Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-3800G

FortiGate 3800G

200 Gbps threat protection — the highest inspected throughput outside a chassis

Threat protection
200 Gbps
Firewall throughput
795 Gbps
IPsec VPN
210 Gbps
Concurrent sessions
210 Million

Front panel

Front panel layout for the FortiGate 3800G: 4 × 400G QSFP, 6 × 200G QSFP56, 18 × 50G SFP56, 2 × 10G RJ454× 400G6× 200G8× 50G10× 50G2× 10G
30 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale. Dashed outlines mark ports whose connector type Fortinet does not state; the speed is published, the cage type is inferred.
  • QSFP cage
  • SFP cage
  • RJ45 copper

The 3800G delivers 200 Gbps of threat protection, 250 Gbps of IPS and 315 Gbps of application control in 3 RU with four power supplies. It carries four 400GE, six 200GE QSFP56 and eighteen 50GE SFP56 ports, and reaches 450 million sessions with Hyperscale.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

The top of the fixed-appliance range for inspected throughput, and the point at which a chassis becomes the only step up. It nearly doubles the 3500G's threat protection and is the only fixed FortiGate with 200GE QSFP56 attachment.

Highlights

  • 200 Gbps threat protection, 250 Gbps IPS
  • 4x 400GE and 6x 200GE QSFP56 — unique in the fixed range
  • Hyperscale: 450M sessions, 7M new sessions/sec
  • 400,000 firewall policies, 4 power supplies

Typical deployments

  • Large data-centre perimeter with full inspection at 200 Gbps
  • 200GE fabric attachment without a chassis
  • Consolidating several older high-end firewalls into one pair
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)795 / 793 / 453 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.210 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.250 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.210 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.200 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.120 Gbps
Application control throughput (HTTP 64K)315 Gbps
Firewall latency3.53 µs

Capacity

Capacity
Concurrent sessions210 Million / 450 Million
New sessions / second1.1 Million / 7 Million
Firewall policies400,000
Max gateway-to-gateway IPsec tunnels40,000
Max client-to-gateway IPsec tunnels200,000
SSL VPN throughput27 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)30,000
Virtual domains (default / max)10 / 500

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)8,192 / 4,096
Max managed FortiSwitches300
Max FortiTokens20,000

Hardware

Hardware
Interfaces4x 400GE, 6x 200GE QSFP56, 18x 50GE SFP56, 2x 10GE RJ45
Local storage2x 1.92 TB (3801G)
Power supplies4 PS
Form factor3 RU
VariantsDC

Model-specific caveats

Fortinet conditions that apply to this model in particular. Worth reading before you order.

Model-specific caveats
Note 1The second figure requires a Hyperscale license.

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare