Description
The FortiGate 30G series delivers next-generation firewall capabilities in a compact desktop form factor with improved performance and integrated SD-WAN for small businesses and branch offices.
FortiGate Entry Level Series
High Performance UTM for Small Networks
Available Variants
Converged Next-Generation Firewall (NGFW) and SD-WAN
The FortiGate and FortiWiFi 30G series integrate firewalling, SD-WAN, and security in one appliance, making them perfect for building secure networks at distributed enterprise sites and transforming WAN architecture at any scale.
The 30G series runs on FortiOS, the industry’s first converged networking and security operating system. This single OS approach enables businesses to gain benefits of operational efficiency and unified protection from the seamless integration of Fortinet Solutions within a Hybrid Mesh Firewall architecture.
As a cornerstone of the Fortinet Security Fabric platform, the FortiGate NGFW works seamlessly with FortiGuard AI-Powered Security Services to deliver coordinated, automated, end-to-end threat protection in real time.
The 30G family is built on the patented SD-WAN-based ASIC, which delivers unmatched performance over traditional CPUs with lower cost and reduced power consumption. This application-specific design and embedded multi-core processor further accelerate the convergence of networking and security functions in the 30G family to optimize secure connections and deliver a robust user experience at branch locations.
| IPS | NGFW | Threat Protection | Interfaces |
|---|---|---|---|
| 800 Mbps | 570 Mbps | 500 Mbps | 4x GE RJ45 ports (including 3x internal ports and 1x WAN port) | Wireless Variant |
Highlights:

FortiGuard AI-Powered Security Services is part of Fortinet’s layered defense and tightly integrated into our FortiGate NGFWs and other products. Infused with the latest threat intelligence from FortiGuard Labs, these services protect organizations against modern attack vectors and threats, including zero-day and sophisticated AI-powered attacks.
Network and file security services protect against network and file-based threats. With over 18,000 signatures, our industry-leading intrusion prevention system (IPS) uses AI/ML models for deep packet/SSL inspection, detecting and blocking malicious content, and applying virtual patches for newly discovered vulnerabilities. Anti-malware protection defends against both known and unknown file-based threats, combining antivirus and sandboxing for multi-layered security. Application control improves security compliance and provides real-time visibility into applications and usage
Web/DNS security services protect against DNS-based attacks, malicious URLs (including those in emails), and botnet communications. DNS filtering blocks the full spectrum of DNSbased attacks while URL filtering uses a database of over 300 million URLs to identify and block malicious links. Meanwhile, IP reputation and anti-botnet services guard against botnet activity and DDoS attacks. FortiGuard Labs blocks over 500 million malicious/phishing/ spam URLs weekly, and blocks 32,000 botnet command-and-control attempts every minute, demonstrating the robust protection offered through Fortinet.
SaaS and data security services cover key security needs for application use and data protection. This includes data loss prevention to ensure visibility, management, and protection (blocking exfiltration) of data in motion across networks, clouds, and users. Our inline cloud access security broker service protects data in motion, at rest, and in the cloud, enforcing compliance standards and managing account, user, and cloud app usage. Services also assess infrastructure, validate configurations, and highlight risks and vulnerabilities, including IoT device detection and vulnerability correlation.
Zero-day threat prevention is achieved through AI-powered inline malware prevention to analyze file content to identify and block unknown malware in real time, delivering sub-second protection across all NGFWs. The service also integrates the MITRE ATT&CK matrix to speed up investigations. Integrated into FortiGate NGFWs, the service provides comprehensive defense by blocking unknown threats, streamlining incident response, and reducing security overhead.
With over 1000 virtual patches, 1100+ OT applications, and 3300+ protocol rules, integrated OT security capabilities detect threats targeting OT infrastructure, perform vulnerability correlation, apply virtual patching, and utilize industry-specific protocol decoders for robust defense of OT environments and devices.

