Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-1000F

FortiGate 1000F

100GE QSFP28 optics and 100,000 firewall policies in 2 RU

Threat protection
13 Gbps
Firewall throughput
198 Gbps
IPsec VPN
55 Gbps
Concurrent sessions
7.5 Million

Front panel

Front panel layout for the FortiGate 1000F: 2 × 100G QSFP28, 8 × 25G SFP28, 16 × 10G SFP+, 8 × 10G RJ45, 1 × 2.5G RJ45, 1 × 1G RJ452× 100G8× 25G8× 10G8× 10G8× 10G1× 2.5G1× 1G
36 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • QSFP cage
  • SFP cage
  • RJ45 copper

The 1000F introduces 100GE QSFP28 optics and a large policy and tunnel scale — 100,000 firewall policies, 20,000 gateway-to-gateway and 100,000 client-to-gateway IPsec tunnels, and up to 250 VDOMs. Firewall throughput is 198 Gbps with 13 Gbps threat protection.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

This is a scale box rather than an inspection box. Its threat protection matches the far smaller 400G, but its tunnel counts are 10x and 2x higher respectively and its VDOM ceiling is 250 against 50. Buy it for VPN concentration, multi-tenancy and policy scale — not for deep inspection throughput.

Highlights

  • 2x 100GE QSFP28 plus 8x 25GE SFP28
  • 100,000 firewall policies, 250 VDOMs
  • 20,000 site-to-site and 100,000 client IPsec tunnels
  • 20,000 FortiTokens

Typical deployments

  • Large hub-and-spoke VPN concentrator terminating thousands of branches
  • Multi-tenant service provider deployments needing many VDOMs
  • Data-centre edge with 100GE uplinks
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)198 / 196 / 134 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.55 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.19 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.15 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.13 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.10 Gbps
Application control throughput (HTTP 64K)44 Gbps
Firewall latency3.45 µs

Capacity

Capacity
Concurrent sessions7.5 Million
New sessions / second650,000
Firewall policies100,000
Max gateway-to-gateway IPsec tunnels20,000
Max client-to-gateway IPsec tunnels100,000
SSL VPN throughput5.3 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)10,000
Virtual domains (default / max)10 / 250

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)4,096 / 2,048
Max managed FortiSwitches196
Max FortiTokens20,000

Hardware

Hardware
Interfaces2x 100GE QSFP28, 8x 25GE SFP28, 16x 10GE SFP+, 8x 10GE RJ45, 1x 2.5GE RJ45, 1x GE RJ45
Local storage960 GB (1001F)
Power suppliesDual PS
Form factor2 RU
Variants

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare