FortiWeb 100F
100 Mbps of HTTP throughput with full WAF inspection
- HTTP throughput
- 100 Mbps
- Form factor
- Rackmount
The FortiWeb 100F delivers 100 Mbps of HTTP throughput, defending web applications and APIs against the OWASP Top 10, bot traffic, credential stuffing and API abuse — attacks that arrive as legitimate HTTPS and pass a network firewall untouched.
At 100 Mbps of HTTP throughput this is a single-application appliance — one public site, one portal, one API endpoint. It has four gigabit copper ports and no bypass interfaces, so a failure takes the path down with it: deploy it where an outage is survivable, or in reverse-proxy mode where you control failover elsewhere. If you are protecting a cardholder-data application to satisfy PCI DSS, check your real peak HTTP rate first; 100 Mbps is easy to exceed on a busy checkout.
Highlights
- 100 Mbps HTTP throughput
- Machine-learning behaviour model, not signatures alone
- API schema validation and rate limiting
- Compact inline or reverse-proxy deployment
Typical deployments
- A single customer-facing web application or portal
- Small PCI DSS scope where a WAF is required in front of one system
- Lab, staging and policy-development environments before production rollout
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
| Throughput (HTTP) | 100 Mbps |
|---|
Hardware
| Total interfaces | 4x GE RJ45 |
|---|
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.