|
Interfaces and Modules |
|
| Hardware Accelerated GE RJ45 Interfacess | 16 |
| Hardware Accelerated GE SFP Slots | 16 |
| GE RJ45 Management Ports | 2 |
| USB Ports | 2 |
| RJ45 Console Port | 1 |
| Onboard Storage | 0 2x 240 GB SSD |
| Included Transceivers | 2x SFP (SX 1 GE) |
| System Performance — Enterprise Traffic Mix | |
| IPS Throughput 2 | 7.8 Gbps |
| NGFW Throughput 2, 4 | 6 Gbps |
| Threat Protection Throughput 2, 5 | 5 Gbps |
| System Performance and Capacity | |
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 32 / 32 / 24 Gbps |
| IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 32 / 32 / 24 Gbps |
| Firewall Latency (64 byte, UDP) | 2.14 μs |
| Firewall Throughput (Packet per Second) | 36Mpps |
| Concurrent Sessions (TCP) | 4 Million |
| New Sessions/Second (TCP) | 450 000 |
| Firewall Policies | 10 000 |
| IPsec VPN Throughput (512 byte) 1 | 20 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 2000 |
| Client-to-Gateway IPsec VPN Tunnels | 50 000 |
| SSL-VPN Throughput | 4.5 Gbps |
| Concurrent SSL-VPN Users
(Recommended Maximum, Tunnel Mode) |
5000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) 3 | 4.8 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) 3 | 4000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) 3 | 300 000 |
| Application Control Throughput (HTTP 64K) 2 | 12 Gbps |
| CAPWAP Throughput (HTTP 64K) | 14.8 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 10 |
| Maximum Number of FortiSwitches Supported | 72 |
| Maximum Number of FortiAPs (Total / Tunnel) | 512 / 256 |
| Maximum Number of FortiTokens | 5000 |
| High Availability Configurations | Active-Active, Active-Passive, Clustering |
Note: All performance values are “up to” and vary depending on system configuration.
- IPsec VPN performance test uses AES256-SHA256.
- IPS (Enterprise Mix), Application Control, NGFW and Threat Protection are measured with Logging enabled.
- SSL Inspection performance values use an average of HTTPS sessions of different cipher suites.
Use Cases
Next Generation Firewall (NGFW)
- FortiGuard Labs’ suite of AI-powered Security Services—natively integrated with your NGFW—secures web, content, and devices and protects networks from ransomware and sophisticated cyberattacks
- Real-time SSL inspection (including TLS 1.3) provides full visibility into users, devices, and applications across the attack surface
- Fortinet’s patented SPU (Security Processing Unit) technology provides industry-leading high-performance protection
Secure SD-WAN
- FortiGate WAN Edge powered by one OS and unified security and management framework and systems transforms and secures WANs
- Delivers superior quality of experience and effective security posture for work-from-any where models, SD-Branch, and cloud-first WAN use cases
- Achieve operational efficiencies at any scale through automation, deep analytics, and self-healing
Universal ZTNA
- Control access to applications no matter where the user is and no matter where the application is hosted for universal application of access policies
- Provide extensive authentications, checks, and enforce policy prior to granting application access—every time
- Agent-based access with FortiClient or agentless access via proxy portal for guest or BYOD
Segmentation
- Dynamic segmentation adapts to any network topology to deliver true end-to-end security—from the branch to the datacenter and across multi-cloud environments
- Ultra-scalable, low latency, VXLAN segmentation bridges physical and virtual domains with Layer 4 firewall rules
- Prevents lateral movement across the network with advanced, coordinated protection from
FortiGuard Security Services detects and prevents known, zero-day, and unknown attacks




















