The FortiGate 900G is a 1 RU upper mid-range firewall designed for large campus cores and the data center entry layer. According to the official data sheet it offers 164 Gbps IPv4 Firewall Throughput, 42 Gbps IPS, 30 Gbps Threat Protection and 16.7 Gbps SSL Inspection Throughput with 1518-byte UDP packets; it carries 28 million concurrent TCP sessions and is accelerated in hardware by the SPU NP7 and CP9 processors (FortiGate 900G Series Data Sheet, 2026).
What size of organization is the FortiGate 900G suited to?
The 900G is for organizations that scale by inspected traffic volume rather than by user count: campuses above 1,500 users, multi-building university and hospital sites, regional data centers and multi-tenant hosting operations. Its distinguishing feature is not raw firewall speed but the performance it sustains with security services enabled: with firewall, IPS and application control running together it delivers 31 Gbps NGFW, and when malware protection is added on top, 30 Gbps Threat Protection is measured. CyberRatings.org reports that more than 95% of global web traffic is encrypted and that some products suffer a marked performance loss when inspecting encrypted traffic (CyberRatings.org, 2025); the 900G's 16.7 Gbps SSL inspection ceiling is meaningful precisely because it is meant to absorb that load. In a 1 RU chassis the device consumes 170 W on average and 313 W at maximum, and has an operating temperature range of 0-45 °C.
What is the difference between the FortiGate 900G, the 600F and the 1000F?
In a table where all three models appear to sit in the same segment, the real difference emerges metric by metric. Between the FortiGate 600F and the 900G the IPv4 firewall gap is roughly 18% (139 Gbps versus 164 Gbps); on inspected traffic, however, the gap widens threefold: IPS 14 Gbps versus 42 Gbps, Threat Protection 10.5 Gbps versus 30 Gbps, concurrent sessions 8 million versus 28 million. The FortiGate 1000F one shelf up leads on raw firewall throughput (198 Gbps) and offers 100GE QSFP28 interfaces, but its Threat Protection figure is 13 Gbps and its concurrent session capacity is 7.5 million — in other words, it falls behind the 900G on the security inspection side. The question that decides the choice is this: do you need 100 Gigabit interfaces, or higher inspected throughput and session capacity?
| Metric (official data sheet) | FortiGate 600F | FortiGate 900G | FortiGate 1000F |
|---|
| IPv4 Firewall Throughput (1518-byte UDP) | 139 Gbps | 164 Gbps | 198 Gbps |
| IPS Throughput (Enterprise Mix) | 14 Gbps | 42 Gbps | 19 Gbps |
| NGFW Throughput | 11.5 Gbps | 31 Gbps | 15 Gbps |
| Threat Protection Throughput | 10.5 Gbps | 30 Gbps | 13 Gbps |
| SSL Inspection Throughput | 9 Gbps | 16.7 Gbps | 10 Gbps |
| Concurrent sessions (TCP) | 8 million | 28 million | 7.5 million |
| New sessions per second (TCP) | 550,000 | 720,000 | 650,000 |
| Fastest interface | 4x 25GE SFP28 ULL | 4x 25GE SFP28 ULL | 2x 100GE QSFP28 |
| Firewall policies | 30,000 | 50,000 | 100,000 |
| VDOMs (default / maximum) | 10 / 50 | 10 / 50 | 10 / 250 |
| Form factor / average power | 1 RU / 169 W | 1 RU / 170 W | 2 RU / 210 W |
What is the interface layout and hardware acceleration on the FortiGate 900G?
Interfaces: the 900G carries four 25GE SFP28 / 10GE SFP+ Ultra Low Latency slots, four 10GE SFP+ / GE SFP slots, eight GE SFP slots and sixteen GE RJ45 switch ports, accompanied by one 2.5GE/GE HA port and one GE management port. The device does not offer 40GE or 100GE interfaces; the core uplink is built by bundling the 25GE SFP28 ports with LACP. On Ultra Low Latency ports the firewall latency drops to 2.5 microseconds with 64-byte UDP packets, while on standard ports it is 3.78 microseconds; packet processing capacity is published as 229.5 Mpps. This latency profile is decisive for stock exchange connections, payment switching systems and real-time production control traffic.
