Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FWF-30G

FortiWiFi 30G

FortiGate 30G with an integrated access point, one box for a small site

Threat protection
500 Mbps
IPsec VPN
3.5 Gbps
Wireless
Integrated AP

Front panel

Front panel layout for the FortiWiFi 30G: 4 × 1G RJ454× 1G
4 fixed ports. Schematic drawn from the published interface list, port order and physical arrangement are indicative, not to scale.
  • RJ45 copper

The FortiWiFi 30G is a FortiGate 30G with a wireless radio built in. The firewall specifications are identical, 500 Mbps of threat protection, 3.5 Gbps of IPsec VPN and 600,000 concurrent sessions, so everything that applies to the FortiGate 30G applies here unchanged.

Is this the right model?

Where it fits, and where it stops fitting

Compare the whole range

The smallest integrated-wireless FortiGate, and the one where the consolidation argument is strongest: at a micro site there is often nowhere sensible to mount a separate access point anyway. Its ceiling is real though, eight FortiSwitches and sixteen FortiAPs, so if the site might grow past a single room, start at the 50G or 70G instead. No VDOMs on this model.

Sizing this model

How to work out whether it fits

The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.

Size the firewall exactly as you would a FortiGate 30G, 500 Mbps of threat protection against your circuit, then check the wireless separately. One integrated radio covers roughly a single room or small open-plan area; concrete, plasterboard and shelving all cut that hard. If the floor plan has more than one enclosed space that needs coverage, the honest answer is a FortiGate plus a separate access point, because you cannot move an antenna bolted to your firewall.

Support and subscriptions

What to order alongside the FortiWiFi 30G

The published threat protection figure for this model is measured with IPS, application control and malware protection all running. Those arrive as a FortiGuard subscription, so the bundle you choose decides whether the hardware can reach the number you sized it on. Every bundle already includes FortiCare Premium 24x7 support.

FortiGuard bundle options for the FortiWiFi 30G
BundleWhat it adds1 yearlist price3 yearslist price5 yearslist price
Enterprise ProtectionENTThe broadest bundle. Everything in UTP, plus the services that cover data, SaaS posture and attack-surface visibility, plus inline zero-day malware prevention.on quoteon quoteon quote
Unified Threat ProtectionUTPThe traditional mid-tier: perimeter defence covering network, file, web and email threats. Everything most sites actually switch on.on quoteon quoteon quote
Advanced Threat ProtectionATPThe narrow bundle: IPS and the full malware stack including cloud sandboxing, without the web and email filtering layers.on quoteon quoteon quote

These are Fortinet list prices. You will not pay them.

Every quote we write is discounted from list, and how far below depends on quantity, term and whether we register the deal with Fortinet. Longer terms also price better per year, which is why three and five year bundles are usually the better buy on a device you intend to keep through a refresh cycle. Part numbers follow Fortinet’s standard bundled convention; not every model carries every combination, so we confirm the exact orderable SKU before anything is placed.

What each bundle includesFortiCare tiersAll support options
Where it sits in the range

FortiWiFi 30G is the entry point in this family

Ranked on threat protection throughput, the figure that separates these models. All values are Fortinet’s own and cited on each product page.

One step down

Nothing below this

This is the smallest model in the family. If it is still more than you need, the honest answer is usually a different product line rather than a smaller box.

This model

FortiWiFi 30G

500 Mbps

6 models in this family span 500 Mbps to 1.3 Gbps.

One step up

FortiWiFi 40F

600 Mbps

20% more headroom. Worth costing if you expect growth inside the refresh cycle, replacing early is dearer than buying up once.

Highlights

  • Identical firewall specification to the FortiGate 30G
  • Integrated access point, no separate AP or controller
  • Manages up to 16 additional FortiAPs as the site grows
  • Region-locked SKU; we confirm the correct part number

Typical deployments

  • Single-room retail units and kiosks
  • Two-to-ten person offices with one wireless cell
  • Sites where mounting a separate AP is impractical
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled, size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)4 / 4 / 3.9 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.3.5 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.800 Mbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.570 Mbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.500 Mbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.400 Mbps
Application control throughput (HTTP 64K)830 Mbps
Firewall latency2.87 µs

Capacity

Capacity
Concurrent sessions600,000
New sessions / second30,000
Firewall policies2,000
Max gateway-to-gateway IPsec tunnels200
Max client-to-gateway IPsec tunnels250
SSL VPN throughput,
Concurrent SSL VPN users (recommended max, tunnel mode),
Virtual domains (default / max),

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)16 / 8
Max managed FortiSwitches8
Max FortiTokens500

Hardware

Hardware
Interfaces4x GE RJ45
Local storage30 GB (31G)
Power suppliesSingle AC PS
Form factorDesktop
VariantsWiFi

Wireless

Fortinet does not publish the wireless radio generation per model in the Product Matrix, and the radio and permitted transmit power vary by regional SKU. We confirm the exact wireless specification and the correct regional part number against your country before ordering, a wrong-region FortiWiFi is not a returnable configuration error.

Wireless
Integrated access pointYes; this is the wireless variant of the FortiGate 30G
Radio generationVaries by model and regional SKU, confirmed at quote
Regulatory domainRegion-locked SKU, must match country of deployment

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.

Buyers also compare