FortiGate 7121F
The largest FortiGate — 520 Gbps threat protection and a billion sessions
- Threat protection
- 520 Gbps
- Firewall throughput
- 1.89 Tbps
- IPsec VPN
- 630 Gbps
- Concurrent sessions
- 1 Billion
Front panel
The 7121F is the top of the entire FortiGate range: 520 Gbps of threat protection, 675 Gbps of IPS, 540 Gbps of SSL inspection and 1.5 Tbps of application control, with one billion concurrent sessions at 9 million new sessions per second. 16 RU with eight power supplies.
Where inspection must happen at hundreds of gigabits and cannot be distributed across multiple firewalls. Against the 7081F it shares firewall throughput but delivers two thirds more threat protection and 1.67x the SSL inspection, for four additional rack units and two more power supplies.
Highlights
- 520 Gbps threat protection, 540 Gbps SSL inspection
- 1.5 Tbps application control — the highest in the range
- 1 billion concurrent sessions, 9M new sessions/sec
- 8 power supplies, DC variant, 16 RU
Typical deployments
- Tier-1 carrier security at national scale
- Hyperscale cloud provider perimeter
- Consolidating a large estate of high-end firewalls into one platform
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 1.89 / 1.88 / 1.129 Tbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 630 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 675 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 550 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 520 Gbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 540 Gbps |
| Application control throughput (HTTP 64K) | 1.5 Tbps |
| Firewall latency | 7.5 µs |
Capacity
| Concurrent sessions | 1 Billion |
|---|---|
| New sessions / second | 9 Million |
| Firewall policies | 200,000 |
| Max gateway-to-gateway IPsec tunnels | 200,000 |
| Max client-to-gateway IPsec tunnels | 260,000 |
| SSL VPN throughput | 13.7 Gbps |
| Concurrent SSL VPN users (recommended max, tunnel mode) | 30,000 |
| Virtual domains (default / max) | 10 / 500 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | — |
|---|---|
| Max managed FortiSwitches | 300 |
| Max FortiTokens | 20,000 |
Hardware
| Interfaces | Varies by FPM module |
|---|---|
| Local storage | 4x 4 TB SSD |
| Power supplies | 8 PS |
| Form factor | 16 RU |
| Variants | DC |
Sources
- Fortinet Product Matrix — FortiGate Network Security Platform (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.
Buyers also compare
FortiGate 7081F
Modular chassis — 1.89 Tbps with hot-swap FPM and FIM blades
FortiGate 4800F
3.1 Tbps firewall and 1.8 billion sessions — the largest fixed FortiGate
FortiGate 3800G
200 Gbps threat protection — the highest inspected throughput outside a chassis