FortiGate 40F vs 50G vs 60F vs 70G vs 90G
A practical comparison of FortiGate small-branch firewalls using threat protection, SSL inspection, sessions, ports, storage and expansion headroom.
Key Points
- Threat protection and SSL inspection figures are more useful than raw firewall throughput for an internet-edge deployment.
- The newer 50G and 70G can outperform some higher-numbered F-series models in inspected workloads, so generation matters as much as model number.
- FortiGate 90G provides the most headroom in this group, including higher threat protection capacity and session scale.
- Storage variants such as 51G, 61F, 71G and 91G add local disk capacity; they are not a faster firewall tier by themselves.
- Size the appliance and FortiGuard bundle together because enabled security services define the real workload.
FortiGate model numbers look like a simple ladder, but the FortiGate 40F, 50G, 60F, 70G and 90G do not scale in a perfectly straight line. Processor generation, inspection workload, interface mix and local-storage variants all affect the decision. This comparison uses Fortinet's September 2026 product matrix and focuses on the metrics that matter when the appliance will run as a next-generation firewall rather than a basic router.
FortiGate 40F vs 50G vs 60F vs 70G vs 90G Performance
| Model | Threat protection* | NGFW* | SSL inspection* | Concurrent sessions |
|---|---|---|---|---|
| FortiGate 40F | 600 Mbps | 800 Mbps | 310 Mbps | 700,000 |
| FortiGate 50G | 1.1 Gbps | 1.25 Gbps | 1.3 Gbps | 720,000 |
| FortiGate 60F | 700 Mbps | 1 Gbps | 630 Mbps | 700,000 |
| FortiGate 70G | 1.3 Gbps | 1.5 Gbps | 1.4 Gbps | 1.4 million |
| FortiGate 90G | 2.2 Gbps | 2.5 Gbps | 2.6 Gbps | 3 million |
*Fortinet publishes these as up-to values using defined test profiles. Production results vary with traffic, policy, firmware and enabled services.
Raw firewall throughput is much higher across the range, but it is the least useful number for a site that will enable IPS, application control, malware protection and encrypted-traffic inspection. Use the threat protection figure as a conservative planning anchor, then account for the site's own traffic mix and growth.
Which FortiGate Model Fits?
FortiGate 40F
FortiGate 40F remains a capable value option for small branches, retail and remote offices with moderate inspected traffic. It is compact and widely deployed, but its 310 Mbps published SSL inspection figure is the tightest constraint in this comparison. It is a poor choice for a new gigabit internet circuit if most web traffic will be decrypted and inspected.
FortiGate 50G
FortiGate 50G is a newer-generation compact model with a notably stronger inspected-workload profile than 40F and 60F in the current matrix. It publishes 1.1 Gbps threat protection and 1.3 Gbps SSL inspection. This makes it attractive for small offices that want modern performance without moving to the larger branch tier. Check feature limitations and memory-related release notes for the exact FortiOS train you plan to run.
FortiGate 60F
FortiGate 60F is the familiar general-purpose branch model with a broad installed base, 10 copper interfaces in the current matrix, and many available variants. It can still be the right buy where price, known operational behavior or a specific SKU is more important than the newer G-series performance. For a new project, compare it directly with 50G and 70G rather than assuming 60F automatically sits between them.
FortiGate 70G
FortiGate 70G offers a balanced step up: 1.3 Gbps threat protection, 1.4 Gbps SSL inspection and 1.4 million sessions in Fortinet's current matrix. It is a strong fit for a busy branch, an office with a gigabit-class inspected internet edge, or a site consolidating firewall, SD-WAN, FortiSwitch and FortiAP management.
FortiGate 90G
FortiGate 90G has the most headroom in this group. Fortinet lists 2.2 Gbps threat protection, 2.6 Gbps SSL inspection, 3 million sessions and 25 Gbps IPsec VPN throughput. It also offers faster interface options. Choose it when growth, encrypted traffic, local segmentation or high session counts justify the premium, not simply because it is the largest number.
Why F Series vs G Series Matters
Generation can outweigh the model ladder. FortiGate 50G publishes higher threat protection and SSL inspection than 60F, and 70G improves materially on both 70F and 80F in the same product matrix. That does not make every G-series appliance universally better: port layout, FortiOS support, mature integrations and the purchase price can still favor an F-series model.
Compare the exact SKU against the current Fortinet matrix instead of reusing an old rule such as “60 is always above 50.” Product lifecycle also matters. A firewall bought for five years of service needs a firmware and support horizon that matches the contract term.
Storage, Wi-Fi and Other Variants
A final digit of “1” commonly identifies a local-storage variant: 51G, 61F, 71G and 91G. The disk supports local logging and related functions, but it does not turn the appliance into a higher performance tier. If logs will be sent to FortiAnalyzer or a cloud service, verify whether local storage is still worth the premium.
FortiWiFi variants add integrated wireless, while selected models offer PoE, DSL, cellular or other specialized interfaces. Integrated features can simplify a very small branch, but separate FortiAPs and FortiSwitches usually provide more placement flexibility and scale. Build the bill of materials from the site design, not from the longest feature list.
Practical Sizing Examples
| Scenario | Starting shortlist | Reason |
|---|---|---|
| Small retail, 100-200 Mbps inspected traffic | 40F / 50G | Value first; 50G adds growth and inspection headroom |
| Office on a 500 Mbps circuit with SSL inspection | 50G / 70G | Stronger encrypted-traffic performance than 40F |
| Busy branch near 1 Gbps inspected traffic | 70G / 90G | Growth margin, sessions and interface flexibility |
| Regional branch with heavy VPN and segmentation | 90G | Highest tunnel, session and protection headroom in this set |
These are shortlists, not guarantees. Use the broader FortiGate buying guide to account for high availability, users and security bundles.
FortiGate Buying Checklist
- Measure peak and 95th-percentile internet traffic.
- Estimate the percentage of traffic that will receive SSL inspection.
- Count sessions, VPN tunnels, FortiAPs and FortiSwitches.
- Confirm interface speeds, media and any integrated Wi-Fi or PoE requirement.
- Choose base or local-storage variant deliberately.
- Match the appliance to the correct FortiCare/FortiGuard bundle and term.
- Compare current SKUs and list prices on https://globalpricelist.com/fortinet.
Sources
- Fortinet Product Matrix - Fortinet, September 2026
- FortiGate Next-Generation Firewall Portfolio - Fortinet
- FortiGate/FortiWiFi 40F Series Datasheet - Fortinet
FAQ
Is FortiGate 50G faster than FortiGate 60F?
For several inspected-workload metrics in Fortinet's September 2026 matrix, yes: 50G publishes higher threat protection and SSL inspection figures. Port layout, features, price and lifecycle still need comparison.
Which FortiGate is best for a 1 Gbps internet connection?
For substantial security inspection, 70G or 90G is a safer starting shortlist than 40F. Actual selection depends on SSL inspection, traffic mix, sessions, VPN and growth margin.
What is the difference between FortiGate 90G and 91G?
91G is the local-storage variant of the 90G family. The disk is useful for local logging and related functions; it is not a separate performance class.
Should I use firewall throughput to size a FortiGate?
Use it only as one reference. Threat protection, NGFW and SSL inspection figures better represent a security-enabled internet edge.
Do FortiGate performance numbers represent guaranteed production speed?
No. Published values are up-to results from defined test methods. Real throughput changes with traffic, policies, firmware, packet size and enabled services.
Check Current Fortinet Pricing
Browse the full, daily-updated Fortinet GPL on GlobalPriceList.com.
View Fortinet Price List