Skip links

FortiGate 400F

RM0.00

FortiGate 400F

FortiGate 400F Series

Fortinet FortiGate 400F

AI/ML Security and Deep Visibility

The FortiGate 400F delivers 12 Gbps IPS throughput, 9 Gbps threat protection, 7.8 million concurrent sessions, and 55 Gbps IPsec VPN with NP7 and CP9 hardware acceleration, 16x GE RJ45, 8x GE SFP, 4x 10GE SFP+, 4x 10GE ULL SFP+ slots, and dual 80Plus power supplies.
12 Gbps
IPS Throughput
9 Gbps
Threat Protection
7,800,000
Concurrent Sessions


Overview

AI/ML Security and Deep Visibility
The FortiGate 400F series delivers AI/ML-powered next generation firewall and SD-WAN for enterprise campus and mid-range deployments. Powered by Fortinet’s NP7 and CP9 ASICs, the FortiGate 400F provides 12 Gbps IPS throughput, 9 Gbps threat protection, and 7.8 million concurrent sessions with industry-leading hardware-accelerated performance.

Network Processor 7 (NP7) Hyperscale Performance: The NP7 delivers hyperscale firewall performance, accelerated session setup, ultra-low latency, and industry-leading throughput for VPN, VXLAN termination, hardware logging, and elephant flows.

Comprehensive High-Density Connectivity: Features 16x GE RJ45 ports, 8x GE SFP slots, 4x 10GE SFP+ slots, 4x 10GE SFP+ Ultra Low Latency slots, and 2x GE RJ45 MGMT/HA ports for versatile enterprise connectivity.

Trusted Platform Module (TPM): A dedicated TPM module hardens the appliance by generating, storing, and authenticating cryptographic keys, protecting against malicious software and phishing attacks.

FortiLink Access Layer Security: FortiLink protocol enables convergence of security and network access by integrating FortiSwitch into the FortiGate as a logical extension of the firewall.

Dual 80Plus Compliant Power Supplies: The FortiGate 400F features 80Plus Compliant dual AC power supplies with 1+1 redundancy, essential for mission-critical enterprise network deployments.

AI/ML-Powered FortiGuard Security Services: Integrated with FortiGuard AI-powered security services delivering real-time threat intelligence, advanced malware prevention, and comprehensive enterprise protection.

Highlights
  • Gartner Magic Quadrant Leader for both Network Firewalls and WAN Edge Infrastructure
  • Security-Driven Networking via FortiOS — the industry’s first converged networking and security operating system
  • State-of-the-Art Unparalleled Performance with Fortinet’s patented NP7 processor
  • Enterprise Security with consolidated AI / ML-powered FortiGuard Services
  • Simplified Operations with centralized management for networking and security
IPSThreat ProtectionConcurrent SessionsInterfaces
12 Gbps9 Gbps7,800,00016x GE RJ45 | 8x GE SFP | 4x 10GE SFP+ | 4x 10GE ULL | Dual PSU | SSD variant (401F)

Features

FortiGuard AI-Powered Security Services

FortiGuard AI-Powered Security Services is part of Fortinet’s layered defense and tightly integrated into our FortiGate NGFWs and other products. Infused with the latest threat intelligence from FortiGuard Labs, these services protect organizations against modern attack vectors and threats, including zero-day and sophisticated AI-powered attacks.


Network and file security

Network and file security services protect against network and file-based threats. With over 18,000 signatures, our industry-leading intrusion prevention system (IPS) uses AI/ML models for deep packet/SSL inspection, detecting and blocking malicious content, and applying virtual patches for newly discovered vulnerabilities. Anti-malware protection defends against both known and unknown file-based threats, combining antivirus and sandboxing for multi-layered security. Application control improves security compliance and provides real-time visibility into applications and usage


Web / DNS Security

Web/DNS security services protect against DNS-based attacks, malicious URLs (including those in emails), and botnet communications. DNS filtering blocks the full spectrum of DNSbased attacks while URL filtering uses a database of over 300 million URLs to identify and block malicious links. Meanwhile, IP reputation and anti-botnet services guard against botnet activity and DDoS attacks. FortiGuard Labs blocks over 500 million malicious/phishing/ spam URLs weekly, and blocks 32,000 botnet command-and-control attempts every minute, demonstrating the robust protection offered through Fortinet.


SaaS and Data Security

SaaS and data security services cover key security needs for application use and data protection. This includes data loss prevention to ensure visibility, management, and protection (blocking exfiltration) of data in motion across networks, clouds, and users. Our inline cloud access security broker service protects data in motion, at rest, and in the cloud, enforcing compliance standards and managing account, user, and cloud app usage. Services also assess infrastructure, validate configurations, and highlight risks and vulnerabilities, including IoT device detection and vulnerability correlation.


Zero-Day Threat Prevention

Zero-day threat prevention is achieved through AI-powered inline malware prevention to analyze file content to identify and block unknown malware in real time, delivering sub-second protection across all NGFWs. The service also integrates the MITRE ATT&CK matrix to speed up investigations. Integrated into FortiGate NGFWs, the service provides comprehensive defense by blocking unknown threats, streamlining incident response, and reducing security overhead.


OT Security

With over 1000 virtual patches, 1100+ OT applications, and 3300+ protocol rules, integrated OT security capabilities detect threats targeting OT infrastructure, perform vulnerability correlation, apply virtual patching, and utilize industry-specific protocol decoders for robust defense of OT environments and devices.


FortiOS Everywhere

FortiOS, Fortinet’s Real-Time Network Security Operating System

FortiOS is the operating system that powers Fortinet Security Fabric platform, enabling enforcement of security policies and holistic visibility across the entire attack surface. FortiOS provides a unified framework for managing and securing networks, cloud-based, hybrid, or a convergence of IT, OT, and IoT. FortiOS enables seamless and efficient interoperation across Fortinet products with consistent and consolidated AI-powered protection across today’s hybrid environments.

Unlike traditional point solutions, Fortinet adopts a holistic approach to cybersecurity, aiming to reduce complexities, eliminate security silos, and improve operational efficiencies. By consolidating security functions into a single platform, FortiOS simplifies management, reduces costs, and enhances overall security posture. Together, FortiGate and FortiOS create intelligent, adaptive protection to help organizations reduce complexity, eliminate security silos, and optimize user experience.

By integrating generative AI (GenAI), FortiOS further enhances the ability to analyze network traffic and threat intelligence, detects deviations or anomalies more effectively, and provides more precise remediation recommendations, ensuring minimum performance impact without compromising security.

Available in:

Intuitive easy to use view into the network and endpoint vulnerabilities

Comprehensive view of network performance, security, and system status


Fortinet ASICs: Unrivaled Security, Unprecedented Performance

Powered by the only purpose-built SPU

Traditional firewalls cannot protect against today’s content and connection-based threats because they rely on off-the-shelf general-purpose central processing units (CPUs), leaving a dangerous security gap. Fortinet’s custom SPUs deliver the power you need to radically increase speed, scale, and efficiency while greatly improving user experience and reducing footprint and power requirements. Fortinet’s SPUs deliver up to 520 Gbps of protected throughput to detect emerging threats and block malicious content while ensuring your network security solution does not become a performance bottleneck.

Fortinet ASICs are designed to be energy-efficient, leading to lower power consumption and improved TCO. They deliver industry-leading throughput, handle more traffic and perform security inspections faster, reduce latency for quicker packet processing and minimize network delays.

Fortinet SPUs are designed with integrated security functions like zero trust, SSL, IPS, and VXLAN to name but a few, dramatically improving the performance of these functions that competitors traditionally implement in software.

