Fortinet FortiGate Sizing Guide 2026: Optimise Your Security Fabric
In today’s hybrid work environment, your network and your security can no longer exist in silos. Fortinet’s "Security-Driven Networking" strategy is designed to make the firewall the heart of your entire infrastructure, converging networking, SD-WAN, and zero-trust access into a single, lightning-fast appliance.
At IP Trading, we specialise in matching businesses with the right FortiGate hardware to power this convergence. Because Fortinet engineers its own custom ASIC processors (SPUs), these appliances provide a "Security Compute Rating" that consistently outperforms standard CPU-based firewalls. Whether you are looking for a silent desktop unit for a branch office or a 400G-ready appliance for a hyperscale data center, this 2026 sizing guide will help you find the performance-to-price leader for your network.
The Fortinet Hardware Advantage
What makes FortiGate different? It’s all in the silicon. Unlike competitors that rely on off-the-shelf processors, Fortinet uses:
- Content Processors (CP9 & CP10): These act as dedicated "security accelerators," handling the heavy lifting of high-speed SSL/TLS inspection so your applications don't lag.
- Network Processors (NP7): These enable massive throughput for firewall and VPN traffic, making FortiGate the go-to choice for ultra-low latency environments.
- FortiGuard AI Services: A unified suite of security "blades" that offer real-time protection against web, content, and device-based attacks.
- Universal Management: With FortiOS, you get a consistent operating system across physical, virtual, and cloud deployments, giving you total visibility through a single pane of glass.
Use the tables below to compare the current F-Series and the next-generation G-Series models based on Threat Protection Throughput, the most critical metric for modern network sizing.

SMB & Small Branch (FortiGate 30G - 80F Series)
The entry-level FortiGate models are the gold standard for small businesses. They are compact, fanless (silent), and often include built-in Wi-Fi and 5G options.
- Best For: Retail stores, cafes, small professional offices, and home offices.
- Key Features: Desktop form factor, optional PoE to power your desk phones, and integrated SD-WAN for reliable internet.
- Performance: These models range from 500 Mbps to 1.3 Gbps in Threat Protection Throughput.
| Specification | FG/FWF-30G | FG/FWF-40F | FG/FWF-50G | FG/FWF-60F | FG-70F | FG/FWF-70G | FG/FWF-80F |
|---|---|---|---|---|---|---|---|
| Performance | |||||||
| Firewall Throughput (1518/512/64 byte UDP) | 4 / 4 / 3.9 Gbps | 5 / 5 / 5 Gbps | 5 / 5 / 4 Gbps | 10 / 10 / 6 Gbps | 10 / 10 / 6 Gbps | 10 / 10 / 10 Gbps | 10 / 10 / 7 Gbps |
| IPsec VPN Throughput | 3.5 Gbps | 4.4 Gbps | 4.5 Gbps | 6.5 Gbps | 6.1 Gbps | 7.1 Gbps | 6.5 Gbps |
| IPS Throughput (Enterprise Mix) | 800 Mbps | 1 Gbps | 2.25 Gbps | 1.4 Gbps | 1.4 Gbps | 2.5 Gbps | 1.4 Gbps |
| NGFW Throughput (Enterprise Mix) | 570 Mbps | 800 Mbps | 1.25 Gbps | 1 Gbps | 1 Gbps | 1.5 Gbps | 1 Gbps |
| Threat Protection Throughput | 500 Mbps | 600 Mbps | 1.1 Gbps | 700 Mbps | 800 Mbps | 1.3 Gbps | 900 Mbps |
| Firewall Latency | 2.87 μs | 2.97 μs | 2.42 μs | 3.3 μs | 2.54 μs | 2.46 μs | 3.23 μs |
| Capacity | |||||||
| Concurrent Sessions | 600,000 | 700,000 | 720,000 | 700,000 | 1.5 Million | 1.4 Million | 1.5 Million |
| New Sessions / Sec | 30,000 | 35,000 | 85,000 | 35,000 | 35,000 | 100,000 | 45,000 |
| Firewall Policies | 2,000 | 2,000 | 2,000 | 2,000 | 5,000 | 5,000 | 5,000 |
| Max Gateway-to-Gateway IPsec Tunnels | 200 | 200 | 200 | 200 | 200 | 200 | 200 |
| Max Client-to-Gateway IPsec Tunnels | 250 | 250 | 250 | 500 | 500 | 500 | 2,500 |
| SSL VPN Throughput | — | 490 Mbps | — | 900 Mbps | 405 Mbps | — | 950 Mbps |
| Concurrent SSL VPN Users | — | 200 | — | 200 | 200 | — | 200 |
| SSL Inspection Throughput | 400 Mbps | 310 Mbps | 1.3 Gbps | 630 Mbps | 700 Mbps | 1.4 Gbps | 715 Mbps |
| Application Control Throughput | 830 Mbps | 990 Mbps | 2.8 Gbps | 1.8 Gbps | 1.8 Gbps | 3.6 Gbps | 1.8 Gbps |
| Hardware | |||||||
| Interfaces | 4x GE RJ45 | 5x GE RJ45 | 5x GE RJ45 | 10x GE RJ45 | 10x GE RJ45 | 10x GE RJ45 | 8x GE RJ45 + 2x Shared |
| Local Storage | 30 GB | — | 64 GB | 128 GB | 128 GB | 64 GB | 128 GB |
| Power Supply | Single AC | Single AC | Single AC | Single AC | Single AC | Single AC | Single AC |
| Form Factor | Desktop | Desktop | Desktop | Desktop | Desktop | Desktop | Desktop |
Shop Fortigate 30G - 80F →
Mid-Sized Business & Branch Office (90G - 200G Series)
This series represents the "sweet spot" for mid-sized organisations that need high-speed fiber connectivity (SFP+) and enough power to inspect encrypted traffic without slowing down.
