FortiGate 90G Series

FG-90G and FG-91G

Highlights

Converged Next-Generation Firewall (NGFW) and SD-WAN

The FortiGate Next-Generation Firewall 90G series is ideal for building security-driven networks at distributed enterprise sites and transforming WAN architecture at any scale.

With a rich set of AI/ML-based FortiGuard security services and Fortinet's integrated Security Fabric platform, the FortiGate 90G series delivers coordinated, automated, end-to-end threat protection across all use cases.

FortiGate features the industry's first integrated SD-WAN and zero-trust network access (ZTNA) enforcement within an NGFW solution, powered by a single OS. FortiGate 90G automatically controls, verifies, and facilitates user access to applications, delivering consistency with a seamless and optimized user experience.

IPSNGFWThreat ProtectionInterfaces
4.5 Gbps2.5 Gbps2.2 GbpsMultiple GE RJ45, 10 GE RJ45, and SFP+ Share Media Slots | Variants with internal storage

FortiOS Everywhere

FortiOS, Fortinet's Advanced Operating System

FortiOS enables the convergence of high-performing networking and security across the Fortinet Security Fabric. It can be deployed anywhere, delivering consistent and context-aware security posture across network, endpoint, and multi-cloud environments.

FortiOS powers all FortiGate deployments, whether as a physical or virtual device, a container, or a cloud service. This universal deployment model consolidates many technologies and use cases into organically built, best-of-breed capabilities, a unified operating system, and ultra-scalability. The solution allows organizations to protect all edges, simplify operations, and run their business without compromising performance or protection.

FortiOS expands the Fortinet Security Fabric's ability to deliver advanced AI/ML-powered services, inline advanced sandbox detection, integrated ZTNA enforcement, and more. It provides protection across hybrid deployment models for hardware, software, and Software-as-a-Service (SASE).

FortiOS enhances visibility and control, ensuring consistent deployment and enforcement of a simplified, single policy and management framework. Its security policies enable centralized management across large-scale networks with key attributes:

GUI Views:

FortiConverter Service

FortiConverter Service provides hassle-free migration to help organizations transition from a wide range of legacy firewalls to FortiGate Next-Generation Firewalls quickly and easily. The service eliminates errors and redundancy by employing best practices with advanced methodologies and automated processes, accelerating network protection with the latest FortiOS technology.

FortiGuard Services

FortiGuard Services offer comprehensive protection against various threats:

Network and File Security

Provides protection against network-based and file-based threats, including Intrusion Prevention (IPS) using AI/ML models for deep packet/SSL inspection and virtual patching. It also includes Anti-Malware for known and unknown file-based threats, with multi-layered protection enhanced by real-time threat intelligence from FortiGuard Labs. Application Control enhances security compliance and offers real-time application visibility.

Web / DNS Security

Protects against web-based threats, including DNS-based threats, malicious URLs (even in emails), and botnet/command and control communications. DNS filtering provides visibility into DNS traffic, blocking high-risk domains, and protecting against DNS tunneling, infiltration, C2 server ID, and DGAs. URL filtering uses a database of over 300 million URLs to block malicious sites and payloads. IP Reputation and anti-botnet services prevent botnet communications and block DDoS attacks.

SaaS and Data Security

Addresses numerous security use cases for application usage and data security, including Data Leak Prevention (DLP) for data visibility, management, and protection across networks, clouds, and users, simplifying compliance and privacy. The Inline Cloud Access Security Broker (CASB) service protects data in motion, at rest, and in the cloud, enforcing compliance standards and managing user/application usage. Services also assess infrastructure, validate configurations, and generate awareness of risks and vulnerabilities, including IoT device detection and vulnerability correlation.

Zero-Day Threat Prevention

Features Fortinet's AI-based inline malware prevention and advanced sandbox service to analyze and block unknown files in real-time, offering sub-second protection against zero-day and sophisticated threats. It includes a built-in MITRE ATT&CK® matrix to accelerate investigations, focusing on comprehensive defense and streamlining incident response.

OT Security

Provides OT detection, OT vulnerability correlation, virtual patching, OT signatures, and industry-specific protocol decoders for robust defense of OT environments and devices.

Secure Any Edge at Any Scale

Powered by Security Processing Unit (SPU)

Traditional firewalls struggle with today's content- and connection-based threats due to reliance on off-the-shelf hardware and general-purpose CPUs, creating a performance gap. Fortinet's custom SPU processors deliver up to 520Gbps to detect emerging threats and block malicious content without becoming a performance bottleneck.

