Back to Blog
Hardware & Software

FortiGate Firewall Buying Guide: Model, License, and TCO (2026)

FortiGate Firewall Buying Guide: Model, License, and TCO (2026)
How to buy a FortiGate firewall the right way: Threat Protection throughput, VPN capacity, FortiGuard licensing, HA, and a practical 3–5 year TCO checklist.
Published
July 24, 2026
Updated
July 24, 2026
Reading Time
13 min read
Author
LeonX Expert Team

Buying a FortiGate firewall is not just picking a box. The right decision rests on Threat Protection throughput, concurrent sessions, SSL VPN users, FortiGuard licensing, HA needs, and a 3–5 year total cost of ownership (TCO). An undersized FortiGate chokes once IPS/AV is enabled; an under-licensed unit feels like “we have a firewall, but not real protection.”

This guide is written for:

  • IT and security managers planning a FortiGate investment
  • Procurement and operations teams comparing vendor quotes
  • Network engineers refreshing an aging edge firewall
  • Decision makers budgeting edge security for ISO 27001, KVKK, and Law No. 5651 logging

Quick Summary

  • The primary buying metric is Threat Protection throughput, not raw firewall throughput.
  • Do not choose a model before measuring users, branches, VPN load, and peak sessions.
  • FortiGuard licensing can be 30-50% of multi-year TCO.
  • For critical edges, plan Active-Passive HA with matching licenses.
  • Interface needs (1G/10G/SFP), form factor, and management model must appear in the quote.
  • A 1 + 3 or 1 + 5 year license/support bundle reduces year-two renewal surprises.

Table of Contents

FortiGate firewall buying guide

Image: Wikimedia Commons - Juniper SRX210 front view (example enterprise firewall form factor).

Before You Buy: What Is FortiGate?

FortiGate is Fortinet’s FortiOS-based NGFW product line. For product definition, see What Is a FortiGate Firewall?; for the broader ecosystem, see What Is Fortinet and What Does It Do?. This guide focuses on the purchase decision: sizing, licensing, HA, and TCO.

Reminder: FortiGate is not “appliance + cable” alone. Without policy, UTM profiles, VPN, and logging design, the investment is incomplete. For packet/policy behavior, see How Does a Fortinet Firewall Work?.

Requirements: What Should You Measure?

Put at least these numbers in the buying brief:

MetricWhy it mattersTypical source
Peak internet bandwidthEdge capacity baselineISP / packet capture
Threat Protection needReal load with IPS+AVVendor datasheet
Concurrent sessionsBusy office/serversCurrent firewall counters
Concurrent SSL VPN usersRemote-access sizingHR / IT inventory
Site-to-site tunnel countIPsec capacityBranch inventory
VLAN / zone countSegmentation complexityNetwork diagram
Log retention (days/years)Analyzer / SIEM / 5651Compliance policy

If you skip measurement, “buy one size up” can still be wrong—and expensive. Planned SSL inspection can raise throughput need by 2-4x; see FortiGate SSL Inspection.

Model Selection: Throughput and Capacity

Datasheets list multiple throughput numbers. Buying priority:

  1. Threat Protection / NGFW throughput (IPS + AV + app control on)
  2. Firewall throughput (reference only)
  3. IPsec VPN throughput
  4. SSL VPN concurrent users
  5. Concurrent sessions / new sessions per second

Rough class framing (always validate against the datasheet):

ScenarioRough Threat Protection needNotes
Small office (10-50 users)200-800 MbpsSingle box + basic UTM
Mid-size / multi-branch hub1-3 GbpsVPN + segmentation
Large campus / DC edge5-20+ GbpsHA + 10G interfaces

For vendor comparison context, see Fortinet vs Palo Alto vs Cisco.

Licensing and FortiGuard Bundles

Hardware price alone misleads. FortiGuard bundles (threat intel, web filtering, AV, sandbox, and more) define protection depth.

Add to the purchase line items:

  • License term: 1, 3, or 5 years
  • Bundle scope: which security services are included?
  • Renewal estimate (year 2+)
  • License symmetry for HA secondary unit
  • FortiAnalyzer / FortiManager if needed (separate SKUs)

An unlicensed FortiGate can still route and firewall basically, but enterprise IPS/web-filter layers weaken or stop. For compliance planning, include FortiGate Access Control for ISO 27001 and ISO 27001 Network Security: Firewall and VPN.

HA, Interfaces, and Form Factor

HA

If internet/VPN downtime is unacceptable, buy Active-Passive HA. You need two identical models, matching FortiOS, and matching license levels. See FortiGate HA Installation.

Interfaces

  • Enough 1G / 10G / SFP for WAN/LAN
  • HA heartbeat ports (preferably 2)
  • Dedicated management port
  • Bypass / redundant path needs

Form factor

Desktop (small office) vs 1U rack (enterprise). Cooling, noise, and rack space belong in the quote notes.

