FortiGate 4800F
3.1 Tbps firewall and 1.8 billion sessions — the largest fixed FortiGate
- Threat protection
- 75 Gbps
- Firewall throughput
- 3.1 Tbps
- IPsec VPN
- 800 Gbps
- Concurrent sessions
- 280 Million
Front panel
- QSFP cage
- SFP cage
- RJ45 copper
The 4800F is the highest-capacity non-chassis FortiGate: 3.1 Tbps of firewall throughput, 800 Gbps of IPsec VPN and, with Hyperscale, 1.8 billion concurrent sessions at 25 million new sessions per second. Eight 400GE and twelve 200GE QSFP56 ports in 4 RU, with DC and NEBS variants.
A carrier and hyperscale platform. Be clear-eyed about what it is: its 75 Gbps of threat protection is identical to the 4400F, so every additional dollar over that model buys forwarding capacity and session scale, not inspection. Deployed for the right workload it is unmatched; deployed to inspect enterprise traffic it is an expensive way to get 75 Gbps.
Highlights
- 3.1 Tbps firewall throughput, 800 Gbps IPsec VPN
- Hyperscale: 1.8 billion sessions, 25M new sessions/sec
- 8x 400GE and 12x 200GE QSFP56
- DC and NEBS variants for carrier facilities
Typical deployments
- Mobile core and 5G user-plane security
- Carrier CGNAT at national scale
- Hyperscale data-centre interconnect
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 3.1 / 3.1 / 0.93 Tbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 800 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 87 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 77 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 75 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 63 Gbps |
| Application control throughput (HTTP 64K) | 180 Gbps |
| Firewall latency | 3.6 µs |
Capacity
| Concurrent sessions | 280 Million / 1.8 Billion |
|---|---|
| New sessions / second | 915,000 / 25 Million |
| Firewall policies | 400,000 |
| Max gateway-to-gateway IPsec tunnels | 40,000 |
| Max client-to-gateway IPsec tunnels | 200,000 |
| SSL VPN throughput | 18 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 30,000 |
| Virtual domains (default / max) | 10 / 500 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 8,192 / 4,096 |
|---|---|
| Max managed FortiSwitches | 300 |
| Max FortiTokens | 20,000 |
Hardware
| Interfaces | 8x 400GE, 12x 200GE QSFP56, 12x 50GE SFP56, 2x 10GE RJ45 |
|---|---|
| Local storage | 2x 1.92 TB (4801F) |
| Power supplies | 4 PS |
| Form factor | 4 RU |
| Variants | DC, NEBS |
Model-specific caveats
Fortinet conditions that apply to this model in particular. Worth reading before you order.
| Note 1 | The second figure requires a Hyperscale license. |
|---|
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 4400F
1.15 Tbps firewall and 310 Gbps IPsec in 4 RU
FortiGate 7081F
Modular chassis — 1.89 Tbps with hot-swap FPM and FIM blades
FortiGate 3800G
200 Gbps threat protection — the highest inspected throughput outside a chassis