Fortinet FG-600F FortiGate 600F Next-Generation Firewall & Secure SD-WAN Appliance
The Fortinet FortiGate FG-600F is a high-performance Next-Generation Firewall (NGFW) and Secure SD-WAN appliance designed for large enterprises, campus networks, data center edges, and high-traffic corporate environments requiring advanced security and high-speed connectivity.
Powered by FortiOS and Fortinet’s purpose-built SPU/ASIC security processing architecture, the FG-600F combines enterprise firewall protection, intrusion prevention, application control, SSL inspection, IPsec VPN, Secure SD-WAN, Zero Trust Network Access (ZTNA), network segmentation, and Fortinet Security Fabric integration in a 1U rackmount platform.
The FG-600F delivers up to 198 Gbps firewall throughput, 55 Gbps IPsec VPN throughput, 31 Gbps IPS throughput, 27 Gbps NGFW throughput, and 25 Gbps threat protection throughput under Fortinet’s published benchmark conditions.
Description
The Fortinet FortiGate 600F (FG-600F) is an enterprise-class Next-Generation Firewall and Secure SD-WAN appliance designed for demanding network environments where high throughput, advanced threat protection, visibility, and secure connectivity are essential.
The FG-600F consolidates networking and security functions into a single platform, allowing organizations to protect users, applications, servers, IoT devices, and network segments while reducing infrastructure complexity.
The appliance runs FortiOS, Fortinet’s converged networking and security operating system. It provides firewall policies, application control, intrusion prevention, web and DNS security, SSL/TLS inspection, IPsec VPN, Secure SD-WAN, network segmentation, ZTNA, and integration with the Fortinet Security Fabric.
Fortinet’s ASIC-based security processing architecture is designed to accelerate security inspection and networking workloads, enabling high throughput and low-latency operation. The 600F Series also incorporates AI/ML-powered security capabilities through the Fortinet Security Fabric and FortiGuard ecosystem.
The FG-600F provides up to 24 million concurrent sessions and up to 1 million new sessions per second, giving it substantial capacity for large enterprise, campus, and data-center-edge deployments.
Key Specifications
| Specification | FortiGate FG-600F |
|---|---|
| Brand | Fortinet |
| Product Family | FortiGate 600F Series |
| Model | FG-600F |
| Product Type | Next-Generation Firewall / Secure SD-WAN Appliance |
| Operating System | FortiOS |
| Form Factor | 1U Rackmount |
| GE RJ45 Interfaces | 16 |
| GE SFP Interfaces | 8 |
| 10GE/GE SFP+ Slots | 4 |
| 25GE/10GE SFP28/SFP+ ULL Slots | 4 |
| Management / HA Interfaces | 2 × GE RJ45 |
| Firewall Throughput | Up to 198 Gbps |
| Firewall Packet Processing | Up to 120 Mpps |
| IPsec VPN Throughput | Up to 55 Gbps |
| IPS Throughput | Up to 31 Gbps |
| NGFW Throughput | Up to 27 Gbps |
| Threat Protection Throughput | Up to 25 Gbps |
| SSL Inspection Throughput | Up to 9 Gbps |
| Concurrent Sessions | Up to 24 million |
| New Sessions/Second | Up to 1 million |
| Firewall Policies | Up to 40,000 |
| Gateway-to-Gateway IPsec Tunnels | Up to 20,000 |
| Client-to-Gateway IPsec Tunnels | Up to 50,000 |
| SSL-VPN Throughput | Up to 4.5 Gbps |
| High Availability | Active-Active / Active-Passive |
| FortiLink | Supported |
| FortiSwitch Integration | Supported |
| FortiAP Integration | Supported |
| FortiToken Support | Supported |
| Virtual Domains | Supported |
| Power Supply | Dual AC, redundant |
| Form Factor | 1U Rackmount |
Fortinet’s current product information identifies the FG-600F with 16 GE RJ45 ports, 8 GE SFP ports, 4 × 10GE/GE SFP+/SFP slots, 4 × 25GE/10GE SFP28/SFP+ ultra-low-latency slots, and 2 × GE RJ45 management/HA ports.
Performance figures are manufacturer-published “up to” benchmark values measured under controlled conditions. Actual throughput varies depending on packet size, traffic type, enabled security services, configuration, and network conditions.
