FortiWiFi 60F
FortiGate 60F with an integrated access point — one box for a small site
- Threat protection
- 700 Mbps
- IPsec VPN
- 6.5 Gbps
- Wireless
- Integrated AP
Front panel
- RJ45 copper
The FortiWiFi 60F is a FortiGate 60F with a wireless radio built in. The firewall specifications are identical — 700 Mbps of threat protection, 6.5 Gbps of IPsec VPN and 700,000 concurrent sessions — so everything that applies to the FortiGate 60F applies here unchanged.
Ten gigabit ports make this the model for a small office that needs real wired capacity alongside wireless — enough to run the whole LAN from one box with no access switch. Buy it for the port count and the Fabric capacity, not the throughput: on inspection the newer 70G is ahead, and the 60F loses SSL VPN on FortiOS 7.6.0+ owing to its 2 GB of RAM.
Highlights
- Identical firewall specification to the FortiGate 60F
- Integrated access point — no separate AP or controller
- Manages up to 64 additional FortiAPs as the site grows
- Region-locked SKU — we confirm the correct part number
Typical deployments
- Small offices running wired and wireless from a single device
- Sites needing several separate physical segments
- Estates already standardised on the 60F platform
The numbers, with their conditions
Every figure below is Fortinet's own, with the test conditions it was measured under.
Performance
Fortinet's published figures. Firewall throughput is measured on UDP with no inspection enabled — size your deployment on threat protection throughput instead, which is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix.
| Firewall throughput (1518 / 512 / 64 byte UDP) | 10 / 10 / 6 Gbps |
|---|---|
| IPsec VPN throughput (512 byte)IPsec VPN performance test uses AES256-SHA256. | 6.5 Gbps |
| IPS throughput (enterprise mix)IPS, application control, NGFW and threat protection are measured with logging enabled. | 1.4 Gbps |
| NGFW throughput (enterprise mix)NGFW performance is measured with firewall, IPS and application control enabled, enterprise mix traffic. | 1 Gbps |
| Threat protection throughput (enterprise mix)Threat protection performance is measured with firewall, IPS, application control and malware protection enabled, enterprise mix traffic. | 700 Mbps |
| SSL inspection throughput (IPS, avg. HTTPS)SSL inspection performance values use an average of HTTPS sessions of different cipher suites. | 630 Mbps |
| Application control throughput (HTTP 64K) | 1.8 Gbps |
| Firewall latency | 3.3 µs |
Capacity
| Concurrent sessions | 700,000 |
|---|---|
| New sessions / second | 35,000 |
| Firewall policies | 2,000 |
| Max gateway-to-gateway IPsec tunnels | 200 |
| Max client-to-gateway IPsec tunnels | 500 |
| SSL VPN throughput | — |
| Concurrent SSL VPN users (recommended max, tunnel mode) | — |
| Virtual domains (default / max) | 10 / 10 |
Security Fabric capacity
How much of the rest of the Fabric this model manages directly, with no separate controller.
| Max managed FortiAPs (total / tunnel) | 64 / 32 |
|---|---|
| Max managed FortiSwitches | 24 |
| Max FortiTokens | 500 |
Hardware
| Interfaces | 10x GE RJ45 |
|---|---|
| Local storage | 128 GB (61F) |
| Power supplies | Single AC PS |
| Form factor | Desktop |
| Variants | WiFi, Storage |
Wireless
Fortinet does not publish the wireless radio generation per model in the Product Matrix, and the radio and permitted transmit power vary by regional SKU. We confirm the exact wireless specification and the correct regional part number against your country before ordering — a wrong-region FortiWiFi is not a returnable configuration error.
| Integrated access point | Yes — this is the wireless variant of the FortiGate 60F |
|---|---|
| Radio generation | Varies by model and regional SKU — confirmed at quote |
| Regulatory domain | Region-locked SKU — must match country of deployment |
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
- Fortinet product line overview — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.