ASIC Advantage:

Centralized Network and Security Management at Scale:

FortiManager, the centralized management solution from Fortinet, enables integrated management of the Fortinet security fabric, including devices like FortiGate, FortiSwitch, and FortiAP. It simplifies and automates oversight of network and security functions across diverse environments, serving as the fundamental component for deploying Hybrid Mesh Firewalls.

GUI View: "Intuitive view and clear insights into network security posture with FortiManager"

Use Cases

Next Generation Firewall (NGFW)

Secure SD-WAN

Universal ZTNA

Network Diagram: A diagram illustrates the FortiGate 90G series in an Enterprise Branch network. It shows connections to the Internet, Data Center, Multi-Cloud (AWS, Azure), and SaaS (Salesforce, Office 365) via Secure SD-WAN. Management is handled by FortiManager, with analytics from FortiAnalyzer. The diagram also depicts ZTNA users, FortiSwitch for secure access, and FortiAP for secure access points.

Hardware

FortiGate 90G/91G

Front Panel Description: The front panel features a console port, USB management port, power status indicator, reset button, and network interface ports, including SFP+ and WAN ports.

Hardware Features:

Interfaces:

Compact and Reliable Form Factor: Designed for small environments, it can be placed on a desktop or wall-mounted. It is small, lightweight, and highly reliable with a superior MTBF (Mean Time Between Failure), minimizing the chance of network disruption.

Specifications

Hardware SpecificationsFORTIGATE 90GFORTIGATE 91G
10/5/2.5/GE RJ45 or 10GE/GE SFP+/ SFP Shared Media pairs22
GE RJ45 Internal Ports88
Wireless Interface--
USB Ports11
Console (RJ45)11
Internal Storage-1 x 120 GB SSD
Trusted Platform Module (TPM)YesYes
Bluetooth Low Energy (BLE)YesYes
System Performance* -- Enterprise Traffic Mix
IPS Throughput 24.5 Gbps4.5 Gbps
NGFW Throughput 2, 42.5 Gbps2.5 Gbps
Threat Protection Throughput 2, 52.2 Gbps2.2 Gbps
System Performance and Capacity
Firewall Throughput (1518 / 512 / 64 byte UDP packets)28 / 28 / 27.9 Gbps28 / 28 / 27.9 Gbps
Firewall Latency (64 byte UDP packets)3.23 µs3.23 µs
Firewall Throughput (Packets Per Second)41.85 Mpps41.85 Mpps
Concurrent Sessions (TCP)1.5 M1.5 M
New Sessions/Second (TCP)124,000124,000
Firewall Policies50005000
IPsec VPN Throughput (512 byte) 125 Gbps25 Gbps
Gateway-to-Gateway IPsec VPN Tunnels200200
Client-to-Gateway IPsec VPN Tunnels25002500
SSL-VPN Throughput 61.4 Gbps1.4 Gbps
Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode)200200
SSL Inspection Throughput (IPS, avg. HTTPS) 32.6 Gbps2.6 Gbps
SSL Inspection CPS (IPS, avg. HTTPS) 314001400
SSL Inspection Concurrent Session (IPS, avg. HTTPS) 3300,000300,000
Application Control Throughput (HTTP 64K) 26.7 Gbps6.7 Gbps
CAPWAP Throughput (HTTP 64K)23.6 Gbps23.6 Gbps
Virtual Domains (Default / Maximum)10 / 1010 / 10
Maximum Number of FortiSwitches Supported2424
Maximum Number of FortiAPs (Total / Tunnel Mode)96 / 4896 / 48
Maximum Number of FortiTokens500500
High Availability ConfigurationsActive-Active, Active-Passive, ClusteringActive-Active, Active-Passive, Clustering
DimensionsFORTIGATE 90GFORTIGATE 91G
Height x Width x Length (inches)1.65 x 8.5 x 7.01.65 x 8.5 x 7.0
Height x Width x Length (mm)42 x 216 x 17842 x 216 x 178
Weight2.47 lbs (1.12 kg)2.47 lbs (1.12 kg)
Form FactorDesktopDesktop
Operating Environment and Certifications
Input Rating12V DC, 3A (dual redundancy optional)12V DC, 3A (dual redundancy optional)
Power Required (Redundancy Optional)Powered by up to 2 External DC Power Adapters (1 adapter included), 100–240V AC, 50/60 HzPowered by up to 2 External DC Power Adapters (1 adapter included), 100–240V AC, 50/60 Hz
Power Supply Efficiency Rating80Plus Compliant80Plus Compliant
Maximum Current115Vac/0.4A, 230Vac/0.2A115Vac/0.4A, 230Vac/0.2A
Power Consumption (Average / Maximum)19.9 W / 20.53 W22.4 W / 23.5 W
Heat Dissipation70.0 BTU/hr80.1 BTU/hr
Operating Temperature32°F to 104°F (0°C to 40°C)32°F to 104°F (0°C to 40°C)
Storage Temperature-31°F to 158°F (-35°C to 70°C)-31°F to 158°F (-35°C to 70°C)
Humidity10% to 90% non-condensing10% to 90% non-condensing
Noise Level21.73 dBA21.73 dBA
Operating AltitudeUp to 10,000 ft (3048 m)Up to 10,000 ft (3048 m)
ComplianceFCC, ICES, CE, RCM, VCCI, BSMI, UL/cUL, CBFCC, ICES, CE, RCM, VCCI, BSMI, UL/cUL, CB
CertificationsUSGv6/IPv6USGv6/IPv6