Secure SD-WAN ASIC SP4

  • Combines a RISC-based CPU with Fortinet’s proprietary SPU content and network processors for unmatched performance
  • Delivers the industry’s fastest application identification and steering for efficient business operations
  • Accelerates IPsec VPN performance for the best user experience on direct internet access
  • Enables best-of-breed NGFW security and deep SSL inspection with high performance
  • Extends security to the access layer to enable SD-Branch transformation with accelerated

Use Cases

Perimeter Protection
  • Protect networks from malicious traffic, guard against file-based threats, block web-based attacks, and secure applications and data with natively integrated FortiGuard AI-Powered Security Services
  • Inspect and control incoming and outgoing traffic based on defined security policies
  • Perform real-time SSL inspection (including TLS 1.3) with full visibility into users, devices, and applications across the attack surface
  • Accelerate performance, protection, and energy efficiency with Fortinet’s patented SPU with converged security and networking technologies

Secure SD-WAN
  • FortiGate enables best-of-breed WAN edge with integrated SD-WAN, WAN optimization, security, and unified management from a single FortiOS operating system
  • FortiGate, built on a patented SD-WAN-based ASIC, delivers faster application identification to avoid delays in accessing applications and accelerates overlay performance regardless of location
  • Enhances hybrid working with a comprehensive SASE solution by integrating cloud-delivered SD-WAN with security service edge (SSE)
  • Achieves operational efficiencies at any scale through automation, deep analytics, and selfhealing

Secure Branch
  • The Fortinet Security Fabric platform enables FortiGate NGFWs to automatically discover and secure IoT devices for faster branch onboarding
  • Fully integrated with FortiSwitch secure Ethernet switches and FortiAP access points, FortiGate easily extends security to WAN, LAN, and WLAN at branch offices for unified protection and reliable connectivity
  • FortiGate and Fortinet products work seamlessly with FortiManager to centralize visibility and simplify management across locations for IT teams
  • FortiGate HA support ensures continuous network protection and minimizes downtime in the event of hardware failures or network disruptions

Hardware

FortiGate 400F / 401F Series

Interfaces

  1. 1x USB Port
  2. 1x Console Port
  3. 2x GE RJ45 MGMT/HA Ports
  4. 16x GE RJ45 Ports
  5. 4x 1GE/10GE SFP+ Slots
  6. 4x 10GE SFP+ Ultra Low Latency Slots
  7. 8x GE SFP Slots
Network Processor 7 (NP7)

Network Processors operate inline to deliver unmatched performance and scalability for critical network functions

  • Hyperscale firewall, accelerated session setup, and ultra-low latency
  • Industry-leading performance for VPN, VXLAN termination, hardware logging, and elephant flows
Content Processor 9 (CP9)

Functions as a co-processor handling resource-intensive SSL (including TLS 1.3) decryption and security functions

  • Pattern matching acceleration and fast inspection of real-time traffic for application identification
  • IPS pre-scan/pre-match, signature correlation offload, and accelerated antivirus processing
Trusted Platform Module (TPM)

A dedicated module that hardens physical networking appliances by generating, storing, and authenticating cryptographic keys. Hardware-based security mechanisms protect against malicious software and phishing attacks.

Access Layer Security (FortiLink)

FortiLink protocol enables you to converge security and network access by integrating the FortiSwitch into the FortiGate as a logical extension of the firewall.

Dual Power Supplies

Power supply redundancy is essential in the operation of mission-critical networks. The FortiGate 400F Series features 80Plus Compliant dual AC power supplies (1+1 redundancy).

