Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-3500G

FortiGate 3500G

105 Gbps threat protection and 400GE optics — the inspection flagship of 2 RU

Threat protection
105 Gbps
Firewall throughput
595 Gbps
IPsec VPN
163 Gbps
Concurrent sessions
179 Million

Front panel

Front panel layout for the FortiGate 3500G: 2 × 400G QSFP-DD, 4 × 100G QSFP28, 30 × 25G SFP28, 2 × 10G RJ452× 400G4× 100G12× 25G18× 25G2× 10G
38 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • QSFP cage
  • SFP cage
  • RJ45 copper

The 3500G is the highest inspected throughput available in a 2 RU FortiGate: 105 Gbps threat protection, 125 Gbps IPS, 112 Gbps SSL inspection and 197 Gbps application control, with two 400GE QSFP-DD and thirty 25GE SFP28 ports.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

If your requirement is maximum inspection per rack unit, this is the model. It delivers two thirds more threat protection than the 3500F in the same space and nearly quadruples its SSL inspection. Above this you are moving to 3 RU and the 3800G.

Highlights

  • 105 Gbps threat protection, 112 Gbps SSL inspection
  • 2x 400GE QSFP-DD plus 30x 25GE SFP28
  • 179 million concurrent sessions natively
  • 2x 1.92 TB storage, 2 RU

Typical deployments

  • Data-centre perimeter demanding maximum inspection density
  • Internal segmentation at 100 Gbps with full UTM enabled
  • Space-constrained facilities where rack units are expensive
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)595 / 590 / 420 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.163 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.125 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.115 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.105 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.112 Gbps
Application control throughput (HTTP 64K)197 Gbps
Firewall latency2.96 µs

Capacity

Capacity
Concurrent sessions179 Million
New sessions / second1.1 Million
Firewall policies200,000
Max gateway-to-gateway IPsec tunnels40,000
Max client-to-gateway IPsec tunnels200,000
SSL VPN throughput9.8 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)30,000
Virtual domains (default / max)10 / 500

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)4,096 / 2,048
Max managed FortiSwitches300
Max FortiTokens20,000

Hardware

Hardware
Interfaces2x 400GE QSFP-DD, 4x 100GE QSFP28, 30x 25GE SFP28, 2x 10GE RJ45
Local storage2x 1.92 TB (3501G)
Power suppliesDual PS
Form factor2 RU
Variants

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare