FortiGate 3800G
200 Gbps threat protection — the highest inspected throughput outside a chassis
- Threat protection
- 200 Gbps
- Firewall throughput
- 795 Gbps
- IPsec VPN
- 210 Gbps
- Concurrent sessions
- 210 Million
Front panel
- QSFP cage
- SFP cage
- RJ45 copper
The 3800G delivers 200 Gbps of threat protection, 250 Gbps of IPS and 315 Gbps of application control in 3 RU with four power supplies. It carries four 400GE, six 200GE QSFP56 and eighteen 50GE SFP56 ports, and reaches 450 million sessions with Hyperscale.
The top of the fixed-appliance range for inspected throughput, and the point at which a chassis becomes the only step up. It nearly doubles the 3500G's threat protection and is the only fixed FortiGate with 200GE QSFP56 attachment.
Highlights
- 200 Gbps threat protection, 250 Gbps IPS
- 4x 400GE and 6x 200GE QSFP56 — unique in the fixed range
- Hyperscale: 450M sessions, 7M new sessions/sec
- 400,000 firewall policies, 4 power supplies
Typical deployments
- Large data-centre perimeter with full inspection at 200 Gbps
- 200GE fabric attachment without a chassis
- Consolidating several older high-end firewalls into one pair
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 795 / 793 / 453 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 210 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 250 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 210 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 200 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 120 Gbps |
| Application control throughput (HTTP 64K) | 315 Gbps |
| Firewall latency | 3.53 µs |
Capacity
| Concurrent sessions | 210 Million / 450 Million |
|---|---|
| New sessions / second | 1.1 Million / 7 Million |
| Firewall policies | 400,000 |
| Max gateway-to-gateway IPsec tunnels | 40,000 |
| Max client-to-gateway IPsec tunnels | 200,000 |
| SSL VPN throughput | 27 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 30,000 |
| Virtual domains (default / max) | 10 / 500 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 8,192 / 4,096 |
|---|---|
| Max managed FortiSwitches | 300 |
| Max FortiTokens | 20,000 |
Hardware
| Interfaces | 4x 400GE, 6x 200GE QSFP56, 18x 50GE SFP56, 2x 10GE RJ45 |
|---|---|
| Local storage | 2x 1.92 TB (3801G) |
| Power supplies | 4 PS |
| Form factor | 3 RU |
| Variants | DC |
Model-specific caveats
Fortinet conditions that apply to this model in particular. Worth reading before you order.
| Note 1 | The second figure requires a Hyperscale license. |
|---|
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 4800F
3.1 Tbps firewall and 1.8 billion sessions — the largest fixed FortiGate
FortiGate 3500G
105 Gbps threat protection and 400GE optics — the inspection flagship of 2 RU
FortiGate 4400F
1.15 Tbps firewall and 310 Gbps IPsec in 4 RU