Back to Blog
Hardware & Software

How to Choose a FortiGate Model: Sizing Guide (2026)

How to Choose a FortiGate Model: Sizing Guide (2026)
How to choose the right FortiGate model using Threat Protection throughput, sessions, VPN, interfaces, and HA in a practical decision matrix.
Published
July 25, 2026
Updated
July 25, 2026
Reading Time
13 min read
Author
LeonX Expert Team

Choosing a FortiGate model is not picking the highest firewall throughput line and buying “one size up.” The right choice weighs Threat Protection capacity, concurrent sessions, SSL VPN users, IPsec throughput, interface types (1G/10G/SFP), and HA needs in one matrix. The wrong model chokes with IPS on, drops VPN sessions, or runs out of headroom in 2–3 years.

This guide is written for:

  • Network and security teams deciding FortiGate series/model class
  • IT managers technically filtering reseller quotes
  • Engineers replacing an aging edge firewall
  • Decision makers who need metrics in the buying brief

Quick Summary

  • The primary metric is Threat Protection throughput; raw firewall throughput is reference only.
  • Measure first: peak bandwidth, sessions, VPN, branches, VLAN/zones.
  • Planned SSL inspection can raise capacity needs by 2-4x.
  • Small office, mid-size hub, and campus/DC edge need different classes.
  • For HA, buy two identical models with matching FortiOS and license level.
  • Read this together with the buying / TCO guide.

Table of Contents

How to choose a FortiGate model

Image: Wikimedia Commons - Netgear ProSafe Dual WAN VPN Gigabit Firewall FVS336G (example enterprise firewall form factor).

Why Model Selection Matters

FortiGate is Fortinet’s FortiOS-based NGFW line. For product definition, see What Is a FortiGate Firewall?; for the company ecosystem, see What Is Fortinet?. Model selection answers “which capacity class?”

Wrong-model cost is more than price delta:

  • Latency and user complaints once IPS/AV is enabled
  • Hitting SSL VPN session limits
  • Being stuck on 1G when 10G is required
  • Single point of failure on a critical non-HA edge

Understanding packet/policy behavior also explains why Threat Protection matters: see How Does a Fortinet Firewall Work?.

Step 1: Measure the Need

Write at least these values into the model brief:

MetricExample questionUnit
Peak internetPeak Mbps at busy hour?Mbps / Gbps
Threat ProtectionTarget with IPS+AV on?Mbps / Gbps
Concurrent sessionsPeak sessions on current firewall?count
SSL VPN usersConcurrent remote users?count
IPsec tunnelsBranch / cloud tunnels?count
Interfaces1G or 10G/SFP?port type
HAIs downtime acceptable?yes/no

If you will use SSL inspection, grow capacity further; see FortiGate SSL Inspection. For segmentation complexity, factor in VLAN Configuration.

Step 2: Read Datasheet Rows Correctly

Datasheets list multiple throughput numbers. Read in this order:

  1. Threat Protection / NGFW throughput — primary
  2. IPS throughput — IPS-heavy designs
  3. IPsec VPN throughput — multi-branch
  4. SSL-VPN concurrent users — remote access
  5. Firewall throughput — upper-bound reference only
  6. Concurrent sessions / new sessions/sec — busy office/servers

Pro Tip: Seeing “Firewall 20 Gbps” while Threat Protection is 2 Gbps and buying on the firewall line is the most common mistake. Size on the profiles you will actually enable.

For vendor comparison, use Fortinet vs Palo Alto vs Cisco.

Step 3: Pick a Class by Scenario

Exact SKUs must be validated with datasheets and partner quotes. This table frames class selection:

ScenarioRough Threat ProtectionTypical needs
Small office (10-50 users)200-800 MbpsSingle box, SSL VPN, basic UTM
Mid-size / branch hub1-3 GbpsSite-to-site + segmentation
Campus / DC edge5-20+ GbpsHA, 10G, high sessions

Scenario patterns:

  • Edge + UTM: Prioritize Threat Protection for internet egress and content control.
  • VPN-heavy: SSL VPN / IPsec counts set the ceiling; see SSL VPN, Site-to-Site VPN.
  • High continuity: Budget HA class and dual appliances; see HA Installation.

Step 4: Interfaces, Form Factor, and HA

Correct capacity with wrong interfaces still fails:

  • Enough 1G / 10G / SFP+ for WAN/LAN
  • At least one (preferably two) HA heartbeat ports
  • Dedicated management port
  • Desktop vs 1U rack (noise, cooling, rack space)

Do not separate HA from model choice: Active-Passive needs two identical models. Mixing models as “sort of standby” is not a healthy cluster design.

