In short. Size a FortiGate by Threat Protection Throughput, not Firewall Throughput: the gap between these two datasheet lines can be tenfold. If you plan HTTPS decryption, use SSL Inspection Throughput and keep 1.5 to 2 times headroom over peak traffic. Also check RJ45 and SFP+ ports, concurrent sessions, IPsec performance and HA support. IPS, antivirus and web filtering subscriptions renew annually; logs need FortiAnalyzer, and several devices need FortiManager.

FortiGate is a next-generation firewall, and choosing a model works differently from choosing a switch or a server. The number in the model name says almost nothing, and datasheet throughput depends on which security features are enabled. Here is how to get it right.

The main trap: which throughput to look at

Every datasheet lists several throughput figures, and they differ several times over:

  • Firewall Throughput is plain rule-based filtering. The largest number on the sheet and the least useful for planning.
  • IPS Throughput is measured with intrusion prevention enabled.
  • NGFW Throughput adds application control on top of IPS.
  • Threat Protection Throughput is the full stack: IPS, antivirus, application control. This is the figure to size by, because these features are why you buy an NGFW.
  • SSL Inspection Throughput is measured with TLS decryption on. The heaviest operation and the most common reason a new device turns out too slow.

The gap between the first and last line can be tenfold. A model chosen by Firewall Throughput hits its ceiling the moment inspection is enabled.

A separate word on SSL inspection

Today most traffic is encrypted. Without TLS decryption, antivirus and web filtering see only the destination address and work at half capacity. If you plan full protection, size your headroom by SSL Inspection Throughput and multiply the required value by at least 1.5 to 2 relative to today's peak traffic.

Hardware acceleration

FortiGate's advantage over software firewalls is the purpose-built processors on the board. Processing does not fall entirely on the general-purpose CPU, so the appliance holds its rated figures under load. Entry-level models have simplified accelerators, higher-end models full ones. Against a firewall on an ordinary server this is the key argument: where the server platform degrades once inspection is on, the hardware pipeline keeps going.

What to consider beyond throughput

ParameterWhy it matters
Number and type of portsCopper RJ45 and optical SFP/SFP+. Check that the physical layer matches your switches
Concurrent sessionsCritical with a large user base and NAT
IPsec VPN performanceA separate figure. Relevant for branch connectivity and remote access
Number of VPN tunnelsLimited by the model. Count your branches and remote employees
HA supportA two-unit cluster is mandatory on the perimeter if downtime is unacceptable
Local storageDetermines whether logs can be kept on the device itself

Logs: why a FortiGate alone is not enough

A firewall generates a large volume of events, and built-in storage covers only a short period. For incident investigation and reporting you need FortiAnalyzer: it collects logs, builds reports and lets you reconstruct an event after the fact. With several devices, add FortiManager for centralised policy management. Without it, configuring ten branches by hand becomes a source of errors.

Licences

The appliance is only part of the cost of ownership. Security features run on subscription: IPS, antivirus, web filtering, application control, sandboxing. It is renewed annually. When it expires, the device keeps filtering by its rules but stops receiving signature updates. Budget the renewal from the start. It is not an option but a condition for the protection to work.

Typical architectures

  • Small office: one entry-level appliance, a basic security bundle licence, logs kept locally or in the cloud.
  • Company with its own server room: an HA cluster of two appliances on the perimeter, FortiAnalyzer for logs, FortiAP access points under unified management.
  • Distributed organisation with branches: a FortiGate at every site, IPsec or SD-WAN links, centralised management via FortiManager, unified analytics in FortiAnalyzer.

We will match a model to your real traffic profile and price it with licences for the term you need: info@itsmart.uz or Telegram.

Related guides and tools: FortiGate for the office.


05/02/2026 88
Related articles