Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FWB-400F

FortiWeb 400F

500 Mbps of HTTP throughput with full WAF inspection

HTTP throughput
500 Mbps
Form factor
Rackmount

The FortiWeb 400F delivers 500 Mbps of HTTP throughput, defending web applications and APIs against the OWASP Top 10, bot traffic, credential stuffing and API abuse, attacks that arrive as legitimate HTTPS and pass a network firewall untouched.

Is this the right model?

Where it fits, and where it stops fitting

Compare the whole range

Five times the 100F's throughput and the first model with fibre uplinks, which matters more than the raw number: 500 Mbps covers a handful of business applications rather than one. Still no hardware bypass, so it belongs behind a load balancer or in a reverse-proxy topology rather than inline on a single critical path. The step to the 600F is the one to consider if inline deployment is likely.

Sizing this model

How to work out whether it fits

The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.

Five hundred megabits covers a handful of business applications comfortably, or one busy public site with headroom. The practical planning number is concurrent connections rather than raw throughput: TLS termination and inspection both cost per connection, so a site with many long-lived sessions will feel the ceiling before the bandwidth figure suggests. If the deployment is inline rather than reverse-proxy, skip to the 600F for the bypass pair, retrofitting resilience after an outage is not a good look.

Support and subscriptions

What to order alongside the FortiWeb 400F

The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.

FortiGuard bundle options for the FortiWeb 400F
BundleWhat it adds1 yearlist price3 yearslist price5 yearslist price
Enterprise ProtectionENTThe broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention.on quoteon quoteon quote
Unified Threat ProtectionUTPThe traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on.on quoteon quoteon quote
Advanced Threat ProtectionATPThe narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers.on quoteon quoteon quote

These are Fortinet list prices. You will not pay them.

Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.

What each bundle includesFortiCare tiersAll support options
Where it sits in the range

FortiWeb 400F is number 2 of 7 in this family

Ranked on throughput, the figure that separates these models. All values are Fortinet’s own and cited on each product page.

One step down

FortiWeb 100F

100 Mbps

400% less than the FortiWeb 400F. Worth it only if your measured requirement genuinely fits inside it.

This model

FortiWeb 400F

500 Mbps

7 models in this family span 100 Mbps to 70 Gbps.

One step up

FortiWeb 600F

1 Gbps

100% more headroom. Worth costing if you expect growth inside the refresh cycle, replacing early is dearer than buying up once.

Highlights

  • 500 Mbps HTTP throughput
  • Machine-learning behaviour model, not signatures alone
  • API schema validation and rate limiting
  • Compact inline or reverse-proxy deployment

Typical deployments

  • A small estate of internal and external web applications
  • Organisations consolidating several unprotected apps behind one WAF
  • Reverse-proxy deployments where the WAF is not a single point of failure
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Performance
Throughput (HTTP)500 Mbps

Hardware

Hardware
Total interfaces4x GE RJ45, 4x GE SFP

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.

Buyers also compare