Fortinet FortiGate 3500F Next-Generation Firewall
[shortdesc] Firewall, 2RU rack mount, 6x 100GE QSFP28, 32x 25GE SFP28, up to 595 Gbps firewall throughput, dual AC PSU [/shortdesc]
[properties]
| Model / SKU | FG-3500F |
| Form Factor | Rack Mount, 2 RU |
| Firewall Throughput | 595 / 590 / 420 Gbps (IPv4, 1518/512/64 byte, UDP) |
| Interfaces | 6x 100 GE QSFP28 / 40 GE QSFP+, 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP, 2x 10 GE / GE RJ45 Management |
| Power Input | 100-240V AC, 50/60 Hz |
| Dimensions (H x W x L) | 3.5 x 17.4 x 21.9 inches (89 x 443 x 556 mm) |
| Weight | 43.8 lbs (19.9 kg) |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) |
[/properties]
[specifications]
| System Performance | |
| IPS Throughput | 72 Gbps |
| NGFW Throughput | 65 Gbps |
| Threat Protection Throughput | 63 Gbps |
| IPv4 Firewall Throughput (1518/512/64 byte, UDP) | 595 / 590 / 420 Gbps |
| IPv6 Firewall Throughput (1518/512/86 byte, UDP) | 595 / 590 / 420 Gbps |
| Firewall Latency | 2.98 μs |
| Firewall Throughput (Packet per Second) | 630 Mpps |
| IPsec VPN Throughput (512 byte) | 165 Gbps |
| SSL-VPN Throughput | 16 Gbps |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 63 Gbps |
| Application Control Throughput (HTTP 64K) | 135 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| System Capacity | |
| Concurrent Sessions (TCP) | 140 Million / 348 Million* |
| New Sessions/Second (TCP) | 1 Million / 5 Million* |
| Firewall Policies | 200,000 |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 15 Million |
| SSL Inspection CPS (IPS, avg. HTTPS) | 60,000 |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4096 / 2048 |
| Maximum Number of FortiTokens | 20,000 |
| Interfaces and Modules | |
| 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 (Hardware Accelerated) |
| 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 32 (Hardware Accelerated) |
| 10 GE / GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1 / 1 |
| Console Port | 1 |
| Power and Environment | |
| Power Supply | Redundant Power Supplies (Hot Swappable), Default dual AC PSU |
| AC Current (Maximum) | 12A@120V, 9A@240V |
| Power Consumption (Average / Maximum) | 760 W / 1174 W |
| Heat Dissipation | 4006 BTU/h |
| Storage Temperature | -31°F to 158°F (-35°C to 70°C) |
| Humidity | 20% to 90% non-condensing |
| Noise Level | 53.5 dBA |
| Operating Altitude | Up to 10,000 ft (3048 m) |
| Forced Airflow | Front to Back |
| Dimensions and Weight | |
| Certifications and Compliance | |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | USGv6/IPv6 |
[/specifications]
[accesories]
| Included Transceivers | 2x SFP+ (SR 10 GE) |
| Optional Accessories | Rack Mount Sliding Rails (SP-FG3040B-RAIL), AC Power Supply (FG-7040E-PS-AC), Transceiver Modules (FN-TRAN / FG-TRAN series), Direct Attach Cables (FN-CABLE series) |
[/accesories]
The FortiGate 3500F Series enables organizations to build security-driven networks, forming the foundation of a robust Hybrid Mesh Firewall architecture. This high-performance next-generation firewall (NGFW) weaves security deep into datacenters and across hybrid IT environments, protecting any edge at any scale. Powered by Fortinet's patented SPU NP7 and CP9 processors, the FG-3500F delivers unparalleled performance with hardware acceleration for critical network functions, ensuring that security never becomes a bottleneck.
Designed for hyperscale environments, the FortiGate 3500F consolidates networking and security to deliver ultra-scalable secure networks. It features the industry's first integrated Zero Trust Network Access (ZTNA) enforcement within an NGFW solution, automatically controlling and verifying user access to applications. With rich AI/ML-based FortiGuard Services and an integrated security fabric platform, this appliance delivers coordinated, automated, end-to-end threat protection across all use cases, from the data center to the hybrid cloud.
High Performance with Flexibility and Hyperscale Security
- Unparalleled Performance: Delivers up to 595 / 590 / 420 Gbps IPv4 firewall throughput (1518/512/64 byte UDP) and 72 Gbps IPS throughput, powered by SPU NP7 and CP9 processors to accelerate security functions and reduce latency.
- Hyperscale Scalability: Supports 140 million / 348 million concurrent TCP sessions and 1 million / 5 million new sessions per second (requires Hyperscale Firewall License for boosted values) for high-volume traffic environments.
- Integrated ZTNA: Integrated Zero Trust Network Access enforcement to control and verify user access to applications, reducing lateral threats and supporting a seamless user experience.
- High-Speed Connectivity: Equipped with 6x 100 GE QSFP28 / 40 GE QSFP+ slots and 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP slots, plus 2x 10 GE / GE RJ45 management ports for flexible, high-density deployments.
- AI-Powered Security: AI/ML-powered security services help protect against ransomware, malware, zero-day threats, and sophisticated attacks, with coordinated protection across use cases.
- Energy Efficient: Energy-efficient SPU/ASIC design supports high inspection performance while reducing power consumption and improving total cost of ownership.
- Next Generation Firewall (NGFW): Secures enterprise networks with real-time SSL inspection (including TLS 1.3) and full visibility into users, devices, and applications.
- Data Center Segmentation: Adapts to any network topology with dynamic segmentation and ultra-scalable, low-latency VXLAN segmentation to bridge physical and virtual domains.
- Hyperscale Architectures: Consolidates networking and security with purpose-built SPUs to support massive connection counts and protect business-critical applications.
- Mobile Security (4G/5G): Provides SPU-accelerated CGNAT and IPv6 migration options, securing radio access networks and user plane traffic with high performance.
- Firewall Throughput: IPv4 (1518/512/64 byte UDP) 595 / 590 / 420 Gbps; IPv6 (1518/512/86 byte UDP) 595 / 590 / 420 Gbps
- IPS / NGFW / Threat Protection: IPS 72 Gbps; NGFW 65 Gbps; Threat Protection 63 Gbps
- Network Interfaces: 6x 100 GE QSFP28 / 40 GE QSFP+; 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP; 2x 10 GE / GE RJ45 management
- VPN Performance: IPsec VPN (512 byte) 165 Gbps; SSL-VPN 16 Gbps
- SSL Inspection: 63 Gbps throughput (IPS, avg. HTTPS); 60,000 CPS; 15 million concurrent sessions
- Session Capacity: 140 million / 348 million concurrent TCP sessions; 1 million / 5 million new sessions/sec (*requires Hyperscale Firewall License)
- Power and Form Factor: 2 RU rack mount; redundant hot-swappable dual AC PSU; power consumption 760 W average / 1174 W maximum
Upgrade Your Network Security
Secure your hyperscale environment with the FortiGate 3500F today.
