FortiWeb 4000F
70 Gbps of HTTP throughput with full WAF inspection
- HTTP throughput
- 70 Gbps
- Form factor
- Rackmount
The FortiWeb 4000F delivers 70 Gbps of HTTP throughput, defending web applications and APIs against the OWASP Top 10, bot traffic, credential stuffing and API abuse — attacks that arrive as legitimate HTTPS and pass a network firewall untouched.
70 Gbps — seven times the 3000F — with 40GE QSFP bypass. This is a carrier and hyperscale application-security platform, and the jump is large enough that arriving here should follow a measurement, not an estimate. If your peak HTTP rate is genuinely tens of gigabits you are almost certainly running an application estate that also needs FortiADC in front of it; we would rather scope that together than quote this in isolation.
Highlights
- 70 Gbps HTTP throughput
- Machine-learning behaviour model, not signatures alone
- API schema validation and rate limiting
- Hardware bypass interfaces for inline deployment
Typical deployments
- Service-provider and hyperscale application protection
- Very large public estates measured in tens of gigabits of HTTP
- Environments where WAF and load balancing are designed as one tier
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
| Throughput (HTTP) | 70 Gbps |
|---|
Hardware
| Total interfaces | 2x 40GE QSFP bypass, 10x 10GE SFP+ (incl. 2 bypass), 8x GE RJ45 bypass |
|---|
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.