An undersized firewall fails loudly. An oversized one fails quietly, on the budget line, for five years.
Getting FortiGate sizing right means working from your real traffic and your real security requirements, then matching them to the datasheet figures that reflect those conditions. This guide walks through the method step by step.
Step 1: Collect the Right Inputs
Every sizing exercise starts with data. Pull as much as possible from existing firewalls, switches, and monitoring tools rather than estimating.
| Input | Where to Find It | Why It Matters |
|---|---|---|
| Peak throughput | Current firewall or WAN interface statistics, busiest hour | Sets the baseline traffic volume |
| Peak concurrent sessions | Current firewall session table at peak | Determines session capacity required |
| Peak new sessions per second | Firewall statistics or flow logs | Drives CPS requirements, especially with SSL inspection |
| Encrypted traffic share | Firewall application reports or proxy logs | Determines the SSL inspection load |
| Security features planned | Security policy requirements | IPS, antivirus, web filtering, and application control each reduce usable throughput |
| Inspection depth | Security policy requirements | Certificate inspection costs far less than full deep inspection |
| VPN requirements | Remote access and site-to-site plans | IPsec and SSL VPN each have separate capacity limits |
| SD-WAN role | Network design | Hub devices carry every branch tunnel and need matching capacity |
| Growth | Business plans for users, sites, and cloud adoption | The device must hold up for its full service life |
| High availability | Resilience requirements | An HA pair must handle full load on one unit during failover |
If no existing data is available, for example on a greenfield site, work from user counts and application profiles, and treat the result as provisional until real traffic confirms it.
Step 2: Read the Right Columns on the Datasheet
FortiGate datasheets list several throughput figures. They measure very different things.
Firewall throughput measures raw packet forwarding with no security inspection. It's the biggest number and the least useful for sizing a modern deployment.
IPS throughput and NGFW throughput measure performance with intrusion prevention, and with IPS plus application control, respectively.
Threat protection throughput measures performance with firewall, IPS, application control, and malware protection all enabled, using an enterprise traffic mix. For most deployments, this is the figure to size against.
SSL inspection throughput, CPS, and concurrent sessions measure performance with deep inspection of encrypted traffic. If you plan to decrypt a significant share of traffic, these figures often become the limiting factor.
Always read the test conditions in the datasheet footnotes. They specify the traffic mix, packet sizes, and TLS parameters behind each number.
Step 3: Calculate the Requirement
Work through each dimension separately, then size to whichever one is most demanding.
Throughput. Take peak throughput, apply your growth factor over the device's planned service life, and compare the result to threat protection throughput.
SSL inspection. Multiply the projected peak throughput by the share of traffic you'll deeply inspect. Compare the result to SSL inspection throughput. Do the same for new sessions per second against SSL inspection CPS.
Sessions. Take peak concurrent sessions, apply the growth factor, and compare to the relevant concurrent session figure.
Headroom. Don't plan to run the device at its datasheet maximum. Define a utilization ceiling up front that leaves room for traffic spikes, new features, and firmware changes, and size so peak load stays below it.
Worked example (hypothetical). A head office has 1,200 users today, expects 1,600 within four years, and records 900 Mbps peak throughput. Roughly 85% of traffic is encrypted, and the security policy requires deep inspection for all of it except exempted banking and healthcare categories, about 75% of total traffic.
- Projected peak throughput: 900 Mbps × (1,600 ÷ 1,200) = 1.2 Gbps
- Projected deep inspection load: 1.2 Gbps × 75% = 900 Mbps
- The candidate model must deliver at least 1.2 Gbps threat protection throughput and at least 900 Mbps SSL inspection throughput, both below the chosen utilization ceiling, plus matching CPS and session figures.
In this example, SSL inspection is likely to be the deciding constraint, not the headline throughput.
Step 4: Account for What the Numbers Don't Show
Some factors don't appear in a simple throughput calculation.
Logging. Heavy local logging and reporting consume resources. Sending logs to FortiAnalyzer offloads that work.
Proxy-based inspection. Proxy mode inspects more deeply than flow mode and costs more. If specific policies need it, factor that load in.
Hardware acceleration boundaries. Fortinet's NP and CP processors accelerate most traffic, but some features and traffic types run on the main CPU. A design review should confirm which parts of the planned policy stay on the accelerated path.
Interfaces. Confirm the model offers enough ports at the right speeds, including high-speed uplinks and dedicated HA links.
Step 5: Validate Before You Buy
For large or complex deployments, a proof of concept with production-like traffic removes guesswork. Run the candidate model with the real security policy, real inspection settings, and representative traffic, and measure CPU, memory, session setup rate, and latency under peak load.
Plan the Deployment With the Right Partner
Sizing gets the hardware right. The design, policy build, and cutover determine whether it performs as planned.
IT Builders is an authorized Fortinet Engage Partner holding seven Partner Specializations, including Secure Networking: Firewall, along with the Engage Tech Support Partner and Engage Preferred Services Partner designations. Across more than 250 clients, our engineers size FortiGate deployments from measured traffic data, validate them before purchase, and carry them through design, implementation, and support.
Planning a firewall purchase or refresh?
Contact the IT Builders Enterprise Engineering Team