FortiOS, Fortinet’s Real-Time Network Security Operating System
FortiOS is the operating system that powers Fortinet Security Fabric platform, enabling enforcement of security policies and holistic visibility across the entire attack surface. FortiOS provides a unified framework for managing and securing networks, cloud-based, hybrid, or a convergence of IT, OT, and IoT. FortiOS enables seamless and efficient interoperation across Fortinet products with consistent and consolidated AI-powered protection across today’s hybrid environments.
Unlike traditional point solutions, Fortinet adopts a holistic approach to cybersecurity, aiming to reduce complexities, eliminate security silos, and improve operational efficiencies. By consolidating security functions into a single platform, FortiOS simplifies management, reduces costs, and enhances overall security posture. Together, FortiGate and FortiOS create intelligent, adaptive protection to help organizations reduce complexity, eliminate security silos, and optimize user experience.
By integrating generative AI (GenAI), FortiOS further enhances the ability to analyze network traffic and threat intelligence, detects deviations or anomalies more effectively, and provides more precise remediation recommendations, ensuring minimum performance impact without compromising security.
Available in:






Intuitive easy to use view into the network and endpoint vulnerabilities

Comprehensive view of network performance, security, and system status

Powered by the only purpose-built SPU
Traditional firewalls cannot protect against today’s content and connection-based threats because they rely on off-the-shelf general-purpose central processing units (CPUs), leaving a dangerous security gap. Fortinet’s custom SPUs deliver the power you need to radically increase speed, scale, and efficiency while greatly improving user experience and reducing footprint and power requirements. Fortinet’s SPUs deliver up to 520 Gbps of protected throughput to detect emerging threats and block malicious content while ensuring your network security solution does not become a performance bottleneck.
Fortinet ASICs are designed to be energy-efficient, leading to lower power consumption and improved TCO. They deliver industry-leading throughput, handle more traffic and perform security inspections faster, reduce latency for quicker packet processing and minimize network delays.
Fortinet SPUs are designed with integrated security functions like zero trust, SSL, IPS, and VXLAN to name but a few, dramatically improving the performance of these functions that competitors traditionally implement in software.
Secure SD-WAN ASIC SP4

FortiManager: Centralized management at scale for distributed enterprises
FortiManager, powered by FortiAI, is a centralized management solution for the Fortinet Security Fabric. It streamlines mass provisioning and policy management for FortiGate, FortiGate VM, cloud security, SD-WAN, SD-Branch, FortiSASE, and ZTNA in hybrid environments. Additionally, FortiManager provides real-time monitoring of the entire managed infrastructure and automates network operation workflows. Leveraging GenAI in FortiAI, it further enhances Day 0–1 configurations and provisioning, and Day N troubleshooting and maintenance, unlocking the full potential of the Fortinet Security Fabric and significantly boosting operational efficiency. FortiGate Cloud: Simplified management for small and mid-size businesses
FortiGate Cloud is a SaaS service offering simplified management, security analytics, and reporting for Fortinet FortiGate NGFWs to help you more efficiently manage your devices and reduce cyber risk. It simplifies the initial deployment, setup, and ongoing management of FortiGates and downstream connected devices such as FortiAP, FortiSwitch, and FortiExtender, with zero-touch provisioning. It provides real-time and historical visibility into traffic analytics and security threats to reduce risks and improve security posture. View various threats, web traffic, and system events stored in the cloud for up to a year, with predefined reports to meet compliance and deliver actionable insights.

Migration to FortiGate NGFW made easy The FortiConverter Service provides hassle-free migration to help organizations transition quickly and easily from a wide range of legacy firewalls to FortiGate NGFWs. The service eliminates errors and redundancy by employing best practices with advanced methodologies and automated processes. Organizations can accelerate their network protection with the latest FortiOS technology.




