FortiGate licences explained: UTM, ATP and Enterprise
The appliance is a one-off purchase. The subscription is not — and what happens when it lapses surprises people.
The FortiGate family is wide and the naming is not obvious at first glance. The difference between a 40F and a 100F is not only price — the wrong choice means either money spent for nothing or a bottleneck a few months after installation.
It carries two pieces of information: the number is capacity, the letter is generation.
So a 90G is not simply the successor to a 90F — it is a current-generation device in its own class.
"There are thirty of us, which model?" has no single answer. What actually decides it:
Datasheets quote several throughput figures. The largest one — usually labelled firewall throughput — measures plain packet forwarding with no inspection. It is the number that gets quoted in sales conversations, and it is the number least relevant to how you will actually run the device.
The figure that matters is threat protection throughput, measured with antivirus, IPS and application control enabled. On many models it is a fraction of the headline number. Turn on SSL inspection as well and it falls further still.
If you have a 500 Mbit line and you intend to inspect traffic, you need a model whose threat protection figure comfortably exceeds 500 Mbit — not one whose firewall throughput does.
40F / 50G — very small office, branch endpoint. 10–20 users, single line, simple rule set. Desktop chassis, quiet operation.
60F / 70G — small business. 20–50 users, redundant line possible, mid-level security services. The most commonly sold class.
80F / 100F / 120G — mid-sized. 50–150 users, multiple VLANs, heavy VPN use. Usually rack-mounted.
200F / 200G — enterprise. 150+ users, HA pair possible, multi-line SD-WAN.
These ranges are a direction, not a decision. The final choice comes from measurement.
Some resellers recommend one class up on the basis that "you will grow into it". Sometimes that is right; often it is not. Beyond the appliance cost, the subscription price also scales with the model — and you renew that every year.
If you are not going to double in three years, buy for what you need now and put the difference into a proper backup or a second internet line, both of which will probably do more for you.
Before recommending anything, we measure. Peak throughput, concurrent sessions, how much of your traffic is encrypted, how many remote users connect and when. That takes a few days of monitoring and it costs you nothing.
You then get a written recommendation that states the reasoning — including the cheaper option where it is adequate. If your existing appliance is fine, we say so.
Ask us about fortinet firewall installation, or request a free assessment directly.
The appliance is a one-off purchase. The subscription is not — and what happens when it lapses surprises people.
If you are not inspecting encrypted traffic, you are inspecting almost nothing. Here is what it takes to do it properly.
A second line only helps if the switchover is automatic and fast. Otherwise it is an expensive standby nobody remembers to use.