Description
The FortiGate 121G extends the 120G with 480 GB onboard SSD storage for local logging and compliance reporting, delivering converged NGFW and SD-WAN with 5.3 Gbps IPS throughput, 35 Gbps IPsec VPN, and SP5 ASIC acceleration.
FortiGate 120G Series
Converged Next-Generation Firewall (NGFW) and SD-WAN
Converged Next-Generation Firewall (NGFW) and SD-WAN
The FortiGate Next-Generation Firewall 120G series is ideal for building security-driven networks at distributed enterprise sites and transforming WAN architecture at any scale.
Robust Port Configuration: The FortiGate 120G is equipped with 18 GE RJ45 ports, including 1 management port and 1 HA port, alongside 16 switch ports. It also features 8 GE SFP slots and 4 10GE SFP+ slots for diverse high-speed connectivity options.
Cutting-edge Performance with SP5 Acceleration: Powered by SP5 hardware acceleration, the device ensures unmatched performance for security and networking functions, delivering significantly higher throughput than previous generations.
Dual AC Power Supplies: Designed with dual non-hot swappable AC power supplies, the FortiGate 120G ensures uninterrupted service and high availability for mission-critical network deployments.
Superior Security Features: Integrated with Fortinet's Security Fabric, the FortiGate 120G offers advanced threat protection, real-time SSL inspection, and AI-powered FortiGuard services for comprehensive enterprise defence.
Streamlined Network Management: Features such as the FortiLink protocol allow seamless integration of security and network management, converging the FortiSwitch as a logical extension of the NGFW.
Highly Scalable and Secure SD-WAN: Delivers exceptional quality of experience and enhanced security posture for diverse deployment scenarios, with full SD-WAN automation, analytics, and self-healing capabilities.
| IPS | NGFW | Threat Protection | Interfaces |
|---|---|---|---|
| 5.3 Gbps | 3.1 Gbps | 2.8 Gbps | 16x GE RJ45 | 8x GE SFP | 4x 10GE SFP+ | 1x 480 GB SSD | Dual PSU |
FortiOS enables the convergence of high performing networking and security across the Fortinet Security Fabric. Because it can be deployed anywhere, it delivers consistent and context-aware security posture across network, endpoint, and multi-cloud environments.
FortiConverter Service provides hassle-free migration to help organizations transition from a wide range of legacy firewalls to FortiGate Next-Generation Firewalls quickly and easily.
Services provide protection against network-based and file-based threats. This consists of Intrusion Prevention (IPS) which uses AI/ML models to perform deep packet/SSL inspection to detect and stop malicious content, and apply virtual patching when a new vulnerability is discovered. It also includes Anti-Malware for defense against known and unknown file-based threats.
Services provide protection against web-based threats including DNS-based threats, malicious URLs, and botnet/command and control communications. DNS filtering provides full visibility into DNS traffic while blocking high-risk domains, and protects against DNS tunneling, DNS infiltration, C2 server ID and Domain Generation Algorithms (DGA). URL filtering leverages a database of 300M+ URLs to identify and block links to malicious sites and payloads.
Services address numerous security use cases across application usage as well as overall data security. This consists of Data Leak Prevention (DLP) which ensures data visibility, management and protection (including blocking exfiltration) across networks, clouds, and users, while simplifying compliance and privacy implementations. Separately, our Inline Cloud Access Security Broker (CASB) service protects data in motion, at rest, and in the cloud.
Zero-day threat prevention entails Fortinet’s AI-based inline malware prevention, our most advanced sandbox service, to analyze and block unknown files in real-time, offering subsecond protection against zero-day and sophisticated threats across all NGFWs.
The service provides OT detection, OT vulnerability correlation, virtual patching, OT signatures, and industry-specific protocol decoders for overall robust defense of OT environments and devices.
Traditional firewalls cannot protect against today’s content- and connection-based threats because they rely on off-the-shelf hardware and general-purpose CPUs, causing a dangerous performance gap. Fortinet’s custom SPU processors deliver the power you need to detect emerging threats and block malicious content while ensuring your network security solution does not become a performance bottleneck.
FortiGate 120G / 121G Series

Interfaces
Power supply redundancy is essential in the operation of mission-critical networks. The FortiGate 120G Series offers dual built-in non-hot swappable power supplies.
FortiLink protocol enables you to converge security and network access by integrating the FortiSwitch into the FortiGate as a logical extension of the NGFW. These FortiLink-enabled ports can be reconfigured as regular ports as needed.
