Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-400G

FortiGate 400G

164 Gbps firewall with 25GE SFP28 optics — the mid-range entry point

Threat protection
13 Gbps
Firewall throughput
164 Gbps
IPsec VPN
55 Gbps
Concurrent sessions
28 Million

Front panel

Front panel layout for the FortiGate 400G: 4 × 25G SFP28, 4 × 10G SFP+, 16 × 1G SFP, 8 × 5G RJ45, 1 × 2.5G RJ45, 1 × 1G RJ454× 25G4× 10G10× 1G6× 1G8× 5G1× 2.5G1× 1G
34 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • SFP cage
  • RJ45 copper

The 400G is a fourfold jump in firewall throughput over the 200G, to 164 Gbps, and introduces 25GE SFP28 optics. It delivers 13 Gbps threat protection, 11.5 Gbps SSL inspection and 28 million concurrent sessions across 34 interfaces.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

Read this model carefully against the 700G. They share identical interfaces and identical 164 Gbps firewall throughput, but the 700G does twice the threat protection (26 vs 13 Gbps) and 38 Gbps of IPS against 25. If your traffic is mostly forwarded rather than deeply inspected, the 400G is the value pick; if you inspect heavily, the 700G is the better box and the price difference is usually justified.

Highlights

  • 164 Gbps firewall throughput, 55 Gbps IPsec VPN
  • 4x 25GE SFP28 plus 4x 10GE SFP+ optics
  • 28 million sessions, 5,000 concurrent SSL VPN users
  • Manages 96 FortiSwitches and 512 FortiAPs

Typical deployments

  • Data-centre edge where forwarding matters more than inspection depth
  • Large campus core with 25GE uplinks
  • Sites needing 5,000 concurrent SSL VPN users
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)164 / 163 / 145 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.55 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.25 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.14 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.13 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.11.5 Gbps
Application control throughput (HTTP 64K)50 Gbps
Firewall latency2.51 µs

Capacity

Capacity
Concurrent sessions28 Million
New sessions / second580,000
Firewall policies10,000
Max gateway-to-gateway IPsec tunnels2,000
Max client-to-gateway IPsec tunnels50,000
SSL VPN throughput6.1 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)5,000
Virtual domains (default / max)10 / 50

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)512 / 256
Max managed FortiSwitches96
Max FortiTokens5,000

Hardware

Hardware
Interfaces4x 25GE SFP28, 4x 10GE SFP+, 16x GE SFP, 8x 5GE RJ45, 1x 2.5GE RJ45, 1x GE RJ45
Local storage960 GB (401G)
Power suppliesDual AC PS
Form factor1 RU
Variants

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare