Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · FortiGate NGFW

FortiGate 70G

The SP5 ASIC-based branch NGFW that replaces the 60F: 10 Gbps symmetric firewall, 1.4 million sessions, PoE and FortiWiFi variants.

Quick answer

The FortiGate 70G is the SP5 ASIC-based desktop NGFW that replaces the 60F, with 10 / 10 / 10 Gbps IPv4 Firewall throughput, 1.3 Gbps Threat Protection and 1.4 Gbps SSL Inspection capacity. It supports 1.4 million concurrent sessions and 100,000 new sessions per second; PoE (FG-70G-POE) and Wi-Fi 6 (FortiWiFi 70G) variants are available.

FortiGate 70G is one of Fortinet's current G-series desktop NGFWs, positioned for branches of 20–50 users and for multi-site chains moving to SD-WAN. According to the official data sheet it delivers 10 Gbps IPv4 Firewall throughput across 1518/512/64 byte UDP packets alike — that is, a symmetric performance profile that does not fall away as packet size shrinks; alongside it come 2.5 Gbps IPS, 1.3 Gbps Threat Protection and 1.4 Gbps SSL Inspection throughput (FortiGate FortiWiFi 70G Series Data Sheet, 2026). Fortinet's current NGFW ordering guide lists the 30G, 50G, 70G, 90G, 120G and 200G under the heading of the latest available models for each series; the 40F and 60F do not appear in that table (Fortinet NGFW/Perimeter Firewalls Ordering Guide, PFW-OG-R28, 2026). That is the basis on which we position the 70G as the refresh path for the 60F.

What size of organization is the FortiGate 70G suited to?

What lifts the 70G into a higher league is not raw bandwidth but its session and packet processing capacity. The device supports 1.4 million concurrent TCP sessions and 100,000 new sessions per second; with a packet processing rate of 15 Mpps it delivers 2.46 µs firewall latency at 64 byte UDP. This profile is decisive for branches that run applications establishing large numbers of short-lived connections (POS terminals, IoT sensors, heavy API traffic, crowded guest networks). The firewall policy limit is 5,000; in branches where segmentation is designed in detail, that headroom gives comfortable room to work. At the access layer, up to 96 FortiAP units (48 of them in tunnel mode) and 24 FortiSwitch units can be managed from a single device.

SP5 Secure SD-WAN ASIC: the 70G family is built on SP5, Fortinet's SD-WAN-focused application-specific integrated circuit. In the data sheet's description, SP5 combines a RISC-based CPU with Fortinet's content and network processors; it accelerates application recognition and steering, IPsec VPN and deep SSL inspection in hardware, and brings access-layer connectivity (FortiSwitch and FortiAP) into the same acceleration domain. Fortinet states that this design delivers higher performance at lower cost and power consumption than conventional CPUs; because the data sheet publishes no numeric multiplier ("30% less power", "3x IPS" and so on), the size of the advantage should be assessed on the measured figures. The measured figure is this: a standard FG-70G consumes only 12.3 W on average while performing 1.4 Gbps of SSL inspection.

On the hardware security side, the 70G series carries two components not found on the 40F and 60F: a Trusted Platform Module (TPM) that generates, stores and validates cryptographic keys, and a physical signed firmware hardware switch that permits only verified FortiOS software to be installed. In store, field office and remote branch deployments where physical access is not fully under control, these two features make a concrete difference. The series also holds an independently verified Environmental Product Declaration (EPD) under ISO 14025 Type III; for organizations that produce sustainability reporting, this is a document that can be added to the procurement file.

How much faster is the FortiGate 70G than the FortiGate 60F in reality?

The claims often repeated in the market — "the 70G is twice the 60F" and "5x SSL performance" — do not match the official data sheets. Large-packet firewall capacity is 10 Gbps on both models; the SSL Inspection difference is from 630 Mbps to 1.4 Gbps, that is roughly 2.2x. The real gain is concentrated in small-packet performance, session capacity and inspected traffic. The table below compares the 70G both with its predecessor, the 60F, and with the 80F in the same segment:

Metric (official data sheet)FortiGate 60FFortiGate 70GFortiGate 80F
IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)10 / 10 / 6 Gbps10 / 10 / 10 Gbps10 / 10 / 7 Gbps
Firewall Throughput (packets per second)9 Mpps15 Mpps10.5 Mpps
Firewall Latency (64 byte UDP)3.3 µs2.46 µs3.23 µs
IPS Throughput1.4 Gbps2.5 Gbps1.4 Gbps
NGFW Throughput1 Gbps1.5 Gbps1 Gbps
Threat Protection Throughput700 Mbps1.3 Gbps900 Mbps
SSL Inspection Throughput630 Mbps1.4 Gbps715 Mbps
IPsec VPN Throughput (512 byte)6.5 Gbps7.1 Gbps6.5 Gbps
Concurrent sessions (TCP)700,0001.4 million1.5 million
New sessions per second (TCP)35,000100,00045,000
Firewall policies2,0005,0005,000
Max. FortiAP (total / tunnel)64 / 3296 / 4896 / 48
PoE power budget60 W (70G-POE)96 W (80F-PoE)

The table reduces model selection to a clear question. If inspected traffic and session establishment rate are your priority, the 70G is markedly ahead of the 80F in the same segment: almost twice as fast on SSL Inspection and more than twice as fast on new sessions per second. If, on the other hand, you need a higher PoE power budget, slightly more concurrent sessions or SFP shared media ports, the FortiGate 80F is the choice. If 10 ports and lower capacity are enough for a small site, the FortiGate 60F is still a valid option. For the positioning of all the models, see our FortiGate product page.

Are there PoE and Wi-Fi options on the FortiGate 70G?

Yes — the series comprises four hardware variants and their wireless counterparts. FG-70G carries 10 GE RJ45 ports in total: 2 WAN ports, 6 internal ports and 2 FortiLink ports. FG-70G-POE keeps the same total port count but reduces the internal port count to 2 and adds 4 GE RJ45 PoE/+ ports; the total usable PoE power budget is 60 W, enough to power IP phones, IP cameras or a FortiAP without needing a separate switch. FG-71G and FG-71G-POE add a 64 GB SSD to the same structure. On the wireless side there is a widespread misconception: the 70G does have an integrated Wi-Fi option. The FortiWiFi 70G (FWF-70G), FWF-70G-POE and FWF-71G SKUs in the ordering list include, in the data sheet's own wording, an "internal dual-band, dual-stream" 802.11ax (Wi-Fi 6) access point. In small single-room branches, wireless coverage can be provided without buying a separate FortiAP; in multi-floor or larger areas, separate FortiAPs are added over FortiLink. Power consumption varies by variant: FG-70G 12.3 W on average, FG-71G 13.4 W, FG-70G-POE 70.3 W, FG-71G-POE 76 W.

Which FortiOS release does the FortiGate 70G support, and does SSL-VPN work?

This is the most important design decision to watch on the 70G: the data sheet lists the SSL-VPN throughput and concurrent SSL-VPN user figures as "N/A" — meaning SSL-VPN is not an option on this model. Remote access must be designed from the outset on IPsec VPN (7.1 Gbps, AES256-SHA256) or the ZTNA Application Gateway. This is consistent with Fortinet's general direction; SSL-VPN was also removed from the 40F and 60F series with FortiOS 7.6.0. On release support, the rule Fortinet publishes is this: on standard releases, 36 months of engineering support is followed by an 18-month "Must Fix" phase, while on LTS releases the total coverage rises to 72 months (Fortinet Product Life Cycle, 2026). Because the end dates of individual releases can be revised, we do not fix dates on this page; on 70G deployments we make the release decision by consulting the official record for the chosen release as it stands on the day. The FortiOS section of the data sheet describes the operating system, in its own words, as a natively AI-powered and quantum-safe platform; for organizations that have put the transition to post-quantum cryptography on their agenda, this is a platform property independent of model choice. We determine the release choice together with you, based on the organization's upgrade window, active feature set and support calendar.

Branch operations and provisioning: the operational reason the 70G becomes a branch standard is that the wired (FG-70G), PoE (FG-70G-POE), SSD (FG-71G) and wireless (FWF-70G) variants of the same family can be managed with a single configuration template: different hardware is shipped according to store type, while the central policy set stays the same. The moment the devices reach the internet on site, they register with central management via their serial numbers and take on their own templates; the only work done on site is cabling. The two ethernet WAN ports can be run active-active or primary/backup under SD-WAN, and application-aware steering shifts till and stock applications onto the other line the instant link quality degrades. On the compliance side, what the 70G really provides is capacity: 5,000 firewall policies and 10 VDOMs are enough to separate the till segment from in-store guest, IoT and staff traffic at the level of detail PCI-DSS expects, while the 1.4 million session table ensures that segmentation does not run out of room under traffic load. On the logging side, forwarding to FortiAnalyzer consolidates the record-keeping obligation under KVKK (Turkey's data protection law) in one central place, regardless of branch count. You can review our entire Fortinet portfolio on our Fortinet solutions page.

The real decision on the 70G is which variant to send: the PoE one, the SSD one, or the one with internal Wi-Fi 6. We make that decision by examining branch type, the devices to be powered and the policy set to be inherited from the 60F together with you; as a Fortinet authorized channel partner we also run the licensing, migration and deployment phases. Write to us through our contact page for a configuration and quotation prepared for your branch inventory.

  • 10 / 10 / 10 Gbps IPv4 Firewall — independent of packet size
  • 1.4 Gbps SSL Inspection, 1.3 Gbps Threat Protection
  • 1.4 million sessions, 100,000 new sessions per second
  • SP5 Secure SD-WAN ASIC, TPM and signed firmware switch
  • PoE (60 W) and Wi-Fi 6 (FortiWiFi 70G) variants
Key features

What this model offers

  • 10 / 10 / 10 Gbps IPv4 Firewall throughput — symmetric performance that holds up even at 64 byte packets
  • 1.3 Gbps Threat Protection and 1.5 Gbps NGFW throughput
  • 2.5 Gbps IPS throughput (Enterprise Mix, logging enabled)
  • 1.4 Gbps SSL Inspection throughput, 140,000 concurrent SSL sessions
  • 7.1 Gbps IPsec VPN throughput (AES256-SHA256, 512 byte)
  • 1.4 million concurrent TCP sessions, 100,000 new sessions per second
  • 15 Mpps packet processing and 2.46 µs firewall latency
  • Application recognition, IPsec and SSL inspection acceleration with the SP5 Secure SD-WAN ASIC
  • Trusted Platform Module (TPM) and a physical signed firmware switch
  • 4x GE RJ45 PoE/+ ports and a 60 W power budget on the FG-70G-POE variant
  • Internal dual-band, dual-stream Wi-Fi 6 (802.11ax) access point on the FortiWiFi 70G variant
  • Central management of 96 FortiAP (48 tunnel) and 24 FortiSwitch units over FortiLink
  • Room for detailed segmentation with 5,000 firewall policies
  • ISO 14025 Type III independently verified Environmental Product Declaration (EPD)
Tech Summary

Technical data

IPv4 Firewall Throughput (1518 / 512 / 64 byte UDP)
10 / 10 / 10 Gbps
Firewall Throughput (packets per second)
15 Mpps
Firewall Latency (64 byte UDP)
2.46 µs
IPS Throughput
2.5 Gbps
NGFW Throughput
1.5 Gbps
Threat Protection Throughput
1.3 Gbps
SSL Inspection Throughput (IPS, avg. HTTPS)
1.4 Gbps
SSL Inspection CPS / concurrent sessions
715 / 140,000
IPsec VPN Throughput (512 byte, AES256-SHA256)
7.1 Gbps
SSL-VPN Throughput
N/A — not supported on this model
Application Control Throughput (HTTP 64K)
3.6 Gbps
CAPWAP Throughput (HTTP 64K)
6.8 Gbps
Concurrent Sessions (TCP)
1.4 million
New Sessions/Second (TCP)
100,000
Firewall Policies
5,000
Interface layout (FG-70G)
2x GE WAN, 6x GE RJ45, 2x GE RJ45 FortiLink (10x GE RJ45 in total), 1x USB, 1x console
Interface layout (FG-70G-POE)
2x GE WAN, 2x GE RJ45, 2x GE RJ45 FortiLink, 4x GE RJ45 PoE/+ ports
PoE power budget (70G-POE / 71G-POE)
60 W
Maximum FortiAP / FortiSwitch
96 (48 tunnel) / 24
Virtual Domains (default / maximum)
10 / 10
Form factor
Desktop — 40.5 x 216 x 160 mm, 0.91 kg
Power consumption (average / maximum)
12.3 W / 12.8 W (71G: 13.4 / 14.1 W · 70G-POE: 70.3 / 72.5 W · 71G-POE: 76 / 79 W)
Use Cases

At what scale is this model preferred?

Retail

POS-heavy store branch

The many short-lived connections created by till terminals, barcode devices and stock applications are handled comfortably by the 70G's capacity of 100,000 new sessions per second. The segment handling card data is kept on a separate VDOM and VLAN, providing PCI-DSS segmentation.

Finance

Standard build for newly opened branches

At new branch openings the 70G loads the template policy in FortiManager automatically with FortiZTP, the moment it comes out of the box and connects to the internet. Every branch is brought into service with the same standard security profile without sending an engineer on site.

Healthcare

Remote branch of a clinic chain

An encrypted connection is established from the remote clinic to the central patient information system over IPsec VPN (7.1 Gbps IPsec capacity). Because SSL-VPN is not available on this model, access is designed from the outset on IPsec or ZTNA; logs are retained in FortiAnalyzer under KVKK (Turkey's data protection law).

Professional services

Single-device small branch: security, PoE and Wi-Fi

With the FortiWiFi 70G-POE variant, the firewall, an internal Wi-Fi 6 access point and a 60 W PoE budget are combined in one chassis; IP phones and cameras are powered without a separate switch. In small branches, the device count and cabling complexity are reduced.

Logistics and manufacturing

Field site where physical access is not controlled

In deployments at warehouses, field offices or the edge of a production line, the TPM and the physical signed firmware switch provide an extra hardware layer against unauthorized software being loaded. IoT and sensor traffic is isolated on a separate segment.

Who is it for?

Branches and head offices of 20–50 users, POS- and IoT-heavy retail sites, multi-branch chains moving to SD-WAN, organizations planning a 60F refresh, and small branches that want PoE and Wi-Fi 6 in a single device.

