Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-3000G

FortiGate 3000G

Same chassis as the 3000F, two and a half times the inspected throughput

Threat protection
80 Gbps
Firewall throughput
397 Gbps
IPsec VPN
105 Gbps
Concurrent sessions
88 Million

Front panel

Front panel layout for the FortiGate 3000G: 6 × 100G QSFP28, 16 × 25G SFP28, 18 × 10G RJ45, 2 × 1G RJ456× 100G12× 25G4× 25G14× 10G4× 10G2× 1G
42 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • QSFP cage
  • SFP cage
  • RJ45 copper

The 3000G is the clearest illustration of what the G generation changed. Firewall throughput is essentially identical to the 3000F at 397 Gbps, but threat protection rises from 33 to 80 Gbps, IPS from 36 to 90 Gbps, and SSL inspection from 29 to 75 Gbps — in the same 2 RU footprint.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

The strongest value in the high-end range for inspection-heavy data-centre work. It adds sixteen 25GE SFP28 ports over the 3000F and raises the session table to 88 million natively. If you are refreshing an F-generation 3000-class firewall, this is a substantially different box, not an incremental one.

Highlights

  • 80 Gbps threat protection — 2.4x the 3000F
  • 75 Gbps SSL inspection, 159 Gbps application control
  • 6x 100GE QSFP28 plus 16x 25GE SFP28
  • 88M sessions natively, 230M with Hyperscale

Typical deployments

  • Data-centre perimeter with full inspection at scale
  • Refreshing an ageing 3000F or 3200F
  • Internal segmentation between high-throughput zones
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)397 / 394 / 234 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.105 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.90 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.85 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.80 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.75 Gbps
Application control throughput (HTTP 64K)159 Gbps
Firewall latency3.7 µs

Capacity

Capacity
Concurrent sessions88 Million / 230 Million
New sessions / second1.1 Million / 3 Million
Firewall policies200,000
Max gateway-to-gateway IPsec tunnels40,000
Max client-to-gateway IPsec tunnels200,000
SSL VPN throughput9 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)30,000
Virtual domains (default / max)10 / 500

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)4,096 / 2,048
Max managed FortiSwitches300
Max FortiTokens20,000

Hardware

Hardware
Interfaces6x 100GE QSFP28/40GE QSFP+, 16x 25GE SFP28, 18x 10GE RJ45, 2x GE RJ45
Local storage2x 960 GB (3001G)
Power suppliesDual PS
Form factor2 RU
Variants

Model-specific caveats

Fortinet conditions that apply to this model in particular. Worth reading before you order.

Model-specific caveats
Note 1The second figure requires a Hyperscale license.

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare