FortiWeb 400F
500 Mbps of HTTP throughput with full WAF inspection
- HTTP throughput
- 500 Mbps
- Form factor
- Rackmount
The FortiWeb 400F delivers 500 Mbps of HTTP throughput, defending web applications and APIs against the OWASP Top 10, bot traffic, credential stuffing and API abuse — attacks that arrive as legitimate HTTPS and pass a network firewall untouched.
Five times the 100F's throughput and the first model with fibre uplinks, which matters more than the raw number: 500 Mbps covers a handful of business applications rather than one. Still no hardware bypass, so it belongs behind a load balancer or in a reverse-proxy topology rather than inline on a single critical path. The step to the 600F is the one to consider if inline deployment is likely.
Highlights
- 500 Mbps HTTP throughput
- Machine-learning behaviour model, not signatures alone
- API schema validation and rate limiting
- Compact inline or reverse-proxy deployment
Typical deployments
- A small estate of internal and external web applications
- Organisations consolidating several unprotected apps behind one WAF
- Reverse-proxy deployments where the WAF is not a single point of failure
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
| Throughput (HTTP) | 500 Mbps |
|---|
Hardware
| Total interfaces | 4x GE RJ45, 4x GE SFP |
|---|
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.