The FortiGate 400F is a 1U enterprise next-generation firewall positioned for campuses and medium-to-large headquarters with 500–1000 users. According to the official Fortinet data sheet, IPv4 and IPv6 firewall throughput is 79.5 / 78.5 / 70 Gbps with 1518/512/64 byte UDP packets, IPS throughput is 12 Gbps, NGFW throughput is 10 Gbps, Threat Protection throughput is 9 Gbps and SSL inspection throughput is 8 Gbps. The appliance carries 7.8 million concurrent TCP sessions and can open 500,000 new sessions per second. This profile takes the 400F out of the branch appliance category and places it at the inspection point between the campus backbone and the data centre.
At this scale, what really matters is not raw speed but the speed that remains under inspection. According to FortiGuard Labs' 2026 Global Threat Landscape report, the number of confirmed ransomware victims reached 7,831 in 2025 and the time to exploitation for critical vulnerabilities dropped to 24–48 hours (Fortinet, 2026). At this tempo, gaining throughput by switching off IPS and malware protection is not a realistic option. That is why, when sizing the 400F, we look not at the 79.5 Gbps firewall figure but at the 9 Gbps Threat Protection and 8 Gbps SSL inspection values that apply with all profiles enabled.
What size of organization is the FortiGate 400F suited to?
The 400F is for organizations expected to carry 500–1000 active users, intra-campus server traffic and centrally terminated branch VPNs together at a single inspection point. The data sheet gives 500,000 new sessions per second and 7.8 million concurrent sessions; this is the critical metric in campus environments where student or employee density spikes suddenly in the morning hours — it is almost twice the 280,000 new sessions per second of the FortiGate 200F. On the IPsec VPN side there is 55 Gbps of throughput with AES256-SHA256 at 512 byte packets, plus 2,000 gateway-to-gateway and 50,000 client-to-gateway tunnel capacity; on the SSL-VPN side the recommended maximum number of concurrent users is 5,000. The 400F can also manage 512 FortiAPs (256 of them in tunnel mode) and, on the FortiSwitch side, 96 switches; support for 96 switches requires FortiOS 7.6.1 or later, while earlier releases go up to 72 switches.
Does the FortiGate 400F have 25GE SFP28 ports?
No. This is the most frequent piece of misinformation we encounter in the field and it directly affects the purchasing decision. The fastest interfaces on the FortiGate 400F are 10GE SFP+ slots: 4 standard 10GE SFP+ and 4 10GE SFP+ Ultra Low Latency, 8 in total. Alongside them are 16 hardware-accelerated GE RJ45 ports, 8 GE SFP slots and 2 GE RJ45 management ports; 2 SFP (SX 1 GE) transceivers ship in the box. In this lineup the closest higher model offering 25GE SFP28 is the FortiGate 600F (4 25GE SFP28 Ultra Low Latency slots). If your backbone side is 25GE, you should plan directly for the 600F rather than the 400F; there is no way to establish a 25GE connection with a 400F. Likewise, the 400F has no 40GE QSFP+ or 100GE QSFP28 ports.
What are the Ultra Low Latency ports for?
Four of the 400F's 10GE SFP+ slots are defined as Ultra Low Latency (ULL). The difference is measurable in the data sheet: firewall latency for 64 byte UDP packets is 4.19 µs on standard ports, dropping to 2.5 µs on ULL ports. Total packet processing capacity is 105 Mpps. When latency-sensitive workloads — financial transaction flows, real-time production telemetry, storage or cluster traffic requiring low latency — are routed through these ports, the latency the firewall adds stays at the microsecond level. At the design stage we recommend allocating the ULL ports to the segments with the tightest latency budget rather than distributing them at random; the remaining traffic is carried over the standard 10GE SFP+ and GE ports.
What do NP7 and CP9 hardware acceleration deliver?
The FortiGate 400F uses Fortinet's NP7 network processor together with the CP9 content processor; it also includes a TPM module that generates and stores cryptographic keys in hardware. The NP7 provides "fastpath" acceleration that takes packet processing for established sessions off the FortiGate CPU and runs it on the ASIC; according to Fortinet documentation, the NP7 can also take over session setup, Carrier Grade NAT, hardware logging, HA hardware session synchronization and DoS protection from the CPU, depending on platform and license (Fortinet Document Library, 2026). Sizing must be based not on the general capability of the ASIC but on the appliance's own data sheet values: for the 400F, 7.8 million concurrent sessions and 79.5 Gbps firewall throughput. The CP9, for its part, provides more than 10 Gbps of pattern matching acceleration in flow-based inspection. The practical result of this pairing is visible in the data sheet: workloads that can be offloaded to the ASIC stay high — Application Control throughput of 28 Gbps, CAPWAP throughput of 65 Gbps, IPsec VPN of 55 Gbps — while full content inspection balances out at 9 Gbps. Compared with the 200F's NP6XLite + CP9 combination, this is precisely where the most pronounced leap occurs.
What is the difference between the FortiGate 400F, the 200F and the 600F?