Note: All performance values are "up to" and vary depending on system configuration. Refer to footnotes in the original document for specific test conditions.

Subscriptions

Service CategoryService OfferingA-la-carteEnterprise ProtectionUnified Threat ProtectionAdvanced Threat Protection
FortiGuard Security ServicesIPS Service
Anti-Malware Protection (AMP) - Antivirus, Mobile Malware, Botnet, CDR, Virus Outbreak Protection and FortiSandbox Cloud Service
URL, DNS & Video Filtering Service
Anti-Spam
AI-based Inline Malware Prevention Service
Data Loss Prevention Service 1
OT Security Service (OT Detection, OT Vulnerability correlation, Virtual Patching, OT Signature / Protocol Decoders) 1
Application ControlIncluded with FortiCare SubscriptionIncluded with FortiCare Subscription
CASB SaaS Control
SD-WAN and SASE ServicesSD-WAN Underlay Bandwidth and Quality Monitoring Service
SD-WAN Overlay-as-a-Service for SaaS-based overlay network provisioning
SD-WAN Connector for FortiSASE Secure Private Access
FortiSASE subscription including cloud management and 10Mbps bandwidth license 2
NOC and SOC ServicesFortiGuard Attack Surface Security Service (IoT Detection, IoT Vulnerability Correlation, and Security Rating Updates) 1
FortiConverter Service
Managed FortiGate Service
FortiGate Cloud (SMB Logging + Cloud Management)
FortiManager Cloud
FortiAnalyzer Cloud
FortiAnalyzer Cloud with SOCaaS
FortiGuard SOCaaS
Hardware and Software SupportFortiCare Essentials 2
FortiCare Premium
FortiCare Elite
Internet Service (SaaS) DB Updates
GeoIP DB Updates
Device/OS Detection Signatures
Trusted Certificate DB Updates
DDNS (v4/v6) Service

1. Full features available when running FortiOS 7.4.1. 2. Desktop Models only.

FortiGuard Bundles: FortiGuard Labs delivers security intelligence services to augment the FortiGate firewall platform, allowing optimization of protection capabilities with FortiGuard Bundles.

FortiCare Services: Fortinet prioritizes customer success through FortiCare Services, optimizing the Fortinet Security Fabric solution. Lifecycle services include Design, Deploy, Operate, Optimize, and Evolve. FortiCare Elite offers heightened SLAs and swift issue resolution with a dedicated support team, including an Extended End-of-Engineering-Support of 18 months. Access the FortiCare Elite Portal for a unified view of device and security health.