VPN and remote access

SSL VPN and site-to-site needs directly affect model capacity. See SSL VPN Setup and Site-to-Site VPN.

TCO: 3–5 Year Cost

Simple formula:

TCO ≈ Hardware + FortiGuard (N years) + (HA second unit + licenses) + Central logging/management + Deployment/ops + Power/rack

Line itemOften forgotten
Hardwarex2 for HA
LicensesRenewal price uplift
Analyzer/SIEM5651 retention window
DeploymentPolicy + migration effort
TrainingOps team readiness
Outage riskCost of non-HA edge

Pro Tip: Compare quotes on Threat Protection capacity + 3-year FortiGuard + HA scenario, not “cheapest appliance.” Otherwise year 2 license shock is almost guaranteed.

Quote Checklist

Ask the partner/reseller for:

  1. Recommended model datasheet (Threat Protection row highlighted)
  2. SKU list: hardware + FortiGuard bundle + term
  3. HA secondary unit and license symmetry
  4. FortiAnalyzer / FortiManager SKUs if required
  5. Lead time and FortiCare support level
  6. Deployment / migration scope (optional but critical)
  7. 3 and 5 year renewal price estimates

Most Common Buying Mistakes

  • Sizing on firewall throughput while ignoring Threat Protection
  • Buying 1 year of license with no renewal budget
  • Running a critical edge without HA
  • Underestimating SSL VPN concurrency
  • Deferring logging/analytics as “later”
  • Ignoring support/license risk on gray-market hardware

If Security Fabric and central visibility are on the roadmap, add What Is Fortinet Security Fabric?.

Related Articles

Checklist

  • Peak bandwidth, sessions, VPN, and branch counts measured
  • Threat Protection throughput requirement set
  • FortiGuard package and 1/3/5 year term chosen
  • HA decided yes/no
  • Interfaces (1G/10G/SFP) and form factor defined
  • Central logging / 5651 retention budgeted
  • 3–5 year TCO table built
  • Quote SKUs cross-checked against datasheet

Next Step with LeonX

A wrong FortiGate model or incomplete license cuts both performance and security. LeonX supports sizing, licensing recommendations, and deployment planning under Hardware and Software Solutions, especially Router, Switch and Firewall Deployment Service and Network Security, Firewall and IPS/IDS Solutions. For discovery or a proposal, continue through Contact.

Frequently Asked Questions

What is the most important metric when buying FortiGate?

Threat Protection (NGFW) throughput. It reflects real capacity with IPS/AV/web filter enabled; raw firewall throughput can mislead.

Can I buy FortiGate without FortiGuard?

The appliance may run, but enterprise threat prevention depends on FortiGuard services. Production without current licenses is high risk.

Is HA mandatory?

For critical edge and VPN paths, strongly recommended. A single appliance failure drops internet and VPN together. HA needs matching model, firmware, and license level.

Should I buy 3-year or 5-year licenses?

3 years is a common budget/predictability balance. 5 years can lower unit cost. Ask for renewal pricing in the quote either way.

What should happen right after purchase?

Build zones + default-deny, restrict admin access, activate FortiGuard, point logs to a central target, and test HA sync if applicable. Do not start with any-any allow.

Sources

Internal Link Path

Continue to the most relevant service pages

Use the links below to move from this article to the primary service, the most relevant detail page and the contact flow.

Share this article

Related Posts

Discover more on similar topics

FortiGate Logging ISO 27001 Requirements (2026 Guide)
Hardware & Software
2026-08-01
14 min read

FortiGate Logging ISO 27001 Requirements (2026 Guide)

FortiGate logging for ISO 27001: which logs, retention, integrity, access rights, reviews, and SoA evidence—with a practical checklist.

Read Article
How to Achieve ISO 27001 Network Security with FortiGate (2026)
Hardware & Software
2026-07-31
14 min read

How to Achieve ISO 27001 Network Security with FortiGate (2026)

Use FortiGate for ISO 27001 network security: segmentation, firewall policy, VPN, logging, admin hardening, and SoA evidence—with a practical checklist.

Read Article
KVKK-Compliant Network Security with FortiGate (2026 Guide)
Hardware & Software
2026-07-30
14 min read

KVKK-Compliant Network Security with FortiGate (2026 Guide)

How to use FortiGate for KVKK-aligned network security: segmentation, access control, VPN, logging, encryption balance, and a practical technical-controls checklist.

Read Article

Subscribe to Our Newsletter

Get the latest insights, trends, and expert advice delivered directly to your inbox. Join our community of IT professionals.

We respect your privacy. Unsubscribe at any time.