FG-3300E and 3301E
The FortiGate 3300E series delivers high performance Next Generation Firewall (NGFW) capabilities for large enterprises and service providers. With multiple high-speed interfaces, high-port density, and high-throughput, ideal deployments are at the enterprise edge, hybrid data center core, and across internal segments. Fortinet leverages industry-leading IPS, SSL inspection, and advanced threat protection to optimize network performance. Fortinet's Security-Driven Networking securely integrates with the new generation of cybersecurity solutions.
Diagram Description: A network topology illustrating FortiGate 3300E deployment in a data center. The diagram shows the Internet connecting to a FortiGate NGFW, which then connects to a FortiGate IPS/Segmentation device. Within the data center, FortiClient VPN Clients connect to the FortiGate IPS/Segmentation. FortiManager (Automation-Driven Network Management) and FortiAnalyzer (Analytics-powered Security & Log Management) are also depicted as part of the data center infrastructure, managing the FortiGate devices.
Hardware Description: The FortiGate 3300E series appliance features a front panel with various ports and indicators. From left to right, it includes: 1. USB Management Port, 2. Console Port, 3. Two GE RJ45 MGMT/Ports, 4. Twelve GE RJ45 Ports, 5. Four 10 GE RJ45 Ports, 6. Fourteen 25 GE SFP28 / 10 GE SFP+ Slots, 7. Two 25 GE SFP28 / 10 GE SFP+ HA Slots, and 8. Four 40 GE QSFP+ Slots. The front panel also indicates the presence of NP6, CP9, 20, 40GE, 25GE, AC DUAL power, and 2TB storage (for 3301E).
Fortinet's new, breakthrough SPU NP6 network processor works inline with FortiOS functions delivering:
Fortinet's new, breakthrough SPU CP9 content processor works outside of the direct flow of traffic and accelerates the inspection of computationally intensive security features:
High-speed connectivity is essential for network security segmentation at the core of data networks. The FortiGate 3300E series provides 40 GE and 25 GE interfaces, simplifying network designs without relying on additional devices to bridge desired connectivity.
The Security Fabric is the cybersecurity platform that enables digital innovations. It delivers broad visibility of the entire attack surface to better manage risk. Its unified and integrated solution reduces the complexity of supporting multiple-point products, while automated workflows increase operational speeds and reduce response times across the Fortinet deployment ecosystem. The Fortinet Security Fabric covers the following key areas under a single management center:
Diagram Description: A conceptual diagram of the Fortinet Security Fabric. At the center is the 'Fabric Management Center'. Surrounding it are interconnected components: 'Network Access', 'Secure WLAN/LAN', 'Endpoint', 'NGFW SD-WAN', 'Cloud Infrastructure', 'Applications', and 'Security Operations'. An 'Open Fabric Ecosystem' is also shown, indicating external integration.
FortiGates are the foundation of the Fortinet Security Fabric—the core is FortiOS. All security and networking capabilities across the entire FortiGate platform are controlled with one intuitive operating system. FortiOS reduces complexity, costs, and response times by truly consolidating next-generation security products and services into one platform.
FortiGuard Labs offers real-time intelligence on the threat landscape, delivering comprehensive security updates across the full range of Fortinet's solutions. Comprised of security threat researchers, engineers, and forensic specialists, the team collaborates with the world's leading threat monitoring organizations and other network and security vendors, as well as law enforcement agencies.
FortiCare customer support team provides global technical support for all Fortinet products. With support staff in the Americas, Europe, Middle East, and Asia, FortiCare offers services to meet the needs of enterprises of all sizes.
For more information, please refer to forti.net/fortiguard and forti.net/forticare.
