FortiGate Sizing Guide: How to Choose the Right Fortinet Firewall for Your Network

Follow Us:

Choosing the right firewall size is one of the most important steps in network security design. Many organizations deploying Fortinet firewalls—especially the FortiGate series—often struggle with a common question: How do you correctly size a FortiGate firewall for your environment?

Selecting a firewall that is too small can lead to performance bottlenecks and degraded security inspection. On the other hand, oversizing a firewall can significantly increase costs without delivering real benefits. This guide explains the key factors used in FortiGate sizing, common mistakes to avoid, and a practical approach to selecting the right model for your network.


FortiGate Firewall Sizing

Part 1: What Is FortiGate Firewall Sizing?

FortiGate sizing refers to the process of determining the appropriate firewall model based on your network’s performance requirements, security features, and traffic patterns.

Unlike traditional routers, modern firewalls perform deep inspection tasks such as:

  • Intrusion Prevention System (IPS)
  • SSL inspection
  • Application control
  • Anti-malware scanning
  • VPN encryption

Each of these security services consumes additional processing power, which means raw firewall throughput alone is not enough to determine the correct model.


Part 2: Key Metrics Used in Fortinet Firewall Sizing

Firewall Throughput

Firewall throughput measures the maximum raw packet processing speed when security inspection is minimal.

Typical requirements vary by organization size.

Example deployment bandwidth ranges:

Deployment Type Typical Bandwidth
Small office networks 1–5 Gbps
Mid-size enterprises 10–20 Gbps
Data centers 40 Gbps or higher

This metric alone does not represent real-world performance when security features are enabled.

Threat Protection Throughput

Threat protection throughput measures performance when multiple security services are enabled simultaneously, including IPS, antivirus, and application control.

This metric is often the most realistic indicator of firewall performance.

Typical threat protection requirements:

Deployment Size Typical Threat Protection Requirement
Small office 500 Mbps – 1 Gbps
Branch office 1 – 3 Gbps
Medium enterprise 3 – 10 Gbps
Large enterprise 10+ Gbps

SSL Inspection Performance

With increasing adoption of HTTPS traffic, SSL inspection has become one of the most demanding firewall tasks.

Organizations enabling deep SSL inspection should evaluate:

  • SSL inspection throughput
  • Maximum concurrent sessions
  • Hardware acceleration capabilities

Without proper sizing, SSL inspection can significantly reduce effective firewall performance.

Concurrent Sessions

Concurrent sessions represent the number of simultaneous connections the firewall can handle.

Environment Typical Concurrent Sessions
Small office 100k – 500k
Medium enterprise 1M – 5M
Large enterprise networks 10M+ sessions

Cloud applications, SaaS platforms, and video conferencing tools can significantly increase session counts.


Part 3: Typical FortiGate Deployment Scenarios

Small Office / SMB

Typical characteristics include:

  • 20–100 users
  • Basic VPN access
  • Standard security inspection

Entry-level FortiGate models are usually sufficient for these deployments.

Branch Office

Branch deployments often require:

  • SD-WAN capabilities
  • Secure VPN connectivity to headquarters
  • Full threat protection

Mid-range FortiGate appliances are commonly used for branch office environments.

Enterprise Campus

Enterprise networks typically include:

  • Multiple VLAN segments
  • High traffic volumes
  • Advanced inspection features

Firewall sizing must account for future growth and increasing encrypted traffic.

Data Center Edge

Data center deployments usually require:

  • Very high throughput
  • Low latency
  • Large session capacity
  • Advanced threat protection

Part 4: Common FortiGate Sizing Mistakes

Choosing Based Only on Firewall Throughput

Many buyers select a firewall based only on advertised maximum throughput numbers. However, enabling IPS, SSL inspection, and antivirus scanning significantly impacts real-world performance.

Ignoring Future Network Growth

Network traffic typically grows 20–30% per year. Organizations that size firewalls only for current traffic demand often face performance issues sooner than expected.

Underestimating SSL Inspection Impact

Encrypted traffic now accounts for the majority of internet traffic. SSL inspection dramatically increases CPU utilization and must be included in the sizing calculation.


Part 5: A Simple FortiGate Sizing Formula

Many network architects use a simple calculation to estimate the required firewall capacity.

Example sizing formula:

Expected Internet Bandwidth × Security Overhead × Growth Factor

Example calculation:

1 Gbps WAN × 1.5 inspection overhead × 1.3 growth factor
≈ 2 Gbps recommended threat protection capacity

This method helps avoid both under-sizing and unnecessary over-sizing.


Part 6: Where to Buy FortiGate Firewalls

After selecting the appropriate firewall model, procurement becomes the next challenge. Many organizations experience issues such as long lead times, limited inventory availability, and pricing differences across vendors.

Working with specialized network hardware suppliers can simplify the purchasing process.

For example, Router-switch provides enterprise networking equipment from major vendors, including firewalls, switches, access points, and network modules.

Organizations often choose suppliers like Router-switch because they offer:

  • Global inventory availability
  • Fast 1–5 day shipping for many models
  • One-stop procurement for network infrastructure
  • Technical consultation from experienced networking engineers

To compare hardware pricing or explore different models, network buyers can also check the free pricing and comparison tool available at IT-Price.


Part 7: Final Thoughts

Correctly sizing a FortiGate firewall requires evaluating more than just raw throughput numbers.

A proper sizing process should consider:

  • Threat protection performance
  • SSL inspection capacity
  • Concurrent session limits
  • Future network growth

By carefully evaluating these factors, organizations can deploy firewall infrastructure that delivers reliable performance, strong security protection, and long-term scalability.


Part 8: FAQ

Q1.How do I calculate the right FortiGate firewall size?

You can estimate firewall size by evaluating expected internet bandwidth, security inspection overhead, and projected traffic growth. Many network architects multiply bandwidth by an inspection factor and growth factor to determine the recommended threat protection capacity.

Q2.Why is threat protection throughput more important than firewall throughput?

Threat protection throughput reflects real-world performance when security services such as IPS, antivirus scanning, and application control are enabled. Firewall throughput alone measures performance without heavy inspection.

Q3.Does SSL inspection significantly affect firewall performance?

Yes. SSL inspection requires decryption and inspection of encrypted traffic, which consumes significant processing power. Organizations planning to enable SSL inspection should size their firewall accordingly.

Q4.What factors influence FortiGate firewall sizing?

Key factors include internet bandwidth, number of users, concurrent sessions, security features enabled, encrypted traffic levels, and projected network growth.

Q5.Where can I compare firewall pricing before buying?

Network buyers can compare enterprise hardware pricing using tools such as IT-Price, which provides model comparisons and pricing references for networking equipment.

Expert

Expertise Builds Trust

20+ Years • 200+ Countries • 21500+ Customers/Projects
CCIE · JNCIE · NSE7 · ACDX · HPE Master ASE · Dell Server/AI Expert