Choosing the right firewall size is one of the most important steps in network security design. Many organizations deploying Fortinet firewalls—especially the FortiGate series—often struggle with a common question: How do you correctly size a FortiGate firewall for your environment?
Selecting a firewall that is too small can lead to performance bottlenecks and degraded security inspection. On the other hand, oversizing a firewall can significantly increase costs without delivering real benefits. This guide explains the key factors used in FortiGate sizing, common mistakes to avoid, and a practical approach to selecting the right model for your network.
- Part 1: What Is FortiGate Firewall Sizing?
- Part 2: Key Metrics Used in Fortinet Firewall Sizing
- Part 3: Typical FortiGate Deployment Scenarios
- Part 4: Common FortiGate Sizing Mistakes
- Part 5: A Simple FortiGate Sizing Formula
- Part 6: Where to Buy FortiGate Firewalls
- Part 7: Final Thoughts
- Part 8: FAQ

Part 1: What Is FortiGate Firewall Sizing?
FortiGate sizing refers to the process of determining the appropriate firewall model based on your network’s performance requirements, security features, and traffic patterns.
Unlike traditional routers, modern firewalls perform deep inspection tasks such as:
- Intrusion Prevention System (IPS)
- SSL inspection
- Application control
- Anti-malware scanning
- VPN encryption
Each of these security services consumes additional processing power, which means raw firewall throughput alone is not enough to determine the correct model.
Part 2: Key Metrics Used in Fortinet Firewall Sizing
Firewall Throughput
Firewall throughput measures the maximum raw packet processing speed when security inspection is minimal.
Typical requirements vary by organization size.
Example deployment bandwidth ranges:
| Deployment Type | Typical Bandwidth |
| Small office networks | 1–5 Gbps |
| Mid-size enterprises | 10–20 Gbps |
| Data centers | 40 Gbps or higher |
This metric alone does not represent real-world performance when security features are enabled.
Threat Protection Throughput
Threat protection throughput measures performance when multiple security services are enabled simultaneously, including IPS, antivirus, and application control.
This metric is often the most realistic indicator of firewall performance.
Typical threat protection requirements:
| Deployment Size | Typical Threat Protection Requirement |
| Small office | 500 Mbps – 1 Gbps |
| Branch office | 1 – 3 Gbps |
| Medium enterprise | 3 – 10 Gbps |
| Large enterprise | 10+ Gbps |
SSL Inspection Performance
With increasing adoption of HTTPS traffic, SSL inspection has become one of the most demanding firewall tasks.
Organizations enabling deep SSL inspection should evaluate:
- SSL inspection throughput
- Maximum concurrent sessions
- Hardware acceleration capabilities
Without proper sizing, SSL inspection can significantly reduce effective firewall performance.
Concurrent Sessions
Concurrent sessions represent the number of simultaneous connections the firewall can handle.
| Environment | Typical Concurrent Sessions |
| Small office | 100k – 500k |
| Medium enterprise | 1M – 5M |
| Large enterprise networks | 10M+ sessions |
Cloud applications, SaaS platforms, and video conferencing tools can significantly increase session counts.
Part 3: Typical FortiGate Deployment Scenarios
Small Office / SMB
Typical characteristics include:
- 20–100 users
- Basic VPN access
- Standard security inspection
Entry-level FortiGate models are usually sufficient for these deployments.
Branch Office
Branch deployments often require:
- SD-WAN capabilities
- Secure VPN connectivity to headquarters
- Full threat protection
Mid-range FortiGate appliances are commonly used for branch office environments.
Enterprise Campus
Enterprise networks typically include:
- Multiple VLAN segments
- High traffic volumes
- Advanced inspection features
Firewall sizing must account for future growth and increasing encrypted traffic.
Data Center Edge
Data center deployments usually require:
- Very high throughput
- Low latency
- Large session capacity
- Advanced threat protection
Part 4: Common FortiGate Sizing Mistakes
Choosing Based Only on Firewall Throughput
Many buyers select a firewall based only on advertised maximum throughput numbers. However, enabling IPS, SSL inspection, and antivirus scanning significantly impacts real-world performance.
Ignoring Future Network Growth
Network traffic typically grows 20–30% per year. Organizations that size firewalls only for current traffic demand often face performance issues sooner than expected.
Underestimating SSL Inspection Impact
Encrypted traffic now accounts for the majority of internet traffic. SSL inspection dramatically increases CPU utilization and must be included in the sizing calculation.
Part 5: A Simple FortiGate Sizing Formula
Many network architects use a simple calculation to estimate the required firewall capacity.
Example sizing formula:
Expected Internet Bandwidth × Security Overhead × Growth Factor
Example calculation:
1 Gbps WAN × 1.5 inspection overhead × 1.3 growth factor
≈ 2 Gbps recommended threat protection capacity
This method helps avoid both under-sizing and unnecessary over-sizing.
Part 6: Where to Buy FortiGate Firewalls
After selecting the appropriate firewall model, procurement becomes the next challenge. Many organizations experience issues such as long lead times, limited inventory availability, and pricing differences across vendors.
Working with specialized network hardware suppliers can simplify the purchasing process.
For example, Router-switch provides enterprise networking equipment from major vendors, including firewalls, switches, access points, and network modules.
Organizations often choose suppliers like Router-switch because they offer:
- Global inventory availability
- Fast 1–5 day shipping for many models
- One-stop procurement for network infrastructure
- Technical consultation from experienced networking engineers
To compare hardware pricing or explore different models, network buyers can also check the free pricing and comparison tool available at IT-Price.
Part 7: Final Thoughts
Correctly sizing a FortiGate firewall requires evaluating more than just raw throughput numbers.
A proper sizing process should consider:
- Threat protection performance
- SSL inspection capacity
- Concurrent session limits
- Future network growth
By carefully evaluating these factors, organizations can deploy firewall infrastructure that delivers reliable performance, strong security protection, and long-term scalability.
Part 8: FAQ
Q1.How do I calculate the right FortiGate firewall size?
You can estimate firewall size by evaluating expected internet bandwidth, security inspection overhead, and projected traffic growth. Many network architects multiply bandwidth by an inspection factor and growth factor to determine the recommended threat protection capacity.
Q2.Why is threat protection throughput more important than firewall throughput?
Threat protection throughput reflects real-world performance when security services such as IPS, antivirus scanning, and application control are enabled. Firewall throughput alone measures performance without heavy inspection.
Q3.Does SSL inspection significantly affect firewall performance?
Yes. SSL inspection requires decryption and inspection of encrypted traffic, which consumes significant processing power. Organizations planning to enable SSL inspection should size their firewall accordingly.
Q4.What factors influence FortiGate firewall sizing?
Key factors include internet bandwidth, number of users, concurrent sessions, security features enabled, encrypted traffic levels, and projected network growth.
Q5.Where can I compare firewall pricing before buying?
Network buyers can compare enterprise hardware pricing using tools such as IT-Price, which provides model comparisons and pricing references for networking equipment.

Expertise Builds Trust
20+ Years • 200+ Countries • 21500+ Customers/Projects
CCIE · JNCIE · NSE7 · ACDX · HPE Master ASE · Dell Server/AI Expert



































































































































