FortiGate 40F is FortiGate's micro-office-class desktop model, designed for single-location deployments of 5–10 users. According to the official data sheet it delivers 5 Gbps IPv4 Firewall throughput with 1518-byte UDP packets, 1 Gbps IPS throughput and 600 Mbps Threat Protection throughput; thanks to fanless passive cooling it runs at 0 dBA and consumes only 7.74 W on average (FortiGate 40F Series Data Sheet, 2026).
What size of organization is the FortiGate 40F suited to?
With 700,000 concurrent TCP sessions and 35,000 new sessions per second, the FortiGate 40F is the right size for single-location businesses of 5–10 users, home offices and single-box micro branches. The unit carries 1 GE RJ45 WAN/DMZ port, 3 GE RJ45 internal ports and 1 GE RJ45 FortiLink port — 5 Gigabit Ethernet ports in total. A FortiSwitch can be attached to the access layer through the FortiLink port so that the small office's wired network is governed by the same policy engine; the data sheet specifies management of up to 8 FortiSwitch and 16 FortiAP units (8 of them in tunnel mode) on this model.
Enterprise-grade quality at micro scale: the FortiGate 40F delivers, at micro scale, the enterprise NGFW capabilities that consumer-grade routers cannot offer. FortiGuard threat intelligence, application control, web filtering, antivirus and IPS can all be enabled on the same unit, and all of them are managed from a single interface under FortiOS, one common operating system. There is one boundary worth knowing at this scale: the footnote to the subscription table in the data sheet states that Content Disarm and Reconstruct, Video Filtering and Inline CASB services are not available on the 40F series in FortiOS 7.4.4 and later (FortiGate 40F Series Data Sheet, 2026). If you have a compliance requirement that depends on one of those three services, it is better to select higher-tier hardware from the start; the 70G does not appear in the restricted model list in that footnote. For small businesses processing personal data, the access-record and log-retention obligations under KVKK (Turkey's data protection law) are met by forwarding the device's logs to FortiAnalyzer or FortiGate Cloud.
What the fanless, silent design means in practice: the 40F contains no moving parts such as fans or disks. The data sheet lists the noise level as 0 dBA; in environments where quiet matters — a home office, a small medical practice, a boutique store, a meeting room — the unit can be placed in the open. Power consumption is 7.74 W on average and 9.46 W maximum; on the 40F-3G4G variant these figures rise to 15.8 W and 18.6 W because of the modem. The unit measures 38.5 x 216 x 160 mm, weighs 1 kg, and can sit on a desk or be wall-mounted. Fortinet states that this form factor, having no moving parts, increases mean time between failures (MTBF); the data sheet does not publish a numeric MTBF figure, so this advantage should be assessed qualitatively.
How does the 40F-3G4G model differ from the standard FortiGate 40F?
Contrary to a widespread misconception, the 40F-3G4G does not work with an external dongle plugged into USB. According to the data sheet, this variant carries an embedded 3G/4G/LTE WWAN module, 2 nano SIM slots and 3 external SMA antenna ports; the standard 40F has none of these components (on both models the number of wireless interfaces and PoE ports is zero). The two SIM slots make it possible to hold lines from different carriers in the same device and switch to the second when one runs into coverage problems. This design suits temporary points of sale, field operations, self-service kiosks and temporary sites established after a disaster — places where there is no wired WAN or where cellular connectivity is wanted only as a backup. Deployment amounts to inserting a SIM and defining WAN prioritization; no separate 4G router and no second management interface are needed.
When is it time to move up to a FortiGate 60F or 70G?
