FortiNAC CA-500F
Mid-range control and application server, manages up to 5,000 ports in the network
- Type
- Mid-range control and application server
- Target environment
- Small environments
- Capacity
- 5,000 ports in the network
The FortiNAC CA-500F is a mid-range control and application server for small environments. Manages up to 5,000 ports in the network. FortiNAC discovers and profiles every device on the network, including the unmanaged ones that cannot run an agent, and enforces what each is permitted to reach.
Up to 5,000 ports. Fortinet defines that as total switch ports plus maximum concurrent wireless connections, not the number of devices you believe you have, and under-sizing on that definition is the most common FortiNAC purchasing error, expensive to correct after deployment. Count access-layer ports and peak wireless clients before anything else.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
Fortinet's port count means total switch ports plus peak concurrent wireless connections, and getting that wrong is the most common FortiNAC purchasing error. Count physical access ports from your switch inventory, add your measured wireless peak, not your device count, and use that number. A site with 2,000 wired ports and 2,000 concurrent wireless clients needs 4,000, not 2,000, and discovering that after deployment is expensive.
What to order alongside the FortiNAC CA-500F
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
Highlights
- Manages up to 5,000 ports in the network
- Agentless discovery and profiling of unmanaged devices
- Multi-vendor, works with the switching you already own
- Dynamic VLAN and ACL enforcement at the access layer
Typical deployments
- Small environments introducing network access control
- Single-site deployments with a defined port count
- Organisations needing IoT and unmanaged-device visibility
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Sizing
| Type | Mid-range control and application server |
|---|---|
| Target environment | Small environments |
| Capacity | Manages up to 5,000 ports in the network |
How capacity is counted
| Ports in the network | Total number of switch ports plus the maximum number of concurrent wireless connections. FortiNAC sizes the appliance on total port count, not on device count. |
|---|
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.