FortiGate 30G
The smallest current-generation FortiGate — full FortiOS for a micro site
- Threat protection
- 500 Mbps
- Firewall throughput
- 4 Gbps
- IPsec VPN
- 3.5 Gbps
- Concurrent sessions
- 600,000
Front panel
- RJ45 copper
The 30G is the entry point to the FortiGate range and the current-generation replacement for the ageing 30-series. Four gigabit copper ports, 500 Mbps of threat protection throughput and 30 GB of onboard storage for local logging. It runs the same FortiOS as a 4800F.
Right for a micro site — a small retail unit, a remote office of a handful of people, a kiosk — on a connection up to a few hundred megabits. It is the wrong choice anywhere you need VDOMs (it publishes none), SSL VPN (it publishes no throughput figure), or more than eight FortiSwitches behind it.
Highlights
- 500 Mbps threat protection with everything switched on
- 30 GB onboard storage — local logging without a FortiAnalyzer
- Manages up to 8 FortiSwitches and 16 FortiAPs
- WiFi variant available as the FortiWiFi 30G
Typical deployments
- Single-till retail sites and franchise locations
- Two-to-ten person remote offices
- Replacing an unmanaged consumer router at a branch with something you can actually write policy on
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 4 / 4 / 3.9 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 3.5 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 800 Mbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 570 Mbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 500 Mbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 400 Mbps |
| Application control throughput (HTTP 64K) | 830 Mbps |
| Firewall latency | 2.87 µs |
Capacity
| Concurrent sessions | 600,000 |
|---|---|
| New sessions / second | 30,000 |
| Firewall policies | 2,000 |
| Max gateway-to-gateway IPsec tunnels | 200 |
| Max client-to-gateway IPsec tunnels | 250 |
| SSL VPN throughput | — |
| Concurrent SSL VPN users (recommended max, tunnel mode) | — |
| Virtual domains (default / max) | — |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 16 / 8 |
|---|---|
| Max managed FortiSwitches | 8 |
| Max FortiTokens | 500 |
Hardware
| Interfaces | 4x GE RJ45 |
|---|---|
| Local storage | 30 GB (31G) |
| Power supplies | Single AC PS |
| Form factor | Desktop |
| Variants | WiFi |
Model-specific caveats
Fortinet conditions that apply to this model in particular. Worth reading before you order.
| Note 1 | Proxy features have limited support on this model — check the data sheet before relying on them. |
|---|
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 40F
Five-port desktop NGFW with LTE variant — the long-serving branch workhorse
FortiGate 50G
The variant-rich branch model — WiFi, DSL, SFP, PoE and 5G in one family
FortiGate 60F
Ten-port desktop NGFW — the most widely deployed FortiGate ever built