Interfaces and Modules | FG-3300E | FG-3301E |
---|---|---|
40 GE QSFP+ Slots | 4 | 4 |
25 GE SFP28 / 10 GE SFP+ HA Slots | 2 | 2 |
25 GE SFP28 / 10 GE SFP+ Slots | 14 | 14 |
10 GE RJ45 Ports | 4 | 4 |
GE RJ45 Ports | 12 | 12 |
GE RJ45 Management/HA Ports | 2 | 2 |
USB Ports (Client / Server) | 1/1 | 1/1 |
Console Port | 1 | 1 |
Internal Storage | NIL | 2x 1 TB SSD |
Included Transceivers | 2x SFP+ (SR 10 GE) | 2x SFP+ (SR 10 GE) |
System Performance – Enterprise Traffic Mix | ||
---|---|---|
IPS Throughput 2 | 27 Gbps | 27 Gbps |
NGFW Throughput 2, 4 | 23 Gbps | 23 Gbps |
Threat Protection Throughput 2, 5 | 17 Gbps | 17 Gbps |
System Performance and Capacity | ||
---|---|---|
Firewall Throughput (1518 / 512 / 64 byte, UDP) | 160 / 158 / 100 Gbps | 160 / 158 / 100 Gbps |
IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) | 160 / 158 / 100 Gbps | 160 / 158 / 100 Gbps |
Firewall Latency (64 byte, UDP) | 4 µs | 4 µs |
Firewall Throughput (Packet per Second) | 150 Mpps | 150 Mpps |
Concurrent Sessions (TCP) | 50 Million | 50 Million |
New Sessions/Second (TCP) | 460,000 | 460,000 |
Firewall Policies | 200,000 | 200,000 |
IPsec VPN Throughput (512 byte) 1 | 98 Gbps | 98 Gbps |
Gateway-to-Gateway IPsec VPN Tunnels | 40,000 | 40,000 |
Client-to-Gateway IPsec VPN Tunnels | 200,000 | 200,000 |
SSL-VPN Throughput | 10 Gbps | 10 Gbps |
Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 | 30,000 |
SSL Inspection Throughput (IPS, avg. HTTPS) 3 | 21 Gbps | 21 Gbps |
SSL Inspection CPS (IPS, avg. HTTPS) 3 | 11,000 | 11,000 |
SSL Inspection Concurrent Session (IPS, avg. HTTPS) 3 | 4 Million | 4 Million |
Application Control Throughput (HTTP 64K) 2 | 70 Gbps | 70 Gbps |
CAPWAP Throughput (HTTP 64K) | 55 Gbps | 55 Gbps |
Virtual Domains (Default / Maximum) | 10 / 500 | 10 / 500 |
Maximum Number of FortiSwitches Supported | 256 | 256 |
Maximum Number of FortiAPs (Total / Tunnel Mode) | 4,096 / 2,048 | 4,096 / 2,048 |
Maximum Number of FortiTokens | 20,000 | 20,000 |
High Availability Configurations | Active / Active, Active / Passive, Clustering | Active / Active, Active / Passive, Clustering |
Dimensions and Power | FG-3300E | FG-3301E |
---|---|---|
Height x Width x Length (inches) | 3.5 x 17.44 x 21.89 | 3.5 x 17.44 x 21.89 |
Height x Width x Length (mm) | 88.9 x 443 x 556 | 88.9 x 443 x 556 |
Weight | 42.9 lbs (19.5 kg) | 44.3 lbs (20.1 kg) |
Form Factor | 2 RU | 2 RU |
AC Power Supply | 100-240V AC, 60-50 Hz | 100-240V AC, 60-50 Hz |
Power Consumption (Average / Maximum) | 492 W / 610 W | 496 W / 617 W |
Maximum Current | 12A@100V, 9A@240V | 12A@100V, 9A@240V |
Heat Dissipation | 2097 BTU/h | 2105 BTU/h |
Redundant Power Supplies | Yes, Hot Swappable | Yes, Hot Swappable |
Operating Environment and Certifications | ||
---|---|---|
Operating Temperature | 32-104°F (0-40°C) | 32-104°F (0-40°C) |
Storage Temperature | -31-158°F (-35-70°C) | -31-158°F (-35-70°C) |
Humidity | 10-90% non-condensing | 10-90% non-condensing |
Noise Level | 70 dBA | 70 dBA |
Operating Altitude | Up to 7,400 ft (2,250 m) | Up to 7,400 ft (2,250 m) |
Compliance | FCC Part 15 Class A, C-Tick, VCCI, CE, UL/cUL, CB | FCC Part 15 Class A, C-Tick, VCCI, CE, UL/cUL, CB |
Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 |
Note: All performance values are "up to" and vary depending on system configuration.
