Home / Firewalls / Fortinet FG-600F FortiGate 600F Next-Generation Firewall & Secure SD-WAN Appliance

Fortinet FG-600F FortiGate 600F Next-Generation Firewall & Secure SD-WAN Appliance

The Fortinet FortiGate FG-600F is a high-performance Next-Generation Firewall (NGFW) and Secure SD-WAN appliance designed for large enterprises, campus networks, data center edges, and high-traffic corporate environments requiring advanced security and high-speed connectivity.

Powered by FortiOS and Fortinet’s purpose-built SPU/ASIC security processing architecture, the FG-600F combines enterprise firewall protection, intrusion prevention, application control, SSL inspection, IPsec VPN, Secure SD-WAN, Zero Trust Network Access (ZTNA), network segmentation, and Fortinet Security Fabric integration in a 1U rackmount platform.

The FG-600F delivers up to 198 Gbps firewall throughput, 55 Gbps IPsec VPN throughput, 31 Gbps IPS throughput, 27 Gbps NGFW throughput, and 25 Gbps threat protection throughput under Fortinet’s published benchmark conditions.

Category:

Description

The Fortinet FortiGate 600F (FG-600F) is an enterprise-class Next-Generation Firewall and Secure SD-WAN appliance designed for demanding network environments where high throughput, advanced threat protection, visibility, and secure connectivity are essential.

The FG-600F consolidates networking and security functions into a single platform, allowing organizations to protect users, applications, servers, IoT devices, and network segments while reducing infrastructure complexity.

The appliance runs FortiOS, Fortinet’s converged networking and security operating system. It provides firewall policies, application control, intrusion prevention, web and DNS security, SSL/TLS inspection, IPsec VPN, Secure SD-WAN, network segmentation, ZTNA, and integration with the Fortinet Security Fabric.

Fortinet’s ASIC-based security processing architecture is designed to accelerate security inspection and networking workloads, enabling high throughput and low-latency operation. The 600F Series also incorporates AI/ML-powered security capabilities through the Fortinet Security Fabric and FortiGuard ecosystem.

The FG-600F provides up to 24 million concurrent sessions and up to 1 million new sessions per second, giving it substantial capacity for large enterprise, campus, and data-center-edge deployments.


Key Specifications

Specification FortiGate FG-600F
Brand Fortinet
Product Family FortiGate 600F Series
Model FG-600F
Product Type Next-Generation Firewall / Secure SD-WAN Appliance
Operating System FortiOS
Form Factor 1U Rackmount
GE RJ45 Interfaces 16
GE SFP Interfaces 8
10GE/GE SFP+ Slots 4
25GE/10GE SFP28/SFP+ ULL Slots 4
Management / HA Interfaces 2 × GE RJ45
Firewall Throughput Up to 198 Gbps
Firewall Packet Processing Up to 120 Mpps
IPsec VPN Throughput Up to 55 Gbps
IPS Throughput Up to 31 Gbps
NGFW Throughput Up to 27 Gbps
Threat Protection Throughput Up to 25 Gbps
SSL Inspection Throughput Up to 9 Gbps
Concurrent Sessions Up to 24 million
New Sessions/Second Up to 1 million
Firewall Policies Up to 40,000
Gateway-to-Gateway IPsec Tunnels Up to 20,000
Client-to-Gateway IPsec Tunnels Up to 50,000
SSL-VPN Throughput Up to 4.5 Gbps
High Availability Active-Active / Active-Passive
FortiLink Supported
FortiSwitch Integration Supported
FortiAP Integration Supported
FortiToken Support Supported
Virtual Domains Supported
Power Supply Dual AC, redundant
Form Factor 1U Rackmount

Fortinet’s current product information identifies the FG-600F with 16 GE RJ45 ports, 8 GE SFP ports, 4 × 10GE/GE SFP+/SFP slots, 4 × 25GE/10GE SFP28/SFP+ ultra-low-latency slots, and 2 × GE RJ45 management/HA ports.

Performance figures are manufacturer-published “up to” benchmark values measured under controlled conditions. Actual throughput varies depending on packet size, traffic type, enabled security services, configuration, and network conditions.


