Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
Sizing calculator

Size my FortiGate

Four questions, and you get a model with the arithmetic shown, including why the cheaper one is or is not enough. No email required.

1 · Internet circuit
2 · Users on this site

Used for the sanity check below, not the primary calculation, circuit speed drives the number.

3 · Deep SSL/TLS inspection

Most traffic is encrypted, so this usually decides the model. “Not sure” is treated as yes, under-sizing is the expensive error.

4 · Form factor
Recommendation

THE WORKING

1 Gbps circuit × 1.4 headroom = 1.4 Gbps required
Binding constraint: SSL inspection throughput (because you are decrypting)

FortiGate Entry-Level Firewalls

FortiGate 90G

FG-90G

Threat protection
2.2 Gbps
SSL inspection
2.6 Gbps
Full specifications

Why not the cheaper FortiGate 70G? It does 1.3 Gbps threat protection and 1.4 Gbps SSL inspection, below the 1.4 Gbps this deployment needs.

Room to grow: the FortiGate 120G steps up to 2.8 Gbps if you expect the circuit or the inspection load to increase inside the refresh cycle.

What would change this answer: concurrent session counts, VDOM requirements, HA pair design, site-to-site VPN tunnel counts, and compliance constraints on logging and retention. None of those fit in four questions, which is why a person checks it before you buy.

How this works

Why does this size on threat protection throughput rather than firewall throughput?

Firewall throughput is measured on UDP with every inspection engine switched off. Threat protection throughput is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix. On a FortiGate 60F those figures are 10 Gbps and 700 Mbps, a factor of fourteen. Sizing on the first number is the most common and most expensive mistake in a Fortinet purchase.

Why does deep SSL inspection change the answer so much?

Decrypting, inspecting and re-encrypting TLS is the most expensive thing a firewall does. Fortinet publishes SSL inspection throughput separately, and on most models it is well below the threat protection figure. If you intend to inspect encrypted traffic, and most of your traffic is encrypted; that becomes the binding constraint rather than threat protection.

How much headroom should I leave?

We size to roughly 40% headroom over your peak requirement. Firewalls are bought on three-to-five-year cycles, traffic grows, and enabling one more inspection feature later should not force a replacement. A box running at 90% of its rated throughput on day one is a box you will replace early.

Is this a substitute for talking to an engineer?

No, and it does not pretend to be. It gets you to the right two or three models so the conversation starts in the right place. Session counts, VDOM requirements, HA design, VPN tunnel counts and compliance constraints can all move the answer, and none of them are in four questions.