Buying a FortiGate firewall is not just picking a box. The right decision rests on Threat Protection throughput, concurrent sessions, SSL VPN users, FortiGuard licensing, HA needs, and a 3–5 year total cost of ownership (TCO). An undersized FortiGate chokes once IPS/AV is enabled; an under-licensed unit feels like “we have a firewall, but not real protection.”
This guide is written for:
- IT and security managers planning a FortiGate investment
- Procurement and operations teams comparing vendor quotes
- Network engineers refreshing an aging edge firewall
- Decision makers budgeting edge security for ISO 27001, KVKK, and Law No. 5651 logging
Quick Summary
- The primary buying metric is Threat Protection throughput, not raw firewall throughput.
- Do not choose a model before measuring users, branches, VPN load, and peak sessions.
- FortiGuard licensing can be
30-50%of multi-year TCO. - For critical edges, plan Active-Passive HA with matching licenses.
- Interface needs (1G/10G/SFP), form factor, and management model must appear in the quote.
- A
1 + 3or1 + 5year license/support bundle reduces year-two renewal surprises.
Table of Contents
- Before You Buy: What Is FortiGate?
- Requirements: What Should You Measure?
- Model Selection: Throughput and Capacity
- Licensing and FortiGuard Bundles
- HA, Interfaces, and Form Factor
- TCO: 3–5 Year Cost
- Quote Checklist
- Most Common Buying Mistakes
- Related Articles
- Checklist
- Next Step with LeonX
- Frequently Asked Questions
- Sources

Image: Wikimedia Commons - Juniper SRX210 front view (example enterprise firewall form factor).
Before You Buy: What Is FortiGate?
FortiGate is Fortinet’s FortiOS-based NGFW product line. For product definition, see What Is a FortiGate Firewall?; for the broader ecosystem, see What Is Fortinet and What Does It Do?. This guide focuses on the purchase decision: sizing, licensing, HA, and TCO.
Reminder: FortiGate is not “appliance + cable” alone. Without policy, UTM profiles, VPN, and logging design, the investment is incomplete. For packet/policy behavior, see How Does a Fortinet Firewall Work?.
Requirements: What Should You Measure?
Put at least these numbers in the buying brief:
| Metric | Why it matters | Typical source |
|---|---|---|
| Peak internet bandwidth | Edge capacity baseline | ISP / packet capture |
| Threat Protection need | Real load with IPS+AV | Vendor datasheet |
| Concurrent sessions | Busy office/servers | Current firewall counters |
| Concurrent SSL VPN users | Remote-access sizing | HR / IT inventory |
| Site-to-site tunnel count | IPsec capacity | Branch inventory |
| VLAN / zone count | Segmentation complexity | Network diagram |
| Log retention (days/years) | Analyzer / SIEM / 5651 | Compliance policy |
If you skip measurement, “buy one size up” can still be wrong—and expensive. Planned SSL inspection can raise throughput need by 2-4x; see FortiGate SSL Inspection.
Model Selection: Throughput and Capacity
Datasheets list multiple throughput numbers. Buying priority:
- Threat Protection / NGFW throughput (IPS + AV + app control on)
- Firewall throughput (reference only)
- IPsec VPN throughput
- SSL VPN concurrent users
- Concurrent sessions / new sessions per second
Rough class framing (always validate against the datasheet):
| Scenario | Rough Threat Protection need | Notes |
|---|---|---|
Small office (10-50 users) | 200-800 Mbps | Single box + basic UTM |
| Mid-size / multi-branch hub | 1-3 Gbps | VPN + segmentation |
| Large campus / DC edge | 5-20+ Gbps | HA + 10G interfaces |
For vendor comparison context, see Fortinet vs Palo Alto vs Cisco.
Licensing and FortiGuard Bundles
Hardware price alone misleads. FortiGuard bundles (threat intel, web filtering, AV, sandbox, and more) define protection depth.
Add to the purchase line items:
- License term:
1,3, or5years - Bundle scope: which security services are included?