Specifications
| FortiGate 120G | FortiGate 121G | |
|---|---|---|
| Hardware Accelerated GE RJ45 Ports | 16 | 16 |
| Hardware Accelerated GE RJ45 Management / HA Ports | 2 | 2 |
| Hardware Accelerated GE SFP Slots | 8 | 8 |
| Hardware Accelerated 10 GE SFP+ FortiLink Slots (default) | 4 | 4 |
| USB Ports | 1 | 1 |
| Console (RJ45) | 1 | 1 |
| Internal Storage | u2013 | 1 x 480 GB SSD |
| Trusted Platform Module (TPM) | Yes | Yes |
| Bluetooth Low Energy (BLE) | Yes | Yes |
| FortiGate 120G | FortiGate 121G | |
|---|---|---|
| IPS Throughput | 5.3 Gbps | |
| NGFW Throughput | 3.1 Gbps | |
| Threat Protection Throughput | 2.8 Gbps | |
| FortiGate 120G | FortiGate 121G | |
|---|---|---|
| Firewall Throughput (1518 / 512 / 64 byte UDP packets) | 39 / 39 / 28 Gbps | |
| Firewall Latency (64 byte UDP packets) | 3.17 u03bcs | |
| Firewall Throughput (Packets Per Second) | 42 Mpps | |
| Concurrent Sessions (TCP) | 3 M | |
| New Sessions/Second (TCP) | 140,000 | |
| Firewall Policies | 10,000 | |
| IPsec VPN Throughput (512 byte) | 35 Gbps | |
| Gateway-to-Gateway IPsec VPN Tunnels | 2,000 | |
| Client-to-Gateway IPsec VPN Tunnels | 16,000 | |
| SSL-VPN Throughput | 1.5 Gbps | |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 500 | |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 3 Gbps | |
| SSL Inspection CPS (IPS, avg. HTTPS) | 2,100 | |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 315,000 | |
| Application Control Throughput (HTTP 64K) | 6.7 Gbps | |
| CAPWAP Throughput (HTTP 64K) | 35 Gbps | |
| Virtual Domains (Default / Maximum) | 10 / 10 | |
| Maximum Number of FortiSwitches Supported | 32 | |
| Maximum Number of FortiAPs (Total / Tunnel Mode) | 128 / 64 | |
| Maximum Number of FortiTokens | 5,000 | |
| High Availability Configurations | Active-Active, Active-Passive, Clustering | |
| FortiGate 120G | FortiGate 121G | |
|---|---|---|
| Height x Width x Length (inches) | 1.73 x 17 x 10 | |
| Height x Width x Length (mm) | 44 x 432 x 254 | |
| Weight | 12.17 lbs (5.52 kg) | |
| Form Factor | Rack Mount, 1RU | |
| FortiGate 120G | FortiGate 121G | |
|---|---|---|
| Input Rating | 100-120VAC, 1A-0.5A Max, 50-60Hz | |
| Redundant Power Supplies | Yes (Default dual non-swappable AC PSU for 1+1 Redundancy) | |
| Maximum Current | 100VAC@1A, 120V@0.5A | |
| Power Consumption (Average / Maximum) | 38 W / 40 W | 43 W / 47 W |
| Heat Dissipation | 138 BTU/hr | 159 BTU/h |
| Operating Temperature | 32u00b0u2013104u00b0F (0u00b0u201340u00b0C) | |
| Storage Temperature | -31u00b0u2013158u00b0F (-35u00b0u201370u00b0C) | |
| Humidity | 20%u201390% noncondensing | 10u201390% non-condensing |
| Noise Level | 49 dBA | |
| Air Flow | Side to back | |
| Operating Altitude | Up to 10,000 ft (3,048 m) | |
| Compliance | FCC Part 15B, Class A, CE, RCM, VCCI, UL/cUL, CB, BSMI | |
| Certifications | USGv6/IPv6 | |
Products
| FortiGate 121G Base Appliance | ||
| FortiGate-121G Firewall 18 Gigabit Ethernet RJ45 & 8 SFP Ports, 4 10GE SFP+ Slots, SP5 Acceleration, 480 GB SSD onboard storage, Dual AC Power | #FG-121G | |
| FortiGate-121G Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | ||
| Includes: Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle plus term of contract | ||
| FortiGate-121G Hardware plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | #FG-121G-BDL-950-12 | |
| FortiGate-121G Hardware plus 3 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | #FG-121G-BDL-950-36 | |
| FortiGate-121G Hardware plus 5 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) | #FG-121G-BDL-950-60 | |
| FortiGate-121G Advanced Threat Protection | ||
| IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium | ||
| FortiGate-121G 1 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium) | #FC-10-F121G-928-02-12 | |
| FortiGate-121G 3 Year Advanced Threat Protection | #FC-10-F121G-928-02-36 | |
| FortiGate-121G 5 Year Advanced Threat Protection | #FC-10-F121G-928-02-60 | |
| FortiGate-121G Unified Threat Protection (UTP) | ||
| IPS, Advanced Malware Protection, Application Control, URL, DNS & Video Filtering, Antispam Service, and FortiCare Premium | ||
| FortiGate-121G 1 Year Unified Threat Protection (UTP) | #FC-10-F121G-950-02-12 | |
| FortiGate-121G 3 Year Unified Threat Protection (UTP) | #FC-10-F121G-950-02-36 | |
| FortiGate-121G 5 Year Unified Threat Protection (UTP) | #FC-10-F121G-950-02-60 | |
Pricing Notes:
Resources
The FortiGate 121G adds 1 x 480 GB onboard SSD storage to the 120G for extended local logging, compliance reporting, and event retention. All performance, connectivity, and security specifications are identical.
The FortiGate 121G uses Fortinet's SP5 ASIC, delivering 5.3 Gbps IPS throughput, 35 Gbps IPsec VPN throughput, and 3 Gbps SSL inspection throughput u00e2u20acu201d significantly higher than previous-generation F-series models.
Choose the 121G if your deployment requires on-box log storage for compliance, forensics, or event retention without relying solely on external logging solutions such as FortiAnalyzer or FortiGate Cloud.
For enterprise deployments, the UTP bundle or Enterprise Protection bundle is recommended, covering IPS, antivirus, web filtering, application control, antispam, and FortiCare Premium. The Enterprise Protection bundle additionally includes DLP, AI-based malware prevention, and CASB.
The FortiGate 121G extends the 120G with 480 GB onboard SSD storage for local logging and compliance reporting, delivering converged NGFW and SD-WAN with 5.3 Gbps IPS throughput, 35 Gbps IPsec VPN, and SP5 ASIC acceleration.