Fortinet FortiGate Sizing Guide 2026: Optimise Your Security Fabric

In today’s hybrid work environment, your network and your security can no longer exist in silos. Fortinet’s "Security-Driven Networking" strategy is designed to make the firewall the heart of your entire infrastructure, converging networking, SD-WAN, and zero-trust access into a single, lightning-fast appliance.

At IP Trading, we specialise in matching businesses with the right FortiGate hardware to power this convergence. Because Fortinet engineers its own custom ASIC processors (SPUs), these appliances provide a "Security Compute Rating" that consistently outperforms standard CPU-based firewalls. Whether you are looking for a silent desktop unit for a branch office or a 400G-ready appliance for a hyperscale data center, this 2026 sizing guide will help you find the performance-to-price leader for your network.

The Fortinet Hardware Advantage

What makes FortiGate different? It’s all in the silicon. Unlike competitors that rely on off-the-shelf processors, Fortinet uses:

  • Content Processors (CP9 & CP10): These act as dedicated "security accelerators," handling the heavy lifting of high-speed SSL/TLS inspection so your applications don't lag.
  • Network Processors (NP7): These enable massive throughput for firewall and VPN traffic, making FortiGate the go-to choice for ultra-low latency environments.
  • FortiGuard AI Services: A unified suite of security "blades" that offer real-time protection against web, content, and device-based attacks.
  • Universal Management: With FortiOS, you get a consistent operating system across physical, virtual, and cloud deployments, giving you total visibility through a single pane of glass.

Use the tables below to compare the current F-Series and the next-generation G-Series models based on Threat Protection Throughput, the most critical metric for modern network sizing.

SMB & Small Branch (FortiGate 30G - 80F Series)

The entry-level FortiGate models are the gold standard for small businesses. They are compact, fanless (silent), and often include built-in Wi-Fi and 5G options.

  • Best For: Retail stores, cafes, small professional offices, and home offices.
  • Key Features: Desktop form factor, optional PoE to power your desk phones, and integrated SD-WAN for reliable internet.
  • Performance: These models range from 500 Mbps to 1.3 Gbps in Threat Protection Throughput.
Specification FG/FWF-30G FG/FWF-40F FG/FWF-50G FG/FWF-60F FG-70F FG/FWF-70G FG/FWF-80F
Performance
Firewall Throughput (1518/512/64 byte UDP) 4 / 4 / 3.9 Gbps 5 / 5 / 5 Gbps 5 / 5 / 4 Gbps 10 / 10 / 6 Gbps 10 / 10 / 6 Gbps 10 / 10 / 10 Gbps 10 / 10 / 7 Gbps
IPsec VPN Throughput 3.5 Gbps 4.4 Gbps 4.5 Gbps 6.5 Gbps 6.1 Gbps 7.1 Gbps 6.5 Gbps
IPS Throughput (Enterprise Mix) 800 Mbps 1 Gbps 2.25 Gbps 1.4 Gbps 1.4 Gbps 2.5 Gbps 1.4 Gbps
NGFW Throughput (Enterprise Mix) 570 Mbps 800 Mbps 1.25 Gbps 1 Gbps 1 Gbps 1.5 Gbps 1 Gbps
Threat Protection Throughput 500 Mbps 600 Mbps 1.1 Gbps 700 Mbps 800 Mbps 1.3 Gbps 900 Mbps
Firewall Latency 2.87 μs 2.97 μs 2.42 μs 3.3 μs 2.54 μs 2.46 μs 3.23 μs
Capacity
Concurrent Sessions 600,000 700,000 720,000 700,000 1.5 Million 1.4 Million 1.5 Million
New Sessions / Sec 30,000 35,000 85,000 35,000 35,000 100,000 45,000
Firewall Policies 2,000 2,000 2,000 2,000 5,000 5,000 5,000
Max Gateway-to-Gateway IPsec Tunnels 200 200 200 200 200 200 200
Max Client-to-Gateway IPsec Tunnels 250 250 250 500 500 500 2,500
SSL VPN Throughput 490 Mbps 900 Mbps 405 Mbps 950 Mbps
Concurrent SSL VPN Users 200 200 200 200
SSL Inspection Throughput 400 Mbps 310 Mbps 1.3 Gbps 630 Mbps 700 Mbps 1.4 Gbps 715 Mbps
Application Control Throughput 830 Mbps 990 Mbps 2.8 Gbps 1.8 Gbps 1.8 Gbps 3.6 Gbps 1.8 Gbps
Hardware
Interfaces 4x GE RJ45 5x GE RJ45 5x GE RJ45 10x GE RJ45 10x GE RJ45 10x GE RJ45 8x GE RJ45 + 2x Shared
Local Storage 30 GB 64 GB 128 GB 128 GB 64 GB 128 GB
Power Supply Single AC Single AC Single AC Single AC Single AC Single AC Single AC
Form Factor Desktop Desktop Desktop Desktop Desktop Desktop Desktop

Shop Fortigate 30G - 80F

Mid-Sized Business & Branch Office (90G - 200G Series)

This series represents the "sweet spot" for mid-sized organisations that need high-speed fiber connectivity (SFP+) and enough power to inspect encrypted traffic without slowing down.

  • Best For: Schools, mid-sized corporate offices, and distributed branches with 50-250 users.
  • Key Features: Introduction of 10GbE ports , dual power supplies for redundancy, and higher concurrent session limits to support more devices.
  • Performance: Look for Threat Protection speeds between 2.2 Gbps and 6 Gbps in this category.
Specification FG-90G FG-120G FG-200G
Performance
Firewall Throughput (1518/512/64 byte UDP) 28 / 28 / 27.9 Gbps 39 / 39 / 28 Gbps 39 / 39 / 26.5 Gbps
IPsec VPN Throughput 25 Gbps 35 Gbps 36 Gbps
IPS Throughput (Enterprise Mix) 4.5 Gbps 5.3 Gbps 9 Gbps
NGFW Throughput (Enterprise Mix) 2.5 Gbps 3.1 Gbps 7 Gbps
Threat Protection Throughput 2.2 Gbps 2.8 Gbps 6 Gbps
Firewall Latency 3.23 μs 3.17 μs 4.36 μs
Capacity
Concurrent Sessions 3 Million 3 Million 11 Million
New Sessions / Sec 124,000 140,000 400,000
Firewall Policies 5,000 10,000 10,000
Max G/W to G/W IPSEC Tunnels 200 2,000 2,000
Max Client to G/W IPSEC Tunnels 2,500 16,000 16,000
SSL VPN Throughput 1.4 Gbps 1.5 Gbps 3 Gbps
Concurrent SSL VPN Users 200 500 500
SSL Inspection Throughput 2.6 Gbps 3 Gbps 7 Gbps
Application Control Throughput 6.7 Gbps 6.7 Gbps 27.8 Gbps
Hardware
Max FortiAPs (Total / Tunnel) 128 / 64 128 / 64 256 / 128
Max FortiSwitches 24 48 64
Max FortiTokens 500 5,000 5,000
Virtual Domains (Default / Max) 10 / 10 10 / 10 10 / 25
Interfaces 8x GE RJ45, 2x 10GE Shared Port Pairs 4x 10GE SFP+, 18x GE RJ45, 8x GE SFP 8x 10GE SFP+, 8x 5GE RJ45, 10x GE RJ45, 4x GE SFP
Local Storage 120 GB (91G) 480 GB (121G) 480 GB (201G)
Power Supplies Single AC PS, dual inputs Dual AC PS Dual AC PS
Form Factor Desktop 1 RU 1 RU
Variants

Shop Fortigate 90G - 200G

Enterprise Perimeter (400F - 900G Series)

As you move into the campus perimeter, port density and high-availability become critical. These rack-mount units are designed to handle the heavy lifting of a busy corporate network.

  • Best For: Large corporate headquarters and high-density campuses.
  • Key Features: Multiple 25GbE SFP28 ports, significant local storage for logging (up to 960GB), and advanced hardware acceleration for SSL inspection.
  • Performance: These models deliver massive NGFW Throughput reaching up to 31 Gbps.
Specification FG-400F FG-700G FG-900G
Performance
Firewall Throughput (1518/512/64 byte UDP) 79.5 / 78.5 / 70 Gbps 164 / 163 / 145 Gbps 164 / 163 / 153 Gbps
IPsec VPN Throughput 55 Gbps 55 Gbps 55 Gbps
IPS Throughput (Enterprise Mix) 12 Gbps 38 Gbps 42 Gbps
NGFW Throughput (Enterprise Mix) 10 Gbps 29 Gbps 31 Gbps
Threat Protection Throughput 9 Gbps 26 Gbps 30 Gbps
Firewall Latency 4.19 μs / 2.5 μs 3.87 μs 3.78 μs / 2.5 μs
Capacity
Concurrent Sessions 7.8 Million 16 Million 16 Million
New Sessions / Sec 500,000 700,000 720,000
Firewall Policies 10,000 10,000 50,000
Max G/W to G/W IPSEC Tunnels 2,000 2,000 2,000
Max Client to G/W IPSEC Tunnels 50,000 50,000 50,000
SSL VPN Throughput 3.6 Gbps 8 Gbps 10 Gbps
Concurrent SSL VPN Users 5,000 10,000 10,000
SSL Inspection Throughput 8 Gbps 14 Gbps 16.7 Gbps
Application Control Throughput 28 Gbps 50 Gbps 74.8 Gbps
Hardware
Max FortiAPs (Total / Tunnel) 512 / 256 1024 / 512 2048 / 1024
Max FortiSwitches 96 96 196
Max FortiTokens 5,000 5,000 5,000
Virtual Domains (Default / Max) 10 / 25 10 / 50 10 / 50
Interfaces 8x 10GE SFP+, 8x GE SFP, 18x GE RJ45 4x 25GE SFP28, 4x 10GE SFP+, 16x GE SFP, 8x 5GE RJ45, 1x GE RJ45 4x 25GE SFP28, 4x 10GE SFP+, 1x 2.5GE RJ45, 8x GE SFP, 17x GE RJ45
Local Storage 960 GB (401F) 960 GB (701G) 960 GB (901G)
Power Supplies Dual AC PS Dual AC PS Dual PS
Form Factor 1 RU 1 RU 1 RU
Variants DC DC

Shop Fortigate 400F - 900G

High-End Enterprise & Data Center (1000F - 7121F Series)

These appliances are built for "hyperscale." They are the workhorses of the modern data center, capable of inspecting massive amounts of "East-West" traffic moving between servers.

  • Best For: Tier 1 enterprises, cloud service providers, and massive data centers.
  • Key Features: Support for 100GbE and 400GbE ports , carrier-grade reliability, and the ability to handle up to 1.8 billion concurrent sessions with hyperscale.
  • Performance: Threat Protection speeds scale from 13 Gbps up to 75 Gbps on the highest-end appliances.
Specification FG-1000F FG-1800F FG-2600F FG-3000F FG-3200F FG-3500F FG-3700F FG-3800G FG-4200F FG-4400F FG-4800F FG-7081F FG-7121F
Performance
Firewall Throughput (1518/512/64 byte UDP) 198 / 196 / 134 Gbps 198 / 197 / 140 Gbps 198 / 196 / 140 Gbps 397 / 389 / 221 Gbps 387 / 385 / 178.5 Gbps 595 / 590 / 420 Gbps 589 / 589 / 420 Gbps 795 / 793 / 453 Gbps 800 / 788 / 400 Gbps 1.15 / 1.14 / 0.50 Tbps 3.1 / 3.1 / 0.93 Tbps 1.89 / 1.88 / 1.129 Tbps 1.89 / 1.88 / 1.129 Tbps
IPsec VPN Throughput 55 Gbps 55 Gbps 55 Gbps 105 Gbps 105 Gbps 165 Gbps 160 Gbps 210 Gbps 210 Gbps 310 Gbps 800 Gbps 378 Gbps 630 Gbps
IPS Throughput (Enterprise Mix) 19 Gbps 22 Gbps 31 Gbps 36 Gbps 63 Gbps 72 Gbps 86 Gbps 250 Gbps 52 Gbps 94 Gbps 87 Gbps 405 Gbps 675 Gbps
NGFW Throughput (Enterprise Mix) 15 Gbps 17 Gbps 27 Gbps 34 Gbps 47 Gbps 65 Gbps 80 Gbps 210 Gbps 47 Gbps 82 Gbps 77 Gbps 330 Gbps 550 Gbps
Threat Protection Throughput 13 Gbps 15 Gbps 25 Gbps 33 Gbps 45 Gbps 63 Gbps 75 Gbps 200 Gbps 45 Gbps 75 Gbps 75 Gbps 312 Gbps 520 Gbps
Firewall Latency 3.45 μs 3.22 μs 3.41 μs 3.92 μs 3.42 μs 2.98 μs 3.56 μs / 1.45 μs 3.53 μs 3.02 μs 2.98 μs 3.6 μs 7.5 μs 7.5 μs
Capacity
Concurrent Sessions 7.5 Million 12 Million / 40 Million 24 Million / 40 Million 70 Million / 230 Million 70 Million 140 Million / 348 Million 140 Million 210 Million / 450 Million 210 Million / 450 Million 210 Million / 700 Million 280 Million / 1.8 Billion 600 Million 1 Billion
New Sessions / Sec 650,000 750,000 / 2 Million 1 Million / 2 Million 870,000 / 3 Million 800,000 1 Million / 5 Million 930,000 1.1 Million / 7 Million 1 Million / 7 Million 1 Million / 10 Million 915,000 / 25 Million 5.4 Million 9 Million
Firewall Policies 100,000 100,000 100,000 200,000 200,000 200,000 200,000 400,000 400,000 400,000 400,000 200,000 200,000
Max G/W to G/W IPSEC Tunnels 20,000 20,000 20,000 40,000 40,000 40,000 40,000 40,000 40,000 40,000 40,000 40,000 40,000
Max Client to G/W IPSEC Tunnels 100,000 100,000 100,000 200,000 200,000 200,000 200,000 200,000 200,000 200,000 200,000 260,000 260,000
SSL VPN Throughput 5.3 Gbps 11 Gbps 16 Gbps 11 Gbps 11 Gbps 16 Gbps 16 Gbps 27 Gbps 16 Gbps 16 Gbps 18 Gbps 13.7 Gbps 13.7 Gbps
Concurrent SSL VPN Users 10,000 10,000 30,000 30,000 30,000 30,000 30,000 30,000 30,000 30,000 30,000 30,000 30,000
SSL Inspection Throughput 10 Gbps 12 Gbps 20 Gbps 29 Gbps 29 Gbps 63 Gbps 55 Gbps 120 Gbps 50 Gbps 86 Gbps 63 Gbps 324 Gbps 540 Gbps
Application Control Throughput 44 Gbps 34 Gbps 64 Gbps 115 Gbps 109 Gbps 135 Gbps 190 Gbps 315 Gbps 135 Gbps 140 Gbps 180 Gbps 900 Gbps 1.5 Tbps
Hardware
Max FortiAPs (Total / Tunnel) 4096 / 2048 4096 / 2048 4096 / 2048 4096 / 2048 4096 / 2048 4096 / 2048 4096 / 2048 8192 / 4096 8192 / 4096 8192 / 4096 8192 / 4096
Max FortiSwitches 196 196 196 300 300 300 300 300 300 300 300 256 300
Max FortiTokens 20,000 20,000 20,000 20,000 20,000 20,000 20,000 20,000 20,000 20,000 20,000 20,000 20,000
Virtual Domains (Default / Max) 10 / 250 10 / 250 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500 10 / 500
Interfaces 2× 100 GE QSFP28, 8× 25 GE SFP28, 16×10 GE SFP+, 8×10GE RJ45, 1× 2.5GE RJ45, 1 GE RJ45 4× 100 GE QSFP28, 12× 25 GE SFP28, 2×10 GE SFP+, 8× GE SFP, 18x GE RJ45 4× 100GE QSFP28/40GE QSFP+, 16× 25GE SFP28, 16× 10GE RJ45, 2× 10GE SFP+, 2x GE RJ45 6× 100GE QSFP28/40GE QSFP+, 16× 25GE SFP28, 18× 10GE RJ45, 2x GE RJ45 4× 400GE QSFP-DD, 12× 50GE SFP56, 4× 25GE SFP28, 2× 10GE RJ45 6× 100GE QSFP28/40GE QSFP+, 32× 25GE SFP28, 2× GE RJ45 4× 400GE QSFP-DD, 4× UL 25GE SFP28, 20× 50GE SFP56, 2× 10GE RJ45 4× 400GE, 6× 200GE QSFP56, 18× 50GE SFP56, 2× 10GE RJ45 8× 100GE QSFP28/40GE QSFP+, 18× 25GE SFP28, 2× GE RJ45 12× 100GE QSFP28/40GE QSFP+, 20× 25GE SFP28, 2× GE RJ45 8× 400GE, 12× 200GE QSFP56, 12× 50GE SFP56, 2× 10GE RJ45 Varied Varied
Local Storage 960 GB (1001F) 2× 960 GB (1801F) 2× 960 GB (2601F) 2× 960 GB (3001F) 2× 960 GB (3201F) 2× 1.92TB (3501F) 2× 1.92TB (3701F) 2× 1.92TB (3801G) 2× 1.92TB (4201F) 2× 1.92TB (4401F) 2× 1.92TB (4801F) 4× 4 TB SSD 4× 4 TB SSD
Power Supplies Dual PS Dual PS Dual PS Dual PS Dual PS Dual PS Dual PS 4 PS Dual PS 4 PS 4 PS 6 PS 8 PS
Form Factor 2 RU 2 RU 2 RU 2 RU 2 RU 2 RU 2 RU 3 RU 3 RU 4 RU 4 RU 12 RU 16 RU
Variants DC DC DC DC DC DC DC, NEBS DC DC

