Centralized VPC inspection on AWS
Traffic from multiple VPCs is routed through a single inspection point; moving from VM-04S to VM-08S raises the policy ceiling from 10,000 to 200,000.
FortiGate running in your cloud subscription or on your hypervisor; capacity is set by the S-series vCPU license, not by a Gbps rating.
FortiGate-VM is the edition of FortiOS that runs as a virtual machine or cloud instance. It deploys on the AWS, Azure, Google Cloud, Oracle OCI, Alibaba and IBM Cloud marketplaces, and on VMware, Hyper-V, KVM, Nutanix AHV and OpenShift Virtualization. There are seven S-series license tiers, from VM-01S up to VM-ULS with unlimited vCPUs; capacity is determined not by hardware but by the vCPUs you assign and the license you select.
FortiGate-VM is the edition of FortiOS that runs as a virtual machine or cloud instance. Fortinet does not publish throughput figures for this product: performance depends on the underlying host hardware and the number of vCPUs you assign to the instance (FortiGate Virtual Appliances Data Sheet, 2025). The right question is therefore not "how many Gbps" but "which license tier, how many vCPUs and which platform".
If your security boundary forms inside a cloud subscription rather than at the entrance to a data center, FortiGate-VM is the right tool: organizations that put AWS VPC or Azure VNet traffic through central inspection, IT teams building east-west segmentation on VMware or Nutanix, multi-region architectures opening a new region without buying hardware, and short-lived dev/test environments. The data sheet lists the AWS (including GovCloud and AWS China), VMware Cloud on AWS, Azure and AzureStack, Google GCP, Oracle OCI, Alibaba Cloud and IBM Cloud marketplaces; in private cloud it lists support for VMware ESXi 6.7/7.0/8.0, NSX-T 3.2/4.0, Hyper-V, KVM/QEMU, XenServer, Nutanix AHV 7.3 (FortiOS 7.6.3+) and Red Hat OpenShift Virtualization 4.17.13 (FortiGate-VM 7.6.0+). The policy model is identical to that of physical FortiGate firewalls.
Current licensing is the S-series; the old VM00/VM02 naming no longer appears in the data sheet. vCPU count is not the only thing the tier determines — the policy ceiling, the number of VDOMs and the number of manageable FortiSwitch, FortiAP and endpoint devices all depend on the license as well.
| License | vCPU (max.) | Firewall policies | VDOM (max.) | FortiSwitch | Registered endpoints |
|---|---|---|---|---|---|
| VM-01S | 1 | 10,000 | 10 | 8 | 2,000 |
| VM-02S | 2 | 10,000 | 25 | 24 | 2,000 |
| VM-04S | 4 | 10,000 | 50 | 64 | 8,000 |
| VM-08S | 8 | 200,000 | 500 | 300 | 20,000 |
| VM-16S | 16 | 200,000 | 500 | 300 | 20,000 |
| VM-32S | 32 | 200,000 | 500 | 300 | 20,000 |
| VM-ULS | Unlimited | 200,000 | 500 | 300 | 20,000 |
Storage is 32 GB – 2 TB at every tier and there is no RAM restriction tied to vCPU count. The sharpest threshold sits between VM-04S and VM-08S: the policy ceiling rises from 10,000 to 200,000, VDOMs from 50 to 500 and FortiSwitch units from 64 to 300. In a multi-tenant design, the choice is VM-08S or above regardless of your raw vCPU requirement. Note also that multi-VDOM requires a separate subscription license, and the number of network interfaces you can define on one instance is 24 as of FortiOS 6.4.0 (18 before that).
On hardware FortiGates, FortiASIC takes over the IPS, SSL inspection and IPsec load; a single NP7 carries up to 200 Gbps and as many as 12 million sessions across two 100 GbE interfaces (Fortinet Document Library, 2026). Virtual instances have no such ASICs; inspection runs on the host CPU. In return, the data sheet defines two software acceleration paths for FortiGate-VM: vSPU, which moves part of packet processing into user space and applies kernel bypass within the operating system — according to the data sheet it raises throughput on a UDP firewall rule to more than three times — and support for Intel QuickAssist (QAT), which accelerates site-to-site IPsec traffic; with QAT a two- to three-fold improvement is reported depending on packet size (FortiGate Virtual Appliances Data Sheet, 2025). FortiGate-VM sizing is therefore based not on link capacity but on the security profiles you intend to enable; the decisive line item is SSL inspection, because more than 95% of global web traffic is encrypted (CyberRatings.org, 2025).
The S-series is supported on FortiOS 6.4.0 and later as well as the 7.x releases; the support calendar drives the version choice. With bulletin CSB-260330-1 dated March 2026, end of support for FortiOS 7.4 was extended to November 11, 2028 and for FortiOS 7.6 to January 25, 2030 (Fortinet Community, 2026). On LTS releases total support extends to 72 months and requires a FortiCare Elite contract; FortiOS 8.0, meanwhile, was announced on March 10, 2026.
| Criterion | FortiGate-VM | FortiGate CNF | Hardware FortiGate |
|---|---|---|---|
| Delivery model | Cloud instance — you operate it | SaaS — Fortinet operates it | Physical appliance |
| Environment | AWS, Azure, GCP, OCI, Alibaba, IBM Cloud, VMware, Hyper-V, KVM, Nutanix, OpenShift | AWS and Azure | Your data center or branch |
| Capacity | S-series license + vCPU | Not published; the service scales | Measured Gbps figures |
| Acceleration | No ASIC; vSPU and Intel QAT support | Not published — managed service | NP7 and CP9/CP10 ASICs |
| Software maintenance | Upgrades are yours | No software maintenance | Upgrades are yours |
The decision rule is simple: if you want the full FortiOS feature set and VDOM separation, choose FortiGate-VM; if you would rather not operate the firewall software layer at all on AWS or Azure, choose FortiGate CNF; and if you need committed throughput and ASIC acceleration, choose hardware — the FortiGate 200F at campus scale, the FortiGate 400F at the data center edge.
As a Fortinet authorized channel partner, Sora Yazılım provides tier assessment, license procurement, deployment on AWS/Azure/GCP/OCI and in VMware, Hyper-V and Nutanix environments, migration of existing hardware policies to the virtual instance, and managed services for FortiGate-VM. For workloads in scope of KVKK (Turkey's data protection law) we plan region selection and log retention together with you. Reach us through our contact page for a quote.
Traffic from multiple VPCs is routed through a single inspection point; moving from VM-04S to VM-08S raises the policy ceiling from 10,000 to 200,000.
Lateral traffic between server groups is separated on ESXi 8.0 and NSX-T 4.0; the 24-interface-per-instance limit is factored into the segment design.
Inspection is performed in the region where data in scope of KVKK (Turkey's data protection law) is processed; log flow is directed to FortiAnalyzer so retention can be set to the organization's policy.
Dev, test and prod environments are separated with VDOMs. VM-08S and above offer 500 VDOMs; the separate VDOM subscription license is added to the budget.
Organizations running hardware at the core and FortiGate-VM in the cloud manage both sides with the same policy language; hardware stays wherever measured Gbps figures are required.
Organizations running workloads on AWS, Azure, GCP or OCI; IT teams operating private clouds based on VMware, Hyper-V, KVM, Nutanix and OpenShift; multi-region architectures that need to open a new region without adding hardware, and owners of hybrid infrastructure.
Fanless desktop NGFW delivering 5 Gbps IPv4 firewall for micro offices of 5–10 users.
Details10-port desktop NGFW delivering 10 Gbps IPv4 firewall for small offices and branches of 10–30 users.
DetailsThe SP5 ASIC-based branch NGFW that replaces the 60F: 10 Gbps symmetric firewall, 1.4 million sessions, PoE and FortiWiFi variants.
DetailsDesktop branch firewall with eight PoE/+ ports and a 96 W budget that also powers the access layer.
DetailsSora Yazılım handles sizing, licensing, deployment and ongoing management — all from a single team.