FortiGate 3000F
397 Gbps firewall and 230 million Hyperscale sessions
- Threat protection
- 33 Gbps
- Firewall throughput
- 397 Gbps
- IPsec VPN
- 105 Gbps
- Concurrent sessions
- 70 Million
Front panel
- QSFP cage
- RJ45 copper
The 3000F doubles the 2600F's firewall throughput to 397 Gbps and, with Hyperscale, reaches 230 million concurrent sessions and 3 million new sessions per second. Six 100GE QSFP28 ports and eighteen 10GE copper ports in 2 RU.
Be careful here: the 3000G is the same chassis generation-refreshed, and it delivers 80 Gbps threat protection against the 3000F's 33 — nearly two and a half times the inspected capacity for the same 2 RU and the same 397 Gbps of raw forwarding. Unless you have a specific reason to buy the F, the G is the better purchase.
Highlights
- 397 Gbps firewall throughput, 105 Gbps IPsec
- Hyperscale: 230M sessions, 3M new sessions/sec
- 6x 100GE QSFP28, 18x 10GE RJ45
- 500 VDOMs, DC power variant
Typical deployments
- High-volume forwarding with selective inspection
- Hyperscale session-table workloads in a data centre
- Estates already standardised on the F generation
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 397 / 389 / 221 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 105 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 36 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 34 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 33 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 29 Gbps |
| Application control throughput (HTTP 64K) | 115 Gbps |
| Firewall latency | 3.92 µs |
Capacity
| Concurrent sessions | 70 Million / 230 Million |
|---|---|
| New sessions / second | 870,000 / 3 Million |
| Firewall policies | 200,000 |
| Max gateway-to-gateway IPsec tunnels | 40,000 |
| Max client-to-gateway IPsec tunnels | 200,000 |
| SSL VPN throughput | 11 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 30,000 |
| Virtual domains (default / max) | 10 / 500 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 4,096 / 2,048 |
|---|---|
| Max managed FortiSwitches | 300 |
| Max FortiTokens | 20,000 |
Hardware
| Interfaces | 6x 100GE QSFP28/40GE QSFP+, 18x 10GE RJ45, 2x GE RJ45 |
|---|---|
| Local storage | 2x 960 GB (3001F) |
| Power supplies | Dual PS |
| Form factor | 2 RU |
| Variants | DC |
Model-specific caveats
Fortinet conditions that apply to this model in particular. Worth reading before you order.
| Note 1 | The second figure requires a Hyperscale license. |
|---|
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 3000G
Same chassis as the 3000F, two and a half times the inspected throughput
FortiGate 3200F
400GE QSFP-DD optics with 45 Gbps threat protection
FortiGate 2600F
The entry point to the high-end range — 25 Gbps inspected in 2 RU