FortiGate 3500F
595 Gbps firewall with 348 million Hyperscale sessions
- Threat protection
- 63 Gbps
- Firewall throughput
- 595 Gbps
- IPsec VPN
- 165 Gbps
- Concurrent sessions
- 140 Million
Front panel
- QSFP cage
- SFP cage
- RJ45 copper
The 3500F pushes firewall throughput to 595 Gbps and, with Hyperscale, 348 million concurrent sessions at 5 million new sessions per second. Thirty-two 25GE SFP28 ports alongside six 100GE QSFP28 give it very high port density in 2 RU.
A session-scale and port-density box. Its 63 Gbps threat protection is respectable but the 3500G delivers 105 Gbps in the same chassis. Choose the F where you need the Hyperscale session ceiling or the 32-port 25GE density; choose the G where you need inspection.
Highlights
- 595 Gbps firewall throughput, 165 Gbps IPsec
- 32x 25GE SFP28 — very high density for 2 RU
- Hyperscale: 348M sessions, 5M new sessions/sec
- 2x 1.92 TB local storage
Typical deployments
- High-density 25GE aggregation in a data centre
- Carrier and hosting environments with extreme session counts
- Large-scale IPsec concentration at 165 Gbps
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 595 / 590 / 420 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 165 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 72 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 65 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 63 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 63 Gbps |
| Application control throughput (HTTP 64K) | 135 Gbps |
| Firewall latency | 2.98 µs |
Capacity
| Concurrent sessions | 140 Million / 348 Million |
|---|---|
| New sessions / second | 1 Million / 5 Million |
| Firewall policies | 200,000 |
| Max gateway-to-gateway IPsec tunnels | 40,000 |
| Max client-to-gateway IPsec tunnels | 200,000 |
| SSL VPN throughput | 16 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 30,000 |
| Virtual domains (default / max) | 10 / 500 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 4,096 / 2,048 |
|---|---|
| Max managed FortiSwitches | 300 |
| Max FortiTokens | 20,000 |
Hardware
| Interfaces | 6x 100GE QSFP28/40GE QSFP+, 32x 25GE SFP28, 2x GE RJ45 |
|---|---|
| Local storage | 2x 1.92 TB (3501F) |
| Power supplies | Dual PS |
| Form factor | 2 RU |
| Variants | — |
Model-specific caveats
Fortinet conditions that apply to this model in particular. Worth reading before you order.
| Note 1 | The second figure requires a Hyperscale license. |
|---|
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 3500G
105 Gbps threat protection and 400GE optics — the inspection flagship of 2 RU
FortiGate 3700F
Ultra-low-latency ports at 1.45 µs — built for trading and real-time workloads
FortiGate 3000G
Same chassis as the 3000F, two and a half times the inspected throughput