Fortinet FortiGate Enterprise Firewalls
Fortinet Enterprise Firewall. Purpose-built silicon. Throughput that holds under full inspection load.
FortiGate enterprise firewalls run on Fortinet's custom NP7 security processors, delivering IPS, SSL inspection, and deep packet inspection at line rate without throttling your traffic. Nine models cover every deployment from compact branch appliances to carrier-grade chassis, all sharing a single FortiOS image and native Fortinet Security Fabric integration for centralized management, SD-WAN, and ZTNA.
Shop by Series
FG-120G / 121G
NP7 ASIC acceleration packed into a compact 1U footprint. The 120G brings enterprise-class UTM, SD-WAN, and ZTNA to branch locations at a price point that fits branch refresh budgets without giving up inspection depth.
Shop FG-120G Series →
FG-200F / 201F
A proven F-generation workhorse for regional offices and mid-market headquarters. NP6 hardware offloading handles UTM and SSL inspection without bottlenecking the link, and the 201F adds a redundant power supply for environments that need it.
Shop FG-200F Series →
FG-200G / 201G
The current-generation step up from the 200F. NP7 silicon nearly doubles encrypted inspection throughput in the same 1U rack space, making the 200G the right call for mid-market sites doing new hardware purchases today.
Shop FG-200G Series →
FG-400E / 401E
A field-proven campus and regional data center platform with built-in redundant power, high-availability failover, and the full FortiOS feature set. Reliable option for organizations running an E-to-newer-generation refresh cycle on a defined budget.
Shop FG-400E Series →
FG-400F / 401F
NP6 offloading pushes firewall throughput to approximately 80 Gbps, with SSL inspection well above 10 Gbps. A strong choice for enterprise campus deployments carrying heavy encrypted east-west traffic or terminating large numbers of VPN sessions simultaneously.
Shop FG-400F Series →
FG-400G / 401G
The current-generation enterprise core appliance. NP7 silicon delivers over 100 Gbps of threat-protection throughput with full UTM inspection active. The right call for demanding campus cores, WAN edge, and internal segmentation points being specced today.
Shop FG-400G Series →
FG-900G / 901G
Built for large headquarters and data center edge roles where firewall throughput is counted in hundreds of gigabits. Dual redundant power, high port density, and NP7 processing hold rated performance under sustained full-inspection loads, around the clock.
Shop FG-900G Series →
FG-3000F / 3001F
A data center perimeter and internal segmentation platform delivering multi-hundred-gigabit firewall capacity in a fixed 2U appliance. Lower power draw and rack cost compared to blade chassis alternatives at equivalent throughput, without sacrificing inspection depth.
Shop FG-3000F Series →
FG-7121F
Fortinet's highest-density chassis platform. Modular line cards and NP7 ASICs support terabits of combined firewall and IPsec throughput, built for cloud providers, service providers, and enterprise mega-sites that cannot tolerate inspection bottlenecks at any load level.
Shop FG-7121F →
Licenses & Renewals
FortiGuard threat intelligence bundles, FortiCare support contracts, and subscription renewals for every FortiGate enterprise model. Keep IPS signatures, firmware updates, and TAC access current without a lapse in coverage.
Shop All Licenses →Fortinet Enterprise Firewalls at a Glance
| Series | Best For | User Count | Form Factor | Key Feature |
|---|---|---|---|---|
| FG-120G / 121G | Branch office | 50 to 200 | Desktop / 1U | NP7 acceleration in a compact branch footprint |
| FG-200F / 201F | Regional office | 200 to 500 | 1U Rack | NP6 UTM with redundant power option (201F) |
| FG-200G / 201G | Mid-market headquarters | 200 to 500 | 1U Rack | NP7 silicon, 2x encrypted throughput vs. 200F |
| FG-400E / 401E | Enterprise campus refresh | 500 to 2,000 | 1U Rack | Proven HA platform with built-in redundant power |
| FG-400F / 401F | Enterprise campus | 500 to 2,000 | 1U Rack | NP6 offloading, approx. 80 Gbps firewall throughput |
| FG-400G / 401G | Enterprise core and WAN edge | 500 to 2,500 | 1U Rack | NP7, 100+ Gbps threat-protection throughput |
| FG-900G / 901G | Large headquarters and data center edge | 2,500 to 10,000 | 2U Rack | 200+ Gbps, high port density, dual redundant power |
| FG-3000F / 3001F | Data center perimeter and segmentation | 10,000+ | 2U Rack | Multi-hundred-gigabit fixed appliance, lower power draw |
| FG-7121F | Carrier and hyperscale | Service provider scale | Chassis | Terabit IPsec and firewall, modular NP7 line cards |
Fortinet Enterprise Firewall FAQ
The letter indicates the hardware generation. E series models use older NP6 and CP9 processors. F series adds NP6 capacity and improved SSL inspection throughput. G series uses the current NP7 processor and delivers roughly twice the encrypted inspection throughput in the same rack space. If you are purchasing new hardware today, G series is the current-generation choice unless budget or a specific legacy requirement points you toward F or E.
The appliance ships with FortiOS and base firewall, routing, and VPN features included. Advanced threat services such as IPS, antivirus, web filtering, and sandboxing require an active FortiGuard subscription. Most enterprise buyers purchase a FortiCare support contract and a FortiGuard bundle at the time of purchase. Our team can recommend the right licensing package for your security requirements.
SPU stands for Security Processing Unit. Fortinet builds its own ASIC processors, NP (Network Processor) for traffic offloading and CP (Content Processor) for SSL and IPS inspection. These chips allow FortiGate firewalls to maintain their rated throughput even when all threat inspection services are active. Software-based firewalls typically see a 70 to 80 percent throughput drop under full UTM load. FortiGate appliances powered by NP7 silicon avoid that penalty.
User count and workload type are the two main sizing inputs. Branch offices with fewer than 200 users typically fit the FG-120G. Regional sites of 200 to 500 users land on the FG-200G. Enterprise campuses of 500 to 2,500 users look at the FG-400F or FG-400G. Large headquarters and data center edge roles call for the FG-900G or FG-3000F. Carrier and hyperscale environments use the FG-7121F chassis. Our engineers will size the right model based on your actual traffic profile and inspection requirements.
Yes. Our certified Fortinet engineers offer pre-shipment configuration services that tune firewall policies, VPN tunnels, SD-WAN rules, and high-availability settings to your environment before the appliance leaves our facility. We also offer ongoing managed firewall services covering firmware management, monitoring, and change request handling.
In-stock models ship the same day when ordered by 3 PM EST. Larger chassis systems and custom configurations may require a short lead time. Our sales team confirms stock availability and lead time for your specific model and licensing bundle before the order is placed.
Not sure which Fortinet Enterprise Firewall is right for you?
Tell us your user count, internet circuit speed, and which threat services you need covered. A certified Fortinet engineer reaches back within one business hour with a model recommendation and pricing sized to your actual environment.
Get a Sizing Recommendation
Login and Registration Form
Existing User