Step 5: Growth Headroom and Ceiling

Add 12-36 months of growth:

  • User growth %20-40
  • New branch / cloud tunnels
  • Move to SSL inspection
  • Logging/analytics load (FortiAnalyzer / SIEM)

Extreme oversizing is also wrong: licenses and TCO inflate. A balanced approach is about 1.5-2x measured Threat Protection need, aligned with the 3–5 year TCO view in the buying guide.

Compliance controls (ISO 27001 access/logging) still need process, but leave CPU/log headroom. See ISO 27001 Network Security: Firewall and VPN and FortiGate Access Control for ISO 27001.

Decision Matrix

CriterionSuggested weightNotes
Threat Protection capacity35%Primary filter
VPN (SSL + IPsec)20%User/tunnel ceiling
Interfaces / form factor15%10G/SFP/rack
Session capacity10%Peak sessions
HA readiness10%Dual identical units
License/TCO fit10%3–5 years

Score candidates with this matrix; do not rank by price alone.

Most Common Model Selection Mistakes

  • Sizing on firewall throughput while ignoring Threat Protection
  • Measuring without SSL inspection, then enabling it in production
  • Underestimating VPN concurrency
  • Choosing a critical edge without HA
  • Buying a 1G-limited model when 10G is required
  • Skipping measurement and defaulting to “one size up”

If Security Fabric and central visibility are growing, plan management/analytics with the model: What Is Fortinet Security Fabric?.

Related Articles

Checklist

  • Peak bandwidth, sessions, VPN, and branch counts measured
  • Threat Protection target capacity written down
  • SSL inspection impact included (if applicable)
  • Datasheet read with Threat Protection first
  • Scenario class chosen (small / mid / campus)
  • Interfaces and form factor validated
  • HA yes/no and identical dual-model decision made
  • 12-36 month growth headroom cross-checked with TCO

Next Step with LeonX

FortiGate model selection is measurement + datasheet + scenario matrix. LeonX validates requirements and class recommendations under Hardware and Software Solutions, especially Router, Switch and Firewall Deployment Service and Network Security, Firewall and IPS/IDS Solutions. For discovery, continue through Contact.

Frequently Asked Questions

Which datasheet row should I check first?

Threat Protection (NGFW) throughput. It reflects production capacity with IPS/AV/app control enabled.

Is the smallest model always enough for a small office?

No. SSL VPN concurrency, SSL inspection, and ISP speed can exceed a small model. Measure first.

Can HA use two different models?

Active-Passive HA expects an identical model pair. Mixing models as “backup” is not a sound cluster design.

Is buying one size up safe?

Not without measurement. Oversizing inflates license/TCO; undersizing breaks production. About 1.5-2x Threat Protection headroom is a common balance.

How is this different from the buying guide?

Model selection is the technical class/capacity decision; the buying guide covers licenses, TCO, and quote checklists. Use both together.

Sources

Internal Link Path

Continue to the most relevant service pages

Use the links below to move from this article to the primary service, the most relevant detail page and the contact flow.

Share this article

Related Posts

Discover more on similar topics

FortiGate Logging ISO 27001 Requirements (2026 Guide)
Hardware & Software
2026-08-01
14 min read

FortiGate Logging ISO 27001 Requirements (2026 Guide)

FortiGate logging for ISO 27001: which logs, retention, integrity, access rights, reviews, and SoA evidence—with a practical checklist.

Read Article
How to Achieve ISO 27001 Network Security with FortiGate (2026)
Hardware & Software
2026-07-31
14 min read

How to Achieve ISO 27001 Network Security with FortiGate (2026)

Use FortiGate for ISO 27001 network security: segmentation, firewall policy, VPN, logging, admin hardening, and SoA evidence—with a practical checklist.

Read Article
KVKK-Compliant Network Security with FortiGate (2026 Guide)
Hardware & Software
2026-07-30
14 min read

KVKK-Compliant Network Security with FortiGate (2026 Guide)

How to use FortiGate for KVKK-aligned network security: segmentation, access control, VPN, logging, encryption balance, and a practical technical-controls checklist.

Read Article

Subscribe to Our Newsletter

Get the latest insights, trends, and expert advice delivered directly to your inbox. Join our community of IT professionals.

We respect your privacy. Unsubscribe at any time.