FortiGate 100F Series
FG-100F and FG-101F
Overview
The FortiGate 100F series delivers next-generation firewall capabilities and SD-WAN solutions for enterprise branch and mid-to-large enterprises. This series offers optimal performance and security for critical business applications, powered by a custom Secure SD-WAN ASIC.
Key features include advanced threat protection, secure web gateway (SWG), and integrated SD-WAN capabilities.
Key Features
Security
- Identifies thousands of applications in network traffic for deep inspection and policy enforcement.
- Protects against malware, exploits, and malicious websites in encrypted and unencrypted traffic.
- Utilizes AI-powered FortiGuard Labs security services for proactive threat prevention and detection.
Performance
- Leverages dedicated Security Processing Unit (SPU) technology for industry-leading threat protection performance and ultra-low latency.
- Offers industry-leading SSL inspection performance and threat protection, being the first firewall to provide TLS 1.3 deep inspection.
Networking
- Provides advanced networking features, integrating with high-end Layer 7 security and Virtual Domains (VDOMs) for flexible deployment and resource utilization.
- Offers a high-density, flexible combination of high-speed interfaces for optimal Total Cost of Ownership (TCO) in data center and WAN deployments.
Management
- Includes an efficient, easy-to-use management console with comprehensive network automation and visibility.
- Features a convenient Security Fabric unified console for zero-touch deployment.
- Provides predefined compliance check lists to analyze deployments and highlight best practices for improving overall security posture.
Security Fabric
- Enables Fortinet and Fabric-ready partners' products to offer broader visibility, integrated point-to-point detection, and threat intelligence sharing for automated remediation.
Deployment Scenarios
Campus Deployment (NGFW)
This scenario illustrates how FortiGate, as a Next-Generation Firewall (NGFW), secures a campus network. It integrates with other Fortinet products like FortiClient (endpoint protection), FortiAP (access points), FortiSwitch (switching), FortiWeb (web application firewall), FortiManager (management), FortiAnalyzer (analytics), and FortiSandbox (advanced threat protection) to provide comprehensive security across the network.
Diagram depicts an Internal User and External User connecting through the Internet to a FortiGate NGFW. The FortiGate is connected to Web Application Servers. Other Fortinet devices like FortiClient, FortiAP, FortiSwitch, FortiWeb, FortiManager, FortiAnalyzer, and FortiSandbox are shown integrated into the network fabric.
Enterprise Branch Deployment (Secure SD-WAN)
This scenario shows a Secure SD-WAN deployment for an enterprise branch. It highlights how FortiGate optimizes WAN connectivity for specific business requirements, accelerates multi-cloud access, and uses Forward Error Correction (FEC) for WAN path correction. It connects the branch to the internet, SaaS applications (like Office 365, Salesforce), and multi-cloud environments (AWS, Azure) via IPSec tunnels and MPLS. Key components include FortiGate, FortiSwitch, FortiAP, SD-WAN Orchestrator, and FortiAnalyzer.
Diagram shows an Enterprise Branch with a FortiGate Secure SD-WAN device connecting to the Internet. The Internet provides access to SaaS applications (Office 365, Salesforce) and Multi-Cloud services (AWS, Azure). IPSec Tunnels and MPLS are shown as connectivity methods. FortiGate is integrated with FortiSwitch, FortiAP, SD-WAN Orchestrator, and FortiAnalyzer.
Hardware
FortiGate 100F/101F
The FortiGate 100F and 101F models feature robust hardware designed for high performance and reliability.
Interfaces
The devices offer a comprehensive set of interfaces:
- 1x USB Port
- 1x Console Port
- 2x GE RJ45 MGMT/DMZ Ports
- 4x GE RJ45 WAN Ports
- 12x GE RJ45 Ports
- 2x 10 GE SFP+ FortiLink Slots
- 4x GE SFP Slots
- 4x GE SFP Shared RJ45 Ports
Hardware Features
- Powered by Secure SD-WAN ASIC SOC4 for enhanced performance.
- Combines RISC-based CPU with Fortinet's dedicated SPU for unparalleled performance in content and network processing.
- Offers industry-leading application identification for efficient business operations.
- Accelerates IPsec VPN performance for an optimal user network experience.
- Provides best-in-class NGFW security and high-performance deep SSL inspection.
- Extends security to the access layer, enabling SD-Branch transformation through accelerated and integrated switching and access points.
