Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-4200F

FortiGate 4200F

800 Gbps firewall throughput with 450 million Hyperscale sessions

Threat protection
45 Gbps
Firewall throughput
800 Gbps
IPsec VPN
210 Gbps
Concurrent sessions
210 Million

Front panel

Front panel layout for the FortiGate 4200F: 8 × 100G QSFP28, 18 × 25G SFP28, 2 × 1G RJ458× 100G10× 25G8× 25G2× 1G
28 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • QSFP cage
  • SFP cage
  • RJ45 copper

The 4200F opens the 4000 series with 800 Gbps of firewall throughput, 210 Gbps IPsec and, with Hyperscale, 450 million concurrent sessions at 7 million new sessions per second. Eight 100GE QSFP28 and eighteen 25GE SFP28 ports in 3 RU.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

A forwarding and session-scale platform. Its 45 Gbps threat protection is the same as the far smaller 3200F, so this is not the box to buy for inspection depth — it is the box to buy when you need to move very large volumes of traffic and hold very large session tables.

Highlights

  • 800 Gbps firewall throughput, 210 Gbps IPsec VPN
  • Hyperscale: 450M sessions, 7M new sessions/sec
  • 8x 100GE QSFP28, 18x 25GE SFP28
  • 400,000 firewall policies, DC variant

Typical deployments

  • Carrier aggregation and CGNAT deployments
  • High-volume forwarding with selective inspection
  • Service provider edge with very large session requirements
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)800 / 788 / 400 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.210 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.52 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.47 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.45 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.50 Gbps
Application control throughput (HTTP 64K)135 Gbps
Firewall latency3.02 µs

Capacity

Capacity
Concurrent sessions210 Million / 450 Million
New sessions / second1 Million / 7 Million
Firewall policies400,000
Max gateway-to-gateway IPsec tunnels40,000
Max client-to-gateway IPsec tunnels200,000
SSL VPN throughput16 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)30,000
Virtual domains (default / max)10 / 500

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)8,192 / 4,096
Max managed FortiSwitches300
Max FortiTokens20,000

Hardware

Hardware
Interfaces8x 100GE QSFP28/40GE QSFP+, 18x 25GE SFP28, 2x GE RJ45
Local storage2x 1.92 TB (4201F)
Power suppliesDual PS
Form factor3 RU
VariantsDC

Model-specific caveats

Fortinet conditions that apply to this model in particular. Worth reading before you order.

Model-specific caveats
Note 1The second figure requires a Hyperscale license.

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare