Fortinet FortiGate 400G / 401G.
Built for large enterprise. Powered by AI.
The FortiGate 400G and 401G pack 145 Gbps of firewall throughput, 25 Gbps of IPS performance, and 28
million concurrent session capacity into a single 1RU chassis. Fortinet's NP7 network processor and CP10
content processor do the heavy lifting so your team is not the bottleneck. The 401G adds 960 GB of onboard
SSD for local log retention without a separate appliance.
Expert Pre-Sales AdviceCertified reps reply in 1 hour.
Config & Managed ServicesSkip the setup. We'll do it.
POs · Tax-Exempt · Net 30Welcomed for Corp, Edu, & Gov.
Same-Day ShippingOrder by 3pm EST, ships today.
Specifications
FortiGate 400G / 401G at a Glance
Performance
Firewall throughput up to 145 Gbps at 64-byte UDP, with 2.51 microsecond latency. IPS runs at 25 Gbps
with logging enabled. NGFW throughput reaches 14 Gbps with firewall, IPS, and application control active
simultaneously. Threat protection throughput is 13 Gbps. Application control throughput hits 50 Gbps.
All performance is hardware accelerated by Fortinet's NP7 and CP10 ASICs.
Interfaces
4x 25/10 GE SFP28/SFP+ slots. 4x 10/GE SFP+ FortiLink slots for FortiSwitch integration. 16x 1GE SFP
slots. 8x 5/2.5/GE RJ45 ports. 1x 2.5/GE RJ45 HA port. 1x GE RJ45 management port. Two SFP SX
transceivers are included. Total of 32 data-plane interfaces in a single 1RU chassis.
VPN and Sessions
28 million concurrent TCP sessions. 580,000 new sessions per second. IPsec VPN throughput at 55 Gbps
using AES256-SHA256, supporting up to 2,000 gateway-to-gateway tunnels and 50,000 client-to-gateway
tunnels. SSL-VPN throughput at 6.1 Gbps with up to 5,000 concurrent tunnel-mode users. SSL inspection
throughput at 11.5 Gbps. Up to 10,000 firewall policies.
Hardware and Storage
1RU rack mount, 1.75 x 17.0 x 13.5 inches, 7.72 lbs. Dual non-swappable AC power supplies with 1+1
redundancy. Trusted Platform Module (TPM) for hardware-based cryptographic key storage. FortiSentry
out-of-band integrity monitoring. The 401G includes 960 GB of onboard SSD storage (2x 480 GB) for local
log retention. Operating temperature 32 to 113 degrees F.
Comparing across the Fortinet enterprise lineup?
The FortiGate 400G / 401G sits in the large enterprise tier. If you are weighing it against a smaller or
larger FortiGate model, our enterprise series page lays out the full lineup by throughput, session count,
and form factor.
The hardware is identical except for onboard storage. The FortiGate 400G ships with
no internal storage. The FortiGate 401G adds 960 GB of onboard SSD (two 480 GB drives) for local log
retention, which means you can store and search logs directly on the appliance without a separate
FortiAnalyzer. Every other spec, including throughput, interfaces, ASICs, and power supplies, is
exactly the same between the two models.
Raw firewall throughput reaches 145 Gbps at 64-byte UDP. With security services
active: IPS runs at 25 Gbps, NGFW (firewall plus IPS plus application control) runs at 14 Gbps, and
full threat protection (adding malware inspection) runs at 13 Gbps. All of these figures include
logging, which is how Fortinet publishes them in the official datasheet. The NP7 and CP10 ASICs
provide the hardware acceleration that keeps performance high even with multiple inspection layers
running at once.
The FortiGate 400G / 401G is sized for up to 5,000 users. It supports 28 million
concurrent TCP sessions and 580,000 new sessions per second, so it handles environments with heavy
traffic loads and large numbers of simultaneous connections without degrading. It also supports up to
5,000 concurrent SSL-VPN tunnel-mode users, 512 managed FortiAPs, and 96 FortiSwitches via FortiLink.
The Unified Threat Protection (UTP) bundle covers IPS, antivirus and botnet
protection, URL and DNS filtering, video filtering, application control, and FortiCare Premium 24x7
support. The Enterprise Protection bundle adds AI-based inline malware prevention, data loss
prevention, anti-spam, attack surface security for IoT devices, and FortiSOC as a service. Application
control and inline CASB are included with any active FortiCare subscription at no extra charge. All
bundles are available in 1, 3, and 5 year terms.
Yes. Secure SD-WAN and universal ZTNA are built into FortiOS and available on all
FortiGate firewalls at no additional license cost. SD-WAN gives you WAN path selection, application
steering, and quality-of-experience monitoring from the same interface you use to manage your security
policy. ZTNA enforces per-session application access verification for both agent-based (FortiClient)
and agentless proxy-portal access, covering users whether they are on your network or working
remotely.
Yes. Our Fortinet Expert certified engineers offer a pre-ship configuration service
that covers 25 or more components tuned to your environment, an analysis call before we touch the
device, remote deployment assistance, and 7 calendar days of post-deployment support. The appliance
arrives ready to plug in, not ready to spend a week figuring out. You can add configuration service to
any hardware order during checkout or by contacting our team.
Not sure the 400G / 401G is the right fit?
Tell us your ISP connection speed, user count, and whether you need local log storage. One of our
Fortinet Expert certified engineers will come back with a specific model recommendation, licensing
guidance, and a quote, usually within one business hour.
Login and Registration Form
Existing User