To map the upgrade path correctly, the official data sheet values of the three models need to be placed side by side. Looking at a single "throughput" figure hides where the difference between these three appliances actually arises.
| Metric (official data sheet) | FortiGate 200F | FortiGate 400F | FortiGate 600F |
|---|
| IPv4 Firewall Throughput (1518/512/64 byte UDP) | 27 / 27 / 11 Gbps | 79.5 / 78.5 / 70 Gbps | 139 / 137.5 / 70 Gbps |
| IPS Throughput (Enterprise Mix) | 5 Gbps | 12 Gbps | 14 Gbps |
| NGFW Throughput | 3.5 Gbps | 10 Gbps | 11.5 Gbps |
| Threat Protection Throughput | 3 Gbps | 9 Gbps | 10.5 Gbps |
| SSL Inspection Throughput | 4 Gbps | 8 Gbps | 9 Gbps |
| IPsec VPN Throughput (512 byte) | 13 Gbps | 55 Gbps | 55 Gbps |
| Concurrent sessions (TCP) | 3 million | 7.8 million | 8 million |
| New sessions per second (TCP) | 280,000 | 500,000 | 550,000 |
| Firewall policies | 10,000 | 10,000 | 30,000 |
| VDOMs (default / maximum) | 10 / 10 | 10 / 25 | 10 / 50 |
| Fastest interface | 4x 10GE SFP+ | 8x 10GE SFP+ (4 of them ULL) | 4x 25GE SFP28 ULL + 4x 10GE SFP+ |
| ASIC | NP6XLite + CP9 | NP7 + CP9 | NP7 + CP9 |
The break in the table lies between the 200F and the 400F, not between the 400F and the 600F. Moving from the 200F to the 400F increases firewall throughput roughly 2.9x, Threat Protection 3x, SSL inspection 2x, IPsec VPN 4.2x and concurrent sessions 2.6x — and the ASIC generation moves from NP6XLite to NP7. Moving from the 400F to the 600F, by contrast, brings a relatively small increase in security inspection metrics (IPS 17%, Threat Protection 17%, SSL inspection 13%); the 600F's real difference is its raw firewall throughput (139 Gbps), its 25GE SFP28 interfaces, a policy base three times larger (30,000) and a VDOM ceiling twice as high. The decision therefore simplifies as follows: you move from the 200F to the 400F for security inspection capacity; you move from the 400F to the 600F for backbone speed, port type, policy count and tenant count. You can find all the models and their positioning compared side by side on our FortiGate product page.
How many VDOMs, and what power and rack planning, are required?
The virtual domain capacity of the 400F is 10 by default, 25 at maximum. This is a genuine expansion over the 200F's 10/10 ceiling: for holding companies and campus structures that segment by subsidiary or tenant beyond basic divisions such as production, test, OT, DMZ and guest network, 25 VDOMs are sufficient in most scenarios. On the physical planning side, the 400F comes in a 1 RU rack mount form factor (44.45 x 432 x 380 mm, 6.4 kg), consumes 154.8 W on average and 189.2 W at maximum, and generates 48 dBA of noise. The power supplies come as hot-swappable dual AC PSUs providing 1+1 redundancy; there is also a DC variant for environments requiring a 48–60 VDC supply. This is an important operational difference compared with the 200F's non-hot-swappable internal dual power supplies: a PSU failure can be addressed without opening a maintenance window. Onboard storage is not present on the standard 400F; for organizations needing local logging and archiving, the FG-401F variant ships with 2 480 GB SSDs.
High availability and version planning: According to the data sheet, the 400F supports Active-Active, Active-Passive and clustering configurations. Two points specific to the 400F stand out when building an HA pair. First, you should not spend Ultra Low Latency ports on heartbeat and session synchronization; the value of those four ports lies in latency-sensitive production traffic, and the HA link should be built over standard 10GE SFP+ or GE ports. Second, because the 400F's power supplies are hot-swappable, PSU maintenance does not require removing the appliance from HA — on the 200F, the same operation requires a planned maintenance window. Fortinet publishes no metric for failover time; since takeover duration depends on the heartbeat interval, the scope of synchronized sessions and the convergence behaviour of neighbouring switches, it must be measured and recorded during commissioning. On the version side, capacity-to-version dependencies such as 96 FortiSwitch support requiring FortiOS 7.6.1+ must be evaluated together with the targeted access layer scale.
Turkey context and compliance: The 400F's 25 VDOM capacity produces a concrete payoff on the compliance side. The access restriction expectation of KVKK (Turkey's data protection law), the need to narrow PCI-DSS scope for segments carrying card data and the segment-level traceability required in BDDK (Turkey's banking regulator) audits can all be met on a single appliance by defining a separate VDOM per unit or subsidiary; each VDOM forms a distinct audit boundary with its own policy base and administrator role. Since the standard 400F has no onboard storage — local retention is possible only with the FG-401F's 2x 480 GB SSDs — forwarding the log stream to a central collector is mandatory; in our deployments we define a separate log stream and report template per VDOM so that each unit's audit output is kept distinct. As a Fortinet authorized channel partner, Sora Yazılım provides licensing, deployment, migration from an existing NGFW, HA clustering, SD-WAN orchestration and managed services for the FortiGate 400F.
If you share your campus topology, your backbone port type (10GE or 25GE), the security profiles you plan to enable and your VDOM requirements, we will compare the 400F's data sheet capacity against your real load and produce a sizing note; if the result points to a lower model (200F) or a higher one (600F), we will say so plainly. Get in touch through our contact page for scoping, a deployment plan and a quote.