FortiGate 40F vs 50G vs 60F vs 70G vs 90G

FortiGate 40F vs 50G vs 60F vs 70G vs 90G

A practical comparison of FortiGate small-branch firewalls using threat protection, SSL inspection, sessions, ports, storage and expansion headroom.

Key Points

  • Threat protection and SSL inspection figures are more useful than raw firewall throughput for an internet-edge deployment.
  • The newer 50G and 70G can outperform some higher-numbered F-series models in inspected workloads, so generation matters as much as model number.
  • FortiGate 90G provides the most headroom in this group, including higher threat protection capacity and session scale.
  • Storage variants such as 51G, 61F, 71G and 91G add local disk capacity; they are not a faster firewall tier by themselves.
  • Size the appliance and FortiGuard bundle together because enabled security services define the real workload.
At a Glance
Value / light branch FortiGate 40F
New-generation compact branch FortiGate 50G / 70G
Established general branch FortiGate 60F
Highest headroom here FortiGate 90G
Compare first Threat protection, SSL inspection, ports and sessions

FortiGate model numbers look like a simple ladder, but the FortiGate 40F, 50G, 60F, 70G and 90G do not scale in a perfectly straight line. Processor generation, inspection workload, interface mix and local-storage variants all affect the decision. This comparison uses Fortinet's September 2026 product matrix and focuses on the metrics that matter when the appliance will run as a next-generation firewall rather than a basic router.

FortiGate 40F vs 50G vs 60F vs 70G vs 90G Performance

ModelThreat protection*NGFW*SSL inspection*Concurrent sessions
FortiGate 40F600 Mbps800 Mbps310 Mbps700,000
FortiGate 50G1.1 Gbps1.25 Gbps1.3 Gbps720,000
FortiGate 60F700 Mbps1 Gbps630 Mbps700,000
FortiGate 70G1.3 Gbps1.5 Gbps1.4 Gbps1.4 million
FortiGate 90G2.2 Gbps2.5 Gbps2.6 Gbps3 million

*Fortinet publishes these as up-to values using defined test profiles. Production results vary with traffic, policy, firmware and enabled services.

Raw firewall throughput is much higher across the range, but it is the least useful number for a site that will enable IPS, application control, malware protection and encrypted-traffic inspection. Use the threat protection figure as a conservative planning anchor, then account for the site's own traffic mix and growth.

Which FortiGate Model Fits?

FortiGate 40F

FortiGate 40F remains a capable value option for small branches, retail and remote offices with moderate inspected traffic. It is compact and widely deployed, but its 310 Mbps published SSL inspection figure is the tightest constraint in this comparison. It is a poor choice for a new gigabit internet circuit if most web traffic will be decrypted and inspected.

FortiGate 50G

FortiGate 50G is a newer-generation compact model with a notably stronger inspected-workload profile than 40F and 60F in the current matrix. It publishes 1.1 Gbps threat protection and 1.3 Gbps SSL inspection. This makes it attractive for small offices that want modern performance without moving to the larger branch tier. Check feature limitations and memory-related release notes for the exact FortiOS train you plan to run.

FortiGate 60F

FortiGate 60F is the familiar general-purpose branch model with a broad installed base, 10 copper interfaces in the current matrix, and many available variants. It can still be the right buy where price, known operational behavior or a specific SKU is more important than the newer G-series performance. For a new project, compare it directly with 50G and 70G rather than assuming 60F automatically sits between them.

FortiGate 70G

FortiGate 70G offers a balanced step up: 1.3 Gbps threat protection, 1.4 Gbps SSL inspection and 1.4 million sessions in Fortinet's current matrix. It is a strong fit for a busy branch, an office with a gigabit-class inspected internet edge, or a site consolidating firewall, SD-WAN, FortiSwitch and FortiAP management.

FortiGate 90G

FortiGate 90G has the most headroom in this group. Fortinet lists 2.2 Gbps threat protection, 2.6 Gbps SSL inspection, 3 million sessions and 25 Gbps IPsec VPN throughput. It also offers faster interface options. Choose it when growth, encrypted traffic, local segmentation or high session counts justify the premium, not simply because it is the largest number.

Why F Series vs G Series Matters

Generation can outweigh the model ladder. FortiGate 50G publishes higher threat protection and SSL inspection than 60F, and 70G improves materially on both 70F and 80F in the same product matrix. That does not make every G-series appliance universally better: port layout, FortiOS support, mature integrations and the purchase price can still favor an F-series model.

Compare the exact SKU against the current Fortinet matrix instead of reusing an old rule such as “60 is always above 50.” Product lifecycle also matters. A firewall bought for five years of service needs a firmware and support horizon that matches the contract term.

Storage, Wi-Fi and Other Variants

A final digit of “1” commonly identifies a local-storage variant: 51G, 61F, 71G and 91G. The disk supports local logging and related functions, but it does not turn the appliance into a higher performance tier. If logs will be sent to FortiAnalyzer or a cloud service, verify whether local storage is still worth the premium.

FortiWiFi variants add integrated wireless, while selected models offer PoE, DSL, cellular or other specialized interfaces. Integrated features can simplify a very small branch, but separate FortiAPs and FortiSwitches usually provide more placement flexibility and scale. Build the bill of materials from the site design, not from the longest feature list.

Practical Sizing Examples

ScenarioStarting shortlistReason
Small retail, 100-200 Mbps inspected traffic40F / 50GValue first; 50G adds growth and inspection headroom
Office on a 500 Mbps circuit with SSL inspection50G / 70GStronger encrypted-traffic performance than 40F
Busy branch near 1 Gbps inspected traffic70G / 90GGrowth margin, sessions and interface flexibility
Regional branch with heavy VPN and segmentation90GHighest tunnel, session and protection headroom in this set

These are shortlists, not guarantees. Use the broader FortiGate buying guide to account for high availability, users and security bundles.

FortiGate Buying Checklist

  1. Measure peak and 95th-percentile internet traffic.
  2. Estimate the percentage of traffic that will receive SSL inspection.
  3. Count sessions, VPN tunnels, FortiAPs and FortiSwitches.
  4. Confirm interface speeds, media and any integrated Wi-Fi or PoE requirement.
  5. Choose base or local-storage variant deliberately.
  6. Match the appliance to the correct FortiCare/FortiGuard bundle and term.
  7. Compare current SKUs and list prices on https://globalpricelist.com/fortinet.

Sources

FAQ

Is FortiGate 50G faster than FortiGate 60F?

For several inspected-workload metrics in Fortinet's September 2026 matrix, yes: 50G publishes higher threat protection and SSL inspection figures. Port layout, features, price and lifecycle still need comparison.

Which FortiGate is best for a 1 Gbps internet connection?

For substantial security inspection, 70G or 90G is a safer starting shortlist than 40F. Actual selection depends on SSL inspection, traffic mix, sessions, VPN and growth margin.

What is the difference between FortiGate 90G and 91G?

91G is the local-storage variant of the 90G family. The disk is useful for local logging and related functions; it is not a separate performance class.

Should I use firewall throughput to size a FortiGate?

Use it only as one reference. Threat protection, NGFW and SSL inspection figures better represent a security-enabled internet edge.

Do FortiGate performance numbers represent guaranteed production speed?

No. Published values are up-to results from defined test methods. Real throughput changes with traffic, policies, firmware, packet size and enabled services.

Check Current Fortinet Pricing

Browse the full, daily-updated Fortinet GPL on GlobalPriceList.com.

View Fortinet Price List