- Best For: Schools, mid-sized corporate offices, and distributed branches with 50-250 users.
- Key Features: Introduction of 10GbE ports , dual power supplies for redundancy, and higher concurrent session limits to support more devices.
- Performance: Look for Threat Protection speeds between 2.2 Gbps and 6 Gbps in this category.
| Specification | FG-90G | FG-120G | FG-200G |
|---|---|---|---|
| Performance | |||
| Firewall Throughput (1518/512/64 byte UDP) | 28 / 28 / 27.9 Gbps | 39 / 39 / 28 Gbps | 39 / 39 / 26.5 Gbps |
| IPsec VPN Throughput | 25 Gbps | 35 Gbps | 36 Gbps |
| IPS Throughput (Enterprise Mix) | 4.5 Gbps | 5.3 Gbps | 9 Gbps |
| NGFW Throughput (Enterprise Mix) | 2.5 Gbps | 3.1 Gbps | 7 Gbps |
| Threat Protection Throughput | 2.2 Gbps | 2.8 Gbps | 6 Gbps |
| Firewall Latency | 3.23 μs | 3.17 μs | 4.36 μs |
| Capacity | |||
| Concurrent Sessions | 3 Million | 3 Million | 11 Million |
| New Sessions / Sec | 124,000 | 140,000 | 400,000 |
| Firewall Policies | 5,000 | 10,000 | 10,000 |
| Max G/W to G/W IPSEC Tunnels | 200 | 2,000 | 2,000 |
| Max Client to G/W IPSEC Tunnels | 2,500 | 16,000 | 16,000 |
| SSL VPN Throughput | 1.4 Gbps | 1.5 Gbps | 3 Gbps |
| Concurrent SSL VPN Users | 200 | 500 | 500 |
| SSL Inspection Throughput | 2.6 Gbps | 3 Gbps | 7 Gbps |
| Application Control Throughput | 6.7 Gbps | 6.7 Gbps | 27.8 Gbps |
| Hardware | |||
| Max FortiAPs (Total / Tunnel) | 128 / 64 | 128 / 64 | 256 / 128 |
| Max FortiSwitches | 24 | 48 | 64 |
| Max FortiTokens | 500 | 5,000 | 5,000 |
| Virtual Domains (Default / Max) | 10 / 10 | 10 / 10 | 10 / 25 |
| Interfaces | 8x GE RJ45, 2x 10GE Shared Port Pairs | 4x 10GE SFP+, 18x GE RJ45, 8x GE SFP | 8x 10GE SFP+, 8x 5GE RJ45, 10x GE RJ45, 4x GE SFP |
| Local Storage | 120 GB (91G) | 480 GB (121G) | 480 GB (201G) |
| Power Supplies | Single AC PS, dual inputs | Dual AC PS | Dual AC PS |
| Form Factor | Desktop | 1 RU | 1 RU |
| Variants | — | — | — |
Shop Fortigate 90G - 200G →
Enterprise Perimeter (400F - 900G Series)
As you move into the campus perimeter, port density and high-availability become critical. These rack-mount units are designed to handle the heavy lifting of a busy corporate network.
- Best For: Large corporate headquarters and high-density campuses.
- Key Features: Multiple 25GbE SFP28 ports, significant local storage for logging (up to 960GB), and advanced hardware acceleration for SSL inspection.
- Performance: These models deliver massive NGFW Throughput reaching up to 31 Gbps.
| Specification | FG-400F | FG-700G | FG-900G |
|---|---|---|---|
| Performance | |||
| Firewall Throughput (1518/512/64 byte UDP) | 79.5 / 78.5 / 70 Gbps | 164 / 163 / 145 Gbps | 164 / 163 / 153 Gbps |
| IPsec VPN Throughput | 55 Gbps | 55 Gbps | 55 Gbps |
| IPS Throughput (Enterprise Mix) | 12 Gbps | 38 Gbps | 42 Gbps |
| NGFW Throughput (Enterprise Mix) | 10 Gbps | 29 Gbps | 31 Gbps |
| Threat Protection Throughput | 9 Gbps | 26 Gbps | 30 Gbps |
| Firewall Latency | 4.19 μs / 2.5 μs | 3.87 μs | 3.78 μs / 2.5 μs |
| Capacity | |||
| Concurrent Sessions | 7.8 Million | 16 Million | 16 Million |
| New Sessions / Sec | 500,000 | 700,000 | 720,000 |
| Firewall Policies | 10,000 | 10,000 | 50,000 |
| Max G/W to G/W IPSEC Tunnels | 2,000 | 2,000 | 2,000 |
| Max Client to G/W IPSEC Tunnels | 50,000 | 50,000 | 50,000 |
| SSL VPN Throughput | 3.6 Gbps | 8 Gbps | 10 Gbps |
| Concurrent SSL VPN Users | 5,000 | 10,000 | 10,000 |
| SSL Inspection Throughput | 8 Gbps | 14 Gbps | 16.7 Gbps |
| Application Control Throughput | 28 Gbps | 50 Gbps | 74.8 Gbps |
| Hardware | |||
| Max FortiAPs (Total / Tunnel) | 512 / 256 | 1024 / 512 | 2048 / 1024 |
| Max FortiSwitches | 96 | 96 | 196 |
| Max FortiTokens | 5,000 | 5,000 | 5,000 |
| Virtual Domains (Default / Max) | 10 / 25 | 10 / 50 | 10 / 50 |
| Interfaces | 8x 10GE SFP+, 8x GE SFP, 18x GE RJ45 | 4x 25GE SFP28, 4x 10GE SFP+, 16x GE SFP, 8x 5GE RJ45, 1x GE RJ45 | 4x 25GE SFP28, 4x 10GE SFP+, 1x 2.5GE RJ45, 8x GE SFP, 17x GE RJ45 |
| Local Storage | 960 GB (401F) | 960 GB (701G) | 960 GB (901G) |
| Power Supplies | Dual AC PS | Dual AC PS | Dual PS |
| Form Factor | 1 RU | 1 RU | 1 RU |
| Variants | DC | — | DC |
Shop Fortigate 400F - 900G →
High-End Enterprise & Data Center (1000F - 7121F Series)
These appliances are built for "hyperscale." They are the workhorses of the modern data center, capable of inspecting massive amounts of "East-West" traffic moving between servers.
- Best For: Tier 1 enterprises, cloud service providers, and massive data centers.
- Key Features: Support for 100GbE and 400GbE ports , carrier-grade reliability, and the ability to handle up to 1.8 billion concurrent sessions with hyperscale.
- Performance: Threat Protection speeds scale from 13 Gbps up to 75 Gbps on the highest-end appliances.
