Fortinet FortiGate 400F (FG-400F)
The Fortinet FortiGate FG-400F is a high-performance Next-Generation Firewall (NGFW) and Secure SD-WAN appliance designed for large enterprises, campus networks, data center edges, high-traffic corporate environments, and organizations requiring advanced security with high-speed network connectivity.
Powered by FortiOS and Fortinet’s purpose-built security processing architecture, the FG-400F combines enterprise firewalling, intrusion prevention, application control, SSL inspection, IPsec VPN, Secure SD-WAN, network segmentation, Zero Trust Network Access (ZTNA), and Fortinet Security Fabric integration in a 1U rackmount appliance.
The FG-400F provides up to 79.5 Gbps firewall throughput, 55 Gbps IPsec VPN throughput, 12 Gbps IPS throughput, 10 Gbps NGFW throughput, and 9 Gbps threat protection throughput under Fortinet’s published test conditions.
Description
The Fortinet FortiGate 400F (FG-400F) is an enterprise-grade Next-Generation Firewall and Secure SD-WAN platform designed for demanding network environments where high throughput, advanced threat protection, and secure connectivity are critical.
The FG-400F consolidates multiple networking and security functions into a single appliance, helping organizations protect users, applications, servers, devices, and network traffic while simplifying their security infrastructure.
The appliance runs FortiOS, Fortinet’s integrated operating system for converged networking and security. It provides firewall policies, application control, intrusion prevention, web and DNS security, SSL inspection, IPsec VPN, Secure SD-WAN, network segmentation, ZTNA, and integration with the Fortinet Security Fabric.
The FG-400F is powered by Fortinet’s ASIC-based security processing architecture, designed to accelerate networking and security workloads while maintaining high throughput and low latency. Fortinet positions the 400F Series for enterprise edge security, hybrid IT environments, and high-performance secure networking.
With support for up to 7.8 million concurrent TCP sessions and up to 500,000 new TCP sessions per second, the FG-400F provides substantial capacity for large enterprise and data-center-edge deployments.
Key Specifications
| Specification | FortiGate FG-400F |
|---|---|
| Brand | Fortinet |
| Product Family | FortiGate 400F Series |
| Model | FG-400F |
| Product Type | Next-Generation Firewall / Secure SD-WAN Appliance |
| Operating System | FortiOS |
| Form Factor | 1U Rackmount |
| GE RJ45 Interfaces | 16 × Gigabit Ethernet RJ45 |
| GE SFP Interfaces | 8 × Gigabit SFP |
| 10GE SFP+ Interfaces | 4 × 10 Gigabit SFP+ |
| 10GE Ultra-Low-Latency Interfaces | 4 × 10 Gigabit SFP+ |
| Management Ports | 2 × GE RJ45 |
| Firewall Throughput | Up to 79.5 Gbps |
| Firewall Packet Processing | Up to 105 Mpps |
| IPsec VPN Throughput | Up to 55 Gbps |
| IPS Throughput | Up to 12 Gbps |
| NGFW Throughput | Up to 10 Gbps |
| Threat Protection Throughput | Up to 9 Gbps |
| SSL Inspection Throughput | Up to 8 Gbps |
| Application Control Throughput | Up to 28 Gbps |
| Concurrent TCP Sessions | Up to 7.8 million |
| New TCP Sessions/Second | Up to 500,000 |
| Firewall Policies | Up to 10,000 |
| Gateway-to-Gateway IPsec Tunnels | Up to 2,000 |
| Client-to-Gateway IPsec Tunnels | Up to 50,000 |
| SSL-VPN Throughput | Up to 3.6 Gbps |
| Concurrent SSL-VPN Users | Up to 5,000 recommended maximum |
| Virtual Domains | 10 default / 25 maximum |
| FortiSwitch Support | Up to 96* |
| FortiAP Support | Up to 512 total / 256 tunnel mode |
| FortiToken Support | Up to 5,000 |
| High Availability | Active-Active, Active-Passive, Clustering |
| Power Supply | Dual AC, hot-swappable |
| Form Factor | 1U Rackmount |
*Fortinet notes that support for up to 96 FortiSwitch devices requires FortiOS 7.6.1 or later; earlier releases support up to 72.
Performance figures are manufacturer-published “up to” benchmark values measured under controlled conditions. Actual performance depends on configuration, traffic type, packet size, enabled security services, and network conditions.
Key Features & Benefits
Next-Generation Firewall Protection
The FG-400F provides advanced firewall capabilities for inspecting, filtering, and controlling traffic across enterprise networks. It enables detailed security policies between users, applications, servers, internal segments, and external networks.
Secure SD-WAN
Integrated Secure SD-WAN combines WAN optimization and intelligent traffic management with enterprise security policies. This enables organizations to securely manage multiple WAN connections and prioritize business-critical applications.
High-Speed Firewall Performance
With up to 79.5 Gbps firewall throughput, the FG-400F is designed for high-bandwidth enterprise, campus, and data center edge environments.
Advanced Threat Protection
The FG-400F supports integrated security technologies including:
- Intrusion Prevention System (IPS)
- Application Control
- Malware protection
- Web filtering
- DNS security
- SSL/TLS inspection
- Threat detection
- Security filtering
- Zero Trust Network Access
Fortinet currently lists the FG-400F with up to 9 Gbps threat protection throughput.
High-Speed IPsec VPN
With up to 55 Gbps IPsec VPN throughput, the FG-400F is designed to support high-speed encrypted communications between enterprise locations, data centers, and remote networks.
High Session Capacity
The appliance supports up to 7.8 million concurrent TCP sessions and up to 500,000 new TCP sessions per second, providing substantial capacity for demanding enterprise environments.
Flexible Fiber & Copper Connectivity
The FG-400F provides a combination of Gigabit RJ45, Gigabit SFP, 10 Gigabit SFP+, and ultra-low-latency 10 Gigabit SFP+ interfaces, allowing deployment across modern copper and fiber network infrastructures.
Redundant Power
The FG-400F supports dual hot-swappable AC power supplies, providing 1+1 power redundancy for environments where high availability is important.
Security & Networking Capabilities
The FortiGate FG-400F supports a broad range of enterprise security and networking functions, including:
- Stateful firewall
- Next-Generation Firewall
- Intrusion Prevention System (IPS)
- Application Control
- SSL/TLS inspection
- Malware protection
- Web filtering
- DNS security
- IPsec VPN
- SSL VPN
- Secure SD-WAN
- Zero Trust Network Access (ZTNA)
- Network segmentation
- FortiLink
- FortiSwitch integration
- FortiAP integration
- High Availability
- Active-Active clustering
- Active-Passive clustering
- Centralized management
- Fortinet Security Fabric integration
Recommended Applications
The FortiGate FG-400F is well suited for:
- Large enterprises
- Corporate headquarters
- Enterprise campus networks
- Data center edge security
- High-traffic Internet gateways
- Regional data centers
- Service-provider edge environments
- Distributed enterprise networks
- Secure SD-WAN deployments
- Site-to-site VPN
- High-speed remote connectivity
- Network segmentation
- Enterprise perimeter security
- Hybrid IT environments
- Fortinet Security Fabric deployments
FortiGuard & FortiCare Licensing
The FG-400F is the physical FortiGate firewall appliance. Fortinet security services and technical support may be purchased separately or included depending on the exact SKU and package being supplied.
FortiGuard subscriptions can provide additional security services, threat intelligence, and advanced protection capabilities, while FortiCare provides technical support and maintenance services.
Important: FortiGuard and FortiCare subscriptions should not be advertised as included unless the exact SKU being sold specifically includes those services.
Compatibility Note
The FG-400F is part of the FortiGate 400F Series and is designed for high-performance enterprise security deployments.
The standard FG-400F provides 16 GE RJ45 ports, 8 GE SFP slots, 4 10GE SFP+ slots, and 4 additional 10GE ultra-low-latency SFP+ slots. It also includes dedicated management and console connectivity.
The FG-400F should be distinguished from the FG-401F, which is a related model in the 400F Series with different hardware characteristics.
The exact hardware configuration, power configuration, licensing status, included transceivers, and accessories should always be verified against the physical product label and exact SKU before listing or shipping.