- Dual Power Supply for critical network availability.
- Access Layer Security: Extends FortiGate's connectivity with FortiSwitch for simplified network management and configuration.
Fortinet Security Fabric
The Fortinet Security Fabric is an industry-leading cybersecurity platform built on FortiGate and FortiOS. It provides comprehensive protection and visibility across every network segment, device, and application, whether in virtual, cloud, or on-premises environments. It offers automated, self-healing network security across the entire digital attack surface.
- Broad: Extensive product portfolio enabling coordinated threat detection and policy enforcement across the digital attack surface and threat lifecycle.
- Integrated: Unified security, operations, and performance across diverse technologies, locations, deployment models, and ecosystems.
- Automated: Integrated, context-aware, self-healing security infrastructure leveraging advanced cloud AI for near real-time, automated protection.
FortiOS is Fortinet's advanced operating system, combining high-performance networking and security across endpoints, networks, and clouds. FortiOS 7.0 extends the security platform to all digital attack vectors, ensuring broad, integrated, and automated security, including SASE, Zero Trust Access, Security-Driven Networking, and Adaptive Cloud Security.
Services
FortiGuard Security Services
FortiGuard Labs provides real-time threat intelligence and comprehensive security updates across the Fortinet Security Fabric. Their expert team of security researchers, engineers, and forensic specialists collaborates with global threat monitoring organizations, other cybersecurity vendors, and law enforcement.
FortiCare Support Services
FortiCare customer support teams offer worldwide technical support for all Fortinet products. FortiCare services help thousands of organizations maximize the benefits of their Fortinet Security Fabric solutions.
Specifications
Specifications | FortiGate 100F | FortiGate 101F | |
---|---|---|---|
Hardware Accelerated Interfaces | |||
GE RJ45 Ports | 12 | 12 | |
GE RJ45 Management/HA/DMZ Ports | 2/1/1 | 2/1/1 | |
GE SFP Slots | 4 | 4 | |
10 GE SFP+ FortiLink Slots (Default) | 2 | 2 | |
GE RJ45 WAN Ports | 2 | 2 | |
GE RJ45 or SFP Shared Ports* | 2 | 2 | |
USB Ports | 1 | 1 | |
Console Port | 1 | 1 | |
Internal Storage | 0 | 1x 480 GB SSD | |
System Performance - Enterprise Traffic Mix | |||
IPS Throughput² | 2.6 Gbps | 2.6 Gbps | |
NGFW Throughput²˒⁴ | 1.6 Gbps | 1.6 Gbps | |
Threat Protection Throughput²˒⁵ | 1 Gbps | 1 Gbps | |
IPv4 Firewall Throughput (1518/512/64-byte UDP) | 20/18/10 Gbps | 20/18/10 Gbps | |
Firewall Latency (64-byte UDP) | 4.97 µs | 4.97 µs | |
Firewall Throughput (Packets per second) | 15 Mpps | 15 Mpps | |
Concurrent Connections (TCP) | 1.5 Million | 1.5 Million | |
New Connections/sec (TCP) | 56,000 | 56,000 | |
Firewall Policies | 10,000 | 10,000 | |
IPsec VPN Throughput (512-byte)¹ | 11.5 Gbps | 11.5 Gbps | |
Gateway-to-Gateway IPsec VPN Tunnels | 2,500 | 2,500 | |
Client-to-Gateway IPsec VPN Tunnels | 16,000 | 16,000 | |
SSL-VPN Throughput | 1 Gbps | 1 Gbps | |
Concurrent SSL-VPN Users (Recommended Max, Tunnel Mode) | 500 | 500 | |
SSL Inspection Throughput (IPS, Avg HTTPS)³ | 1 Gbps | 1 Gbps | |
SSL Inspection CP (IPS, Avg HTTPS)³ | 1,800 | 1,800 | |
SSL Inspection Concurrent Connections (IPS, Avg HTTPS)³ | 135,000 | 135,000 | |
Application Control Throughput (HTTP 64K)² | 2.2 Gbps | 2.2 Gbps | |
CAPWAP Throughput (HTTP 64K) | 15 Gbps | 15 Gbps | |
Virtual Domains (Default/Max) | 10/10 | 10/10 | |
