UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
FREE TOOL · FORTINET SECURITY FABRIC SIZING

Which FortiGate do
you actually need?

Enter your users, bandwidth and needs — get the right FortiGate firewall, FortiSwitch, FortiAP and licensing as one Security Fabric. Sized on Threat Protection throughput, the number that reflects real capacity — not the headline firewall figure that leads businesses to under-buy.

Sized on real inspected capacityFull Fabric BOMVerified datasheet specsOne-click quote
✨ Describe your setup — we’ll fill it in
75
Each ≈ +10 users (Fortinet rule)
The pipe the firewall must inspect
30%
Recommended firewall
FortiGate 90G
Entry / desktop
Threat Protection
2.2 Gbps
real inspected capacity
Firewall (headline)
28 Gbps
13× overstated — we ignore it
Concurrent sessions
3M
New sess/sec
124,000
IPsec VPN
25 Gbps
Sized for
≥ 2.2 Gbps
8x GE RJ45, 2x 10GE Shared Port Pairs
Why this size
  • Sized on SSL-inspection throughput — the real inspected capacity, not the headline firewall number.
  • 75 devices + 3 server(s) ×10 = 105 effective users.
  • Fortinet's sizing guide maps 105 users to the FortiGate 90G class (≈2.2 Gbps Threat Protection, already margined for growth).
  • Your 1000 Mbps internet link + 30% growth headroom = 1.3 Gbps of inspection to size against.
  • Requirement = 2.2 Gbps SSL-inspection throughput (the higher of the user-band and bandwidth demands).
  • Deep SSL/SSH inspection is enabled — sized to clear demand on BOTH Threat Protection and SSL-inspection throughput (whichever is more constraining for this model), so the appliance genuinely handles decrypted traffic.
More headroom? Step up to the FortiGate 120G (2.8 Gbps TP).
Get this Fabric quoted →
Your Security Fabric
One managed platform — firewall, switching, wireless and licensing, all from the FortiGate.
Switching
7× FS-124G-FPOE
  • 60 wired + 75 phone(s) + 12 camera(s) + 8 AP(s) = 155 access ports.
  • PoE demand ≈ 878 W (+20% margin → 1054 W); each FS-124G-FPOE gives 780 W.
  • → 7 × FS-124G-FPOE (24-port, 802.3bt PoE).
Wireless
8× FAP-231K
Wi-Fi 7 · Wi-Fi 7 indoor, standard
  • Fortinet Wi-Fi design starts with the clients, then coverage.
  • 120 concurrent clients ÷ 40/AP (office density) = 3 AP(s).
  • 1500 m² ÷ 200 m²/AP ≈ 8 AP(s).
  • Took the higher of the two → 8 × FAP-231K (Wi-Fi 7).
Licensing
UTP
UTP adds web/DNS filtering and anti-botnet/C2 on top of ATP — the right balance for most businesses; Premium support is included.
+ FortiCare Premium
1 hour (telephone) · 24x7x365
Pricing is quote-based — Fortinet subscription SKUs change frequently.
Get this Fabric designed & quoted
FG-90G
We'll validate the sizing, confirm exact SKUs and licensing, and send a firm quotation. No obligation.
Figures are indicative planning estimates from verified Fortinet datasheets. A formal design + quotation follows a scoping call.

The one number that gets FortiGate sizing wrong

Every FortiGate datasheet leads with a big “firewall throughput” figure. It is measured with no inspection running at all — pure packet forwarding. Turn on the security you actually bought the firewall for (IPS, application control, anti-malware) and real capacity drops sharply. Fortinet publishes that real number as Threat Protection throughput, and its own deployment guide tells you to size on it. Most buyers never see it.

Firewall throughput vs. what it can actually inspectFirewall (headline)Threat ProtectionFG/FWF-60F10 Gbps700 Mbps14× gapFG-90G28 Gbps2.2 Gbps13× gapFG-120G39 Gbps2.8 Gbps14× gapFG-400G164 Gbps13 Gbps13× gapFG-900G164 Gbps30 Gbps5× gap
Verified from the Fortinet Product Matrix (July 2026). The headline “firewall throughput” assumes zero inspection — with full threat protection enabled, real capacity is a fraction of it. This tool sizes on the red bar, never the grey.

The gap is not small. An FG-60F forwards 10 Gbps of raw traffic but inspects only 700 Mbps with full threat protection — a firewall sized on the headline number can be ~14× too small in practice. This tool sizes on Threat Protection and, when you enable deep SSL/SSH inspection, on the (usually lower) SSL-inspection figure too — so the box it recommends genuinely handles your traffic, decrypted.

One firewall runs the whole network

A FortiGate isn’t just a firewall — its wireless controller is built in (no extra licence), and FortiSwitch and FortiAP are managed from the same console over FortiLink. That is why the tool sizes the switches and access points alongside the firewall: they’re one platform, one bill of materials, one thing to run.

One platform, one console — the Security FabricFortiLinkFortiGate NGFWFirewall + built-in wireless controllerno separate controller · no per-switch licenceFortiSwitchPoE access — phones, cameras, APsFortiAPWi-Fi 7 / 6E / 6EndpointsWired + wireless clients
The FortiGate’s wireless controller is built in (no extra licence), and FortiSwitch/FortiAP are managed from the same console over FortiLink — the reason a Fortinet stack is simpler to run than mixed vendors.

FortiGate models & Threat Protection throughput

The current top-selling FortiGate lineup, sorted by real inspected capacity. Source: Fortinet Product Matrix, July 2026.

ModelTierThreat ProtectionFirewallIPsec VPNConcurrent sessions
FortiGate 30GEntry / desktop500 Mbps4 Gbps3.5 Gbps600K
FortiGate 40FEntry / desktop600 Mbps5 Gbps4.4 Gbps700K
FortiGate 60FEntry / desktop700 Mbps10 Gbps6.5 Gbps700K
FortiGate 70FEntry / desktop800 Mbps10 Gbps6.1 Gbps1.5M
FortiGate 80FEntry / desktop900 Mbps10 Gbps6.5 Gbps1.5M
FortiGate 50GEntry / desktop1.1 Gbps5 Gbps4.5 Gbps720K
FortiGate 70GEntry / desktop1.3 Gbps10 Gbps7.1 Gbps1.4M
FortiGate 90GEntry / desktop2.2 Gbps28 Gbps25 Gbps3M
FortiGate 120GBranch & mid-range2.8 Gbps39 Gbps35 Gbps3M
FortiGate 200GBranch & mid-range6 Gbps39 Gbps36 Gbps11M
FortiGate 400GBranch & mid-range13 Gbps164 Gbps55 Gbps28M
FortiGate 700GCampus / enterprise edge26 Gbps164 Gbps55 Gbps28M
FortiGate 900GCampus / enterprise edge30 Gbps164 Gbps55 Gbps28M
FortiGate 1000FData centre13 Gbps198 Gbps55 Gbps7.5M
FortiGate 1800FData centre15 Gbps198 Gbps55 Gbps12M
FortiGate 2600FData centre25 Gbps198 Gbps55 Gbps24M
FortiGate 3000FData centre33 Gbps397 Gbps105 Gbps70M
FortiGate 3200FData centre45 Gbps387 Gbps105 Gbps70M
FortiGate 4200FData centre45 Gbps800 Gbps210 Gbps210M
FortiGate 3500FData centre63 Gbps595 Gbps165 Gbps140M
FortiGate 3700FData centre75 Gbps589 Gbps160 Gbps140M
FortiGate 4400FData centre75 Gbps1150 Gbps310 Gbps210M
FortiGate 4800FData centre75 Gbps3100 Gbps800 Gbps280M
FortiGate 3000GData centre80 Gbps397 Gbps105 Gbps88M
FortiGate 3500GData centre105 Gbps595 Gbps163 Gbps179M
FortiGate 3800GData centre200 Gbps795 Gbps210 Gbps210M
FortiGate 7081FHyperscale chassis312 Gbps1890 Gbps378 Gbps600M
FortiGate 7121FHyperscale chassis520 Gbps1890 Gbps630 Gbps1000M

Fortinet sizing — FAQs

Which FortiGate do I need?

It depends on the traffic you need to inspect, not your staff count alone. The tool sizes on Threat Protection throughput — the firewall’s real capacity with IPS, application control and malware protection all enabled — plus concurrent sessions and interfaces. Enter your users, servers and internet bandwidth and it returns the smallest FortiGate that clears the demand with growth headroom.

Why not just size on firewall throughput?

Because “firewall throughput” is measured with no inspection at all, so it overstates real-world capacity by up to ~14× (an FG-60F is 10 Gbps firewall but 700 Mbps Threat Protection). Sizing on it is the most common way businesses under-buy a firewall. This tool deliberately ignores the headline number and sizes on Threat Protection.

What is Threat Protection throughput?

Fortinet’s benchmark for a FortiGate running Firewall + IPS + Application Control + Malware Protection together on an “Enterprise Mix” of traffic — i.e. the box doing its actual job. It is the number Fortinet’s own deployment guide tells you to size on, and it is what every figure in this tool is based on.

Does the tool cover switches and access points too?

Yes. Toggle on Switching and Wireless and it sizes FortiSwitch (by port count and PoE budget against your phones, cameras and APs) and FortiAP (clients-first, then coverage) — a complete Security Fabric bill of materials, all managed from the one FortiGate over FortiLink.

How accurate is it?

Every hardware spec comes from Fortinet’s own July 2026 Product/Wireless matrices and datasheets — no figures are invented. The requirements-to-capacity translation uses transparent, industry-typical planning assumptions that are shown on screen. It is a sound starting point; a Servnet engineer validates the design and confirms exact SKUs before any quotation.

Do you show prices?

No — Fortinet hardware and especially subscription/licensing SKUs change too often to quote reliably online, and we never publish distributor pricing. The tool builds the right bill of materials; request a quote and we return firm pricing with finance options.

💷 Spread the cost · IT finance

Spread the cost of your Fortinet Security Fabric

Once you've sized it, fund the whole Fabric — FortiGate, FortiSwitch, FortiAP and licensing — over 1–5 years with hire purchase, lease or subscription for UK businesses.

Explore Fortinet finance

Indicative estimate · subject to change · no credit check at this stage · hire purchase, lease & subscription for UK businesses

Indicative illustration only. Servnet Limited is not authorised or regulated by the FCA and does not provide financial advice or arrange finance. All finance opportunities are referred to Number Eight Business Finance. Finance policy

Explore Fortinet at Servnet

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111