SPU NP7 + CP9 hardware acceleration: in Fortinet's official ordering information the FortiGate 900G is described as "SPU NP7 and CP9 hardware accelerated". The NP7 network processor takes session handling off the CPU to provide fastpath acceleration; according to Fortinet documentation a single NP7 supports up to 200 Gbps of data throughput over two 100 Gigabit interfaces and up to 12 million sessions (Fortinet Document Library, 2026). The CP9 content processor performs more than 10 Gbps of pattern matching acceleration in flow-based inspection and executes IPsec bulk encryption and public key operations in hardware (Fortinet Document Library, 2026). The 900G's figures of 42 Gbps IPS and 16.7 Gbps SSL inspection are the result of this architecture. The device also contains a Trusted Platform Module (TPM) that generates and stores cryptographic keys in hardware, plus a Bluetooth Low Energy (BLE) module.
Capacity and the access layer: the 900G supports 50,000 firewall policies, 10 default and 50 maximum VDOMs, 2,000 gateway-to-gateway and 50,000 client-to-gateway IPsec tunnels. IPsec VPN throughput is 55 Gbps with 512-byte packets (measured with AES256-SHA256). At the access layer, 2,048 FortiAPs (1,024 of them in tunnel mode) and, with FortiOS 7.6.1 and above, 196 FortiSwitches are managed from the same device; on older releases the FortiSwitch limit is 96. Campus wired and wireless access thus becomes a logical extension of the firewall without a separate controller layer. In organizations that want a single management plane across the site, a central logging and reporting layer is added with FortiAnalyzer; the long-term record retention required in KVKK (Turkey's data protection law), PCI-DSS and BDDK (Turkish banking regulator) audits is met at this layer.
When do you need to move up to the 1000F or 1800F class?
There are three concrete thresholds that call for a step up from the 900G. The first is interface speed: if a 40GE or 100GE connection is mandatory, the 900G is not enough; the FortiGate 1000F starts with two 100GE QSFP28 / 40GE QSFP+ slots, while the FortiGate 1800F offers four 100GE QSFP28 slots (100GE support requires FortiOS 7.0.16+, 7.2.8+, 7.4+ or 7.6+). The second is VDOM and policy scale: if the limit of 50 VDOMs or 50,000 policies is being filled, you need the 1000F's 250 VDOM and 100,000 policy capacity. The third is inspected throughput: here the common mistake is assuming that security inspection gets faster as the model number grows. The 900G's 30 Gbps Threat Protection figure is above that of many models on higher shelves, including the 1000F (13 Gbps), the 1800F (15 Gbps) and the 2600F (25 Gbps). If you have hit that ceiling, the answer is not the next model number but a move to the data center class: the first model to surpass the 900G on Threat Protection is the FortiGate 3700F at 75 Gbps. For a full model-by-model comparison and selection criteria, take a look at our FortiGate product page.
High availability and continuity: in production environments the 900G is positioned as a two-device cluster. According to the data sheet the device supports active-active, active-passive and clustering configurations; there is a dedicated 2.5GE/GE HA port for heartbeat traffic. The device ships by default with two hot-swappable 80Plus power supplies and is offered in both AC (100-240V) and DC (48-60V) models — which is how DC power requirements in telecom and colocation environments are met. The measured noise level is published as 58 dBA and heat dissipation as 1,069 BTU/h; both values feed into the cooling calculation when planning a campus equipment room.
Release and lifecycle: the FortiGate 900G runs on the current FortiOS 7.4 and 7.6 branches. According to the CSB-260330-1 bulletin dated March 2026, engineering support for FortiOS 7.4 was extended to 11 May 2027 and end of full support to 11 November 2028, while for FortiOS 7.6 the dates were extended to 25 July 2028 and 25 January 2030 respectively (Fortinet Community, CSB-260330-1, 2026). Because some capabilities such as management of 196 FortiSwitches are only unlocked on FortiOS 7.6.1 and above, the 7.6 branch is recommended for new deployments. For organizations that want to push the support window beyond these dates, the option the data sheet points to is FortiCare Elite: alongside an enhanced SLA and a dedicated support team it provides 18 months of extended end-of-engineering support.
As a Fortinet authorized channel partner we carry out traffic profile analysis, HA and VDOM design, 25GE core integration, configuration migration from 600F or older generation devices, and commissioning work for the FortiGate 900G. To determine the right choice among the 600F, 900G and 1000F for your organization and to request a hardware and subscription quote, reach us through our contact page.