The upgrade decision depends far less on user count than on which security profiles will be switched on. The 40F's SSL Inspection throughput is 310 Mbps; if all encrypted traffic is to be inspected, that figure sets the practical ceiling. In the same way, the 2,000 firewall policy limit and 700,000 concurrent sessions can fill up early in multi-VLAN scenarios or where guest networking is heavy. The table below places the official data sheet figures for the three entry-level models side by side:
| Metric (official data sheet) | FortiGate 40F | FortiGate 60F | FortiGate 70G |
|---|
| IPv4 Firewall Throughput (1518 byte UDP) | 5 Gbps | 10 Gbps | 10 Gbps |
| IPv4 Firewall Throughput (64 byte UDP) | 5 Gbps | 6 Gbps | 10 Gbps |
| IPS Throughput | 1 Gbps | 1.4 Gbps | 2.5 Gbps |
| NGFW Throughput | 800 Mbps | 1 Gbps | 1.5 Gbps |
| Threat Protection Throughput | 600 Mbps | 700 Mbps | 1.3 Gbps |
| SSL Inspection Throughput | 310 Mbps | 630 Mbps | 1.4 Gbps |
| IPsec VPN Throughput (512 byte) | 4.4 Gbps | 6.5 Gbps | 7.1 Gbps |
| Concurrent sessions (TCP) | 700,000 | 700,000 | 1.4 million |
| New sessions per second (TCP) | 35,000 | 35,000 | 100,000 |
| Firewall policies | 2,000 | 2,000 | 5,000 |
| GE RJ45 port count | 5 | 10 | 10 |
Here is what the table shows: if what you need is port count and large-packet firewall capacity, the FortiGate 60F is enough; the real jump is in inspected traffic, namely SSL Inspection (310 Mbps → 1.4 Gbps) and Threat Protection (600 Mbps → 1.3 Gbps), and it is the FortiGate 70G that delivers that jump. You will find the positioning of every FortiGate hardware and virtual model on our FortiGate product page, and the entire Fortinet portfolio compared side by side on our Fortinet solutions page.
How are ZTNA and central management set up on the FortiGate 40F?
Remote access with ZTNA: the 40F carries the ZTNA Application Gateway capability of FortiOS without requiring any additional licence. At micro-office scale the practical meaning is this: for the handful of people connecting from outside you do not need to build a separate VPN concentrator or an extra identity infrastructure; the access decision is made in the 40F's own policy engine. The user reaches only the application they are authorized for rather than the whole network, and that decision is recalculated for every session. An employee connecting from home to the accounting application never seeing the POS or camera segment on the same network is a direct result of this model. One important release note: SSL-VPN is not supported on the 40F series in FortiOS 7.6.0 and above, so new deployments should be planned on IPsec VPN or ZTNA.
Central management and scaling: the device supports 10 VDOMs by default and at maximum, which is more than enough in a small business to split management, guest and operational traffic into mutually isolated virtual firewalls. In multi-site deployments, zero-touch provisioning is handled with FortiZTP: when the unit is taken out of the box and connected to the internet it is recognized by its serial number, and the pre-prepared template configuration is loaded automatically by FortiManager or FortiGate Cloud. Dozens of micro sites can therefore be brought up with the same standard policy set without sending an engineer on site. On the logging side the device forwards traffic and threat records to FortiAnalyzer or FortiGate Cloud; audit reports are produced in that layer.
We can work out together whether you need a FortiGate 40F or a higher model, how many users' encrypted traffic will be inspected, and whether the 3G4G variant is useful for your business. As a Fortinet authorized channel partner we take on licensing, deployment and migration from your existing device; write to us through our contact page for a configuration and quotation sized to your needs.
Tech SummaryTechnical data
- IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)
- 5 / 5 / 5 Gbps
- Firewall Throughput (packets per second)
- 7.5 Mpps
- Firewall Latency (64 byte UDP)
- 2.97 µs
- IPS Throughput
- 1 Gbps
- NGFW Throughput
- 800 Mbps
- Threat Protection Throughput
- 600 Mbps
- SSL Inspection Throughput (IPS, avg. HTTPS)
- 310 Mbps
- SSL Inspection CPS / concurrent sessions
- 320 / 55,000
- IPsec VPN Throughput (512 byte, AES256-SHA256)
- 4.4 Gbps
- Application Control Throughput (HTTP 64K)
- 990 Mbps
- Concurrent Sessions (TCP)
- 700,000
- New Sessions/Second (TCP)
- 35,000
- Firewall Policies
- 2,000
- Interface layout
- 1x GE RJ45 WAN/DMZ, 3x GE RJ45 internal, 1x GE RJ45 FortiLink, 1x USB, 1x console
- Virtual Domains (default / maximum)
- 10 / 10
- Form factor
- Desktop, fanless — 38.5 x 216 x 160 mm, 1 kg, 0 dBA
- Power consumption (average / maximum)
- 7.74 W / 9.46 W (40F-3G4G: 15.8 W / 18.6 W)