Fortinet FG-900G FortiGate 900G Next-Generation Firewall & Secure SD-WAN Appliance
The Fortinet FortiGate FG-900G is a high-performance Next-Generation Firewall (NGFW) and Secure SD-WAN appliance designed for large enterprises, data centers, campus networks, high-traffic Internet gateways, and demanding hybrid IT environments.
Powered by FortiOS and Fortinet’s purpose-built SPU/ASIC security processing architecture, the FG-900G combines advanced firewall protection, intrusion prevention, application control, SSL inspection, IPsec VPN, Secure SD-WAN, Zero Trust Network Access (ZTNA), network segmentation, and Fortinet Security Fabric integration in a 1U rackmount platform.
The FG-900G provides up to 164 Gbps firewall throughput, 55 Gbps IPsec VPN throughput, 26 Gbps IPS throughput, 22 Gbps NGFW throughput, and 20 Gbps threat protection throughput under Fortinet’s published benchmark conditions.
Description
The Fortinet FortiGate 900G (FG-900G) is an enterprise-class Next-Generation Firewall and Secure SD-WAN appliance engineered for high-performance network security at large enterprise, campus, and data center edge locations.
The FG-900G consolidates networking and security functions into a single appliance, helping organizations protect users, applications, servers, IoT devices, and network segments while simplifying their security infrastructure.
The appliance runs FortiOS, Fortinet’s converged networking and security operating system. It provides firewall policies, application control, intrusion prevention, web and DNS security, SSL/TLS inspection, IPsec VPN, Secure SD-WAN, network segmentation, ZTNA, and integration with the Fortinet Security Fabric.
Fortinet’s SPU/ASIC-based architecture is designed to accelerate networking and security workloads, providing high throughput and low latency for demanding enterprise environments. Fortinet also highlights AI/ML-powered security capabilities through the FortiGuard ecosystem and Security Fabric.
The FG-900G supports up to 16 million concurrent TCP sessions and up to 720,000 new TCP sessions per second, making it suitable for large-scale enterprise deployments with substantial traffic and connection volumes.
Key Specifications
| Specification | FortiGate FG-900G |
|---|---|
| Brand | Fortinet |
| Product Family | FortiGate 900G Series |
| Model | FG-900G |
| Product Type | Next-Generation Firewall / Secure SD-WAN Appliance |
| Operating System | FortiOS |
| Form Factor | 1U Rackmount |
| GE RJ45 Interfaces | 16 |
| GE SFP Interfaces | 8 |
| 10GE SFP+ / GE SFP Slots | 4 |
| 25GE SFP28 / 10GE SFP+ ULL Slots | 4 |
| GE Management Port | 1 |
| 2.5GE / GE HA Port | 1 |
| Firewall Throughput | Up to 164 Gbps |
| Firewall Packet Processing | Up to 229.5 Mpps |
| IPsec VPN Throughput | Up to 55 Gbps |
| IPS Throughput | Up to 26 Gbps |
| NGFW Throughput | Up to 22 Gbps |
| Threat Protection Throughput | Up to 20 Gbps |
| SSL Inspection Throughput | Up to 16.7 Gbps |
| Application Control Throughput | Up to 74.8 Gbps |
| Concurrent TCP Sessions | Up to 16 million |
| New TCP Sessions/Second | Up to 720,000 |
| Firewall Policies | Up to 10,000 |
| Gateway-to-Gateway IPsec Tunnels | Up to 2,000 |
| Client-to-Gateway IPsec Tunnels | Up to 50,000 |
| SSL-VPN Throughput | Up to 10 Gbps |
| Concurrent SSL-VPN Users | Up to 10,000 recommended maximum |
| SSL Inspection Concurrent Sessions | Up to 1.6 million |
| Virtual Domains | 10 default / 10 maximum |
| FortiSwitch Support | Up to 96 |
| FortiAP Support | Up to 2,048 total / 1,024 tunnel mode |
| FortiToken Support | Up to 5,000 |
| High Availability | Active-Active / Active-Passive / Clustering |
| Power Supply | Dual Hot-Swappable AC |
| Form Factor | 1U Rackmount |
Specifications are based on Fortinet’s FG-900G Series datasheet.
Performance figures are manufacturer-published “up to” benchmark values measured under controlled conditions. Actual performance varies depending on packet size, traffic type, configuration, enabled security services, and network conditions.
Key Features & Benefits
Next-Generation Firewall Protection
The FG-900G provides advanced firewall functionality for inspecting, filtering, and controlling traffic across enterprise networks. Security policies can be applied between users, applications, servers, devices, and network segments.
Secure SD-WAN
Integrated Secure SD-WAN combines intelligent WAN traffic management with security enforcement. Organizations can manage multiple WAN connections, prioritize applications, and maintain centralized security policies through the same FortiGate platform.
High-Speed Firewall Performance
With up to 164 Gbps firewall throughput, the FG-900G is designed for high-bandwidth enterprise, campus, and data center edge environments.
Advanced Threat Protection
The FG-900G supports integrated security technologies including:
- Intrusion Prevention System (IPS)
- Application Control
- Malware protection
- Web filtering
- DNS security
- SSL/TLS inspection
- Threat detection
- Security filtering
- Zero Trust Network Access
Fortinet lists the FG-900G at up to 20 Gbps threat protection throughput.
High-Speed IPsec VPN
With up to 55 Gbps IPsec VPN throughput, the FG-900G can provide high-performance encrypted connectivity between enterprise locations, data centers, branch offices, and remote networks.
Large Session Capacity
The FG-900G supports up to 16 million concurrent TCP sessions and up to 720,000 new TCP sessions per second, providing substantial capacity for large-scale enterprise networks.
High-Performance SSL Inspection
The appliance supports up to 16.7 Gbps SSL inspection throughput, helping organizations inspect encrypted traffic while maintaining high network performance.
Flexible High-Speed Connectivity
The FG-900G combines Gigabit RJ45, Gigabit SFP, 10 Gigabit SFP+, and 25 Gigabit SFP28 connectivity. Its ultra-low-latency interfaces are designed for demanding high-speed network environments.
Redundant Power
The FG-900G includes two hot-swappable AC power supplies by default, providing power redundancy for enterprise environments where high availability is important.
Security & Networking Capabilities
The FortiGate FG-900G supports a broad range of enterprise security and networking functions, including:
- Stateful firewall
- Next-Generation Firewall
- Intrusion Prevention System (IPS)
- Application Control
- SSL/TLS inspection
- Malware protection
- Web filtering
- DNS security
- IPsec VPN
- SSL VPN
- Secure SD-WAN
- Zero Trust Network Access (ZTNA)
- Network segmentation
- FortiLink
- FortiSwitch integration
- FortiAP integration
- High Availability
- Active-Active clustering
- Active-Passive clustering
- Centralized management
- Fortinet Security Fabric integration
- AI/ML-powered security capabilities
Fortinet describes the 900G Series as combining AI/ML security, Secure SD-WAN, ZTNA, and Security Fabric capabilities with ASIC-accelerated performance.
Recommended Applications
The FortiGate FG-900G is well suited for:
- Large enterprises
- Corporate headquarters
- Enterprise campus networks
- Data center edge security
- Regional data centers
- High-traffic Internet gateways
- Large branch environments
- Hybrid IT environments
- Enterprise WAN infrastructure
- Secure SD-WAN deployments
- High-speed site-to-site VPN
- Network segmentation
- Enterprise perimeter security
- Zero Trust network architectures
- High-speed encrypted traffic inspection
- Fortinet Security Fabric environments
FortiGuard & FortiCare Licensing
The FG-900G is the physical FortiGate firewall appliance. Fortinet security services and technical support may be purchased separately or included depending on the exact SKU and package being supplied.
FortiGuard subscriptions can provide additional security services, threat intelligence, and advanced protection capabilities, while FortiCare provides technical support and maintenance services.
Important: FortiGuard and FortiCare subscriptions should not be advertised as included unless the exact SKU being sold specifically includes those services.
Compatibility Note
The FG-900G belongs to the FortiGate 900G Series and is designed for high-performance enterprise and data-center-edge deployments.
The standard FG-900G provides:
- 16 × GE RJ45
- 8 × GE SFP
- 4 × 10GE SFP+/GE SFP
- 4 × 25GE SFP28/10GE SFP+ ultra-low-latency slots
- 1 × GE management port
- 1 × 2.5GE/GE HA port
- Console and USB connectivity
The FG-900G should be distinguished from related models such as the FG-901G, FG-900G-DC, and FG-901G-DC, which have different hardware configurations.
The exact model, power configuration, hardware revision, licensing status, transceivers, and included accessories should always be verified against the physical product label and exact SKU before listing or shipping.