| Specification | FG-1000F | FG-1800F | FG-2600F | FG-3000F | FG-3200F | FG-3500F | FG-3700F | FG-3800G | FG-4200F | FG-4400F | FG-4800F | FG-7081F | FG-7121F |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Performance | |||||||||||||
| Firewall Throughput (1518/512/64 byte UDP) | 198 / 196 / 134 Gbps | 198 / 197 / 140 Gbps | 198 / 196 / 140 Gbps | 397 / 389 / 221 Gbps | 387 / 385 / 178.5 Gbps | 595 / 590 / 420 Gbps | 589 / 589 / 420 Gbps | 795 / 793 / 453 Gbps | 800 / 788 / 400 Gbps | 1.15 / 1.14 / 0.50 Tbps | 3.1 / 3.1 / 0.93 Tbps | 1.89 / 1.88 / 1.129 Tbps | 1.89 / 1.88 / 1.129 Tbps |
| IPsec VPN Throughput | 55 Gbps | 55 Gbps | 55 Gbps | 105 Gbps | 105 Gbps | 165 Gbps | 160 Gbps | 210 Gbps | 210 Gbps | 310 Gbps | 800 Gbps | 378 Gbps | 630 Gbps |
| IPS Throughput (Enterprise Mix) | 19 Gbps | 22 Gbps | 31 Gbps | 36 Gbps | 63 Gbps | 72 Gbps | 86 Gbps | 250 Gbps | 52 Gbps | 94 Gbps | 87 Gbps | 405 Gbps | 675 Gbps |
| NGFW Throughput (Enterprise Mix) | 15 Gbps | 17 Gbps | 27 Gbps | 34 Gbps | 47 Gbps | 65 Gbps | 80 Gbps | 210 Gbps | 47 Gbps | 82 Gbps | 77 Gbps | 330 Gbps | 550 Gbps |
| Threat Protection Throughput | 13 Gbps | 15 Gbps | 25 Gbps | 33 Gbps | 45 Gbps | 63 Gbps | 75 Gbps | 200 Gbps | 45 Gbps | 75 Gbps | 75 Gbps | 312 Gbps | 520 Gbps |
| Firewall Latency | 3.45 μs | 3.22 μs | 3.41 μs | 3.92 μs | 3.42 μs | 2.98 μs | 3.56 μs / 1.45 μs | 3.53 μs | 3.02 μs | 2.98 μs | 3.6 μs | 7.5 μs | 7.5 μs |
| Capacity | |||||||||||||
| Concurrent Sessions | 7.5 Million | 12 Million / 40 Million | 24 Million / 40 Million | 70 Million / 230 Million | 70 Million | 140 Million / 348 Million | 140 Million | 210 Million / 450 Million | 210 Million / 450 Million | 210 Million / 700 Million | 280 Million / 1.8 Billion | 600 Million | 1 Billion |
| New Sessions / Sec | 650,000 | 750,000 / 2 Million | 1 Million / 2 Million | 870,000 / 3 Million | 800,000 | 1 Million / 5 Million | 930,000 | 1.1 Million / 7 Million | 1 Million / 7 Million | 1 Million / 10 Million | 915,000 / 25 Million | 5.4 Million | 9 Million |
| Firewall Policies | 100,000 | 100,000 | 100,000 | 200,000 | 200,000 | 200,000 | 200,000 | 400,000 | 400,000 | 400,000 | 400,000 | 200,000 | 200,000 |
| Max G/W to G/W IPSEC Tunnels | 20,000 | 20,000 | 20,000 | 40,000 | 40,000 | 40,000 | 40,000 | 40,000 | 40,000 | 40,000 | 40,000 | 40,000 | 40,000 |
| Max Client to G/W IPSEC Tunnels | 100,000 | 100,000 | 100,000 | 200,000 | 200,000 | 200,000 | 200,000 | 200,000 | 200,000 | 200,000 | 200,000 | 260,000 | 260,000 |
| SSL VPN Throughput | 5.3 Gbps | 11 Gbps | 16 Gbps | 11 Gbps | 11 Gbps | 16 Gbps | 16 Gbps | 27 Gbps | 16 Gbps | 16 Gbps | 18 Gbps | 13.7 Gbps | 13.7 Gbps |
| Concurrent SSL VPN Users | 10,000 | 10,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 | 30,000 |
| SSL Inspection Throughput | 10 Gbps | 12 Gbps | 20 Gbps | 29 Gbps | 29 Gbps | 63 Gbps | 55 Gbps | 120 Gbps | 50 Gbps | 86 Gbps | 63 Gbps | 324 Gbps | 540 Gbps |
| Application Control Throughput | 44 Gbps | 34 Gbps | 64 Gbps | 115 Gbps | 109 Gbps | 135 Gbps | 190 Gbps | 315 Gbps | 135 Gbps | 140 Gbps | 180 Gbps | 900 Gbps | 1.5 Tbps |
| Hardware | |||||||||||||
| Max FortiAPs (Total / Tunnel) | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 | 4096 / 2048 | 8192 / 4096 | 8192 / 4096 | 8192 / 4096 | 8192 / 4096 | — | — |
| Max FortiSwitches | 196 | 196 | 196 | 300 | 300 | 300 | 300 | 300 | 300 | 300 | 300 | 256 | 300 |
| Max FortiTokens | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 | 20,000 |
| Virtual Domains (Default / Max) | 10 / 250 | 10 / 250 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 | 10 / 500 |
| Interfaces | 2× 100 GE QSFP28, 8× 25 GE SFP28, 16×10 GE SFP+, 8×10GE RJ45, 1× 2.5GE RJ45, 1 GE RJ45 | 4× 100 GE QSFP28, 12× 25 GE SFP28, 2×10 GE SFP+, 8× GE SFP, 18x GE RJ45 | 4× 100GE QSFP28/40GE QSFP+, 16× 25GE SFP28, 16× 10GE RJ45, 2× 10GE SFP+, 2x GE RJ45 | 6× 100GE QSFP28/40GE QSFP+, 16× 25GE SFP28, 18× 10GE RJ45, 2x GE RJ45 | 4× 400GE QSFP-DD, 12× 50GE SFP56, 4× 25GE SFP28, 2× 10GE RJ45 | 6× 100GE QSFP28/40GE QSFP+, 32× 25GE SFP28, 2× GE RJ45 | 4× 400GE QSFP-DD, 4× UL 25GE SFP28, 20× 50GE SFP56, 2× 10GE RJ45 | 4× 400GE, 6× 200GE QSFP56, 18× 50GE SFP56, 2× 10GE RJ45 | 8× 100GE QSFP28/40GE QSFP+, 18× 25GE SFP28, 2× GE RJ45 | 12× 100GE QSFP28/40GE QSFP+, 20× 25GE SFP28, 2× GE RJ45 | 8× 400GE, 12× 200GE QSFP56, 12× 50GE SFP56, 2× 10GE RJ45 | Varied | Varied |
| Local Storage | 960 GB (1001F) | 2× 960 GB (1801F) | 2× 960 GB (2601F) | 2× 960 GB (3001F) | 2× 960 GB (3201F) | 2× 1.92TB (3501F) | 2× 1.92TB (3701F) | 2× 1.92TB (3801G) | 2× 1.92TB (4201F) | 2× 1.92TB (4401F) | 2× 1.92TB (4801F) | 4× 4 TB SSD | 4× 4 TB SSD |
| Power Supplies | Dual PS | Dual PS | Dual PS | Dual PS | Dual PS | Dual PS | Dual PS | 4 PS | Dual PS | 4 PS | 4 PS | 6 PS | 8 PS |
| Form Factor | 2 RU | 2 RU | 2 RU | 2 RU | 2 RU | 2 RU | 2 RU | 3 RU | 3 RU | 4 RU | 4 RU | 12 RU | 16 RU |
| Variants | — | DC | DC | DC | — | — | — | DC | DC | DC | DC, NEBS | DC | DC |
Shop Fortigate 1000F - 7121F →
Fortinet NGFW vs. Threat Protection: What’s the Difference?
When you look at a FortiGate spec sheet, the numbers can be overwhelming. To size your network correctly, you need to understand exactly what each metric is measuring.
| Metric | What It Means |
|---|---|
| Firewall Throughput | Basic packet filtering (the "speed limit" with no security checks). |
| NGFW Throughput | Performance with Firewall + IPS + Application Control active. |
| Threat Protection | The Gold Standard: NGFW + Malware Protection. |
| SSL Inspection | Performance when "opening the envelope" of encrypted traffic. |
For a real-world deployment that won't lag, always size your hardware based on Threat Protection Throughput and SSL Inspection Throughput.
How to Size a FortiGate Correctly
When reading a Fortinet product matrix, focus on these three metrics to avoid mistakes:
- Threat Protection Throughput: This is the "real-world" speed. It measures the performance with Firewall, IPS, Application Control, and Malware Protection all running. Always size based on this number.
- SSL Inspection Performance: Since most modern traffic is encrypted, the firewall has to work twice as hard to see it. If you plan on doing deep-packet inspection, ensure your model's SSL throughput can handle your full internet pipe.
- The "1" vs "0" Rule: Models ending in 1 (e.g. FG-101F) include onboard storage for local logging. Models ending in 0 (e.g. FG-100F) do not. If you don't have a FortiAnalyzer, buy the "1" version.
VPN & Remote Access Sizing
With the rise of hybrid work, your firewall is now your primary gateway for remote employees. According to the 2026 Fortinet Product Matrix, VPN capacity scales significantly across the lineup:
- Entry Models (30G - 80F): Support 200 VPN users only on 70F & 80F. SSL VPN not supported on FortiOS 7.6.0 and above, for models with 2GB RAM (40F & 60F).
- Mid-Range (90G - 200G): Support 200 - 500 SSL VPN users.
- Enterprise (400F - 1800F): Support 5,000 - 10,000 users.
- Selected High-End Models: Support up to 30,000 recommended SSL VPN users.
Note: IPsec tunnels can scale up to 200,000 on high-end units for massive site-to-site connectivity. If remote work is critical to your business, you must factor in VPN throughput separately from your standard NGFW throughput to ensure a smooth user experience. *SSLVPN has been discontinued.
View all Fortinet Products | Request a Custom Sizing Quote
