Home  /  Blog  /  Fortinet

Choosing a FortiGate model: 40F, 60F, 90G or 100F?

The model number goes up and so does the price. But which one does your office actually need?

The FortiGate family is wide and the naming is not obvious at first glance. The difference between a 40F and a 100F is not only price — the wrong choice means either money spent for nothing or a bottleneck a few months after installation.

What the model number tells you

It carries two pieces of information: the number is capacity, the letter is generation.

  • The higher the number, the greater the processing capacity, port count and concurrent session capacity. A 40F is for a small office; a 900G is for a data centre.
  • The letter indicates the generation. The F series is in widespread use; the G series is newer and delivers higher performance in the same class.

So a 90G is not simply the successor to a 90F — it is a current-generation device in its own class.

User count alone is not enough

"There are thirty of us, which model?" has no single answer. What actually decides it:

  • Your internet bandwidth. If you have a 1 Gbit line, the firewall has to carry that throughput with security services switched on — not with everything disabled.
  • Which services you will enable. With antivirus, IPS and SSL inspection running, real capacity drops well below the highest figure on the datasheet.
  • VPN user count. Forty people connecting from home is a heavier load than forty people sitting in the office.
  • Number of branch sites. Every site-to-site tunnel consumes resources.

The single most common sizing mistake

Datasheets quote several throughput figures. The largest one — usually labelled firewall throughput — measures plain packet forwarding with no inspection. It is the number that gets quoted in sales conversations, and it is the number least relevant to how you will actually run the device.

The figure that matters is threat protection throughput, measured with antivirus, IPS and application control enabled. On many models it is a fraction of the headline number. Turn on SSL inspection as well and it falls further still.

If you have a 500 Mbit line and you intend to inspect traffic, you need a model whose threat protection figure comfortably exceeds 500 Mbit — not one whose firewall throughput does.

A rough guide by class

40F / 50G — very small office, branch endpoint. 10–20 users, single line, simple rule set. Desktop chassis, quiet operation.

60F / 70G — small business. 20–50 users, redundant line possible, mid-level security services. The most commonly sold class.

80F / 100F / 120G — mid-sized. 50–150 users, multiple VLANs, heavy VPN use. Usually rack-mounted.

200F / 200G — enterprise. 150+ users, HA pair possible, multi-line SD-WAN.

These ranges are a direction, not a decision. The final choice comes from measurement.

Buying too large is also a mistake

Some resellers recommend one class up on the basis that "you will grow into it". Sometimes that is right; often it is not. Beyond the appliance cost, the subscription price also scales with the model — and you renew that every year.

If you are not going to double in three years, buy for what you need now and put the difference into a proper backup or a second internet line, both of which will probably do more for you.

How we decide

Before recommending anything, we measure. Peak throughput, concurrent sessions, how much of your traffic is encrypted, how many remote users connect and when. That takes a few days of monitoring and it costs you nothing.

You then get a written recommendation that states the reasoning — including the cheaper option where it is adequate. If your existing appliance is fine, we say so.

Need help with this?

Ask us about fortinet firewall installation, or request a free assessment directly.

Fortinet firewall installation
Blog

More articles

Fortinet

FortiGate licences explained: UTM, ATP and Enterprise

The appliance is a one-off purchase. The subscription is not — and what happens when it lapses surprises people.

Fortinet

SSL inspection on FortiGate: why it matters and how to deploy it

If you are not inspecting encrypted traffic, you are inspecting almost nothing. Here is what it takes to do it properly.

Fortinet

End internet outages: dual WAN with FortiGate SD-WAN

A second line only helps if the switchover is automatic and fast. Otherwise it is an expensive standby nobody remembers to use.