Firewalls
Every FortiGate model Fortinet currently ships, grouped the way you actually shop: by the throughput and session load the box has to survive with inspection turned on, not by the headline number on the front of the datasheet.
Where to start
The FortiGate range spans a factor of roughly a thousand in inspected throughput, from 500 Mbps on a desktop 30G to 520 Gbps on a 7121F chassis. Every one of them runs the same FortiOS; you are not buying a reduced operating system at the bottom of the range, you are buying less silicon. Policy, VPN, SD-WAN and Security Fabric features are present throughout; what changes is how much traffic the ASICs can offload before the CPU becomes the limit.
The single most consequential thing to understand before choosing is which number to size on. Firewall throughput is measured on UDP with every inspection engine switched off, and on smaller models it is five to fourteen times higher than what you will actually see. Threat protection throughput, measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix, is the figure that reflects a real deployment. A FortiGate 60F does 10 Gbps of the first and 700 Mbps of the second.
The second thing is generation. The G-series models are not modest refreshes: a 3000G delivers 80 Gbps of threat protection against the 3000F's 33, in the same two rack units and with near-identical raw forwarding. Where a G-series equivalent exists and you are inspecting traffic, it is usually the better purchase even at a higher list price.
Decide these first
How much of your traffic will you actually inspect?
This decides the model more than circuit speed does. Deep SSL/TLS inspection is the most expensive thing a firewall does, and Fortinet publishes it as a separate figure for good reason, on most models it sits well below threat protection throughput and becomes the binding constraint.
Is this a perimeter, a segmentation point, or a VPN concentrator?
Perimeters are inspection-heavy and want threat protection. Segmentation points want throughput and low latency. VPN concentrators want IPsec throughput and tunnel counts, which scale quite differently, a 1000F carries ten times the site-to-site tunnels of a 400G while delivering the same threat protection.
How many switches and access points will it manage?
FortiGate manages FortiSwitch and FortiAP directly with no separate controller, but the ceiling is per-model: 8 switches on a 30G, 300 at the high end. For a site with a real access layer this often decides the model before throughput does.
Desktop, rack, rugged or virtual?
Environment eliminates most of the catalogue before performance is discussed. Confirm rack space, power feeds, operating temperature and whether the site is industrial before comparing numbers.
Browse firewalls
FortiGate Entry-Level Firewalls
Branch, retail and small-office NGFW, desktop form factor, full FortiOS
8 products →FortiGate 120G–1800FFortiGate Mid-Range Firewalls
Campus edge and mid-size data centre, 1 RU and 2 RU, SFP+/SFP28 optics
7 products →FortiGate 2600F–4800F, 3000G/3500G/3800GFortiGate High-End Firewalls
Data centre and service provider, 400GE optics, Hyperscale, terabit class
11 products →FortiGate 7000F seriesFortiGate Chassis Platforms
Modular chassis for carrier and hyperscale, terabit inspection, hot-swap modules
2 products →FortiGate Rugged (FGR) seriesFortiGate Rugged Firewalls
OT, industrial and outdoor, extended temperature, DIN rail, fanless
1 product →FortiWiFi (FWF) seriesFortiWiFi Integrated Wireless Firewalls
FortiGate with an integrated access point, one box for a small site
6 products →FortiGate-VMFortiGate Virtual Appliances
The same FortiOS on your hypervisor or in your cloud account
1 product →