Key Features & Benefits

Next-Generation Firewall Protection

The FG-600F provides advanced firewall functionality for inspecting, filtering, and controlling traffic across enterprise networks. Security policies can be applied between users, applications, servers, devices, and network segments.

Secure SD-WAN

Integrated Secure SD-WAN combines intelligent WAN traffic management with security enforcement, allowing organizations to manage multiple WAN connections while maintaining centralized security policies.

This makes the FG-600F suitable for enterprise WAN modernization and hybrid network architectures.

Extremely High Firewall Performance

With up to 198 Gbps firewall throughput, the FG-600F is designed for high-bandwidth enterprise, campus, and data-center-edge deployments.

Advanced Threat Protection

The FG-600F supports integrated security technologies including:

  • Intrusion Prevention System (IPS)
  • Application Control
  • Malware protection
  • Web filtering
  • DNS security
  • SSL/TLS inspection
  • Threat detection
  • Security filtering
  • Zero Trust Network Access

Fortinet currently lists the FG-600F at up to 25 Gbps threat protection throughput and 9 Gbps SSL inspection throughput in its product performance matrix.

High-Speed IPsec VPN

With up to 55 Gbps IPsec VPN throughput, the FG-600F provides high-performance encrypted connectivity for enterprise sites, data centers, branch offices, and remote networks.

Massive Session Capacity

The FG-600F supports up to 24 million concurrent sessions and up to 1 million new sessions per second, providing substantial capacity for large enterprise environments.

Flexible High-Speed Interfaces

The FG-600F provides a combination of Gigabit Ethernet RJ45, Gigabit SFP, 10 Gigabit SFP+/SFP, and 25 Gigabit SFP28/SFP+ ultra-low-latency connectivity, supporting modern copper and fiber network architectures.

AI/ML-Powered Security

The 600F Series incorporates AI/ML-powered security capabilities and integrates with Fortinet’s FortiGuard and Security Fabric ecosystem to improve threat detection, visibility, and coordinated response.


Security & Networking Capabilities

The FortiGate FG-600F supports a broad range of enterprise security and networking functions, including:

  • Stateful firewall
  • Next-Generation Firewall
  • Intrusion Prevention System (IPS)
  • Application Control
  • SSL/TLS inspection
  • Malware protection
  • Web filtering
  • DNS security
  • IPsec VPN
  • SSL VPN
  • Secure SD-WAN
  • Zero Trust Network Access (ZTNA)
  • Network segmentation
  • FortiLink
  • FortiSwitch integration
  • FortiAP integration
  • High Availability
  • Active-Active clustering
  • Active-Passive clustering
  • Centralized management
  • Fortinet Security Fabric integration
  • AI/ML-assisted security capabilities

Recommended Applications

The FortiGate FG-600F is well suited for:

  • Large enterprises
  • Corporate headquarters
  • Enterprise campus networks
  • Data center edge security
  • Regional data centers
  • High-traffic Internet gateways
  • Large branch environments
  • Hybrid IT environments
  • Enterprise WAN infrastructure
  • Secure SD-WAN deployments
  • High-speed site-to-site VPN
  • Network segmentation
  • Enterprise perimeter security
  • Zero Trust network architectures
  • Fortinet Security Fabric environments

FortiGuard & FortiCare Licensing

The FG-600F is the physical FortiGate firewall appliance. Fortinet security services and technical support may be purchased separately or included depending on the exact SKU and package being supplied.

FortiGuard subscriptions can provide additional security services, threat intelligence, and advanced protection capabilities, while FortiCare provides technical support and maintenance services.

Important: FortiGuard and FortiCare subscriptions should not be advertised as included unless the exact SKU being sold specifically includes those services.


Compatibility Note

The FG-600F is part of the FortiGate 600F Series and is designed for high-performance enterprise, campus, and data-center-edge deployments.

The appliance provides a mixture of copper and fiber interfaces, including GE RJ45, GE SFP, 10GE/GE SFP+/SFP, and 25GE/10GE SFP28/SFP+ ultra-low-latency slots. This allows it to integrate into both existing Gigabit infrastructure and newer high-speed fiber networks.

The FG-600F should be distinguished from the FG-601F, which is a related 600F-series model. The exact model, hardware revision, interface configuration, power supplies, licensing status, transceivers, and accessories should always be verified against the physical product label and exact SKU before listing or shipping.