Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 40F

Fanless desktop NGFW delivering 5 Gbps IPv4 firewall for micro offices of 5–10 users.

Quick answer

The FortiGate 40F is Fortinet's micro-office-class desktop NGFW: with 5 GE RJ45 ports, 5 Gbps IPv4 firewall throughput and 600 Mbps Threat Protection capacity, it is built for micro offices, home offices and micro branches of 5–10 users. It runs on the SoC4 ASIC, is fanless and draws 7.74 W on average; the 40F-3G4G variant includes an embedded LTE modem.

FortiGate 40F is FortiGate's micro-office-class desktop model, designed for single-location deployments of 5–10 users. According to the official data sheet it delivers 5 Gbps IPv4 Firewall throughput with 1518-byte UDP packets, 1 Gbps IPS throughput and 600 Mbps Threat Protection throughput; thanks to fanless passive cooling it runs at 0 dBA and consumes only 7.74 W on average (FortiGate 40F Series Data Sheet, 2026).

What size of organization is the FortiGate 40F suited to?

With 700,000 concurrent TCP sessions and 35,000 new sessions per second, the FortiGate 40F is the right size for single-location businesses of 5–10 users, home offices and single-box micro branches. The unit carries 1 GE RJ45 WAN/DMZ port, 3 GE RJ45 internal ports and 1 GE RJ45 FortiLink port — 5 Gigabit Ethernet ports in total. A FortiSwitch can be attached to the access layer through the FortiLink port so that the small office's wired network is governed by the same policy engine; the data sheet specifies management of up to 8 FortiSwitch and 16 FortiAP units (8 of them in tunnel mode) on this model.

Enterprise-grade quality at micro scale: the FortiGate 40F delivers, at micro scale, the enterprise NGFW capabilities that consumer-grade routers cannot offer. FortiGuard threat intelligence, application control, web filtering, antivirus and IPS can all be enabled on the same unit, and all of them are managed from a single interface under FortiOS, one common operating system. There is one boundary worth knowing at this scale: the footnote to the subscription table in the data sheet states that Content Disarm and Reconstruct, Video Filtering and Inline CASB services are not available on the 40F series in FortiOS 7.4.4 and later (FortiGate 40F Series Data Sheet, 2026). If you have a compliance requirement that depends on one of those three services, it is better to select higher-tier hardware from the start; the 70G does not appear in the restricted model list in that footnote. For small businesses processing personal data, the access-record and log-retention obligations under KVKK (Turkey's data protection law) are met by forwarding the device's logs to FortiAnalyzer or FortiGate Cloud.

What the fanless, silent design means in practice: the 40F contains no moving parts such as fans or disks. The data sheet lists the noise level as 0 dBA; in environments where quiet matters — a home office, a small medical practice, a boutique store, a meeting room — the unit can be placed in the open. Power consumption is 7.74 W on average and 9.46 W maximum; on the 40F-3G4G variant these figures rise to 15.8 W and 18.6 W because of the modem. The unit measures 38.5 x 216 x 160 mm, weighs 1 kg, and can sit on a desk or be wall-mounted. Fortinet states that this form factor, having no moving parts, increases mean time between failures (MTBF); the data sheet does not publish a numeric MTBF figure, so this advantage should be assessed qualitatively.

How does the 40F-3G4G model differ from the standard FortiGate 40F?

Contrary to a widespread misconception, the 40F-3G4G does not work with an external dongle plugged into USB. According to the data sheet, this variant carries an embedded 3G/4G/LTE WWAN module, 2 nano SIM slots and 3 external SMA antenna ports; the standard 40F has none of these components (on both models the number of wireless interfaces and PoE ports is zero). The two SIM slots make it possible to hold lines from different carriers in the same device and switch to the second when one runs into coverage problems. This design suits temporary points of sale, field operations, self-service kiosks and temporary sites established after a disaster — places where there is no wired WAN or where cellular connectivity is wanted only as a backup. Deployment amounts to inserting a SIM and defining WAN prioritization; no separate 4G router and no second management interface are needed.

When is it time to move up to a FortiGate 60F or 70G?