Product | SKU | Description |
---|---|---|
FortiGate 3300E | FG-3300E | 4x 40 GE QSFP+ slots, 16x 25 GE SFP28 slots (including 14x ports, 2x HA ports), 14x GE RJ45 ports (including 12x ports, 2x management ports), 4x 10GBase-T ports, SPU NP6 and CP9 hardware accelerated, and dual AC power supplies. |
FortiGate 3301E | FG-3301E | 4x 40 GE QSFP+ slots, 16x 25 GE SFP28 slots (including 14x ports, 2x HA ports), 14x GE RJ45 ports (including 12x ports, 2x management ports), 4x 10GBase-T ports, SPU NP6 and CP9 hardware accelerated, and dual AC power supplies, with 2x 1 TB SSD onboard storage. |
SKU | Description | |
---|---|---|
Rack Mount Sliding Rails | SP-FG3040B-RAIL | Rack mount sliding rails for FG-1000C/-DC, FG-1200D, FG-1500D/DC, FG-3040B/-DC, FG-3140B/-DC, FG-3240C/-DC, FG-3000D/-DC, FG-3100D/-DC, FG-3200D/-DC, FG-3400/3401E, FG-3600/3601E, FG-3700D/-DC, FG-3700DX, FG-3810D/-DC and FG-3950B/-DC. |
AC power supply | SP-FG3800D-PS | AC power supply for FG-2200/2201E, FG-3300/3301E, FG-3400/3401E, FG-3600/3601E, FG-3700D, FG-3700D-NEBS, FG-3700DX, FG-3810D and FG-3815D. |
40 GE QSFP+ Transceiver Module, Short Range | FG-TRAN-QSFP+SR | 40 GE QSFP+ transceiver module, short range for all systems with QSFP+ slots. |
40 GE QSFP+ Transceiver Module, Short Range BiDi | FG-TRAN-QSFP+SR-BIDI | 40 GE QSFP+ transceiver module, short range BiDi for all systems with QSFP+ slots. |
40 GE QSFP+ Transceiver Module, Long Range | FG-TRAN-QSFP+LR | 40 GE QSFP+ transceiver module, long range for all systems with QSFP+ slots. |
10 GE SFP+ Transceiver Module, Short Range | FG-TRAN-SFP+SR | 10 GE SFP+ transceiver module, short range for all systems with SFP+ and SFP/SFP+ slots. |
10 GE SFP+ Transceiver Module, Long Range | FG-TRAN-SFP+LR | 10 GE SFP+ transceiver module, long range for all systems with SFP+ and SFP/SFP+ slots. |
10 GE SFP+ Active Direct Attach Cable, 10m / 32.8 ft | SP-CABLE-ADASFP+ | 10 GE SFP+ active direct attach cable, 10m / 32.8 ft for all systems with SFP+ and SFP/SFP+ slots. |
25 GE / 10 GE Dual Rate SFP28 Transceiver Module, Short Range | FG-TRAN-SFP28-SR | 25 GE / 10 GE dual rate SFP28 transceiver module, short range for all systems with SFP28/SFP+ slots. |
25 GE SFP28 Transceiver Module, Long Range | FG-TRAN-SFP28-LR | 25 GE SFP28 transceiver module, long range for all systems with SFP28 slots. |
40 GE QSFP+ to 4x 10GE SFP+ Optical Breakout | FG-TRAN-QSFP+4XSFP | 40GE QSFP+ Parallel Breakout Active Optical Cable with 1m length for all systems with QSFP+ slots. |
QSFP+ to 4xSFP+ Optical breakout 5m | FG-TRAN-QSFP+4SFP-5 | 40G QSFP+ Parallel Breakout MPO to 4xLC connectors, 5m reach, transceivers not included. |
FortiGuard Labs delivers a number of security intelligence services to augment the FortiGate firewall platform. Customers can easily optimize the protection capabilities of their FortiGate with one of these FortiGuard Bundles.