Max Number of Supported Switches | 32 | 32 | |
Max APs (Total/Tunnel) | 128/64 | 128/64 | |
Max FortiToken Count | 5,000 | 5,000 | |
High Availability Configuration | Active-Active, Active-Passive, Clustering | Active-Active, Active-Passive, Clustering | |
Dimensions (H x W x D) (inches) | 1.73 x 17 x 10 | 1.73 x 17 x 10 | |
Dimensions (H x W x D) (mm) | 44 x 432 x 254 | 44 x 432 x 254 | |
Form Factor (Supports EIA/Non-EIA) | Rack Mount, 1 RU | Rack Mount, 1 RU | |
AC Power | 100-240V AC, 50/60 Hz | 100-240V AC, 50/60 Hz | |
Power Consumption (Avg/Max) | 35.1 W / 38.7 W | 35.3 W / 39.1 W | |
Current (Max) | 100V/1A, 240V/0.5A | 100V/1A, 240V/0.5A | |
Heat Dissipation | 119.77 BTU/h | 121.13 BTU/h | |
Redundant Power Supply | Yes | Yes | |
Operating Temperature | 32–104°F (0–40° C) | 32–104°F (0–40° C) | |
Storage Temperature | -31–158°F (-35–70° C) | -31–158°F (-35–70° C) | |
Humidity | 10–90% non-condensing | 10–90% non-condensing | |
Noise Level | 40.4 dBA | 40.4 dBA | |
Airflow | Side to Back | Side to Back | |
Operating Altitude | Up to 7,400 ft (2,250 m) | Up to 7,400 ft (2,250 m) | |
Compliance | FCC Part 15B, Class A, RCM, VCCI, CE, UL/cUL, CB, BSMI | FCC Part 15B, Class A, RCM, VCCI, CE, UL/cUL, CB, BSMI | |
Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN, IPv6 | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN, IPv6 |
Notes: Performance values are "up to" and vary depending on system configuration. Specific test conditions apply for IPsec VPN, IPS, NGFW, and Threat Protection throughput. SSL inspection performance is an average of HTTPS sessions with various cipher suites.
Ordering Information
Products
Product | SKU | Description |
---|---|---|
FortiGate 100F | FG-100F | 22x GE RJ45 ports (includes 2x WAN, 1x DMZ, 1x Mgmt, 2x HA, 16x Switch, 4x SFP shared media), 4x SFP slots, 2x 10 GE SFP+ FortiLink, dual redundant power supplies. |
FortiGate 101F | FG-101F | 22x GE RJ45 ports (includes 2x WAN, 1x DMZ, 1x Mgmt, 2x HA, 16x Switch, 4x SFP shared media), 4x SFP slots, 2x 10 GE SFP+ FortiLink, 480GB onboard storage, dual redundant power supplies. |
Optional Accessories
Description | SKU |
---|---|
1x GE SFP RJ45 Transceiver Module | FN-TRAN-GC |
1x GE SFP SX Transceiver Module | FN-TRAN-SX |
1x GE SFP LX Transceiver Module | FN-TRAN-LX |
10 GE SFP+ RJ45 Transceiver Module | FN-TRAN-SFP+GC |
10 GE SFP+ Transceiver Module, Short Range | FN-TRAN-SFP+SR |
10 GE SFP+ Transceiver Module, Long Range | FN-TRAN-SFP+LR |
10 GE SFP+ Transceiver Module, Extended Range | FN-TRAN-SFP+ER |
Product Bundles
FortiGuard Bundles
FortiGuard Labs offers a wide range of security intelligence services to enhance FortiGate firewall platforms. FortiGuard product bundles allow for easy optimization of FortiGate product functionalities.
Bundle Name | FortiGuard Application Control | FortiGuard IPS | FortiGuard Advanced Malware Protection (AMP) | FortiGuard Web & Video Filtering | FortiGuard Anti-Spam | FortiGuard Security Rating | FortiGuard IoT Detection | FortiGuard Industrial | FortiConverter Service | SD-WAN Orchestrator License | SD-WAN Cloud-Assisted Monitoring | SD-WAN Overlay Controller VPN Service | Fortinet SOCaaS | FortiAnalyzer Cloud Service | FortiManager Cloud Service |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
360 Protection | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |||||||
Enterprise Protection | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | ||||||||||
Unified Threat Protection | ✔️ | ✔️ | ✔️ | ✔️ | |||||||||||
Advanced Threat Protection | ✔️ | ✔️ | ✔️ |
Note: 360 Protection includes 24x7 plus advanced technical support.