Shop Fortigate 1000F - 7121F

Fortinet NGFW vs. Threat Protection: What’s the Difference?

When you look at a FortiGate spec sheet, the numbers can be overwhelming. To size your network correctly, you need to understand exactly what each metric is measuring.

Metric What It Means
Firewall Throughput Basic packet filtering (the "speed limit" with no security checks).
NGFW Throughput Performance with Firewall + IPS + Application Control active.
Threat Protection The Gold Standard: NGFW + Malware Protection.
SSL Inspection Performance when "opening the envelope" of encrypted traffic.

For a real-world deployment that won't lag, always size your hardware based on Threat Protection Throughput and SSL Inspection Throughput.

How to Size a FortiGate Correctly

When reading a Fortinet product matrix, focus on these three metrics to avoid mistakes:

  1. Threat Protection Throughput: This is the "real-world" speed. It measures the performance with Firewall, IPS, Application Control, and Malware Protection all running. Always size based on this number.
  2. SSL Inspection Performance: Since most modern traffic is encrypted, the firewall has to work twice as hard to see it. If you plan on doing deep-packet inspection, ensure your model's SSL throughput can handle your full internet pipe.
  3. The "1" vs "0" Rule: Models ending in 1 (e.g. FG-101F) include onboard storage for local logging. Models ending in 0 (e.g. FG-100F) do not. If you don't have a FortiAnalyzer, buy the "1" version.

VPN & Remote Access Sizing

With the rise of hybrid work, your firewall is now your primary gateway for remote employees. According to the 2026 Fortinet Product Matrix, VPN capacity scales significantly across the lineup:

  • Entry Models (30G - 80F): Support 200 VPN users only on 70F & 80F. SSL VPN not supported on FortiOS 7.6.0 and above, for models with 2GB RAM (40F & 60F).
  • Mid-Range (90G - 200G): Support 200 - 500 SSL VPN users.
  • Enterprise (400F - 1800F): Support 5,000 - 10,000 users.
  • Selected High-End Models: Support up to 30,000 recommended SSL VPN users.

Note: IPsec tunnels can scale up to 200,000 on high-end units for massive site-to-site connectivity. If remote work is critical to your business, you must factor in VPN throughput separately from your standard NGFW throughput to ensure a smooth user experience. *SSLVPN has been discontinued.

View all Fortinet Products | Request a Custom Sizing Quote

Frequently Asked Questions(FAQ)

1. What is the best FortiGate for a small office?

For an office with 10 - 20 people, the FortiGate 40F or 60F is usually perfect. If you need the latest Wi-Fi or 5G integrated, look at the G-Series like the 50G.

2. What is the best FortiGate firewall for 200 users?

Typically, the FG-120G or FG-200G is the best fit. The final choice depends on how much SSL inspection (encrypted traffic) you need to perform for those 200 users.

3. What FortiGate model supports 10,000 VPN users?

You should look at the FG-400F and above. While these models handle the user count, always verify your specific SSL VPN throughput requirements to ensure the hardware can handle the data load of 10,000 active connections.

4. What is the difference between the FortiGate 60F and 70F?

The 70F is the higher-performance sibling. It provides significantly more NGFW throughput and a higher concurrent session capacity, making it better suited for offices with a high density of IoT devices or heavy web usage.
  • Take the next step

    We are here to support your organisation's needs every step of the way.

    Connect with us  
  • Silver laptop on wooden desk