Tier-1 mobile operator IP backbone
Inspecting subscriber traffic at the backbone layer with 5.4 million new sessions per second and 600 million concurrent sessions; direct connection to core routers over 400GE QSFP-DD uplinks.
12U 8-slot modular chassis: 1.89 Tbps IPv4 firewall and 600 million concurrent sessions with six FPMs.
The FortiGate 7081F is Fortinet's 12U, 8-slot modular NGFW chassis. With six FPM-7620F processing modules installed it produces 1.89 Tbps of IPv4 firewall, 405 Gbps IPS, 330 Gbps NGFW and 312 Gbps Threat Protection throughput, and carries 600 million concurrent sessions. It is built for Tier-1 carrier backbones and mega data centers.
The FortiGate 7081F is Fortinet's chassis-class NGFW platform: a 12U-high, 8-slot modular body. In a configuration with six FPM-7620F processing modules installed, it produces 1.89 Tbps of IPv4 firewall throughput with 1518 byte UDP packets, along with 405 Gbps IPS, 330 Gbps NGFW and 312 Gbps Threat Protection throughput; it carries 600 million concurrent TCP sessions and 5.4 million new sessions per second. It is designed for carrier and mega data center workloads that simply will not fit into a single box.
All of these values come from Fortinet's official FortiGate 7000F Series data sheet, and that data sheet carries an important footnote: the performance figures published for the FG-7081F are based on a six-FPM combination (Fortinet, 2026). In other words, 1.89 Tbps is not a "single box" number but the combined capacity of six processing modules, and that distinction is decisive for ordering and capacity planning. An official source also quantifies why defenses at this scale must be continuously fed: according to FortiGuard Labs' 2026 Global Threat Landscape Report, the number of confirmed ransomware victims reached 7,831 in 2025 and global exploitation attempts rose 25.49% year over year (Fortinet, 2026).
The 7081F is built for the IP backbones of Tier-1 mobile operators and large internet service providers, the data center cores of national-scale content and cloud providers, and mega data centers whose traffic cannot be squeezed into a single 4U appliance. The decision threshold is clear: if the ceilings of the largest single-body FortiGate — 75 Gbps of inspected traffic, 210 million sessions and 1 million new sessions per second — do not meet your demand, the chassis class becomes unavoidable. Below those thresholds, the FortiGate 4400F is both more economical and operationally far simpler; and if 589 Gbps of firewall throughput with 400GE uplinks is enough, the FortiGate 3700F is a 2 RU alternative. What you get in return on the chassis side is this: 40,000 gateway-to-gateway and 260,000 client-to-gateway IPsec tunnels, 200,000 firewall policies and up to 500 VDOMs, so a multi-tenant carrier architecture is carried on a single platform.
The platform uses two types of line card. The FIM (Fortinet Interface Module) is the input/output module and brings traffic into the chassis: with NP7 acceleration, the FIM-7921F and FIM-7941F each offer 2x 400GE QSFP-DD data ports (ports 19 and 20), 18x 100GE QSFP28 data ports (1–18), 2x 100GE QSFP28 and 2x 25GE SFP28 management/HA ports, 2x GE RJ45 management ports and 2x 4 TB of local log storage per module. The FPM (Fortinet Processor Module) is the processing module: the FPM-7620F is accelerated by the NP7 network processor and the CP9 content processor, and carries 2x 400GE QSFP-DD / 100GE QSFP28 slots plus 8x 25GE SFP28 / 10GE SFP+ slots per module. Both module types are hot-swappable. The base FG-7081F SKU ships with 1x FPM-7620F, 1x FIM-7921F, 2x system management modules and 6x 2500 W hot-swap redundant power supplies; the FG-7081F-2 variant comes with the FIM-7941F instead of the FIM-7921F. At chassis level, total interface capacity is 16x 400GE QSFP-DD / 100GE QSFP28 / 40GE QSFP+, 36x 100GE QSFP28 / 40GE QSFP+ data slots and 80x 25GE SFP28 / 10GE SFP+ slots; in addition there are 4x 100GE QSFP28 / 40GE QSFP+ and 4x 25GE SFP28 / 10GE SFP+ management/HA slots.
Fortinet separately publishes the figures a single FPM-7620F produces on its own. The most accurate way to see how chassis capacity is built up — and where it stands against a lower class — is to read these three columns side by side.
| Metric | Single FPM-7620F | FG-7081F (6x FPM) | FortiGate 4400F (comparison) |
|---|---|---|---|
| IPv4 Firewall Throughput (1518 byte UDP) | 396 Gbps | 1.89 Tbps | 1.15 Tbps |
| IPS Throughput (Enterprise Mix) | 67.5 Gbps | 405 Gbps | 94 Gbps |
| NGFW Throughput | 55 Gbps | 330 Gbps | 82 Gbps |
| Threat Protection Throughput | 52 Gbps | 312 Gbps | 75 Gbps |
| SSL Inspection Throughput | 54 Gbps | 324 Gbps | 86 Gbps |
| IPsec VPN Throughput (512 byte) | 63 Gbps | 378 Gbps | 310 Gbps |
| Concurrent sessions (TCP) | 100 million | 600 million | 210 million |
| New sessions per second (TCP) | 900,000 | 5.4 million | 1 million |
| Power consumption (average) | 675 W | 6100 W (chassis total) | 1533 W |
Three footnotes matter when reading this table. First, on the 7000F series the Threat Protection metric is measured with firewall, IPS, application control and malware protection including sandboxing enabled — on other FortiGate models, including the 4400F, sandboxing is not part of that footnote, so 312 Gbps and 75 Gbps are not the results of an identical test. Second, the 378 Gbps IPsec VPN figure given for the chassis was measured with VPN load balancing. Third, the 13.5 Gbps SSL-VPN throughput was measured on a single FPM. As a general Fortinet rule, all performance values are "up to" figures and vary with system configuration. On the capacity side, the chassis carries 288,000 SSL inspection CPS and 60 million concurrent SSL inspection sessions; HTTP 64K application control throughput is listed at 900 Gbps. CAPWAP throughput is N/A on this series and no supported FortiAP count is given — the 7081F is not positioned as a wireless controller but as a pure backbone platform; it does, however, support 300 FortiSwitch units and 12,000 FortiTokens.
The FortiGate 7081F cannot be planned like an ordinary rack appliance. The chassis measures 543.9 x 440 x 675.5 mm and weighs 165.68 kg; it draws 6100 W on average and 7300 W at maximum, and dissipates an average of 24,900 BTU/h (6160 W / 7370 W and 25,174 BTU/h on the FG-7081F-2 variant). The most frequently overlooked detail is supply voltage: the AC power supplies operate in the 200–277 VAC range with a maximum current of 6 x 16 A, and the DC option is -48 to -60 V DC. In other words, this is not an appliance you plug into a standard 100–240 V single-phase outlet. Cabinet power architecture, floor load-bearing capacity, hot/cold aisle placement and loading-dock access all have to be verified before you order. The operating temperature range is 0–40 °C and internal storage is 4x 4 TB SSD.
In Turkey, installations of this class are typically found in carrier and large financial data centers. Log retention under KVKK (Turkey's data protection law), the environment separation required by the BDDK (Turkish banking regulator) information systems regulation and PCI-DSS segmentation can all be solved on a single platform with 500 VDOMs and a 200,000-policy capacity; the 4x 4 TB of local disk on the chassis should be planned together with a central analytics layer for long-term log retention. On the high availability side, Active-Active (FGSP), Active-Passive and Clustering configurations are supported; on a critical backbone you should design a two-chassis cluster rather than a single chassis. As a Fortinet authorized channel partner, Sora Yazılım runs module configuration, licensing, migration and managed service processes on projects of this scale.
The decision to move to the chassis class is not made on a single throughput number; it is made together with the session profile, the SSL inspection ratio, the required number of FPMs and the physical site infrastructure. Share your current traffic measurements and we will report the difference between the 4400F and the FortiGate 7081F, along with the number of modules you need, using official data sheet values. You can compare all models on the FortiGate product family page, and reach us through our contact page for sizing and a quote.
Inspecting subscriber traffic at the backbone layer with 5.4 million new sessions per second and 600 million concurrent sessions; direct connection to core routers over 400GE QSFP-DD uplinks.
Inspecting transit traffic with 1.89 Tbps of firewall capacity and terminating enterprise customer VPNs across 260,000 client-to-gateway IPsec tunnels; capacity grows incrementally as FPMs are added.
Multi-tenant isolation with 500 VDOMs, a 200,000-policy rule base and visibility into encrypted application traffic with 324 Gbps of SSL inspection; uninterrupted service with a two-chassis cluster.
Designing the environment separation required by the BDDK (Turkish banking regulator) information systems regulation and PCI-DSS segmentation with a VDOM architecture; log management with 4x 4 TB local disk plus a central analytics layer.
Hosting multiple institutions on a single chassis in separate VDOMs; centralized operation with TPM-backed key protection, an Active-Passive cluster and a KVKK-compliant (Turkey's data protection law) log flow.
Tier-1 mobile operators and internet service providers, national-scale cloud and content providers, systemically important banks and public sector data center operators.
Fanless desktop NGFW delivering 5 Gbps IPv4 firewall for micro offices of 5–10 users.
Details10-port desktop NGFW delivering 10 Gbps IPv4 firewall for small offices and branches of 10–30 users.
DetailsThe SP5 ASIC-based branch NGFW that replaces the 60F: 10 Gbps symmetric firewall, 1.4 million sessions, PoE and FortiWiFi variants.
DetailsDesktop branch firewall with eight PoE/+ ports and a 96 W budget that also powers the access layer.
DetailsSora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.