Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FWF-40F

FortiWiFi 40F

FortiGate 40F with an integrated access point — one box for a small site

Threat protection
600 Mbps
IPsec VPN
4.4 Gbps
Wireless
Integrated AP

Front panel

Front panel layout for the FortiWiFi 40F: 5 × 1G RJ455× 1G
5 fixed ports. Schematic drawn from the published interface list — port order and physical arrangement are indicative, not to scale.
  • RJ45 copper

The FortiWiFi 40F is a FortiGate 40F with a wireless radio built in. The firewall specifications are identical — 600 Mbps of threat protection, 4.4 Gbps of IPsec VPN and 700,000 concurrent sessions — so everything that applies to the FortiGate 40F applies here unchanged.

Is this the right model?

Where it fits — and where it stops fitting

Compare the whole range

Choose this over the FortiWiFi 50G only if you specifically need the F-series 3G4G variant alongside wireless — a small site that is both cellular-connected and wireless-served. On every inspection metric the 50G is ahead, and on FortiOS 7.6.0 and later the 40F loses SSL VPN entirely because of its 2 GB of RAM, which matters if anyone works remotely from that site.

Highlights

  • Identical firewall specification to the FortiGate 40F
  • Integrated access point — no separate AP or controller
  • Manages up to 16 additional FortiAPs as the site grows
  • Region-locked SKU — we confirm the correct part number

Typical deployments

  • Cellular-connected small sites that also need wireless
  • Estates already standardised on the 40F where spares consistency wins
  • Temporary and pop-up locations
Specifications

The numbers, with their conditions

Every figure below is Fortinet's own, with the test conditions it was measured under.

Performance

Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.

Performance
Firewall throughput (1518 / 512 / 64 byte UDP)5 / 5 / 5 Gbps
IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256.4.4 Gbps
IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled.1 Gbps
NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic.800 Mbps
Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic.600 Mbps
SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites.310 Mbps
Application control throughput (HTTP 64K)990 Mbps
Firewall latency2.97 µs

Capacity

Capacity
Concurrent sessions700,000
New sessions / second35,000
Firewall policies2,000
Max gateway-to-gateway IPsec tunnels200
Max client-to-gateway IPsec tunnels250
SSL VPN throughput
Concurrent SSL VPN users (recommended max, tunnel mode)
Virtual domains (default / max)10 / 10

Security Fabric capacity

How much of the rest of the Fabric this model manages directly, with no separate controller.

Security Fabric capacity
Max managed FortiAPs (total / tunnel)16 / 8
Max managed FortiSwitches8
Max FortiTokens500

Hardware

Hardware
Interfaces5x GE RJ45
Local storage
Power suppliesSingle AC PS
Form factorDesktop
VariantsWiFi, 3G4G

Wireless

Fortinet does not publish the wireless radio generation per model in the Product Matrix, and the radio and permitted transmit power vary by regional SKU. We confirm the exact wireless specification and the correct regional part number against your country before ordering — a wrong-region FortiWiFi is not a returnable configuration error.

Wireless
Integrated access pointYes — this is the wireless variant of the FortiGate 40F
Radio generationVaries by model and regional SKU — confirmed at quote
Regulatory domainRegion-locked SKU — must match country of deployment

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare