Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FortiGate 30G–90G / 40F–80F

FortiGate Entry-Level Firewalls

Branch, retail and small-office NGFW, desktop form factor, full FortiOS

Compare all 8 models

Figures are Fortinet’s own, sortable, cited on every product page
anythreat protection throughput. Models below the line dim rather than disappear; you can still see what you ruled out.
FortiGate Entry-Level Firewalls model comparison
Modelenterprise mix512 byteIPS, avg. HTTPSActions
FortiGate 90GFG-90G2.2 Gbps25 Gbps2.6 Gbps3 Million8x GE RJ45, 2x 10GE shared port pairsDetails
FortiGate 70GFG-70G1.3 Gbps7.1 Gbps1.4 Gbps1.4 Million10x GE RJ45Details
FortiGate 50GFG-50G1.1 Gbps4.5 Gbps1.3 Gbps720,0005x GE RJ45Details
FortiGate 80FFG-80F900 Mbps6.5 Gbps715 Mbps1.5 Million8x GE RJ45, 2x shared port pairsDetails
FortiGate 70FFG-70F800 Mbps6.1 Gbps700 Mbps1.5 Million10x GE RJ45Details
FortiGate 60FFG-60F700 Mbps6.5 Gbps630 Mbps700,00010x GE RJ45Details
FortiGate 40FFG-40F600 Mbps4.4 Gbps310 Mbps700,0005x GE RJ45Details
FortiGate 30GFG-30G500 Mbps3.5 Gbps400 Mbps600,0004x GE RJ45Details

How to read these numbers

Entry-level FortiGates run the same FortiOS as the chassis platforms at the top of the range. You are not buying a cut-down operating system; you are buying less silicon. Every policy, VPN, SD-WAN and Security Fabric feature is present; the ceiling is throughput and session count.

More on choosing within this range

The number that decides which model you need is threat protection throughput, not firewall throughput. Firewall throughput is measured on UDP with every inspection engine switched off, and on these models it is five to ten times the figure you will actually see once IPS, application control and malware scanning are running. A FortiGate 60F does 10 Gbps of firewall throughput and 700 Mbps of threat protection. Size on the second number.

The G-series models (30G, 50G, 70G, 90G) are the current generation and carry markedly better inspection performance per dollar than the F-series they replace, the 90G alone does 2.2 Gbps of threat protection, more than triple the 80F. Where a G-series equivalent exists, it is usually the better buy unless you specifically need an F-series variant such as 3G4G or DSL.

Before you order

How much internet bandwidth does the site actually have?

Match threat protection throughput to your circuit, with headroom. A 500 Mbps circuit with full inspection wants at least a 50G or 70G, not a 40F. If you are provisioning gigabit fibre to a branch, start at the 70G or 90G.

Do you need to terminate SSL inspection?

SSL inspection is the most expensive thing a small FortiGate does, and it is the figure that collapses first. Note that the 30G, 40F, 50G, 60F and 70G publish no SSL VPN throughput at all, and several F-series models lose SSL VPN entirely on FortiOS 7.6.0+ because they only carry 2 GB of RAM. If remote-access VPN matters, that constraint decides the model.

Are you managing switches and access points from the firewall?

FortiGate manages FortiSwitch and FortiAP directly with no separate controller, but the limits are per-model: a 30G handles 8 switches and 16 APs, a 90G handles 24 and 128. For a site with more than a couple of APs, this often matters more than throughput.

PoE, LTE failover, DSL or WiFi?

These come as model variants rather than add-on cards at this tier. The 50G alone ships in WiFi, DSL, SFP, PoE and 5G variants. Decide the variant before the model, a 70G PoE and a 70G are ordered as different SKUs.

All FortiGate Entry-Level Firewalls