FortiWeb 600F
1 Gbps of HTTP throughput with full WAF inspection
- HTTP throughput
- 1 Gbps
- Form factor
- Rackmount
The FortiWeb 600F delivers 1 Gbps of HTTP throughput, defending web applications and APIs against the OWASP Top 10, bot traffic, credential stuffing and API abuse — attacks that arrive as legitimate HTTPS and pass a network firewall untouched.
The first FortiWeb built for inline deployment: two of its four copper ports are hardware bypass, so a device failure fails open rather than taking the application offline. At 1 Gbps it suits a mid-size application estate. If you intend to sit this in the path of production traffic — which is where a WAF is most useful and most dangerous — this is the entry point, not the 400F.
Highlights
- Hardware bypass port pair — a device failure does not break the path
- 1 Gbps HTTP throughput with full inspection
- 2x bypass RJ45 plus 4x GE SFP for fibre uplinks
Typical deployments
- Inline WAF deployment in front of production applications
- Mid-size application estates with mixed internal and public services
- Environments where the change window for a WAF failure is unacceptable
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
| Throughput (HTTP) | 1 Gbps |
|---|
Hardware
| Total interfaces | 2 (+2 bypass) x GE RJ45, 4x GE SFP |
|---|
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.