Key Features & Benefits
Next-Generation Firewall Protection
The FG-600F provides advanced firewall functionality for inspecting, filtering, and controlling traffic across enterprise networks. Security policies can be applied between users, applications, servers, devices, and network segments.
Secure SD-WAN
Integrated Secure SD-WAN combines intelligent WAN traffic management with security enforcement, allowing organizations to manage multiple WAN connections while maintaining centralized security policies.
This makes the FG-600F suitable for enterprise WAN modernization and hybrid network architectures.
Extremely High Firewall Performance
With up to 198 Gbps firewall throughput, the FG-600F is designed for high-bandwidth enterprise, campus, and data-center-edge deployments.
Advanced Threat Protection
The FG-600F supports integrated security technologies including:
- Intrusion Prevention System (IPS)
- Application Control
- Malware protection
- Web filtering
- DNS security
- SSL/TLS inspection
- Threat detection
- Security filtering
- Zero Trust Network Access
Fortinet currently lists the FG-600F at up to 25 Gbps threat protection throughput and 9 Gbps SSL inspection throughput in its product performance matrix.
High-Speed IPsec VPN
With up to 55 Gbps IPsec VPN throughput, the FG-600F provides high-performance encrypted connectivity for enterprise sites, data centers, branch offices, and remote networks.
Massive Session Capacity
The FG-600F supports up to 24 million concurrent sessions and up to 1 million new sessions per second, providing substantial capacity for large enterprise environments.
Flexible High-Speed Interfaces
The FG-600F provides a combination of Gigabit Ethernet RJ45, Gigabit SFP, 10 Gigabit SFP+/SFP, and 25 Gigabit SFP28/SFP+ ultra-low-latency connectivity, supporting modern copper and fiber network architectures.
AI/ML-Powered Security
The 600F Series incorporates AI/ML-powered security capabilities and integrates with Fortinet’s FortiGuard and Security Fabric ecosystem to improve threat detection, visibility, and coordinated response.
Security & Networking Capabilities
The FortiGate FG-600F supports a broad range of enterprise security and networking functions, including:
- Stateful firewall
- Next-Generation Firewall
- Intrusion Prevention System (IPS)
- Application Control
- SSL/TLS inspection
- Malware protection
- Web filtering
- DNS security
- IPsec VPN
- SSL VPN
- Secure SD-WAN
- Zero Trust Network Access (ZTNA)
- Network segmentation
- FortiLink
- FortiSwitch integration
- FortiAP integration
- High Availability
- Active-Active clustering
- Active-Passive clustering
- Centralized management
- Fortinet Security Fabric integration
- AI/ML-assisted security capabilities
Recommended Applications
The FortiGate FG-600F is well suited for:
- Large enterprises
- Corporate headquarters
- Enterprise campus networks
- Data center edge security
- Regional data centers
- High-traffic Internet gateways
- Large branch environments
- Hybrid IT environments
- Enterprise WAN infrastructure
- Secure SD-WAN deployments
- High-speed site-to-site VPN
- Network segmentation
- Enterprise perimeter security
- Zero Trust network architectures
- Fortinet Security Fabric environments
FortiGuard & FortiCare Licensing
The FG-600F is the physical FortiGate firewall appliance. Fortinet security services and technical support may be purchased separately or included depending on the exact SKU and package being supplied.
FortiGuard subscriptions can provide additional security services, threat intelligence, and advanced protection capabilities, while FortiCare provides technical support and maintenance services.
Important: FortiGuard and FortiCare subscriptions should not be advertised as included unless the exact SKU being sold specifically includes those services.
Compatibility Note
The FG-600F is part of the FortiGate 600F Series and is designed for high-performance enterprise, campus, and data-center-edge deployments.
The appliance provides a mixture of copper and fiber interfaces, including GE RJ45, GE SFP, 10GE/GE SFP+/SFP, and 25GE/10GE SFP28/SFP+ ultra-low-latency slots. This allows it to integrate into both existing Gigabit infrastructure and newer high-speed fiber networks.
The FG-600F should be distinguished from the FG-601F, which is a related 600F-series model. The exact model, hardware revision, interface configuration, power supplies, licensing status, transceivers, and accessories should always be verified against the physical product label and exact SKU before listing or shipping.



