Fortinet Engage Partner Specialization — firewall
All insights
ITBUILDERS INTELLIGENCEFortinet

The Complete FortiGate Sizing Guide: Calculating Concurrent Sessions, Throughput, and SSL Inspection Overhead

Size a FortiGate against real traffic, not datasheet headlines. A step-by-step method for concurrent sessions, threat protection throughput, and SSL inspection overhead.

By ITBuilders3 min read

An undersized firewall fails loudly. An oversized one fails quietly, on the budget line, for five years.

Getting FortiGate sizing right means working from your real traffic and your real security requirements, then matching them to the datasheet figures that reflect those conditions. This guide walks through the method step by step.

Step 1: Collect the Right Inputs

Every sizing exercise starts with data. Pull as much as possible from existing firewalls, switches, and monitoring tools rather than estimating.

InputWhere to Find ItWhy It Matters
Peak throughputCurrent firewall or WAN interface statistics, busiest hourSets the baseline traffic volume
Peak concurrent sessionsCurrent firewall session table at peakDetermines session capacity required
Peak new sessions per secondFirewall statistics or flow logsDrives CPS requirements, especially with SSL inspection
Encrypted traffic shareFirewall application reports or proxy logsDetermines the SSL inspection load
Security features plannedSecurity policy requirementsIPS, antivirus, web filtering, and application control each reduce usable throughput
Inspection depthSecurity policy requirementsCertificate inspection costs far less than full deep inspection
VPN requirementsRemote access and site-to-site plansIPsec and SSL VPN each have separate capacity limits
SD-WAN roleNetwork designHub devices carry every branch tunnel and need matching capacity
GrowthBusiness plans for users, sites, and cloud adoptionThe device must hold up for its full service life
High availabilityResilience requirementsAn HA pair must handle full load on one unit during failover

If no existing data is available, for example on a greenfield site, work from user counts and application profiles, and treat the result as provisional until real traffic confirms it.

Step 2: Read the Right Columns on the Datasheet

FortiGate datasheets list several throughput figures. They measure very different things.

Firewall throughput measures raw packet forwarding with no security inspection. It's the biggest number and the least useful for sizing a modern deployment.

IPS throughput and NGFW throughput measure performance with intrusion prevention, and with IPS plus application control, respectively.

Threat protection throughput measures performance with firewall, IPS, application control, and malware protection all enabled, using an enterprise traffic mix. For most deployments, this is the figure to size against.

SSL inspection throughput, CPS, and concurrent sessions measure performance with deep inspection of encrypted traffic. If you plan to decrypt a significant share of traffic, these figures often become the limiting factor.

Always read the test conditions in the datasheet footnotes. They specify the traffic mix, packet sizes, and TLS parameters behind each number.

Step 3: Calculate the Requirement

Work through each dimension separately, then size to whichever one is most demanding.

Throughput. Take peak throughput, apply your growth factor over the device's planned service life, and compare the result to threat protection throughput.

SSL inspection. Multiply the projected peak throughput by the share of traffic you'll deeply inspect. Compare the result to SSL inspection throughput. Do the same for new sessions per second against SSL inspection CPS.

Sessions. Take peak concurrent sessions, apply the growth factor, and compare to the relevant concurrent session figure.

Headroom. Don't plan to run the device at its datasheet maximum. Define a utilization ceiling up front that leaves room for traffic spikes, new features, and firmware changes, and size so peak load stays below it.

Worked example (hypothetical). A head office has 1,200 users today, expects 1,600 within four years, and records 900 Mbps peak throughput. Roughly 85% of traffic is encrypted, and the security policy requires deep inspection for all of it except exempted banking and healthcare categories, about 75% of total traffic.

  • Projected peak throughput: 900 Mbps × (1,600 ÷ 1,200) = 1.2 Gbps
  • Projected deep inspection load: 1.2 Gbps × 75% = 900 Mbps
  • The candidate model must deliver at least 1.2 Gbps threat protection throughput and at least 900 Mbps SSL inspection throughput, both below the chosen utilization ceiling, plus matching CPS and session figures.

In this example, SSL inspection is likely to be the deciding constraint, not the headline throughput.

Step 4: Account for What the Numbers Don't Show

Some factors don't appear in a simple throughput calculation.

Logging. Heavy local logging and reporting consume resources. Sending logs to FortiAnalyzer offloads that work.

Proxy-based inspection. Proxy mode inspects more deeply than flow mode and costs more. If specific policies need it, factor that load in.

Hardware acceleration boundaries. Fortinet's NP and CP processors accelerate most traffic, but some features and traffic types run on the main CPU. A design review should confirm which parts of the planned policy stay on the accelerated path.

Interfaces. Confirm the model offers enough ports at the right speeds, including high-speed uplinks and dedicated HA links.

Step 5: Validate Before You Buy

For large or complex deployments, a proof of concept with production-like traffic removes guesswork. Run the candidate model with the real security policy, real inspection settings, and representative traffic, and measure CPU, memory, session setup rate, and latency under peak load.

Plan the Deployment With the Right Partner

Sizing gets the hardware right. The design, policy build, and cutover determine whether it performs as planned.

IT Builders is an authorized Fortinet Engage Partner holding seven Partner Specializations, including Secure Networking: Firewall, along with the Engage Tech Support Partner and Engage Preferred Services Partner designations. Across more than 250 clients, our engineers size FortiGate deployments from measured traffic data, validate them before purchase, and carry them through design, implementation, and support.

Planning a firewall purchase or refresh?

Contact the IT Builders Enterprise Engineering Team
Fortinet Engage Partner Specialization — firewallFortinet Engage Partner Specialization — lanFortinet Engage Partner Specialization — sdwanFortinet Engage Partner Specialization — saseFortinet Engage Partner Specialization — secopsFortinet Engage Partner Specialization — cloudFortinet Engage Partner Specialization — ot
TALK TO A SPECIALIST

Turn this insight into a practical next step.

Discuss your environment with our team and get a clear recommendation grounded in your operational reality.

Start a conversation
CONTINUE READING

Related intelligence