FortiGate 3500G
105 Gbps threat protection and 400GE optics — the inspection flagship of 2 RU
- Threat protection
- 105 Gbps
- Firewall throughput
- 595 Gbps
- IPsec VPN
- 163 Gbps
- Concurrent sessions
- 179 Million
Front panel
- QSFP cage
- SFP cage
- RJ45 copper
The 3500G is the highest inspected throughput available in a 2 RU FortiGate: 105 Gbps threat protection, 125 Gbps IPS, 112 Gbps SSL inspection and 197 Gbps application control, with two 400GE QSFP-DD and thirty 25GE SFP28 ports.
If your requirement is maximum inspection per rack unit, this is the model. It delivers two thirds more threat protection than the 3500F in the same space and nearly quadruples its SSL inspection. Above this you are moving to 3 RU and the 3800G.
Highlights
- 105 Gbps threat protection, 112 Gbps SSL inspection
- 2x 400GE QSFP-DD plus 30x 25GE SFP28
- 179 million concurrent sessions natively
- 2x 1.92 TB storage, 2 RU
Typical deployments
- Data-centre perimeter demanding maximum inspection density
- Internal segmentation at 100 Gbps with full UTM enabled
- Space-constrained facilities where rack units are expensive
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 595 / 590 / 420 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 163 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 125 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 115 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 105 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 112 Gbps |
| Application control throughput (HTTP 64K) | 197 Gbps |
| Firewall latency | 2.96 µs |
Capacity
| Concurrent sessions | 179 Million |
|---|---|
| New sessions / second | 1.1 Million |
| Firewall policies | 200,000 |
| Max gateway-to-gateway IPsec tunnels | 40,000 |
| Max client-to-gateway IPsec tunnels | 200,000 |
| SSL VPN throughput | 9.8 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 30,000 |
| Virtual domains (default / max) | 10 / 500 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 4,096 / 2,048 |
|---|---|
| Max managed FortiSwitches | 300 |
| Max FortiTokens | 20,000 |
Hardware
| Interfaces | 2x 400GE QSFP-DD, 4x 100GE QSFP28, 30x 25GE SFP28, 2x 10GE RJ45 |
|---|---|
| Local storage | 2x 1.92 TB (3501G) |
| Power supplies | Dual PS |
| Form factor | 2 RU |
| Variants | — |
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 3800G
200 Gbps threat protection — the highest inspected throughput outside a chassis
FortiGate 3000G
Same chassis as the 3000F, two and a half times the inspected throughput
FortiGate 3700F
Ultra-low-latency ports at 1.45 µs — built for trading and real-time workloads