Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-3200F

FortiGate 3200F

400GE QSFP-DD optics with 45 Gbps threat protection

Threat protection
45 Gbps
Firewall throughput
387 Gbps
IPsec VPN
105 Gbps
Concurrent sessions
70 Million

Front panel

Front panel layout for the FortiGate 3200F: 4 × 400G QSFP-DD, 12 × 50G SFP56, 4 × 25G SFP28, 2 × 10G RJ454× 400G12× 50G2× 25G2× 25G2× 10G
22 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • QSFP cage
  • SFP cage
  • RJ45 copper

The 3200F is the lowest-cost route to 400GE optics in the FortiGate range, carrying four 400GE QSFP-DD and twelve 50GE SFP56 ports. It delivers 45 Gbps threat protection and 29 Gbps SSL inspection with 70 million concurrent sessions in 2 RU.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

Chosen for its optics rather than its inspection performance. If your spine is 400GE and you need a firewall that can attach to it directly without breakout cables, this is the entry point. On pure inspected throughput the 3000G outperforms it substantially — so if 400GE is not a requirement, look there first.

Highlights

  • 4x 400GE QSFP-DD — the range's cheapest 400GE attachment
  • 12x 50GE SFP56 for spine and leaf uplinks
  • 45 Gbps threat protection, 109 Gbps application control
  • 70 million concurrent sessions

Typical deployments

  • 400GE spine attachment without breakout optics
  • Modern data-centre fabrics standardised on QSFP-DD
  • High-bandwidth segmentation between fabric zones
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)387 / 385 / 178.5 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.105 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.63 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.47 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.45 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.29 Gbps
Application control throughput (HTTP 64K)109 Gbps
Firewall latency3.42 µs

Capacity

Capacity
Concurrent sessions70 Million
New sessions / second800,000
Firewall policies200,000
Max gateway-to-gateway IPsec tunnels40,000
Max client-to-gateway IPsec tunnels200,000
SSL VPN throughput11 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)30,000
Virtual domains (default / max)10 / 500

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)4,096 / 2,048
Max managed FortiSwitches300
Max FortiTokens20,000

Hardware

Hardware
Interfaces4x 400GE QSFP-DD, 12x 50GE SFP56, 4x 25GE SFP28, 2x 10GE RJ45
Local storage2x 960 GB (3201F)
Power suppliesDual PS
Form factor2 RU
Variants

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare