Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 7081F

12U 8-slot modular chassis: 1.89 Tbps IPv4 firewall and 600 million concurrent sessions with six FPMs.

Quick answer

The FortiGate 7081F is Fortinet's 12U, 8-slot modular NGFW chassis. With six FPM-7620F processing modules installed it produces 1.89 Tbps of IPv4 firewall, 405 Gbps IPS, 330 Gbps NGFW and 312 Gbps Threat Protection throughput, and carries 600 million concurrent sessions. It is built for Tier-1 carrier backbones and mega data centers.

The FortiGate 7081F is Fortinet's chassis-class NGFW platform: a 12U-high, 8-slot modular body. In a configuration with six FPM-7620F processing modules installed, it produces 1.89 Tbps of IPv4 firewall throughput with 1518 byte UDP packets, along with 405 Gbps IPS, 330 Gbps NGFW and 312 Gbps Threat Protection throughput; it carries 600 million concurrent TCP sessions and 5.4 million new sessions per second. It is designed for carrier and mega data center workloads that simply will not fit into a single box.

All of these values come from Fortinet's official FortiGate 7000F Series data sheet, and that data sheet carries an important footnote: the performance figures published for the FG-7081F are based on a six-FPM combination (Fortinet, 2026). In other words, 1.89 Tbps is not a "single box" number but the combined capacity of six processing modules, and that distinction is decisive for ordering and capacity planning. An official source also quantifies why defenses at this scale must be continuously fed: according to FortiGuard Labs' 2026 Global Threat Landscape Report, the number of confirmed ransomware victims reached 7,831 in 2025 and global exploitation attempts rose 25.49% year over year (Fortinet, 2026).

What size of organization is the FortiGate 7081F right for?

The 7081F is built for the IP backbones of Tier-1 mobile operators and large internet service providers, the data center cores of national-scale content and cloud providers, and mega data centers whose traffic cannot be squeezed into a single 4U appliance. The decision threshold is clear: if the ceilings of the largest single-body FortiGate — 75 Gbps of inspected traffic, 210 million sessions and 1 million new sessions per second — do not meet your demand, the chassis class becomes unavoidable. Below those thresholds, the FortiGate 4400F is both more economical and operationally far simpler; and if 589 Gbps of firewall throughput with 400GE uplinks is enough, the FortiGate 3700F is a 2 RU alternative. What you get in return on the chassis side is this: 40,000 gateway-to-gateway and 260,000 client-to-gateway IPsec tunnels, 200,000 firewall policies and up to 500 VDOMs, so a multi-tenant carrier architecture is carried on a single platform.

How does the chassis architecture work — what are FIM and FPM modules?

The platform uses two types of line card. The FIM (Fortinet Interface Module) is the input/output module and brings traffic into the chassis: with NP7 acceleration, the FIM-7921F and FIM-7941F each offer 2x 400GE QSFP-DD data ports (ports 19 and 20), 18x 100GE QSFP28 data ports (1–18), 2x 100GE QSFP28 and 2x 25GE SFP28 management/HA ports, 2x GE RJ45 management ports and 2x 4 TB of local log storage per module. The FPM (Fortinet Processor Module) is the processing module: the FPM-7620F is accelerated by the NP7 network processor and the CP9 content processor, and carries 2x 400GE QSFP-DD / 100GE QSFP28 slots plus 8x 25GE SFP28 / 10GE SFP+ slots per module. Both module types are hot-swappable. The base FG-7081F SKU ships with 1x FPM-7620F, 1x FIM-7921F, 2x system management modules and 6x 2500 W hot-swap redundant power supplies; the FG-7081F-2 variant comes with the FIM-7941F instead of the FIM-7921F. At chassis level, total interface capacity is 16x 400GE QSFP-DD / 100GE QSFP28 / 40GE QSFP+, 36x 100GE QSFP28 / 40GE QSFP+ data slots and 80x 25GE SFP28 / 10GE SFP+ slots; in addition there are 4x 100GE QSFP28 / 40GE QSFP+ and 4x 25GE SFP28 / 10GE SFP+ management/HA slots.

How does capacity scale with the number of modules?

Fortinet separately publishes the figures a single FPM-7620F produces on its own. The most accurate way to see how chassis capacity is built up — and where it stands against a lower class — is to read these three columns side by side.

MetricSingle FPM-7620FFG-7081F (6x FPM)FortiGate 4400F (comparison)
IPv4 Firewall Throughput (1518 byte UDP)396 Gbps1.89 Tbps1.15 Tbps
IPS Throughput (Enterprise Mix)67.5 Gbps405 Gbps94 Gbps
NGFW Throughput55 Gbps330 Gbps82 Gbps
Threat Protection Throughput52 Gbps312 Gbps75 Gbps
SSL Inspection Throughput54 Gbps324 Gbps86 Gbps
IPsec VPN Throughput (512 byte)63 Gbps378 Gbps310 Gbps
Concurrent sessions (TCP)100 million600 million210 million
New sessions per second (TCP)900,0005.4 million1 million
Power consumption (average)675 W6100 W (chassis total)1533 W

Three footnotes matter when reading this table. First, on the 7000F series the Threat Protection metric is measured with firewall, IPS, application control and malware protection including sandboxing enabled — on other FortiGate models, including the 4400F, sandboxing is not part of that footnote, so 312 Gbps and 75 Gbps are not the results of an identical test. Second, the 378 Gbps IPsec VPN figure given for the chassis was measured with VPN load balancing. Third, the 13.5 Gbps SSL-VPN throughput was measured on a single FPM. As a general Fortinet rule, all performance values are "up to" figures and vary with system configuration. On the capacity side, the chassis carries 288,000 SSL inspection CPS and 60 million concurrent SSL inspection sessions; HTTP 64K application control throughput is listed at 900 Gbps. CAPWAP throughput is N/A on this series and no supported FortiAP count is given — the 7081F is not positioned as a wireless controller but as a pure backbone platform; it does, however, support 300 FortiSwitch units and 12,000 FortiTokens.

How should power, cooling and site planning be handled?

The FortiGate 7081F cannot be planned like an ordinary rack appliance. The chassis measures 543.9 x 440 x 675.5 mm and weighs 165.68 kg; it draws 6100 W on average and 7300 W at maximum, and dissipates an average of 24,900 BTU/h (6160 W / 7370 W and 25,174 BTU/h on the FG-7081F-2 variant). The most frequently overlooked detail is supply voltage: the AC power supplies operate in the 200–277 VAC range with a maximum current of 6 x 16 A, and the DC option is -48 to -60 V DC. In other words, this is not an appliance you plug into a standard 100–240 V single-phase outlet. Cabinet power architecture, floor load-bearing capacity, hot/cold aisle placement and loading-dock access all have to be verified before you order. The operating temperature range is 0–40 °C and internal storage is 4x 4 TB SSD.

In Turkey, installations of this class are typically found in carrier and large financial data centers. Log retention under KVKK (Turkey's data protection law), the environment separation required by the BDDK (Turkish banking regulator) information systems regulation and PCI-DSS segmentation can all be solved on a single platform with 500 VDOMs and a 200,000-policy capacity; the 4x 4 TB of local disk on the chassis should be planned together with a central analytics layer for long-term log retention. On the high availability side, Active-Active (FGSP), Active-Passive and Clustering configurations are supported; on a critical backbone you should design a two-chassis cluster rather than a single chassis. As a Fortinet authorized channel partner, Sora Yazılım runs module configuration, licensing, migration and managed service processes on projects of this scale.

The decision to move to the chassis class is not made on a single throughput number; it is made together with the session profile, the SSL inspection ratio, the required number of FPMs and the physical site infrastructure. Share your current traffic measurements and we will report the difference between the 4400F and the FortiGate 7081F, along with the number of modules you need, using official data sheet values. You can compare all models on the FortiGate product family page, and reach us through our contact page for sizing and a quote.

  • 12U, 8-slot modular chassis (165.68 kg)
  • 1.89 Tbps IPv4 firewall throughput with 6x FPM
  • 312 Gbps Threat Protection, 324 Gbps SSL inspection
  • 600 million sessions, 5.4 million new sessions/sec
  • 16x 400GE QSFP-DD / 100GE QSFP28 slots
Key features

What this model offers

  • 1.89 / 1.88 / 1.129 Tbps IPv4 firewall throughput (1518 / 512 / 64 byte UDP, 6x FPM)
  • 1,680 Mpps packet processing and 7.5 µs firewall latency (64 byte UDP)
  • 405 Gbps IPS, 330 Gbps NGFW, 312 Gbps Threat Protection (Enterprise Mix, logging enabled)
  • 324 Gbps SSL inspection throughput; 288,000 SSL CPS, 60 million concurrent SSL sessions
  • 378 Gbps IPsec VPN throughput (512 byte, AES256-SHA256, with VPN load balancing)
  • 600 million concurrent TCP sessions and 5.4 million new sessions per second
  • 12U, 8-slot modular chassis; hot-swap FIM (I/O) and FPM (processing) modules
  • FPM-7620F processing module: NP7 + CP9 acceleration, 2x 400GE QSFP-DD/100GE QSFP28 and 8x 25GE SFP28/10GE SFP+ slots
  • FIM-7921F / FIM-7941F I/O module: NP7 acceleration, 2x 400GE QSFP-DD, 18x 100GE QSFP28 data ports, 2x 4 TB log storage
  • 16x 400GE QSFP-DD / 100GE QSFP28 / 40GE QSFP+ and 80x 25GE SFP28 / 10GE SFP+ slots
  • 6x 2500 W hot-swap redundant power supplies; AC 200–277 V or DC -48…-60 V
  • 200,000 firewall policies, 500 VDOMs, 40,000 G2G / 260,000 C2G IPsec tunnels
  • Active-Active (FGSP), Active-Passive and Clustering high availability options
  • Trusted Platform Module (TPM) and 4x 4 TB internal SSD storage
Tech Summary

Technical data

IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP, 6x FPM)
1.89 / 1.88 / 1.129 Tbps
Firewall Throughput (packets per second)
1,680 Mpps
Firewall Latency (64 byte UDP)
7.5 µs
IPS Throughput (Enterprise Mix)
405 Gbps
NGFW Throughput
330 Gbps
Threat Protection Throughput
312 Gbps (measured with sandboxing included on this series)
SSL Inspection Throughput
324 Gbps
IPsec VPN Throughput (512 byte, AES256-SHA256)
378 Gbps (with VPN load balancing)
Concurrent Sessions (TCP)
600 million
New Sessions/Second (TCP)
5.4 million
Firewall Policies
200,000
Application Control Throughput (HTTP 64K)
900 Gbps
Interface configuration
16x 400GE QSFP-DD/100GE QSFP28/40GE QSFP+, 36x 100GE QSFP28/40GE QSFP+ data slots, 80x 25GE SFP28/10GE SFP+, 4x 100GE QSFP28/40GE QSFP+ management/HA slots, 4x 25GE SFP28/10GE SFP+ management/HA slots, 2x USB, 8x console
VDOM (default / maximum)
10 / 500
Internal storage
4x 4 TB SSD
Form factor
12U, 8-slot chassis (543.9 x 440 x 675.5 mm, 165.68 kg)
Power consumption (average / maximum)
6100 W / 7300 W (FG-7081F-2: 6160 W / 7370 W)
Power supply
6x 2500 W hot-swap redundant PSUs; AC 200–277 V (50/60 Hz) or DC -48…-60 V, 80Plus
Use Cases

At what scale is this model preferred?

Telecom

Tier-1 mobile operator IP backbone

Inspecting subscriber traffic at the backbone layer with 5.4 million new sessions per second and 600 million concurrent sessions; direct connection to core routers over 400GE QSFP-DD uplinks.

Internet service provider

National-scale peering and transit protection

Inspecting transit traffic with 1.89 Tbps of firewall capacity and terminating enterprise customer VPNs across 260,000 client-to-gateway IPsec tunnels; capacity grows incrementally as FPMs are added.

Mega data center

Cloud and content provider core

Multi-tenant isolation with 500 VDOMs, a 200,000-policy rule base and visibility into encrypted application traffic with 324 Gbps of SSL inspection; uninterrupted service with a two-chassis cluster.

Banking and finance

Systemic bank backbone security

Designing the environment separation required by the BDDK (Turkish banking regulator) information systems regulation and PCI-DSS segmentation with a VDOM architecture; log management with 4x 4 TB local disk plus a central analytics layer.