Product Information
Product Information
Shipping & Returns
Shipping & Returns


Fortinet FortiGate 3500F Next-Generation Firewall
Fortinet FortiGate 3500F Next-Generation Firewall
[shortdesc] Firewall, 2RU rack mount, 6x 100GE QSFP28, 32x 25GE SFP28, up to 595 Gbps firewall throughput, dual AC PSU [/shortdesc]
[properties]
| Model / SKU | FG-3500F |
| Form Factor | Rack Mount, 2 RU |
| Firewall Throughput | 595 / 590 / 420 Gbps (IPv4, 1518/512/64 byte, UDP) |
| Interfaces | 6x 100 GE QSFP28 / 40 GE QSFP+, 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP, 2x 10 GE / GE RJ45 Management |
| Power Input | 100-240V AC, 50/60 Hz |
| Dimensions (H x W x L) | 3.5 x 17.4 x 21.9 inches (89 x 443 x 556 mm) |
| Weight | 43.8 lbs (19.9 kg) |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) |
[/properties]
[specifications]
| System Performance | |
| IPS Throughput | 72 Gbps |
| NGFW Throughput | 65 Gbps |
| Threat Protection Throughput | 63 Gbps |
| IPv4 Firewall Throughput (1518/512/64 byte, UDP) | 595 / 590 / 420 Gbps |
| IPv6 Firewall Throughput (1518/512/86 byte, UDP) | 595 / 590 / 420 Gbps |
| Firewall Latency | 2.98 μs |
| Firewall Throughput (Packet per Second) | 630 Mpps |
| IPsec VPN Throughput (512 byte) | 165 Gbps |
| SSL-VPN Throughput | 16 Gbps |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 63 Gbps |
| Application Control Throughput (HTTP 64K) | 135 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| System Capacity | |
| Concurrent Sessions (TCP) | 140 Million / 348 Million* |
| New Sessions/Second (TCP) | 1 Million / 5 Million* |
| Firewall Policies | 200,000 |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 15 Million |
| SSL Inspection CPS (IPS, avg. HTTPS) | 60,000 |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4096 / 2048 |
| Maximum Number of FortiTokens | 20,000 |
| Interfaces and Modules | |
| 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 (Hardware Accelerated) |
| 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 32 (Hardware Accelerated) |
| 10 GE / GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1 / 1 |
| Console Port | 1 |
| Power and Environment | |
| Power Supply | Redundant Power Supplies (Hot Swappable), Default dual AC PSU |
| AC Current (Maximum) | 12A@120V, 9A@240V |
| Power Consumption (Average / Maximum) | 760 W / 1174 W |
| Heat Dissipation | 4006 BTU/h |
| Storage Temperature | -31°F to 158°F (-35°C to 70°C) |
| Humidity | 20% to 90% non-condensing |
| Noise Level | 53.5 dBA |
| Operating Altitude | Up to 10,000 ft (3048 m) |
| Forced Airflow | Front to Back |
| Dimensions and Weight | |
| Certifications and Compliance | |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | USGv6/IPv6 |
[/specifications]
[accesories]
| Included Transceivers | 2x SFP+ (SR 10 GE) |
| Optional Accessories | Rack Mount Sliding Rails (SP-FG3040B-RAIL), AC Power Supply (FG-7040E-PS-AC), Transceiver Modules (FN-TRAN / FG-TRAN series), Direct Attach Cables (FN-CABLE series) |
[/accesories]
The FortiGate 3500F Series enables organizations to build security-driven networks, forming the foundation of a robust Hybrid Mesh Firewall architecture. This high-performance next-generation firewall (NGFW) weaves security deep into datacenters and across hybrid IT environments, protecting any edge at any scale. Powered by Fortinet's patented SPU NP7 and CP9 processors, the FG-3500F delivers unparalleled performance with hardware acceleration for critical network functions, ensuring that security never becomes a bottleneck.
Designed for hyperscale environments, the FortiGate 3500F consolidates networking and security to deliver ultra-scalable secure networks. It features the industry's first integrated Zero Trust Network Access (ZTNA) enforcement within an NGFW solution, automatically controlling and verifying user access to applications. With rich AI/ML-based FortiGuard Services and an integrated security fabric platform, this appliance delivers coordinated, automated, end-to-end threat protection across all use cases, from the data center to the hybrid cloud.
High Performance with Flexibility and Hyperscale Security
- Unparalleled Performance: Delivers up to 595 / 590 / 420 Gbps IPv4 firewall throughput (1518/512/64 byte UDP) and 72 Gbps IPS throughput, powered by SPU NP7 and CP9 processors to accelerate security functions and reduce latency.
- Hyperscale Scalability: Supports 140 million / 348 million concurrent TCP sessions and 1 million / 5 million new sessions per second (requires Hyperscale Firewall License for boosted values) for high-volume traffic environments.
- Integrated ZTNA: Integrated Zero Trust Network Access enforcement to control and verify user access to applications, reducing lateral threats and supporting a seamless user experience.
- High-Speed Connectivity: Equipped with 6x 100 GE QSFP28 / 40 GE QSFP+ slots and 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP slots, plus 2x 10 GE / GE RJ45 management ports for flexible, high-density deployments.
- AI-Powered Security: AI/ML-powered security services help protect against ransomware, malware, zero-day threats, and sophisticated attacks, with coordinated protection across use cases.
