FortiGate Firewall Sizing Guide: Choosing the Right Model for Your Business

  • Home
  • FortiGate Firewall Sizing Guide: Choosing the Right Model for Your Business
FortiGate Firewall Sizing Guide: Choosing the Right Model for Your Business
FortiGate Firewall Sizing Guide: Choosing the Right Model for Your Business
FortiGate Firewall Sizing Guide: Choosing the Right Model for Your Business
FortiGate Firewall Sizing Guide: Choosing the Right Model for Your Business

One of the most common questions we get at P J Networks is: “Which FortiGate model do I need?” And the honest answer is: it depends — on your throughput requirements, user count, security features, and growth plans. Get the sizing wrong and you either overpay for capacity you don’t need, or worse, undersize and watch your network grind to a halt under real-world traffic.

We’ve deployed thousands of FortiGates across Indian enterprises — from a single FG-30G at a retail pharmacy in Pune to clustered FG-700Gs at a Mumbai data centre. Here’s our practical sizing guide, from branch office to data centre.

Start With Your Throughput, Not Your Budget

The single biggest mistake in FortiGate firewall sizing is picking a model based on budget and then hoping it handles the traffic. Firewall throughput is not a suggestion — it’s the difference between a functional network and a bottleneck that frustrates users, drops packets, and creates security gaps when you have to disable inspection features to keep up.

When sizing, consider these throughput metrics from Fortinet’s spec sheets. The numbers on the box are maximums — your real-world mileage will vary:

  • Firewall throughput — raw packet forwarding (easiest to meet, least realistic)
  • IPS throughput — with intrusion prevention enabled (typically 2-3x lower than raw firewall throughput)
  • Threat protection throughput — IPS + antivirus + application control (typically 3-5x lower than raw, this is your real number)
  • VPN throughput — IPsec and SSL, critical for branch connectivity and remote access
  • SSL inspection throughput — decrypting and inspecting HTTPS traffic (the heaviest workload by far)

Always size on the threat protection throughput — that’s the real-world performance when all security features are enabled. I’ve seen Indian enterprises buy a FortiGate based on a 10 Gbps firewall figure, only to discover that with IPS, AV, and application control, they’re getting barely 2 Gbps.

FortiGate Model Tiers (2026)

Entry Level: FG-30G / FG-40F / FG-50G

For: Small offices, retail branches, home offices, 5-25 users

  • Firewall throughput: 1-3 Gbps
  • Threat protection: 100-400 Mbps
  • Key features: Desktop form factor, basic SD-WAN, essential security
  • Approximate India pricing (incl. 1-year FortiGuard): ₹30,000-80,000
  • Best for: Budget-conscious SMBs, single-site operations, low-bandwidth branches

Ideal for small retail outlets, diagnostic centres, or remote offices where the internet link is 50-100 Mbps and user count is low. Don’t expect full SSL inspection at line rate — but for the price, they deliver exceptional value.

Mid-Range: FG-70G / FG-80F / FG-90G

For: Medium businesses, larger branches, 25-100 users

  • Firewall throughput: 4-10 Gbps
  • Threat protection: 500 Mbps-2 Gbps
  • Key features: Full SD-WAN, advanced routing, higher VPN capacity
  • Approximate India pricing: ₹1-3 lakhs
  • Best for: Multi-site SMBs, primary offices, locations with security subscriptions enabled

The FG-80F, in particular, is our most deployed model — balancing cost with real-world threat protection throughput and full SD-WAN capabilities for multi-site connectivity.

Enterprise: FG-100F / FG-120G / FG-200F / FG-200G

For: Large enterprises, campus deployments, 100-500 users

  • Firewall throughput: 10-40 Gbps
  • Threat protection: 2-8 Gbps
  • Key features: High availability clustering, advanced SD-WAN, extensive logging
  • Approximate India pricing: ₹3-12 lakhs
  • Best for: Enterprise headquarters, large campuses, data centre edge

At this tier, you get full SSL inspection for hundreds of users, multiple security subscriptions simultaneously, and HA clustering for zero-downtime failover. For 200-300 users with compliance requirements, the FG-200F or FG-200G is the recommended starting point.

High-End: FG-400F / FG-400G / FG-600F / FG-700G+

For: Data centres, ISPs, large enterprises, 500+ users

  • Firewall throughput: 40-200+ Gbps
  • Threat protection: 8-40+ Gbps
  • Key features: Full line-rate threat protection, massive VPN capacity, carrier-grade features
  • Approximate India pricing: ₹15-50+ lakhs
  • Best for: Data centre security, backbone deployments, high-throughput environments

These are serious machines for serious traffic. If you’re running a data centre, aggregating multiple branch links, or handling north-south traffic for a large campus, this is your tier.

Real-World Sizing: A Practical Example

A mid-sized Indian logistics company with 150 head office users, 30 branch offices, and a central data centre. The head office has a 500 Mbps internet link.

Wrong approach: “We have 150 users and a 500 Mbps link, so we need a FortiGate that can do 500 Mbps firewall throughput.” This logic fails because you’re not accounting for IPS, SSL inspection, and application control, which will drop real throughput to 30-40% of the raw firewall number.

Right approach: “We have 150 users on a 500 Mbps link with all security features enabled. We need the threat protection throughput to be at least 500 Mbps. That means looking at the FG-200F class or higher.”

Sizing Tips From Our Deployment Team

  1. Always add 30% headroom. Network traffic grows 25-35% year over year. A firewall sized for today’s throughput will be undersized in 18 months. Buy for your projected traffic 2 years out.
  2. Don’t forget the security subscriptions. FortiGuard (IPS, antivirus, web filtering, application control) is essential and adds 30-40% to the total cost over 3 years. Budget for it upfront.
  3. Consider HA pairs. For critical deployments, budget for two units in active-passive HA. The hardware cost doubles but the downtime cost of a single failure is higher — especially for manufacturing or BFSI where every minute of firewall failure means lost revenue.
  4. Test with your actual traffic. Spec sheet throughput is measured under ideal conditions with 1518-byte packets and no security features enabled. Your real-world traffic mix — encrypted, with all security features enabled — will achieve 50-70% of advertised threat protection throughput.
  5. Factor in FortiSwitch and FortiAP offload. If you’re using FortiSwitch and FortiAP in your deployment, some traffic can be offloaded at the switch level, reducing the load on your FortiGate. Factor this into your sizing calculation.

FortiGate Pricing Reality (India 2026)

List prices are often 40-50% above what a Fortinet partner can offer. Here’s what you should budget:

  • Hardware + 1-year FortiGuard: The figures above are realistic street prices from an authorised partner
  • Years 2-3: FortiGuard renewal is typically 25-30% of the initial bundle cost per year
  • Total 3-year TCO: Expect the 3-year TCO to be roughly 1.5x the first-year bundle cost

Need a Sizing Consultation?

Choosing the wrong model costs more than the upgrade — it costs performance, security, and team trust. We help Indian enterprises select, deploy, and manage FortiGate deployments of all sizes.

Contact P J Networks for a free sizing assessment tailored to your environment. We’ll analyse your traffic patterns, user count, and growth projections, and recommend the exact FortiGate model that fits — nothing more, nothing less.


P J Networks is a Fortinet MSSP partner with over a decade of FortiGate deployment experience across India. We sell and manage every FortiGate model, from FG-30G to FG-700G.

Leave a Reply

Your email address will not be published. Required fields are marked *