- Renewal estimate (year
2+) - License symmetry for HA secondary unit
- FortiAnalyzer / FortiManager if needed (separate SKUs)
An unlicensed FortiGate can still route and firewall basically, but enterprise IPS/web-filter layers weaken or stop. For compliance planning, include FortiGate Access Control for ISO 27001 and ISO 27001 Network Security: Firewall and VPN.
HA, Interfaces, and Form Factor
HA
If internet/VPN downtime is unacceptable, buy Active-Passive HA. You need two identical models, matching FortiOS, and matching license levels. See FortiGate HA Installation.
Interfaces
- Enough
1G/10G/ SFP for WAN/LAN - HA heartbeat ports (preferably
2) - Dedicated management port
- Bypass / redundant path needs
Form factor
Desktop (small office) vs 1U rack (enterprise). Cooling, noise, and rack space belong in the quote notes.
VPN and remote access
SSL VPN and site-to-site needs directly affect model capacity. See SSL VPN Setup and Site-to-Site VPN.
TCO: 3–5 Year Cost
Simple formula:
TCO ≈ Hardware + FortiGuard (N years) + (HA second unit + licenses) + Central logging/management + Deployment/ops + Power/rack
| Line item | Often forgotten |
|---|---|
| Hardware | x2 for HA |
| Licenses | Renewal price uplift |
| Analyzer/SIEM | 5651 retention window |
| Deployment | Policy + migration effort |
| Training | Ops team readiness |
| Outage risk | Cost of non-HA edge |
Pro Tip: Compare quotes on
Threat Protection capacity + 3-year FortiGuard + HA scenario, not “cheapest appliance.” Otherwise year2license shock is almost guaranteed.
Quote Checklist
Ask the partner/reseller for:
- Recommended model datasheet (Threat Protection row highlighted)
- SKU list: hardware + FortiGuard bundle + term
- HA secondary unit and license symmetry
- FortiAnalyzer / FortiManager SKUs if required
- Lead time and FortiCare support level
- Deployment / migration scope (optional but critical)
3and5year renewal price estimates
Most Common Buying Mistakes
- Sizing on firewall throughput while ignoring Threat Protection
- Buying
1year of license with no renewal budget - Running a critical edge without HA
- Underestimating SSL VPN concurrency
- Deferring logging/analytics as “later”
- Ignoring support/license risk on gray-market hardware
If Security Fabric and central visibility are on the roadmap, add What Is Fortinet Security Fabric?.
Related Articles
- What Is a FortiGate Firewall?
- What Is Fortinet and What Does It Do?
- How Does a Fortinet Firewall Work?
- Fortinet Firewall vs Palo Alto vs Cisco
- FortiGate HA Installation Guide
- FortiGate SSL VPN Setup
- ISO 27001 Network Security: Firewall and VPN
Checklist
- Peak bandwidth, sessions, VPN, and branch counts measured
- Threat Protection throughput requirement set
- FortiGuard package and
1/3/5year term chosen - HA decided yes/no
- Interfaces (1G/10G/SFP) and form factor defined
- Central logging / 5651 retention budgeted
-
3–5 yearTCO table built - Quote SKUs cross-checked against datasheet
Next Step with LeonX
A wrong FortiGate model or incomplete license cuts both performance and security. LeonX supports sizing, licensing recommendations, and deployment planning under Hardware and Software Solutions, especially Router, Switch and Firewall Deployment Service and Network Security, Firewall and IPS/IDS Solutions. For discovery or a proposal, continue through Contact.
Frequently Asked Questions
What is the most important metric when buying FortiGate?
Threat Protection (NGFW) throughput. It reflects real capacity with IPS/AV/web filter enabled; raw firewall throughput can mislead.
Can I buy FortiGate without FortiGuard?
The appliance may run, but enterprise threat prevention depends on FortiGuard services. Production without current licenses is high risk.
Is HA mandatory?
For critical edge and VPN paths, strongly recommended. A single appliance failure drops internet and VPN together. HA needs matching model, firmware, and license level.
Should I buy 3-year or 5-year licenses?
3 years is a common budget/predictability balance. 5 years can lower unit cost. Ask for renewal pricing in the quote either way.
What should happen right after purchase?
Build zones + default-deny, restrict admin access, activate FortiGuard, point logs to a central target, and test HA sync if applicable. Do not start with any-any allow.