- Energy Efficient: Energy-efficient SPU/ASIC design supports high inspection performance while reducing power consumption and improving total cost of ownership.
- Next Generation Firewall (NGFW): Secures enterprise networks with real-time SSL inspection (including TLS 1.3) and full visibility into users, devices, and applications.
- Data Center Segmentation: Adapts to any network topology with dynamic segmentation and ultra-scalable, low-latency VXLAN segmentation to bridge physical and virtual domains.
- Hyperscale Architectures: Consolidates networking and security with purpose-built SPUs to support massive connection counts and protect business-critical applications.
- Mobile Security (4G/5G): Provides SPU-accelerated CGNAT and IPv6 migration options, securing radio access networks and user plane traffic with high performance.
- Firewall Throughput: IPv4 (1518/512/64 byte UDP) 595 / 590 / 420 Gbps; IPv6 (1518/512/86 byte UDP) 595 / 590 / 420 Gbps
- IPS / NGFW / Threat Protection: IPS 72 Gbps; NGFW 65 Gbps; Threat Protection 63 Gbps
- Network Interfaces: 6x 100 GE QSFP28 / 40 GE QSFP+; 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP; 2x 10 GE / GE RJ45 management
- VPN Performance: IPsec VPN (512 byte) 165 Gbps; SSL-VPN 16 Gbps
- SSL Inspection: 63 Gbps throughput (IPS, avg. HTTPS); 60,000 CPS; 15 million concurrent sessions
- Session Capacity: 140 million / 348 million concurrent TCP sessions; 1 million / 5 million new sessions/sec (*requires Hyperscale Firewall License)
- Power and Form Factor: 2 RU rack mount; redundant hot-swappable dual AC PSU; power consumption 760 W average / 1174 W maximum
Upgrade Your Network Security
Secure your hyperscale environment with the FortiGate 3500F today.
Product Information
Product Information
Shipping & Returns
Shipping & Returns
Description
[shortdesc] Firewall, 2RU rack mount, 6x 100GE QSFP28, 32x 25GE SFP28, up to 595 Gbps firewall throughput, dual AC PSU [/shortdesc]
[properties]
| Model / SKU | FG-3500F |
| Form Factor | Rack Mount, 2 RU |
| Firewall Throughput | 595 / 590 / 420 Gbps (IPv4, 1518/512/64 byte, UDP) |
| Interfaces | 6x 100 GE QSFP28 / 40 GE QSFP+, 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP, 2x 10 GE / GE RJ45 Management |
| Power Input | 100-240V AC, 50/60 Hz |
| Dimensions (H x W x L) | 3.5 x 17.4 x 21.9 inches (89 x 443 x 556 mm) |
| Weight | 43.8 lbs (19.9 kg) |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) |
[/properties]
[specifications]
| System Performance | |
| IPS Throughput | 72 Gbps |
| NGFW Throughput | 65 Gbps |
| Threat Protection Throughput | 63 Gbps |
| IPv4 Firewall Throughput (1518/512/64 byte, UDP) | 595 / 590 / 420 Gbps |
| IPv6 Firewall Throughput (1518/512/86 byte, UDP) | 595 / 590 / 420 Gbps |
| Firewall Latency | 2.98 μs |
| Firewall Throughput (Packet per Second) | 630 Mpps |
| IPsec VPN Throughput (512 byte) | 165 Gbps |
| SSL-VPN Throughput | 16 Gbps |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 63 Gbps |
| Application Control Throughput (HTTP 64K) | 135 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| System Capacity | |
| Concurrent Sessions (TCP) | 140 Million / 348 Million* |
| New Sessions/Second (TCP) | 1 Million / 5 Million* |
| Firewall Policies | 200,000 |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 15 Million |
| SSL Inspection CPS (IPS, avg. HTTPS) | 60,000 |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4096 / 2048 |
| Maximum Number of FortiTokens | 20,000 |
| Interfaces and Modules | |
| 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 (Hardware Accelerated) |
| 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 32 (Hardware Accelerated) |
| 10 GE / GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1 / 1 |
| Console Port | 1 |
| Power and Environment | |
| Power Supply | Redundant Power Supplies (Hot Swappable), Default dual AC PSU |
| AC Current (Maximum) | 12A@120V, 9A@240V |
| Power Consumption (Average / Maximum) | 760 W / 1174 W |
| Heat Dissipation | 4006 BTU/h |