Specifications

Technical Specifications

Hardware Specifications 10
FortiGate 400F FortiGate 401F
Hardware Accelerated GE RJ45 Interfaces 16 16
Hardware Accelerated GE SFP Slots 8 8
Hardware Accelerated 10GE SFP+ Slots 4 4
10GE SFP+ Ultra Low Latency Slots 4 4
GE RJ45 Management Ports 2 2
USB Ports 1 1
Console Port (RJ45) 1 1
Internal Storage u2013 2x 480 GB SSD
Included Transceivers 2x SFP (SX 1 GE) 2x SFP (SX 1 GE)
Trusted Platform Module (TPM) Yes Yes
System Performance u2014 Enterprise Traffic Mix 3
FortiGate 400F FortiGate 401F
IPS Throughput 12 Gbps
NGFW Throughput 10 Gbps
Threat Protection Throughput 9 Gbps
System Performance 22
FortiGate 400F FortiGate 401F
IPv4 Firewall Throughput (1518/512/64 byte, UDP) 79.5 / 78.5 / 70 Gbps
IPv6 Firewall Throughput (1518/512/64 byte, UDP) 79.5 / 78.5 / 70 Gbps
Firewall Latency (64 byte, UDP) 4.19 u03bcs / 2.5 u03bcs
Firewall Throughput (Packets Per Second) 105 Mpps
Concurrent Sessions (TCP) 7.8 Million
New Sessions/Second (TCP) 500,000
Firewall Policies 10,000
IPsec VPN Throughput (512 byte) 55 Gbps
Gateway-to-Gateway IPsec VPN Tunnels 2,000
Client-to-Gateway IPsec VPN Tunnels 50,000
SSL-VPN Throughput 3.6 Gbps
Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) 5,000
SSL Inspection Throughput (IPS, avg. HTTPS) 8 Gbps
SSL Inspection CPS (IPS, avg. HTTPS) 6,000
SSL Inspection Concurrent Session (IPS, avg. HTTPS) 800,000
Application Control Throughput (HTTP 64K) 28 Gbps
CAPWAP Throughput (HTTP 64K) 65 Gbps
Virtual Domains (Default / Maximum) 10 / 10
Maximum Number of FortiSwitches Supported 72
Maximum Number of FortiAPs (Total / Tunnel Mode) 512 / 256
Maximum Number of FortiTokens 5,000
High Availability Configurations Active-Active, Active-Passive, Clustering
Dimensions 4
FortiGate 400F FortiGate 401F
Height x Width x Length (inches) 1.75 x 17.0 x 15.0
Height x Width x Length (mm) 44.45 x 432 x 380
Form Factor Rack Mount, 1 RU
Weight 14.11 lbs (6.4 kg) 14.33 lbs (6.5 kg)
Operating Environment and Certifications 14
FortiGate 400F FortiGate 401F
AC Power Consumption (Average / Maximum) 154.8 W / 189.2 W 161.1 W / 196.9 W
AC Power Input 100u2013240V AC, 50/60Hz
AC Current (Maximum) 6A
DC Power Supply 48-60VDC
Heat Dissipation 645.58 BTU/h 671.85 BTU/h
Power Supply 80Plus Compliant, Dual AC PSU (1+1 Redundancy)
Operating Temperature 32u00b0F to 104u00b0F (0u00b0C to 40u00b0C)
Storage Temperature -31u00b0F to 158u00b0F (-35u00b0C to 70u00b0C)
Humidity 5u201390% non-condensing
Noise Level LPA 48 dBA / LWA 55 dBA
Operating Altitude Up to 10,000 ft (3,048 m)
Airflow Side and Front to Back
Compliance FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB
Certifications USGv6/IPv6

Products

Fortinet Products

FortiGate 400F Base Appliance
FortiGate-400F 18 x GE RJ45 ports (including 1 x MGMT port, 1 X HA port, 16 x switch ports), 8 x GE SFP slots, 8 x 10GE SFP+ slots, SPU NP7 and CP9 hardware accelerated, dual AC power supplies #FG-400F
FortiGate-400F Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP)
Includes: Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle plus term of contract
FortiGate-400F Hardware plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) #FG-400F-BDL-950-12
FortiGate-400F Hardware plus 3 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) #FG-400F-BDL-950-36
FortiGate-400F Hardware plus 5 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) #FG-400F-BDL-950-60
FortiGate-400F Advanced Threat Protection
IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium
FortiGate-400F 1 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) #FC-10-0400F-928-02-12
FortiGate-400F 3 Year Advanced Threat Protection #FC-10-0400F-928-02-36
FortiGate-400F 5 Year Advanced Threat Protection #FC-10-0400F-928-02-60
FortiGate-400F FortiGate Cloud Standard Subscription
Management, Analysis, 1 Year Log Retention
FortiGate-400F 1 Year FortiGate Cloud Standard Subscription (Management, Analysis, 1 Year Log Retention) #FC-10-0400F-131-02-12
FortiGate-400F 3 Year FortiGate Cloud Standard Subscription #FC-10-0400F-131-02-36
FortiGate-400F 5 Year FortiGate Cloud Standard Subscription #FC-10-0400F-131-02-60
FortiGate-400F Unified Threat Protection (UTP)
IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium
FortiGate-400F 1 Year Unified Threat Protection (UTP) #FC-10-0400F-950-02-12
FortiGate-400F 3 Year Unified Threat Protection (UTP) #FC-10-0400F-950-02-36
FortiGate-400F 5 Year Unified Threat Protection (UTP) #FC-10-0400F-950-02-60