The upgrade decision depends far less on user count than on which security profiles will be switched on. The 40F's SSL Inspection throughput is 310 Mbps; if all encrypted traffic is to be inspected, that figure sets the practical ceiling. In the same way, the 2,000 firewall policy limit and 700,000 concurrent sessions can fill up early in multi-VLAN scenarios or where guest networking is heavy. The table below places the official data sheet figures for the three entry-level models side by side:

Metric (official data sheet)FortiGate 40FFortiGate 60FFortiGate 70G
IPv4 Firewall Throughput (1518 byte UDP)5 Gbps10 Gbps10 Gbps
IPv4 Firewall Throughput (64 byte UDP)5 Gbps6 Gbps10 Gbps
IPS Throughput1 Gbps1.4 Gbps2.5 Gbps
NGFW Throughput800 Mbps1 Gbps1.5 Gbps
Threat Protection Throughput600 Mbps700 Mbps1.3 Gbps
SSL Inspection Throughput310 Mbps630 Mbps1.4 Gbps
IPsec VPN Throughput (512 byte)4.4 Gbps6.5 Gbps7.1 Gbps
Concurrent sessions (TCP)700,000700,0001.4 million
New sessions per second (TCP)35,00035,000100,000
Firewall policies2,0002,0005,000
GE RJ45 port count51010

Here is what the table shows: if what you need is port count and large-packet firewall capacity, the FortiGate 60F is enough; the real jump is in inspected traffic, namely SSL Inspection (310 Mbps → 1.4 Gbps) and Threat Protection (600 Mbps → 1.3 Gbps), and it is the FortiGate 70G that delivers that jump. You will find the positioning of every FortiGate hardware and virtual model on our FortiGate product page, and the entire Fortinet portfolio compared side by side on our Fortinet solutions page.

How are ZTNA and central management set up on the FortiGate 40F?

Remote access with ZTNA: the 40F carries the ZTNA Application Gateway capability of FortiOS without requiring any additional licence. At micro-office scale the practical meaning is this: for the handful of people connecting from outside you do not need to build a separate VPN concentrator or an extra identity infrastructure; the access decision is made in the 40F's own policy engine. The user reaches only the application they are authorized for rather than the whole network, and that decision is recalculated for every session. An employee connecting from home to the accounting application never seeing the POS or camera segment on the same network is a direct result of this model. One important release note: SSL-VPN is not supported on the 40F series in FortiOS 7.6.0 and above, so new deployments should be planned on IPsec VPN or ZTNA.

Central management and scaling: the device supports 10 VDOMs by default and at maximum, which is more than enough in a small business to split management, guest and operational traffic into mutually isolated virtual firewalls. In multi-site deployments, zero-touch provisioning is handled with FortiZTP: when the unit is taken out of the box and connected to the internet it is recognized by its serial number, and the pre-prepared template configuration is loaded automatically by FortiManager or FortiGate Cloud. Dozens of micro sites can therefore be brought up with the same standard policy set without sending an engineer on site. On the logging side the device forwards traffic and threat records to FortiAnalyzer or FortiGate Cloud; audit reports are produced in that layer.

We can work out together whether you need a FortiGate 40F or a higher model, how many users' encrypted traffic will be inspected, and whether the 3G4G variant is useful for your business. As a Fortinet authorized channel partner we take on licensing, deployment and migration from your existing device; write to us through our contact page for a configuration and quotation sized to your needs.

  • 5 Gbps IPv4 Firewall throughput (1518 byte UDP)
  • 600 Mbps Threat Protection, 310 Mbps SSL Inspection
  • 5x GE RJ45 ports, SoC4 ASIC
  • Fanless, 0 dBA — 7.74 W on average
  • 40F-3G4G: embedded LTE modem + 2x nano SIM
Key features