Interfaces
Specifications
| FortiGate 30G | FortiGate 31G | |
|---|---|---|
| Hardware Accelerated GE WAN Port | 1 | 1 |
| Hardware Accelerated GE RJ45 Ports | 2 | 2 |
| Hardware Accelerated GE RJ45 FortiLink Port (Default) | 1 | 1 |
| USB Ports | - | - |
| Console Port (RJ45) | 1 | 1 |
| Storage Capacity | - | 30 GB |
| Trusted Platform Module (TPM) | u2713 | u2713 |
| Bluetooth Low Energy (BLE) | - | - |
| Signed Firmware Hardware Switch | - | - |
| Wireless Interface | - | - |
| FortiGate 30G | FortiGate 31G | |
|---|---|---|
| IPS Throughput | 800 Mbps | |
| NGFW Throughput | 570 Mbps | |
| Threat Protection Throughput | 500 Mbps | |
| FortiGate 30G | FortiGate 31G | |
|---|---|---|
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 4/ 4/ 3.9 Gbps | |
| IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) | 4/ 4/ 3.9 Gbps | |
| Firewall Latency (64 byte UDP packets) | 2.87 u03bcs | |
| Firewall Throughput (Packets Per Second) | 5.85 Mpps | |
| Concurrent Sessions (TCP) | 600,000 | |
| New Sessions/Second (TCP) | 30,000 | |
| Firewall Policies | 2,000 | |
| IPsec VPN Throughput (512 byte) | 3.5 Gbps | |
| Gateway-to-Gateway IPsec VPN Tunnels | 200 | |
| Client-to-Gateway IPsec VPN Tunnels | 250 | |
| SSL-VPN Throughput | - | |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | - | |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 400 Mbps | |
| SSL Inspection CPS (IPS, avg. HTTPS) | 260 | |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 55,000 | |
| Application Control Throughput (HTTP 64K) | 830 Mbps | |
| CAPWAP Throughput (HTTP 64K) | TBA Gbps | |
| Virtual Domains (Default / Maximum) | Not Supported | |
| Maximum Number of FortiSwitches Supported | 8 | |
| Maximum Number of FortiAPs (Total / Tunnel Mode) | 16/8 | |
| Maximum Number of FortiTokens | 500 | |
| High Availability Configurations | Active-Passive, Active-Active | |
| FortiGate 30G | FortiGate 31G | |
|---|---|---|
| Height x Width x Length (inches) | 1.6 x 5.6 x 6.3 | |
| Height x Width x Length (mm) | 40.5 x 142 x 160 | |
| Weight | 1.3 lbs (0.6 kg) | |
| Rack Mount Type | NA | |
| Wall Mountable | Optional | |
| Form Factor (supports EIA/nonu2011EIA standards) | Desktop | |
| FortiGate 30G | FortiGate 31G | |
|---|---|---|
| Power Rating | 12VDC, 2A | |
| Power Source Powered by external DC power adapter | 100-240V AC, 50/60 Hz | |
| Maximum Current | 100V/0.11A, 240V/0.055A | 110V/0.17A, 240V/0.085A |
| Power Consumption (Average / Maximum) | 6.8 W / 8.2 W | 8.1 W / 9.3 W |
| Heat Dissipation | 28 BTU/hr | 31.713 BTU/hr |
| Operating Temperature | 32u00b0 to 104u00b0F (0u00b0 to 40u00b0C) | |
| Storage Temperature | -31u00b0 to 158u00b0F (-35u00b0 to 70u00b0C) | |
| Humidity | 20% to 90% non-condensing | |
| Noise Level | N/A | |
| Operating Altitude | 10,000 ft (3048 m) | |
| Compliance | FCC, IC, CE, UL/cUL, CB, VCCI, BSMI, RCM, UKCA | |
| Certifications | USGv6/IPv6 | |
Products
| FortiGate 30G Base Appliance | ||
| FortiGate-30G 4 x GE RJ45 ports (including 3 x Internal Ports, 1 x WAN Ports) | #FG-30G | |
| Fortigate-30G Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | ||
| FortiGate-30G Hardware plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | #FG-30G-BDL-950-12 | |
| FortiGate-30G Hardware plus 3 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | #FG-30G-BDL-950-36 | |
| FortiGate-30G Hardware plus 5 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | #FG-30G-BDL-950-60 | |
| FortiGate-30G Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) | ||
| FortiGate-30G 1 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) | #FC-10-FG30G-928-02-12 | |
| FortiGate-30G 3 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) | #FC-10-FG30G-928-02-36 | |
| FortiGate-30G 5 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) | #FC-10-FG30G-928-02-60 | |
| FortiGate-30G Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium) | ||
| FortiGate-30G 1 Year Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium) | #FC-10-FG30G-950-02-12 | |
| FortiGate-30G 3 Year Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium) | #FC-10-FG30G-950-02-36 | |
| FortiGate-30G 5 Year Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium) | #FC-10-FG30G-950-02-60 | |
The FortiGate 31G is the 1U rackmount variant of the 30G. It includes 32 GB of internal SSD storage for extended local logging and ships in a rackmount chassis. The 30G is a compact desktop unit. Both models share identical firewall performance and security feature sets.
Yes. The 30G includes one GE SFP WAN slot in addition to the GE RJ45 WAN port, giving you fibre or SFP-based ISP connectivity options without a separate switch or media converter.
Yes. The FortiGate 30G series is the successor to the 30E, delivering significantly higher IPS, NGFW, and threat protection throughput, along with a built-in GE SFP slot and improved concurrent session capacity.
The FortiGate 30G series delivers next-generation firewall capabilities in a compact desktop form factor with improved performance and integrated SD-WAN for small businesses and branch offices.