Pricing Notes:

  • Hardware plus FortiCare Premium and FortiGuard Enterprise Protection Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Enterprise Services Bundle (IPS, AI-based Inline Malware Prevention, Advanced Malware Protection, Inline CASB Database, Data Loss Prevention, Application Control, URL, DNS & Video Filtering, Antispam, Attack Surface Security, and FortiConverter Service) plus term of contract
  • Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP) Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, URL, DNS & Video Filtering and Antispam Service) plus term of contract
  • Enterprise Protection (IPS, AI-based Inline Malware Prevention, Inline CASB Database, DLP, App Control, Adv Malware Protection, URL/DNS/Video Filtering, Anti-spam, Attack Surface Security, Converter Svc, FortiCare Premium) FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Enterprise Services Bundle (IPS, AI-based Inline Malware Prevention, Advanced Malware Protection, Inline CASB Database, Data Loss Prevention, Application Control, URL, DNS & Video Filtering, Antispam, Attack Surface Security, and FortiConverter Service)
  • Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium) FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, URL, DNS & Video Filtering and Antispam Service)
  • Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Advanced Threat Protection Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct Service, Application Control)
  • FortiCare Essential Support FortiCare Essential Ticket Handling, Hardware Replacement, Firmware and General Upgrades, Application Control
  • FortiCare Premium Support FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Application Control
  • FortiCare Elite Support FortiCare Premium Support with FortiCare Elite Ticket Handling.
  • Prices are for one year of Premium RMA support. Usual discounts can be applied.
  • Annual contracts only. No multi-year SKUs are available for these services.
  • Contact Fortinet Renewals team for upgrade quotations for existing FortiCare contracts.
  • Pricing and product availability subject to change without notice.

FAQ

Common Questions

Can't find what you're looking for? Reach out and our team will be happy to help.

The FortiGate 401F adds 2 x 480 GB onboard SSD storage to the 400F for extended local logging, compliance reporting, and event retention. All performance, connectivity, and security specifications are identical between the two models.

The FortiGate 400F is powered by Fortinet's NP7 network processor and CP9 content processor. The NP7 delivers hyperscale firewall performance with ultra-low latency, while the CP9 accelerates SSL inspection (including TLS 1.3) and IPS processing.

The FortiGate 400F supports up to 72 FortiSwitches and 512 FortiAPs (256 in tunnel mode), making it suitable for large campus deployments with extensive wired and wireless infrastructure.

For enterprise deployments, the UTP (Unified Threat Protection) bundle is recommended, covering IPS, antivirus, web filtering, application control, antispam, and FortiCare Premium. The Advanced Threat Protection bundle is also available for targeted IPS and malware protection.

Description

The FortiGate 400F series delivers AI/ML-powered NGFW and SD-WAN for enterprise campus and mid-range deployments. Powered by NP7 and CP9 hardware acceleration, the 400F provides 12 Gbps IPS throughput, 9 Gbps threat protection, 7.8 million concurrent sessions, 16x GE RJ45, 8x GE SFP, 4x 10GE SFP+, 4x 10GE SFP+ Ultra Low Latency slots, and dual 80Plus power supplies.

This website uses cookies to improve your web experience.