The FortiGate 600F is a 1U next-generation firewall used by organizations that need to inspect heavy traffic at campus scale. According to the official data sheet it delivers 139 Gbps IPv4 Firewall Throughput, 14 Gbps IPS and 10.5 Gbps Threat Protection with 1518-byte UDP packets; with 8 million concurrent TCP sessions and four 25GE SFP28 Ultra Low Latency slots it carries a large campus core (FortiGate 600F Series Data Sheet, 2026).
Who is the FortiGate 600F the right device for?
The flagship of the mid-range segment: while the FortiGate 200F is ideal for a head office, the 600F is designed for higher-density environments — large universities, multi-company holding groups, government agency headquarters. With 139 Gbps IPv4 firewall throughput it takes on the data center entry (north-south) layer, and at the same time it hosts up to 50 isolated virtual firewalls through multi-VDOM for microsegmentation inside the campus. The device operates in a 1 RU rack form factor and draws 169 W on average and 255 W at maximum, which translates into a high inspection capacity within a single rack unit.
What are the fastest interfaces on the FortiGate 600F?
25GE SFP28 Ultra Low Latency slots and data center integration: the 600F does not have a 40GE QSFP+ port. The fastest interfaces on the device are its four 25GE SFP28 / 10GE SFP+ Ultra Low Latency slots, accompanied by four 10GE SFP+/GE SFP, eight GE SFP, sixteen GE RJ45 and two GE RJ45 MGMT/HA ports. Uplink to the core is typically achieved by bundling these four SFP28 slots into a single logical link with LACP. For the ULL slots the data sheet quotes a firewall latency of 2.5 microseconds with 64-byte UDP packets; the equivalent figure on the device's standard ports is 4.12 microseconds. On the inspection side, SSL Inspection Throughput is 9 Gbps and IPS Throughput is 14 Gbps, while the Threat Protection Throughput measured with firewall, IPS, application control and malware protection running together is published as 10.5 Gbps.
What do NP7 and CP9 hardware acceleration deliver on the 600F?
Why is 105 Mpps packet processing possible? In the FG-600F ordering information the device is described as "SPU NP7 and CP9 hardware accelerated", and there is a clear division of labor between the two processors. The data sheet associates the NP7 network processor with hyperscale firewall, accelerated session setup, ultra low latency, VXLAN termination, hardware logging and elephant flow handling; the 600F's published figures of 139 Gbps firewall and 8 million sessions stay within the ceiling of 200 Gbps and 12 million sessions that Fortinet documentation gives for a single NP7 (Fortinet Document Library, 2026). The CP9 content processor, in turn, takes over SSL decryption including TLS 1.3, IPS pre-scanning and signature correlation, and antivirus processing; it provides more than 10 Gbps of pattern matching acceleration in flow-based inspection (Fortinet Document Library, 2026). On the packet processing side, the published figures of 105 Mpps and 550,000 new sessions per second are also the result of this division of labor. In addition, the chassis contains a Trusted Platform Module (TPM) that generates and stores keys in hardware, plus a Bluetooth Low Energy (BLE) module; a Signed Firmware Hardware Switch is not listed for this model.
| Metric (official data sheet) | FortiGate 400F | FortiGate 600F | FortiGate 900G |
|---|
| IPv4 Firewall Throughput (1518-byte UDP) | 79.5 Gbps | 139 Gbps | 164 Gbps |
| IPS Throughput (Enterprise Mix) | 12 Gbps | 14 Gbps | 42 Gbps |
| NGFW Throughput | 10 Gbps | 11.5 Gbps | 31 Gbps |
| Threat Protection Throughput | 9 Gbps | 10.5 Gbps | 30 Gbps |
| SSL Inspection Throughput | 8 Gbps | 9 Gbps | 16.7 Gbps |
| Concurrent sessions (TCP) | 7.8 million | 8 million | 28 million |
| New sessions per second (TCP) | 500,000 | 550,000 | 720,000 |
| Fastest interface | 4x 10GE SFP+ ULL | 4x 25GE SFP28 ULL | 4x 25GE SFP28 ULL |
| Firewall policies | 10,000 | 30,000 | 50,000 |
| Form factor / average power | 1 RU / 154.8 W | 1 RU / 169 W | 1 RU / 170 W |
Multi-tenant operation with multi-VDOM: the 600F supports 10 VDOMs by default and 50 VDOMs at maximum. At a holding group's head office each company's traffic can be isolated in its own VDOM; a single 600F HA pair is enough for a group of 30 companies. Every VDOM carries an independent routing table, policy set and administrative scope, so a faulty rule change made in one VDOM does not affect the traffic of another. In total the device allows 30,000 firewall policies, 2,000 gateway-to-gateway and 50,000 client-to-gateway IPsec tunnels to be defined; on the wireless and wired access side, management of up to 1,024 FortiAPs (512 of them in tunnel mode) and, with FortiOS 7.6.1+, up to 128 FortiSwitches is handled from the same chassis, while on releases earlier than FortiOS 7.6.1 that ceiling stays at 96 switches.
When does the 600F fall short?
The upgrade decision is made by looking not at raw firewall throughput but at the inspected traffic ceiling. The 600F's Threat Protection figure is 10.5 Gbps and its SSL inspection figure is 9 Gbps; if your goal is to inspect all encrypted traffic and you are approaching that ceiling, the FortiGate 900G comes into play. In the same 1 RU chassis the 900G offers 30 Gbps Threat Protection, 42 Gbps IPS, 16.7 Gbps SSL inspection and 28 million concurrent sessions. For a smaller head office the FortiGate 400F may be sufficient; if 100GE interfaces or 250 VDOMs are required, you move up to the 1000F class. You can find the whole family and the selection criteria side by side on our FortiGate product page.
HA cluster and continuity: in production environments the 600F is almost always positioned as a two-device cluster. The data sheet lists the supported high availability modes as active-active, active-passive and clustering; the field standard is FGCP (active-passive), and FGSP in critical environments that require session synchronization. The two GE RJ45 ports that can be used as MGMT/HA are dedicated to heartbeat traffic. The device ships with two 80Plus certified, hot-swappable power supplies, so a single PSU failure does not turn into a service outage. The only supply option on the 600F is 100-240V AC; in colocation environments where DC power is required this distinction must be taken into account from the outset. This design is critical for environments where downtime is costly, such as bank branches, hospital information systems and production line SCADA networks.
Integrated operation with FortiManager and FortiAnalyzer: for organizations in the 600F class, the combination of FortiManager (policy management) + FortiAnalyzer (log analysis) + FortiSIEM (SOC) is the standard trio. FortiManager handles policy management for multi-branch, distributed organizations from a central point; FortiAnalyzer produces reports for KVKK (Turkey's data protection law) and PCI-DSS audits through long-term log retention; FortiSIEM escalates critical events to SOC operators. In release planning, Fortinet's CSB-260330-1 bulletin dated March 2026 is decisive: on the 7.4 branch engineering support ends on 11 May 2027 and full support on 11 November 2028, while on the 7.6 branch these two dates are 25 July 2028 and 25 January 2030 (Fortinet Community, CSB-260330-1, 2026). For new deployments the 7.6 branch is preferred because of its longer support window.
As a Fortinet authorized channel partner, we handle sizing, HA design, VDOM planning, 25GE core integration and configuration migration from your existing device for the FortiGate 600F. Let us review your current traffic profile and inspection targets together and clarify which of the 400F, 600F and 900G is the right fit; you can reach us through our contact page for a hardware and subscription quote.