_ResourcesGet the sizing right
The four things that cost people the most money when buying Fortinet, written down properly.
/ 01
How to size a FortiGate (and why the big number is the wrong one)
Firewall throughput is measured on UDP with every inspection engine switched off. Threat protection throughput is measured with firewall, IPS, application control and malware protection all running against an enterprise traffic mix. On a FortiGate 60F those numbers are 10 Gbps and 700 Mbps — a factor of fourteen. Size on the second one, then leave headroom, because turning on SSL inspection later will consume it.
- —Start from threat protection throughput, not firewall throughput
- —Add SSL inspection separately — it is the figure that collapses first
- —Check concurrent sessions if your traffic is many small connections
- —Check the max-FortiSwitch and max-FortiAP limits before designing the LAN
/ 02
FortiCare tiers: what you are actually buying
The tier decides two things during an outage: how fast someone answers, and how fast a replacement arrives. Essentials is business hours. Premium is 24x7 with next-business-day hardware replacement. Elite is 24x7 with an accelerated response target and advanced replacement. If the device being down stops the business and there is no failover, a business-hours contract means a Friday-evening failure is a Monday-morning fix.
- —Match the tier to what an hour of downtime actually costs
- —'Next business day' runs from despatch qualification, not from when you notice
- —Multi-year terms price better and remove the annual scramble
- —A lapsed contract means no firmware updates — including security patches
/ 03
FortiGuard bundles: UTP vs Enterprise vs ATP
A FortiGate with no FortiGuard subscription is a stateful firewall with a VPN. IPS signatures, antivirus, web and DNS filtering, application control and inline sandboxing all arrive as subscriptions. The common mistake is buying the box on a threat-protection figure and then licensing a bundle that omits the services that figure was measured with.
- —Write down which features you will actually enable, then pick the bundle
- —SD-WAN features are licensed separately from threat inspection
- —Co-terminate FortiCare, FortiGuard and hardware onto one renewal date
- —Expired FortiGuard leaves the box passing traffic but not protecting it
/ 04
Migrating off another firewall vendor
Automated policy conversion from ASA, SonicWall, Palo Alto or Check Point gets most of the way. The value is in the review afterwards: every ruleset that has accumulated for six years contains rules nobody understands and nobody dares delete. A migration is the one moment they can be decided on properly, with the old device still available to roll back to.
- —Convert, then review — do not carry six years of unexamined rules across
- —Stage the cutover; do not flip a production perimeter in one window
- —Write the rollback plan before the window opens, not during it
- —Keep the old device powered and reachable until you are confident
_Primary sourcesFortinet’s own documentation
We link these rather than re-hosting them, so you always get Fortinet’s current version rather than whatever a reseller mirrored two years ago.
About our data
Why does this site cite its sources on every product page?
Because a customer sizes a network on these numbers. Every specification here is transcribed from Fortinet published documentation with the document named and the date we read it. Where two Fortinet sources disagreed we went to the individual model data sheet and recorded which one won — that happened twice while this catalog was built.
How current are these specifications?
The bulk of the catalog comes from the July 2026 edition of the Fortinet Product Matrix. Fortinet revises it periodically and can change specifications without notice, so where a figure is load-bearing for your design, ask us to confirm it in writing before you order.
Can I get the data sheet for a specific model?
Yes — ask and you will have it the same working day, for the exact variant and region you are considering. That matters more than it sounds: rugged and wireless models vary meaningfully by regional SKU.