Fortinet data sheet, IPv4 and IPv6 firewall throughput is 79.5/78.5/70 Gbps with 1518/512/64 byte UDP packets, IPS throughput 12 Gbps, NGFW throughput 10 Gbps, Threat Protection throughput 9 Gbps, SSL inspection throughput 8 Gbps and IPsec VPN throughput (512 byte, AES256-SHA256) 55 Gbps. These six metrics come from different test conditions; sizing must use the value corresponding to the security profiles that will be enabled.
Does the FortiGate 400F have 25GE SFP28 ports?
No. The fastest interfaces on the 400F are 10GE SFP+ slots: 4 standard and 4 Ultra Low Latency, 8 in total. For 25GE SFP28 you need to move to a higher class, the FortiGate 600F (4 25GE SFP28 ULL). The 400F also has no 40GE QSFP+ or 100GE QSFP28 ports. Organizations whose backbone side is 25GE should plan directly for the 600F.
What difference do the Ultra Low Latency ports make?
According to the data sheet, firewall latency for 64 byte UDP packets is 4.19 µs on standard ports, dropping to 2.5 µs on the four Ultra Low Latency 10GE SFP+ ports. The appliance's total packet processing capacity is 105 Mpps. Allocating latency-sensitive workloads (financial transaction flows, production telemetry, low-latency storage traffic) to these ports keeps the latency the firewall adds at the microsecond level.
How many VDOMs does the FortiGate 400F support?
10 by default, 25 at maximum. This is a genuine expansion over the 200F's 10/10 ceiling and is sufficient in most scenarios for structures that segment by subsidiary or tenant. In multi-tenant environments where 25 VDOMs are not enough, the 600F (10 default / 50 maximum) should be evaluated.
When should you move from the FortiGate 200F to the 400F?
There are three triggers. The first is security inspection capacity: Threat Protection rises from 3 Gbps to 9 Gbps and SSL inspection from 4 Gbps to 8 Gbps. The second is the session profile: new sessions per second rise from 280,000 to 500,000 and concurrent sessions from 3 million to 7.8 million. The third is segmentation: the VDOM ceiling rises from 10 to 25. If any one of these is under pressure, the upgrade is justified.
What is the difference between the FortiGate 400F and the 600F?
The gap in security inspection metrics is relatively small: IPS 12 versus 14 Gbps, Threat Protection 9 versus 10.5 Gbps, SSL inspection 8 versus 9 Gbps. The real difference lies elsewhere — the 600F's raw IPv4 firewall throughput is 139/137.5/70 Gbps, its firewall policy capacity is 30,000 (10,000 on the 400F), its VDOM ceiling is 50 (25 on the 400F) and its fastest interface is 25GE SFP28. In other words, you move to the 600F for backbone speed, port type, policy count and tenant count.
Which ASIC does the FortiGate 400F use?
The NP7 network processor is used together with the CP9 content processor; the appliance also contains a TPM module. The NP7 offloads packet processing for established sessions to the ASIC to free the CPU, and depending on platform and license it can also take on session setup, CGNAT, hardware logging and DoS protection. The CP9, for its part, accelerates pattern matching in flow-based inspection. Appliance capacity must be based not on the general capability of the ASIC but on the data sheet values: 79.5 Gbps firewall throughput and 7.8 million concurrent sessions. The lower model, the 200F, uses the older NP6XLite processor.
How many FortiSwitches and FortiAPs can be managed?
According to the data sheet, 96 FortiSwitches and a total of 512 FortiAPs (256 of them in tunnel mode) can be managed. Support for 96 switches requires FortiOS 7.6.1 or later; earlier releases go up to 72 switches. This capacity is enough to manage the access layer of a mid-sized campus from a single console as a logical extension of the firewall.
How should power, rack and redundancy be planned?
The 400F comes in a 1 RU rack mount form factor (44.45 x 432 x 380 mm, 6.4 kg), consumes 154.8 W on average and 189.2 W at maximum, and generates 48 dBA of noise. The dual AC power supplies are hot-swappable and provide 1+1 redundancy; there is a DC variant for environments requiring a 48–60 VDC supply. Hot-swappability is an operational advantage over the 200F, because it allows a PSU failure to be addressed without opening a maintenance window.
Which FortiOS version and HA configuration are recommended?
On the 400F, two things determine the version decision: the targeted access layer scale and the support calendar. Managing 96 FortiSwitches requires FortiOS 7.6.1 or later; in deployments staying below 72 switches this constraint does not apply. On the support side, under bulletin CSB-260330-1, engineering support for v7.4 ends on 11 May 2027 and full support on 11 November 2028; for v7.6 the dates are 25 July 2028 and 25 January 2030 respectively — LTS access requires a FortiCare Elite contract. On the HA side, the 400F supports Active-Active, Active-Passive and clustering; since Fortinet publishes no metric for failover time, this value must be measured during commissioning.

FortiGate 400F — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support