Public sector and defense

National data center consolidation

Hosting multiple institutions on a single chassis in separate VDOMs; centralized operation with TPM-backed key protection, an Active-Passive cluster and a KVKK-compliant (Turkey's data protection law) log flow.

Who is it for?

Tier-1 mobile operators and internet service providers, national-scale cloud and content providers, systemically important banks and public sector data center operators.

Frequently Asked Questions

Common questions about this model

How many Tbps is the FortiGate 7081F firewall throughput?
According to the official data sheet, IPv4 firewall throughput is 1.89 / 1.88 / 1.129 Tbps with 1518 / 512 / 64 byte UDP packets. With Enterprise Mix traffic and logging enabled, IPS is measured at 405 Gbps, NGFW at 330 Gbps, Threat Protection at 312 Gbps and SSL inspection at 324 Gbps.
What does a "6-FPM configuration" mean?
Fortinet notes in a footnote that the performance values it publishes for the FG-7081F belong to a system with six FPM-7620F processing modules installed. Because the base SKU ships with a single FPM, projects that want to reach the peak figures in the data sheet must budget for six modules.
How many U high is the chassis and how many slots does it have?
It is 12U high with 8 slots (543.9 x 440 x 675.5 mm, 165.68 kg). The next platform up, the FortiGate 7121F, is a 16U chassis with 12 slots housing 10 FPM and 2 FIM slots; its performance values are published on the basis of 10 FPMs.
What is the difference between FIM and FPM modules?
The FIM (Fortinet Interface Module) is the input/output module; with NP7 acceleration, the FIM-7921F and FIM-7941F offer 2x 400GE QSFP-DD and 18x 100GE QSFP28 data ports, 2x 100GE and 2x 25GE management/HA ports and 2x 4 TB of log storage per module. The FPM (Fortinet Processor Module) is the processing module; the FPM-7620F is accelerated by NP7 and CP9 and carries 2x 400GE QSFP-DD / 100GE QSFP28 plus 8x 25GE SFP28 / 10GE SFP+ slots per module. Both are hot-swappable.
How much capacity does a single FPM-7620F provide?
A single module produces 396 / 395 / 263 Gbps IPv4 firewall, 67.5 Gbps IPS, 55 Gbps NGFW, 52 Gbps Threat Protection, 54 Gbps SSL inspection and 63 Gbps IPsec VPN; it supports 100 million concurrent sessions with 900,000 new sessions per second and draws 675 W on average.
How many concurrent sessions does the 7081F support?
600 million concurrent TCP sessions and 5.4 million new sessions per second. It also supports 200,000 firewall policies, 40,000 gateway-to-gateway and 260,000 client-to-gateway IPsec tunnels, 500 VDOMs and 12,000 FortiTokens.
What are the power and cooling requirements?
6100 W on average and 7300 W at maximum, with average heat dissipation of 24,900 BTU/h. Six 2500 W hot-swap redundant power supplies are used. AC models operate in the 200–277 VAC range (maximum 6 x 16 A) and DC models are fed with -48 to -60 V DC; this is not an appliance that plugs into a standard 100–240 V outlet.
When do you need a 7081F instead of a 4400F?
In three situations: when the 75 Gbps Threat Protection ceiling of a single-body appliance is not enough, when your session economics exceed the 4400F's standard 210 million concurrent / 1 million new sessions per second figures, and when 400GE QSFP-DD uplinks are mandatory. The need to grow capacity incrementally by adding modules is also an argument in favor of the chassis; each additional FPM-7620F brings 396 Gbps of firewall throughput and 100 million sessions. If none of these apply, the 4400F is both more economical and simpler to operate.
How is the 312 Gbps Threat Protection figure measured?
On the 7000F series the Threat Protection footnote states that firewall, IPS, application control and malware protection including sandboxing are enabled, and the measurement is taken with logging on. On other FortiGate models sandboxing is not part of that footnote, so comparisons are not one to one.
How is high availability designed?
Active-Active (FGSP), Active-Passive and Clustering configurations are supported; the chassis provides 4x 100GE QSFP28 / 40GE QSFP+ management/HA slots and 4x 25GE SFP28 / 10GE SFP+ management/HA slots. On backbones with zero tolerance for downtime, plan a two-chassis cluster rather than a single chassis.

FortiGate 7081F — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support