FortiGate 120G
First rack-mount model — 1 RU, dual PSUs, 10GE SFP+ and 26 ports
- Threat protection
- 2.8 Gbps
- Firewall throughput
- 39 Gbps
- IPsec VPN
- 35 Gbps
- Concurrent sessions
- 3 Million
Front panel
- SFP cage
- RJ45 copper
The 120G is where the range becomes infrastructure: 1 RU, dual AC power supplies, and 30 interfaces including four 10GE SFP+. It delivers 2.8 Gbps threat protection and 35 Gbps IPsec VPN, and manages 48 FortiSwitches.
Take the 120G over the 90G when you need rack mounting, genuinely redundant power supplies (not just dual inputs), or SFP+ optics. On threat protection the two are close — 2.8 against 2.2 Gbps — so if the site is happy with a desktop box, the 90G is better value. The 120G's real advantages are physical and operational.
Highlights
- 1 RU with dual hot-swap AC power supplies
- 4x 10GE SFP+, 18x GE RJ45, 8x GE SFP
- Manages 48 FortiSwitches, 128 FortiAPs
- 5,000 FortiTokens — 10x the entry-level ceiling
Typical deployments
- Campus edge for a single-building organisation
- Sites needing fibre uplinks to a core switch
- Anywhere a desktop appliance is not acceptable in a rack
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 39 / 39 / 28 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 35 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 5.3 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 3.1 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 2.8 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 3 Gbps |
| Application control throughput (HTTP 64K) | 6.7 Gbps |
| Firewall latency | 3.17 µs |
Capacity
| Concurrent sessions | 3 Million |
|---|---|
| New sessions / second | 140,000 |
| Firewall policies | 10,000 |
| Max gateway-to-gateway IPsec tunnels | 2,000 |
| Max client-to-gateway IPsec tunnels | 16,000 |
| SSL VPN throughput | 1.5 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 500 |
| Virtual domains (default / max) | 10 / 10 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 128 / 64 |
|---|---|
| Max managed FortiSwitches | 48 |
| Max FortiTokens | 5,000 |
Hardware
| Interfaces | 4x 10GE SFP+, 18x GE RJ45, 8x GE SFP |
|---|---|
| Local storage | 480 GB (121G) |
| Power supplies | Dual AC PS |
| Form factor | 1 RU |
| Variants | — |
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 200G
11 million sessions and 27.8 Gbps application control in 1 RU
FortiGate 90G
28 Gbps firewall and 25 Gbps IPsec in a desktop chassis — the top of entry-level
FortiGate 400G
164 Gbps firewall with 25GE SFP28 optics — the mid-range entry point