Frequently Asked Questions

Common questions about this model

Is the FortiGate 70G twice as fast as the 60F?
No — this common claim does not match the official data sheets. At 1518 byte UDP packets both models deliver 10 Gbps. The real differences lie elsewhere: 6 Gbps versus 10 Gbps at 64 byte UDP, 9 Mpps versus 15 Mpps in packet processing, 700,000 versus 1.4 million concurrent sessions, 35,000 versus 100,000 new sessions per second, and 630 Mbps versus 1.4 Gbps on SSL Inspection (roughly 2.2x).
What is the FortiGate 70G's SSL Inspection capacity in reality?
According to the official data sheet it is 1.4 Gbps; concurrent SSL session capacity is 140,000 and the SSL Inspection CPS figure is 715. The claims that circulate from time to time — "3.2 Gbps SSL" or "5x the 60F" — have no basis in any Fortinet document. The real ratio against the 60F is roughly 2.2x (1.4 Gbps / 630 Mbps).
Can I use SSL-VPN on the FortiGate 70G?
No. The data sheet lists the SSL-VPN throughput and concurrent SSL-VPN user figures for this model as "N/A"; SSL-VPN is not an option on this hardware. Remote access must be designed from the outset on IPsec VPN (7.1 Gbps) or the ZTNA Application Gateway. For organizations migrating away from SSL-VPN, we redesign the access architecture.
Is there a Wi-Fi version of the FortiGate 70G?
Yes. The ordering list includes the FortiWiFi 70G (FWF-70G), FWF-70G-POE and FWF-71G SKUs; in the data sheet's own wording, these models have an "internal dual-band, dual-stream" 802.11ax (Wi-Fi 6) access point. In small single-room branches no separate FortiAP is needed; for multi-floor or larger areas, additional FortiAPs are connected over FortiLink (the model supports up to 96 FortiAP units).
How many watts does the PoE model deliver?
The FG-70G-POE and FG-71G-POE variants have 4 GE RJ45 PoE/+ ports and a total usable PoE power budget of 60 W. That budget is enough to power several IP phones, IP cameras or a FortiAP. If a higher budget is required, the FortiGate 80F-PoE with 96 W should be considered. On the PoE variant the device's own power consumption also rises to 70.3 W on average.
What does the SP5 ASIC do, and how much does it accelerate?
SP5 is Fortinet's application-specific integrated circuit focused on Secure SD-WAN. In the data sheet's description it combines a RISC-based CPU with Fortinet's content and network processors; it accelerates application recognition and steering, IPsec VPN, NGFW and deep SSL inspection in hardware. Fortinet does not publish a numeric acceleration multiplier; the gain has to be assessed on the measured figures — for example, being able to perform 1.4 Gbps of SSL inspection at an average consumption of 12.3 W.
How should I choose between the 70G and the 80F?
If inspected traffic and session establishment rate are the priority, the 70G is ahead: SSL Inspection 1.4 Gbps versus 715 Mbps, Threat Protection 1.3 Gbps versus 900 Mbps, new sessions per second 100,000 versus 45,000. Against that, the 80F offers slightly more concurrent sessions (1.5 million), a higher PoE budget (96 W) and SFP shared media ports. The decision is made on PoE needs and fibre uplink requirements.
Does the 70G have a TPM, and what is it for?
Yes. The 70G series comes with a Trusted Platform Module not found on the 40F and 60F; it generates, stores and validates cryptographic keys inside the hardware. There is also a physical signed firmware switch: at the highest security level it permits only verified FortiOS software to be installed. In store and field deployments where physical access is not fully under control, it is a meaningful additional layer.
Which FortiOS release is recommended?
The support rule Fortinet publishes is 36 months of engineering plus 18 months of "Must Fix" on standard releases, and a total of 72 months on LTS releases. Because release-specific end dates are updated by Fortinet, we do not give a fixed date here — we verify the current life cycle calendar together with you before deployment. On the 70G the decisive constraint is not the release number but the complete absence of SSL-VPN on this hardware: whichever FortiOS release you choose, remote access has to be built on IPsec VPN or ZTNA.
Can we open new branches without sending an engineer on site?
Yes. At new branch openings the 70G takes on the branch template from central management the moment it comes out of the box and connects to the internet; the only operation performed on site is cabling. The point specific to the 70G is this: the template cannot contain SSL-VPN — the remote access profile has to be defined as IPsec or ZTNA from the outset. On PoE variants, writing the port profiles into the template as well (which port will power the IP phone, which the camera) shortens deployment time. We draw up the branch standard together with our certified engineers; get in touch for details and a quotation.

FortiGate 70G — licensing + deployment + support

Sora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.

WhatsApp Support