Home / Firewalls / Fortinet FortiGate 400F (FG-400F)

Fortinet FortiGate 400F (FG-400F)

The Fortinet FortiGate FG-400F is a high-performance Next-Generation Firewall (NGFW) and Secure SD-WAN appliance designed for large enterprises, campus networks, data center edges, high-traffic corporate environments, and organizations requiring advanced security with high-speed network connectivity.

Powered by FortiOS and Fortinet’s purpose-built security processing architecture, the FG-400F combines enterprise firewalling, intrusion prevention, application control, SSL inspection, IPsec VPN, Secure SD-WAN, network segmentation, Zero Trust Network Access (ZTNA), and Fortinet Security Fabric integration in a 1U rackmount appliance.

The FG-400F provides up to 79.5 Gbps firewall throughput, 55 Gbps IPsec VPN throughput, 12 Gbps IPS throughput, 10 Gbps NGFW throughput, and 9 Gbps threat protection throughput under Fortinet’s published test conditions.

Category:

Description

The Fortinet FortiGate 400F (FG-400F) is an enterprise-grade Next-Generation Firewall and Secure SD-WAN platform designed for demanding network environments where high throughput, advanced threat protection, and secure connectivity are critical.

The FG-400F consolidates multiple networking and security functions into a single appliance, helping organizations protect users, applications, servers, devices, and network traffic while simplifying their security infrastructure.

The appliance runs FortiOS, Fortinet’s integrated operating system for converged networking and security. It provides firewall policies, application control, intrusion prevention, web and DNS security, SSL inspection, IPsec VPN, Secure SD-WAN, network segmentation, ZTNA, and integration with the Fortinet Security Fabric.

The FG-400F is powered by Fortinet’s ASIC-based security processing architecture, designed to accelerate networking and security workloads while maintaining high throughput and low latency. Fortinet positions the 400F Series for enterprise edge security, hybrid IT environments, and high-performance secure networking.

With support for up to 7.8 million concurrent TCP sessions and up to 500,000 new TCP sessions per second, the FG-400F provides substantial capacity for large enterprise and data-center-edge deployments.


Key Specifications

Specification FortiGate FG-400F
Brand Fortinet
Product Family FortiGate 400F Series
Model FG-400F
Product Type Next-Generation Firewall / Secure SD-WAN Appliance
Operating System FortiOS
Form Factor 1U Rackmount
GE RJ45 Interfaces 16 × Gigabit Ethernet RJ45
GE SFP Interfaces 8 × Gigabit SFP
10GE SFP+ Interfaces 4 × 10 Gigabit SFP+
10GE Ultra-Low-Latency Interfaces 4 × 10 Gigabit SFP+
Management Ports 2 × GE RJ45
Firewall Throughput Up to 79.5 Gbps
Firewall Packet Processing Up to 105 Mpps
IPsec VPN Throughput Up to 55 Gbps
IPS Throughput Up to 12 Gbps
NGFW Throughput Up to 10 Gbps
Threat Protection Throughput Up to 9 Gbps
SSL Inspection Throughput Up to 8 Gbps
Application Control Throughput Up to 28 Gbps
Concurrent TCP Sessions Up to 7.8 million
New TCP Sessions/Second Up to 500,000
Firewall Policies Up to 10,000
Gateway-to-Gateway IPsec Tunnels Up to 2,000
Client-to-Gateway IPsec Tunnels Up to 50,000
SSL-VPN Throughput Up to 3.6 Gbps
Concurrent SSL-VPN Users Up to 5,000 recommended maximum
Virtual Domains 10 default / 25 maximum
FortiSwitch Support Up to 96*
FortiAP Support Up to 512 total / 256 tunnel mode
FortiToken Support Up to 5,000
High Availability Active-Active, Active-Passive, Clustering
Power Supply Dual AC, hot-swappable
Form Factor 1U Rackmount

*Fortinet notes that support for up to 96 FortiSwitch devices requires FortiOS 7.6.1 or later; earlier releases support up to 72.

Performance figures are manufacturer-published “up to” benchmark values measured under controlled conditions. Actual performance depends on configuration, traffic type, packet size, enabled security services, and network conditions.


Key Features & Benefits

Next-Generation Firewall Protection

The FG-400F provides advanced firewall capabilities for inspecting, filtering, and controlling traffic across enterprise networks. It enables detailed security policies between users, applications, servers, internal segments, and external networks.

Secure SD-WAN

Integrated Secure SD-WAN combines WAN optimization and intelligent traffic management with enterprise security policies. This enables organizations to securely manage multiple WAN connections and prioritize business-critical applications.

High-Speed Firewall Performance

With up to 79.5 Gbps firewall throughput, the FG-400F is designed for high-bandwidth enterprise, campus, and data center edge environments.

Advanced Threat Protection

The FG-400F supports integrated security technologies including:

  • Intrusion Prevention System (IPS)
  • Application Control
  • Malware protection
  • Web filtering
  • DNS security
  • SSL/TLS inspection
  • Threat detection
  • Security filtering
  • Zero Trust Network Access

Fortinet currently lists the FG-400F with up to 9 Gbps threat protection throughput.

High-Speed IPsec VPN

With up to 55 Gbps IPsec VPN throughput, the FG-400F is designed to support high-speed encrypted communications between enterprise locations, data centers, and remote networks.

High Session Capacity

The appliance supports up to 7.8 million concurrent TCP sessions and up to 500,000 new TCP sessions per second, providing substantial capacity for demanding enterprise environments.

Flexible Fiber & Copper Connectivity

The FG-400F provides a combination of Gigabit RJ45, Gigabit SFP, 10 Gigabit SFP+, and ultra-low-latency 10 Gigabit SFP+ interfaces, allowing deployment across modern copper and fiber network infrastructures.

Redundant Power

The FG-400F supports dual hot-swappable AC power supplies, providing 1+1 power redundancy for environments where high availability is important.


Security & Networking Capabilities

The FortiGate FG-400F supports a broad range of enterprise security and networking functions, including:

  • Stateful firewall
  • Next-Generation Firewall
  • Intrusion Prevention System (IPS)
  • Application Control
  • SSL/TLS inspection
  • Malware protection
  • Web filtering
  • DNS security
  • IPsec VPN
  • SSL VPN
  • Secure SD-WAN
  • Zero Trust Network Access (ZTNA)
  • Network segmentation
  • FortiLink
  • FortiSwitch integration
  • FortiAP integration
  • High Availability
  • Active-Active clustering
  • Active-Passive clustering
  • Centralized management
  • Fortinet Security Fabric integration

Recommended Applications

The FortiGate FG-400F is well suited for:

  • Large enterprises
  • Corporate headquarters
  • Enterprise campus networks
  • Data center edge security
  • High-traffic Internet gateways
  • Regional data centers
  • Service-provider edge environments
  • Distributed enterprise networks
  • Secure SD-WAN deployments
  • Site-to-site VPN
  • High-speed remote connectivity
  • Network segmentation
  • Enterprise perimeter security
  • Hybrid IT environments
  • Fortinet Security Fabric deployments

FortiGuard & FortiCare Licensing

The FG-400F is the physical FortiGate firewall appliance. Fortinet security services and technical support may be purchased separately or included depending on the exact SKU and package being supplied.

FortiGuard subscriptions can provide additional security services, threat intelligence, and advanced protection capabilities, while FortiCare provides technical support and maintenance services.

Important: FortiGuard and FortiCare subscriptions should not be advertised as included unless the exact SKU being sold specifically includes those services.


Compatibility Note

The FG-400F is part of the FortiGate 400F Series and is designed for high-performance enterprise security deployments.

The standard FG-400F provides 16 GE RJ45 ports, 8 GE SFP slots, 4 10GE SFP+ slots, and 4 additional 10GE ultra-low-latency SFP+ slots. It also includes dedicated management and console connectivity.

The FG-400F should be distinguished from the FG-401F, which is a related model in the 400F Series with different hardware characteristics.

The exact hardware configuration, power configuration, licensing status, included transceivers, and accessories should always be verified against the physical product label and exact SKU before listing or shipping.