fortigate model sizing guide
All insights
ITBUILDERS INTELLIGENCEFortinet

Which FortiGate Model Is Right for My Business? A Sizing Guide

Undersize a FortiGate and it becomes a bottleneck. Oversize it and you waste capital. The three engineering factors behind a professional sizing decision, explained.

By ITBuilders Editorial Team6 min read

We hear the same question from IT leaders across the Kingdom, over and over: "Which FortiGate model is right for my business?"

It's a high-stakes call, and both ways of getting it wrong hurt. Pick a model that's undersized and it turns into a network bottleneck — users frustrated, operations dragging, everyone blaming the internet. Over-spec the hardware and you've sunk capital into capacity you'll never touch, money that could have funded the security services actually running on the box.

A certified partner should always run a proper traffic analysis before making the final call, but three engineering factors drive every professional sizing decision. Understand these and you'll see through the datasheet.

Factor 1: threat protection throughput, not marketing throughput

Here's the first trap, and it catches almost everyone. Organisations size their firewall off the big "Firewall Throughput" number at the top of the datasheet. That number is close to meaningless for a modern deployment.

Firewall throughput measures raw packet forwarding with essentially no inspection — a scenario that describes no real enterprise deployment anywhere. In a Saudi enterprise environment, where fibre speeds in Riyadh and Jeddah keep climbing, basic stateful throughput tells you almost nothing about real-world performance.

The metric that matters is Threat Protection Throughput. That's the firewall's performance with all the critical security engines running at once: IPS, antivirus, application control. The gap between the two numbers is huge — often a factor of five or more — and it's where people get burned.

Do the arithmetic. If your internet line is 500 Mbps but your firewall can only inspect threats at 200 Mbps, you've bought an internet connection you can't actually use securely. You have two options, and both are bad: throttle yourself to 200 Mbps, or switch off protection to keep the speed. And switching off protection defeats the entire purchase — which is exactly what happens in practice, quietly, when users start complaining.

Add deep SSL inspection to the picture and the numbers tighten further. Since most web traffic is encrypted, a firewall that can't decrypt at line rate can't inspect the traffic that matters. Sizing has to account for the decryption load, not just the inspection load.

Factor 2: user density and concurrent sessions

Counting heads in the office stopped working years ago. You have to account for device density and session load, and the multiplier is bigger than most people expect.

The typical professional now carries three devices — laptop, smartphone, tablet — and every one of them holds multiple concurrent sessions open to cloud services like Microsoft 365, Salesforce, and Zoom. Modern applications are chatty: a single Teams session maintains several persistent connections, and a browser with a dozen tabs open to SaaS platforms is holding dozens more.

So a business with 100 users might really be supporting 400+ active devices, each juggling its own live connections. A correctly sized FortiGate needs enough RAM and CPU to hold those session tables without dropping connections or introducing latency.

Undersize this and the symptoms are maddening to diagnose: intermittent slowdowns that don't map cleanly to bandwidth utilisation, connections that drop under load, applications that work fine in the morning and struggle at 2 p.m. Your monitoring shows the link isn't saturated, so nobody suspects the firewall — but the session table is full.

Factor 3: architectural complexity (SD-WAN and segmentation)

Your topology drives the hardware more than your headcount does, and this is the factor most sizing exercises skip.

Sizing for a single-site office is a completely different exercise from sizing for a regional hub that terminates SD-WAN tunnels from dozens of branches and enforces segmentation across user, server, IoT, and OT zones. Every one of those functions consumes processing capacity. VPN termination costs CPU. SD-WAN path measurement costs CPU. Inter-VLAN policy enforcement means the firewall inspects internal east-west traffic on top of everything crossing the perimeter — and in a well-segmented network, east-west volume can dwarf north-south.

A firewall that's comfortable as a simple perimeter device can buckle the moment you ask it to be the core of a segmented, multi-site architecture. So the question isn't just "how many users" — it's "what is this box actually being asked to do?"

Understanding the FortiGate series

To narrow the field, Fortinet hardware falls broadly into tiers. Entry-level models suit small businesses and branch sites with modest throughput and simple topologies. Mid-range models serve growing mid-market organisations with real inspection requirements and some segmentation. Enterprise and data-centre-class models handle large, high-throughput, heavily segmented environments, hub roles terminating many tunnels, and demanding SSL inspection loads. [1]

The right tier is the intersection of your threat-protection throughput needs, your real device count, and your architectural complexity — not whichever model matches a competitor's choice or a peer's recommendation. Two companies with identical headcounts can need very different appliances if one is a single office and the other is a segmented hub for forty branches.

The three-year question

One more consideration that separates a good sizing decision from an adequate one. The firewall you buy today has to still fit in year three.

That means factoring in your growth plan, your compliance roadmap, and the direction your architecture is heading. If you're planning SD-WAN, moving toward segmentation, or expanding sites, the appliance needs headroom for the load those changes bring. Sizing precisely for today's traffic is how organisations end up back in a procurement cycle eighteen months later.

Frequently asked questions

Can I size from the datasheet myself? You can get in the right neighbourhood, but the datasheet doesn't know your traffic mix, your SSL inspection needs, your session profile, or your topology. Those are what determine the real answer.

What happens if we undersize? The firewall becomes a bottleneck. Typically the response is to disable inspection features to recover speed — which means you paid for security you're not using.

What happens if we oversize? You waste capital on unused capacity. It's less dangerous than undersizing but still a poor use of budget that could have funded licensing, tuning, or managed services.

How does SSL inspection affect sizing? Significantly. Decryption is processor-intensive, and most traffic is encrypted. A firewall sized without accounting for the decryption load will underperform badly once you enable deep inspection.

Get an expert sizing recommendation

A datasheet only tells you part of the story, and it's the least useful part. To make sure your investment lands right, you need an assessment that looks at your actual traffic patterns, your compliance roadmap, and your three-year growth plan.

We're a leading FortiGate provider in Riyadh and across KSA, and we don't just sell boxes. We run structured assessments so you invest in a model that delivers maximum performance and security value — dodging both the bottleneck of undersizing and the waste of oversizing.

Don't guess your capacity. Know it. Request a free firewall sizing consultation. Call 920-020-750, email [email protected], or visit itbuilders.com.sa.

Sources & references

  1. Fortinet, FortiGate/FortiOS Data Sheets
  2. Fortinet, FortiOS Documentation
TALK TO A SPECIALIST

Turn this insight into a practical next step.

Discuss your environment with our team and get a clear recommendation grounded in your operational reality.

Start a conversation
CONTINUE READING

Related intelligence