Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FG-900G

FortiGate 900G

1 RU with ultra-low-latency ports and 74.8 Gbps application control

Threat protection
30 Gbps
Firewall throughput
164 Gbps
IPsec VPN
55 Gbps
Concurrent sessions
28 Million

Front panel

Front panel layout for the FortiGate 900G: 4 × 25G SFP28, 4 × 10G SFP+, 1 × 2.5G RJ45, 8 × 1G SFP, 17 × 1G RJ454× 25G4× 10G1× 2.5G8× 1G1× 1G16× 1G
34 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • SFP cage
  • RJ45 copper

The 900G is the top of the 1 RU range: 30 Gbps threat protection, 16.7 Gbps SSL inspection and 74.8 Gbps application control, with ultra-low-latency ports that drop firewall latency from 3.78 µs to 2.5 µs. It manages 196 FortiSwitches and 2,048 FortiAPs and offers a DC-power variant.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

Take the 900G where you need mid-range inspection performance and either low latency or a very large Fabric. Against the 1000F it has less raw firewall throughput but more than twice the threat protection (30 vs 13 Gbps) — another case where the headline number points the wrong way.

Highlights

  • 30 Gbps threat protection, 74.8 Gbps application control
  • Ultra-low-latency ports — 2.5 µs firewall latency
  • Manages 196 FortiSwitches, 2,048 FortiAPs
  • 50,000 firewall policies, DC power variant

Typical deployments

  • Latency-sensitive campus and trading-floor edge
  • Large distributed Fabric estates managed from one firewall pair
  • DC-powered facilities and carrier environments
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)164 / 163 / 153 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.55 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.42 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.31 Gbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.30 Gbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.16.7 Gbps
Application control throughput (HTTP 64K)74.8 Gbps
Firewall latency3.78 µs / 2.5 µs

Capacity

Capacity
Concurrent sessions28 Million
New sessions / second720,000
Firewall policies50,000
Max gateway-to-gateway IPsec tunnels2,000
Max client-to-gateway IPsec tunnels50,000
SSL VPN throughput10 Gbps
Concurrent SSL VPN users (recommended max, tunnel mode)10,000
Virtual domains (default / max)10 / 50

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)2,048 / 1,024
Max managed FortiSwitches196
Max FortiTokens5,000

Hardware

Hardware
Interfaces4x 25GE SFP28, 4x 10GE SFP+, 1x 2.5GE RJ45, 8x GE SFP, 17x GE RJ45
Local storage960 GB (901G)
Power suppliesDual PS
Form factor1 RU
VariantsDC

Model-specific caveats

Fortinet conditions that apply to this model in particular. Worth reading before you order.

Model-specific caveats
Note 1The second latency figure is achieved with ultra-low-latency ports.

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare