- 60 wired + 75 phone(s) + 12 camera(s) + 8 AP(s) = 155 access ports.
- PoE demand ≈ 878 W (+20% margin → 1054 W); each FS-124G-FPOE gives 780 W.
- → 7 × FS-124G-FPOE (24-port, 802.3bt PoE).
- Fortinet Wi-Fi design starts with the clients, then coverage.
- 120 concurrent clients ÷ 40/AP (office density) = 3 AP(s).
- 1500 m² ÷ 200 m²/AP ≈ 8 AP(s).
- Took the higher of the two → 8 × FAP-231K (Wi-Fi 7).
The one number that gets FortiGate sizing wrong
Every FortiGate datasheet leads with a big “firewall throughput” figure. It is measured with no inspection running at all — pure packet forwarding. Turn on the security you actually bought the firewall for (IPS, application control, anti-malware) and real capacity drops sharply. Fortinet publishes that real number as Threat Protection throughput, and its own deployment guide tells you to size on it. Most buyers never see it.
The gap is not small. An FG-60F forwards 10 Gbps of raw traffic but inspects only 700 Mbps with full threat protection — a firewall sized on the headline number can be ~14× too small in practice. This tool sizes on Threat Protection and, when you enable deep SSL/SSH inspection, on the (usually lower) SSL-inspection figure too — so the box it recommends genuinely handles your traffic, decrypted.
One firewall runs the whole network
A FortiGate isn’t just a firewall — its wireless controller is built in (no extra licence), and FortiSwitch and FortiAP are managed from the same console over FortiLink. That is why the tool sizes the switches and access points alongside the firewall: they’re one platform, one bill of materials, one thing to run.
FortiGate models & Threat Protection throughput
The current top-selling FortiGate lineup, sorted by real inspected capacity. Source: Fortinet Product Matrix, July 2026.
| Model | Tier | Threat Protection | Firewall | IPsec VPN | Concurrent sessions |
|---|---|---|---|---|---|
| FortiGate 30G | Entry / desktop | 500 Mbps | 4 Gbps | 3.5 Gbps | 600K |
| FortiGate 40F | Entry / desktop | 600 Mbps | 5 Gbps | 4.4 Gbps | 700K |
| FortiGate 60F | Entry / desktop | 700 Mbps | 10 Gbps | 6.5 Gbps | 700K |
| FortiGate 70F | Entry / desktop | 800 Mbps | 10 Gbps | 6.1 Gbps | 1.5M |
| FortiGate 80F | Entry / desktop | 900 Mbps | 10 Gbps | 6.5 Gbps | 1.5M |
| FortiGate 50G | Entry / desktop | 1.1 Gbps | 5 Gbps | 4.5 Gbps | 720K |
| FortiGate 70G | Entry / desktop | 1.3 Gbps | 10 Gbps | 7.1 Gbps | 1.4M |
| FortiGate 90G | Entry / desktop | 2.2 Gbps | 28 Gbps | 25 Gbps | 3M |
| FortiGate 120G | Branch & mid-range | 2.8 Gbps | 39 Gbps | 35 Gbps | 3M |
| FortiGate 200G | Branch & mid-range | 6 Gbps | 39 Gbps | 36 Gbps | 11M |
| FortiGate 400G | Branch & mid-range | 13 Gbps | 164 Gbps | 55 Gbps | 28M |
| FortiGate 700G | Campus / enterprise edge | 26 Gbps | 164 Gbps | 55 Gbps | 28M |
| FortiGate 900G | Campus / enterprise edge | 30 Gbps | 164 Gbps | 55 Gbps | 28M |
| FortiGate 1000F | Data centre | 13 Gbps | 198 Gbps | 55 Gbps | 7.5M |
| FortiGate 1800F | Data centre | 15 Gbps | 198 Gbps | 55 Gbps | 12M |
| FortiGate 2600F | Data centre | 25 Gbps | 198 Gbps | 55 Gbps | 24M |
| FortiGate 3000F | Data centre | 33 Gbps | 397 Gbps | 105 Gbps | 70M |
| FortiGate 3200F | Data centre | 45 Gbps | 387 Gbps | 105 Gbps | 70M |
| FortiGate 4200F | Data centre | 45 Gbps | 800 Gbps | 210 Gbps | 210M |
| FortiGate 3500F | Data centre | 63 Gbps | 595 Gbps | 165 Gbps | 140M |
| FortiGate 3700F | Data centre | 75 Gbps | 589 Gbps | 160 Gbps | 140M |
| FortiGate 4400F | Data centre | 75 Gbps | 1150 Gbps | 310 Gbps | 210M |
| FortiGate 4800F | Data centre | 75 Gbps | 3100 Gbps | 800 Gbps | 280M |
| FortiGate 3000G | Data centre | 80 Gbps | 397 Gbps | 105 Gbps | 88M |
| FortiGate 3500G | Data centre | 105 Gbps | 595 Gbps | 163 Gbps | 179M |
| FortiGate 3800G | Data centre | 200 Gbps | 795 Gbps | 210 Gbps | 210M |
| FortiGate 7081F | Hyperscale chassis | 312 Gbps | 1890 Gbps | 378 Gbps | 600M |
| FortiGate 7121F | Hyperscale chassis | 520 Gbps | 1890 Gbps | 630 Gbps | 1000M |
Fortinet sizing — FAQs
Which FortiGate do I need?
It depends on the traffic you need to inspect, not your staff count alone. The tool sizes on Threat Protection throughput — the firewall’s real capacity with IPS, application control and malware protection all enabled — plus concurrent sessions and interfaces. Enter your users, servers and internet bandwidth and it returns the smallest FortiGate that clears the demand with growth headroom.
Why not just size on firewall throughput?
Because “firewall throughput” is measured with no inspection at all, so it overstates real-world capacity by up to ~14× (an FG-60F is 10 Gbps firewall but 700 Mbps Threat Protection). Sizing on it is the most common way businesses under-buy a firewall. This tool deliberately ignores the headline number and sizes on Threat Protection.
What is Threat Protection throughput?
Fortinet’s benchmark for a FortiGate running Firewall + IPS + Application Control + Malware Protection together on an “Enterprise Mix” of traffic — i.e. the box doing its actual job. It is the number Fortinet’s own deployment guide tells you to size on, and it is what every figure in this tool is based on.
Does the tool cover switches and access points too?
Yes. Toggle on Switching and Wireless and it sizes FortiSwitch (by port count and PoE budget against your phones, cameras and APs) and FortiAP (clients-first, then coverage) — a complete Security Fabric bill of materials, all managed from the one FortiGate over FortiLink.
How accurate is it?
Every hardware spec comes from Fortinet’s own July 2026 Product/Wireless matrices and datasheets — no figures are invented. The requirements-to-capacity translation uses transparent, industry-typical planning assumptions that are shown on screen. It is a sound starting point; a Servnet engineer validates the design and confirms exact SKUs before any quotation.
Do you show prices?
No — Fortinet hardware and especially subscription/licensing SKUs change too often to quote reliably online, and we never publish distributor pricing. The tool builds the right bill of materials; request a quote and we return firm pricing with finance options.
Talk to a UK specialist
Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.