What this model offers

  • 5 / 5 / 5 Gbps IPv4 Firewall throughput (1518 / 512 / 64 byte UDP)
  • 600 Mbps Threat Protection and 800 Mbps NGFW throughput
  • 1 Gbps IPS throughput (Enterprise Mix, logging enabled)
  • 310 Mbps SSL Inspection throughput, 55,000 concurrent SSL sessions
  • 4.4 Gbps IPsec VPN throughput (AES256-SHA256, 512 byte)
  • 5x GE RJ45 ports: 1 WAN/DMZ + 3 internal + 1 FortiLink
  • Hardware-accelerated firewall and VPN through the SoC4 ASIC
  • Built-in SD-WAN and network controller included at no extra cost, in the data sheet's own wording
  • Embedded 3G/4G/LTE modem, 2x nano SIM and 3x SMA antenna ports on the 40F-3G4G
  • Fanless passive cooling, 0 dBA noise level
  • Management of 8 FortiSwitch and 16 FortiAP units (8 in tunnel mode) over FortiLink
  • Isolated virtual firewall separation with 10 VDOMs
  • FortiGuard AI-powered security subscriptions (IPS, antivirus, web filtering, application control)
  • FortiAnalyzer / FortiGate Cloud log forwarding and zero-touch deployment with FortiZTP
Tech Summary

Technical data

IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)
5 / 5 / 5 Gbps
Firewall Throughput (packets per second)
7.5 Mpps
Firewall Latency (64 byte UDP)
2.97 µs
IPS Throughput
1 Gbps
NGFW Throughput
800 Mbps
Threat Protection Throughput
600 Mbps
SSL Inspection Throughput (IPS, avg. HTTPS)
310 Mbps
SSL Inspection CPS / concurrent sessions
320 / 55,000
IPsec VPN Throughput (512 byte, AES256-SHA256)
4.4 Gbps
Application Control Throughput (HTTP 64K)
990 Mbps
Concurrent Sessions (TCP)
700,000
New Sessions/Second (TCP)
35,000
Firewall Policies
2,000
Interface layout
1x GE RJ45 WAN/DMZ, 3x GE RJ45 internal, 1x GE RJ45 FortiLink, 1x USB, 1x console
Virtual Domains (default / maximum)
10 / 10
Form factor
Desktop, fanless — 38.5 x 216 x 160 mm, 1 kg, 0 dBA
Power consumption (average / maximum)
7.74 W / 9.46 W (40F-3G4G: 15.8 W / 18.6 W)
Use Cases

At what scale is this model preferred?

Micro office

Single-location team of 8 people

A single FortiGate 40F becomes the one point handling internet egress, the site-to-site IPsec tunnel to the cloud environment hosting accounting and the file server, and ZTNA access for the few users connecting from home. The 700,000 session and 2,000 policy limits work comfortably at this scale; the critical threshold is how much of the encrypted traffic will be inspected (310 Mbps SSL Inspection).

Home office

Executive home office segregation

In the home of a hybrid-working executive, the 40F keeps corporate traffic on a separate VLAN from household traffic and connects it to headquarters over an encrypted tunnel. The fanless 0 dBA design allows the unit to be placed in the study.

Retail

Cellular-connected micro point of sale

In a small store or temporary stand where no wired line can be installed, the 40F-3G4G provides primary or backup WAN through its embedded LTE modem and two nano SIMs; POS traffic is kept on a separate segment and sent to headquarters encrypted.

Healthcare

Family doctor and small medical practice

Access to appointment and prescription systems, encryption of traffic carrying patient data and web filtering on the internet egress are all provided by a single device. Logs are forwarded to FortiAnalyzer, satisfying the record-keeping obligation under KVKK (Turkey's data protection law).

Education

Nursery school or small training centre

Student, teacher and guest networks are divided into separate VLANs, and web filtering blocks inappropriate content. When a FortiSwitch is added over the FortiLink port, the access layer is brought under the same policy as well.

Who is it for?

Micro offices, home offices and single-box micro branches and stores of 5–10 users, small medical practices, nursery schools and training centres, and cellular-connected field sites with no wired WAN.

Frequently Asked Questions

Common questions about this model

How many users does the FortiGate 40F support?
Fortinet does not publish user counts; scale is inferred from capacity figures. 700,000 concurrent TCP sessions, 35,000 new sessions per second and a 2,000 firewall policy limit typically correspond to a single-location office of 5–10 users. The determining limit is usually the 310 Mbps SSL Inspection throughput: if all encrypted traffic is to be inspected, that figure forms the practical ceiling. For higher inspection capacity, the 60F or 70G should be considered.
What is the FortiGate 40F's real threat prevention capacity?
The official data sheet lists three separate metrics, and they are frequently confused: IPS throughput 1 Gbps, NGFW throughput 800 Mbps (firewall + IPS + application control) and Threat Protection throughput 600 Mbps (with malware protection enabled on top of those). With a full protection profile including antivirus, the figure to expect is 600 Mbps; the 800 Mbps number is the NGFW value, not Threat Protection.
What is the difference between the 40F-3G4G and the standard 40F?
The 40F has wired WAN only. The 40F-3G4G, on the other hand, includes an embedded 3G/4G/LTE WWAN module, 2 nano SIM slots and 3 external SMA antenna ports; no external USB dongle is needed for cellular connectivity. Power consumption also differs: 7.74 W on average on the standard model, 15.8 W on the 3G4G model.
Is there a PoE or Wi-Fi version of the FortiGate 40F?
No. The official data sheet lists 0 PoE/+ ports and 0 wireless interfaces for both the 40F and the 40F-3G4G; the ordering list likewise contains only the FG-40F, FG-40F-HA, FG-40F-3G4G and FG-40F-3G4G-HA SKUs. Where PoE is required, a FortiSwitch is added to the FortiLink port; if an integrated wireless access point is wanted, a wireless-capable model such as the FortiWiFi 70G or a separate FortiAP is the choice.
How many FortiAP and FortiSwitch units can the FortiGate 40F manage?
According to the data sheet, up to 16 FortiAP units (8 of them in tunnel mode) and 8 FortiSwitch units are supported. That is enough for a small single-floor office. If a broader access layer is required, the 60F (64 FortiAP / 24 FortiSwitch) or the 70G (96 FortiAP / 24 FortiSwitch) should be considered.
Can I use SSL-VPN on the FortiGate 40F?
You will see 490 Mbps SSL-VPN throughput for the 40F in the spec table, but footnote 6 attached to that row invalidates the figure: SSL-VPN is not supported in FortiOS 7.6.0 and above. In practice this means that on a new 40F installed with a current release, remote users will connect over an IPsec client or ZTNA. For micro offices still running SSL-VPN on 7.4, our recommendation is to move client profiles to IPsec without waiting for the upgrade and to make the transition in one go.
Does the 40F lose performance because it is fanless?
No. All published figures were measured on fanless hardware to begin with; passive cooling is a design choice, not a constraint. The device has no moving parts such as fans or disks and its noise level is 0 dBA. Fortinet states that this form factor improves mean time between failures; however, since no numeric MTBF figure is published in the data sheet, that advantage should be assessed qualitatively.
How many virtual firewalls (VDOMs) can be defined?
The FortiGate 40F supports 10 VDOMs by default and at maximum. In a small business that number is enough to isolate management, guest, operational and POS traffic from one another. In scenarios requiring more isolation domains, higher models should be considered.
Can we deploy the FortiGate 40F without sending an engineer on site?
Yes. Zero-touch provisioning is supported on the 40F as well: when the device reaches the internet on site it registers with the cloud management layer via its serial number and pulls down the template configuration prepared for it. At micro sites the practical meaning is that you ship the box and only the cable needs to be plugged in locally. Because it is critical that the template (policy set, IPsec tunnel definitions, ZTNA rules) is built correctly up front, we prepare the first template together with a certified engineer.
How do the licensing and support models work?
The hardware cost is one-off; the recurring part is the FortiCare support contract and the FortiGuard AI-powered security services. When the subscription lapses, the 40F carries on performing firewall, NAT and VPN duties, but IPS, antivirus and web filtering signatures are no longer updated — this is the most common gap we encounter in micro-office deployments. Because desktop models can start at the FortiCare Essentials tier, the package choice on the 40F can be flexed to budget; we can work out the right setup and quotation for your organization through our contact page.

FortiGate 40F — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support