FortiGate 900G
1 RU with ultra-low-latency ports and 74.8 Gbps application control
- Threat protection
- 30 Gbps
- Firewall throughput
- 164 Gbps
- IPsec VPN
- 55 Gbps
- Concurrent sessions
- 28 Million
Front panel
- SFP cage
- RJ45 copper
The 900G is the top of the 1 RU range: 30 Gbps threat protection, 16.7 Gbps SSL inspection and 74.8 Gbps application control, with ultra-low-latency ports that drop firewall latency from 3.78 µs to 2.5 µs. It manages 196 FortiSwitches and 2,048 FortiAPs and offers a DC-power variant.
Take the 900G where you need mid-range inspection performance and either low latency or a very large Fabric. Against the 1000F it has less raw firewall throughput but more than twice the threat protection (30 vs 13 Gbps), another case where the headline number points the wrong way.
What to order alongside the FortiGate 900G
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | $73,710FG-900G-BDL-809-12 | $137,970FG-900G-BDL-809-36 | $202,230FG-900G-BDL-809-60 |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | $68,040FG-900G-BDL-950-12 | $120,960FG-900G-BDL-950-36 | $173,880FG-900G-BDL-950-60 |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | FG-900G-BDL-928-12 | FG-900G-BDL-928-36 | FG-900G-BDL-928-60 |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
FortiGate 900G is the top in this family
Ranked on threat protection throughput, the figure that separates these models. All values are Fortinet’s own and cited on each product page.
FortiGate 700G
26 Gbps
15% less than the FortiGate 900G. Worth it only if your measured requirement genuinely fits inside it.
FortiGate 900G
30 Gbps
7 models in this family span 2.8 Gbps to 30 Gbps.
Top of the family
Nothing larger in this line. Beyond this the design changes, clustering, a different product, or a conversation rather than a bigger box.
Highlights
- 30 Gbps threat protection, 74.8 Gbps application control
- Ultra-low-latency ports, 2.5 µs firewall latency
- Manages 196 FortiSwitches, 2,048 FortiAPs
- 50,000 firewall policies, DC power variant
Typical deployments
- Latency-sensitive campus and trading-floor edge
- Large distributed Fabric estates managed from one firewall pair
- DC-powered facilities and carrier environments
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled, size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 164 / 163 / 153 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 55 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 42 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 31 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 30 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 16.7 Gbps |
| Application control throughput (HTTP 64K) | 74.8 Gbps |
| Firewall latency | 3.78 µs / 2.5 µs |
Capacity
| Concurrent sessions | 28 Million |
|---|---|
| New sessions / second | 720,000 |
| Firewall policies | 50,000 |
| Max gateway-to-gateway IPsec tunnels | 2,000 |
| Max client-to-gateway IPsec tunnels | 50,000 |
| SSL VPN throughput | 10 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 10,000 |
| Virtual domains (default / max) | 10 / 50 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 2,048 / 1,024 |
|---|---|
| Max managed FortiSwitches | 196 |
| Max FortiTokens | 5,000 |
Hardware
| Interfaces | 4x 25GE SFP28, 4x 10GE SFP+, 1x 2.5GE RJ45, 8x GE SFP, 17x GE RJ45 |
|---|---|
| Local storage | 960 GB (901G) |
| Power supplies | Dual PS |
| Form factor | 1 RU |
| Variants | DC |
Model-specific caveats
Fortinet conditions that apply to this model in particular. Worth reading before you order.
| Note 1 | The second latency figure is achieved with ultra-low-latency ports. |
|---|
Sources
- Fortinet Product Matrix, FortiGate Network Security Platform (July 2026), retrieved 2026-09-01
- Fortinet Partner Portal price list, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.
Buyers also compare
FortiGate 700G
Twice the 400G's inspected throughput on the same interfaces
FortiGate 1000F
100GE QSFP28 optics and 100,000 firewall policies in 2 RU
FortiGate 1800F
Hyperscale-capable, 40 million sessions and 2 million new sessions/sec