Ordering Information

ProductSKUDescription
FortiGate 90GFG-90G8 x GE RJ45 ports, 2 x 10GE RJ45/SFP+ shared media WAN ports.
FortiGate 91GFG-91G8 x GE RJ45 ports, 2 x 10GE RJ45/SFP+ shared media WAN ports with 120GB SSD.
Optional Accessories
AC Power AdaptorSP-FG60E-PDC-5Pack of 5 AC power adaptors for FG/FWF 60E/61E, FG/FWF 60F/61F, FG-80E/81E, FG-80F/81F, and FG-90G/91G.
Wall Mount KitSP-FG60F-MOUNT-20Pack of 20 wall mount kits for FG/FWF-60F, FG-90G/91G and FG/FWF-80F series.
1 GE SFP RJ45 Transceiver ModuleFN-TRAN-GC1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP+ slots.
1 GE SFP SX Transceiver ModuleFN-TRAN-SX1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP+ slots.
1 GE SFP LX Transceiver ModuleFN-TRAN-LX1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP+ slots.
10 GE SFP+ RJ45 Transceiver ModuleFN-TRAN-SFP+GC10 GE SFP+ RJ45 transceiver module for systems with SFP+ slots.
10 GE SFP+ Transceiver Module, Short RangeFN-TRAN-SFP+SR10 GE SFP+ transceiver module, short range for all systems with SFP+ and SFP/SFP+ slots.
10 GE SFP+ Transceiver Module, Long RangeFN-TRAN-SFP+LR10 GE SFP+ transceiver module, long range for all systems with SFP+ and SFP/SFP+ slots.
10 GE SFP+ Transceiver Module, Extended RangeFN-TRAN-SFP+ER10 GE SFP+ transceiver module, extended range for all systems with SFP+ and SFP/SFP+ slots.
10GE SFP+ Transceiver Module, 30km Long RangeFN-TRAN-SFP+BD2710GE SFP+ transceiver module, 30km long range single BiDi for systems with SFP+ and SFP/SFP+ slots (connects to FN-TRAN-SFP+BD33, ordered separately).
10GE SFP+ Transceiver Module, (connects to FN-TRAN-SFP+BD27, ordered separately)FN-TRAN-SFP+BD3310GE SFP+ transceiver module, 30km long range single BiDi for systems with SFP+ and SFP/SFP+ slots (connects to FN-TRAN-SFP+BD27, ordered separately).
10 GE SFP+ passive direct attach cable, 1mFN-CABLE-SFP+110 GE SFP+ passive direct attach cable, 1m for systems with SFP+ and SFP/SFP+ slots.
10 GE SFP+ passive direct attach cable, 3mFN-CABLE-SFP+310 GE SFP+ passive direct attach cable, 3m for systems with SFP+ and SFP/SFP+ slots.
10 GE SFP+ passive direct attach cable, 5mFN-CABLE-SFP+510 GE SFP+ passive direct attach cable, 5m for systems with SFP+ and SFP/SFP+ slots.

Fortinet CSR Policy

Fortinet is committed to driving progress and sustainability for all through cybersecurity, with respect for human rights and ethical business practices, making possible a digital world you can always trust. Users of Fortinet products are required to comply with the Fortinet EULA and report any suspected violations of the EULA via the procedures outlined in the Fortinet Whistleblower Policy.

www.fortinet.com

Copyright © 2024 Fortinet, Inc. All rights reserved. Fortinet, FortiGate, FortiCare and FortiGuard, and certain other marks are registered trademarks of Fortinet, Inc. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice.

Document Revision: FG-90G-DAT-R05-20240105, Dated: January 5, 2024

PDF preview unavailable. Download the PDF instead.

fortigate-fortiwifi-90g-series , Inc. Adobe PDF Library 17.0

Related Documents

Preview FortiGate 90G Series QuickStart Guide: Setup and Configuration
A concise guide to setting up and configuring the FortiGate 90G and 91G series network security appliances, covering essential setup, package contents, front and rear panel details, and regulatory information.
Preview FortiGate 90G Series QuickStart Guide
A quick start guide for the FortiGate 90G Series, including FG-90G and FG-91G models. This guide covers initial setup, essential information, and regulatory compliance.
Preview FortiGate 90G Series QuickStart Guide: Setup, Configuration, and Features
Get started quickly with the FortiGate 90G Series firewall. This guide covers setup, essential features, front/rear panel descriptions, and regulatory information for the FG-90G and FG-91G models.
Preview Fortinet NGFW/Perimeter Firewalls Ordering Guide
This ordering guide details Fortinet's Next-Generation Firewalls (NGFW) and Perimeter Firewalls, highlighting their advanced AI/ML capabilities, FortiGuard services, and the integrated Fortinet Security Fabric for comprehensive enterprise threat protection and policy control.
Preview FortiGate 6000F Series: High-Performance Next-Generation Firewall Datasheet
Technical datasheet for Fortinet's FortiGate 6000F series, including models FG-6300F, FG-6301F, FG-6500F, and FG-6501F. Features high-performance threat protection, advanced networking, and Security Fabric integration for enterprise data centers and cloud environments.
Preview FortiGate 200G Series Datasheet: AI-Powered Next-Generation Firewall
Comprehensive datasheet for Fortinet's FortiGate 200G Series (FG-200G and FG-201G) Next-Generation Firewall (NGFW), featuring AI/ML security, deep visibility, and advanced threat protection.
Preview Fortinet Secure SD-WAN Ordering Guide: Models, Bundles, and Specifications
This guide provides comprehensive ordering information for Fortinet's Secure SD-WAN solutions, detailing appliance models, performance specifications, bundle options, cloud integration, and management platforms for enterprise networks.
Preview FortiGate 600F Series: Secure SD-WAN and Next-Generation Firewall
Discover the FortiGate 600F Series, a scalable and secure SD-WAN solution with advanced Next-Generation Firewall (NGFW) capabilities for enterprises. Featuring high performance, comprehensive security services, and seamless integration into the Fortinet Security Fabric.