Bundles | 360 Protection | Enterprise Protection | UTM | Threat Protection |
---|---|---|---|---|
FortiCare | ASE 1 | 24x7 | 24x7 | 24x7 |
FortiGuard App Control Service | ● | ● | ● | ● |
FortiGuard IPS Service | ● | ● | ● | ● |
FortiGuard Advanced Malware Protection (AMP) – Antivirus, Mobile Malware, Botnet, CDR, Virus Outbreak Protection and FortiSandbox Cloud Service | ● | ● | ● | ● |
FortiGuard Web Filtering Service | ● | ● | ● | ● |
FortiGuard Antispam Service | ● | ● | ● | ● |
FortiGuard Security Rating Service | ● | ● | ||
FortiGuard Industrial Service | ● | ● | ||
FortiCASB SaaS-only Service | ● | ● | ||
FortiConverter Service | ● | |||
SD-WAN Cloud Assisted Monitoring 2 | ● | |||
SD-WAN Overlay Controller VPN Service 2 | ● | |||
FortiAnalyzer Cloud 2 | ● | |||
FortiManager Cloud 2 | ● |
1 24x7 plus Advanced Services Ticket Handling
2 Available when running FortiOS 6.2
![]() |
FortiGate 6000F Series: High-Performance Next-Generation Firewall Datasheet Technical datasheet for Fortinet's FortiGate 6000F series, including models FG-6300F, FG-6301F, FG-6500F, and FG-6501F. Features high-performance threat protection, advanced networking, and Security Fabric integration for enterprise data centers and cloud environments. |
![]() |
Fortinet NGFW/Perimeter Firewalls Ordering Guide This ordering guide details Fortinet's Next-Generation Firewalls (NGFW) and Perimeter Firewalls, highlighting their advanced AI/ML capabilities, FortiGuard services, and the integrated Fortinet Security Fabric for comprehensive enterprise threat protection and policy control. |
![]() |
FortiOS 6.4.3 Release Notes Official release notes for FortiOS version 6.4.3, detailing new features, enhancements, resolved issues, and known issues for Fortinet's network security operating system. Includes supported models and upgrade information. |
![]() |
Fortinet Secure SD-WAN Ordering Guide: Models, Bundles, and Specifications This guide provides comprehensive ordering information for Fortinet's Secure SD-WAN solutions, detailing appliance models, performance specifications, bundle options, cloud integration, and management platforms for enterprise networks. |
![]() |
Fortinet FortiGate 3400E Series Data Sheet: High-Performance Network Security Detailed data sheet for the Fortinet FortiGate 3400E and 3401E series, highlighting their capabilities as Next Generation Firewalls (NGFW) with advanced threat protection, segmentation, IPS, and high-speed connectivity for enterprise and service provider networks. Features SPU NP6 and CP9 processors, Security Fabric integration, and comprehensive specifications. |
![]() |
Fortinet Secure SD-WAN Ordering Guide: Product Specifications and Bundles This guide provides detailed specifications, ordering information, and bundle options for Fortinet's Secure SD-WAN solutions, including FortiGate appliances, FortiManager, and related services. |
![]() |
FortiGate 200G Series Datasheet: AI-Powered Next-Generation Firewall Comprehensive datasheet for Fortinet's FortiGate 200G Series (FG-200G and FG-201G) Next-Generation Firewall (NGFW), featuring AI/ML security, deep visibility, and advanced threat protection. |
![]() |
Fortinet FortiGate Network Security Platform Top Selling Models Matrix A comprehensive matrix detailing the top-selling models of the Fortinet FortiGate Network Security Platform, including specifications for firewall throughput, IPsec VPN throughput, IPS throughput, NGFW throughput, threat protection throughput, firewall latency, concurrent sessions, new sessions per second, firewall policies, maximum tunnels, SSL VPN throughput, concurrent SSL VPN users, SSL inspection throughput, application control throughput, maximum FortiAPs, FortiSwitches, FortiTokens, and virtual domains. |