FortiNAC CA-600F
High performance control and application server, manages up to 15,000 ports in the network
- Type
- High performance control and application server
- Target environment
- Medium environments
- Capacity
- 15,000 ports in the network
The FortiNAC CA-600F is a high performance control and application server for medium environments. Manages up to 15,000 ports in the network. FortiNAC discovers and profiles every device on the network, including the unmanaged ones that cannot run an agent, and enforces what each is permitted to reach.
Up to 15,000 ports on a higher-performance control and application server, aimed at medium environments. Three times the 500F's capacity on the same sizing definition. If your count sits near a boundary, size up: the cost of re-platforming a NAC deployment mid-flight far exceeds the appliance difference.
How to work out whether it fits
The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.
Fifteen thousand ports on the same counting rule as the 500F. If your number lands anywhere near a boundary, size up: NAC touches every access port in the estate, and re-platforming it mid-deployment means revisiting every switch configuration. The appliance difference is trivial against that. Do the port inventory properly first, from switch configs, not from memory.
What to order alongside the FortiNAC CA-600F
The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.
| Bundle | What it adds | 1 yearlist price | 3 yearslist price | 5 yearslist price |
|---|---|---|---|---|
| Enterprise ProtectionENT | The broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention. | on quote | on quote | on quote |
| Unified Threat ProtectionUTP | The traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on. | on quote | on quote | on quote |
| Advanced Threat ProtectionATP | The narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers. | on quote | on quote | on quote |
These are Fortinet list prices. You will not pay them.
Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.
Highlights
- Manages up to 15,000 ports in the network
- Agentless discovery and profiling of unmanaged devices
- Multi-vendor, works with the switching you already own
- Dynamic VLAN and ACL enforcement at the access layer
Typical deployments
- Medium enterprises and multi-building campuses
- Healthcare and manufacturing estates dense with unmanaged devices
- Deployments enforcing dynamic VLAN assignment at scale
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Sizing
| Type | High performance control and application server |
|---|---|
| Target environment | Medium environments |
| Capacity | Manages up to 15,000 ports in the network |
How capacity is counted
| Ports in the network | Total number of switch ports plus the maximum number of concurrent wireless connections. FortiNAC sizes the appliance on total port count, not on device count. |
|---|
Sources
- Fortinet Product Matrix (July 2026), retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.