| Storage Temperature | -31°F to 158°F (-35°C to 70°C) |
| Humidity | 20% to 90% non-condensing |
| Noise Level | 53.5 dBA |
| Operating Altitude | Up to 10,000 ft (3048 m) |
| Forced Airflow | Front to Back |
| Dimensions and Weight | |
| Certifications and Compliance | |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | USGv6/IPv6 |
[/specifications]
[accesories]
| Included Transceivers | 2x SFP+ (SR 10 GE) |
| Optional Accessories | Rack Mount Sliding Rails (SP-FG3040B-RAIL), AC Power Supply (FG-7040E-PS-AC), Transceiver Modules (FN-TRAN / FG-TRAN series), Direct Attach Cables (FN-CABLE series) |
[/accesories]
The FortiGate 3500F Series enables organizations to build security-driven networks, forming the foundation of a robust Hybrid Mesh Firewall architecture. This high-performance next-generation firewall (NGFW) weaves security deep into datacenters and across hybrid IT environments, protecting any edge at any scale. Powered by Fortinet's patented SPU NP7 and CP9 processors, the FG-3500F delivers unparalleled performance with hardware acceleration for critical network functions, ensuring that security never becomes a bottleneck.
Designed for hyperscale environments, the FortiGate 3500F consolidates networking and security to deliver ultra-scalable secure networks. It features the industry's first integrated Zero Trust Network Access (ZTNA) enforcement within an NGFW solution, automatically controlling and verifying user access to applications. With rich AI/ML-based FortiGuard Services and an integrated security fabric platform, this appliance delivers coordinated, automated, end-to-end threat protection across all use cases, from the data center to the hybrid cloud.
High Performance with Flexibility and Hyperscale Security
- Unparalleled Performance: Delivers up to 595 / 590 / 420 Gbps IPv4 firewall throughput (1518/512/64 byte UDP) and 72 Gbps IPS throughput, powered by SPU NP7 and CP9 processors to accelerate security functions and reduce latency.
- Hyperscale Scalability: Supports 140 million / 348 million concurrent TCP sessions and 1 million / 5 million new sessions per second (requires Hyperscale Firewall License for boosted values) for high-volume traffic environments.
- Integrated ZTNA: Integrated Zero Trust Network Access enforcement to control and verify user access to applications, reducing lateral threats and supporting a seamless user experience.
- High-Speed Connectivity: Equipped with 6x 100 GE QSFP28 / 40 GE QSFP+ slots and 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP slots, plus 2x 10 GE / GE RJ45 management ports for flexible, high-density deployments.
- AI-Powered Security: AI/ML-powered security services help protect against ransomware, malware, zero-day threats, and sophisticated attacks, with coordinated protection across use cases.
- Energy Efficient: Energy-efficient SPU/ASIC design supports high inspection performance while reducing power consumption and improving total cost of ownership.
- Next Generation Firewall (NGFW): Secures enterprise networks with real-time SSL inspection (including TLS 1.3) and full visibility into users, devices, and applications.
- Data Center Segmentation: Adapts to any network topology with dynamic segmentation and ultra-scalable, low-latency VXLAN segmentation to bridge physical and virtual domains.
- Hyperscale Architectures: Consolidates networking and security with purpose-built SPUs to support massive connection counts and protect business-critical applications.
- Mobile Security (4G/5G): Provides SPU-accelerated CGNAT and IPv6 migration options, securing radio access networks and user plane traffic with high performance.
- Firewall Throughput: IPv4 (1518/512/64 byte UDP) 595 / 590 / 420 Gbps; IPv6 (1518/512/86 byte UDP) 595 / 590 / 420 Gbps
- IPS / NGFW / Threat Protection: IPS 72 Gbps; NGFW 65 Gbps; Threat Protection 63 Gbps
- Network Interfaces: 6x 100 GE QSFP28 / 40 GE QSFP+; 32x 25 GE SFP28 / 10 GE SFP+ / GE SFP; 2x 10 GE / GE RJ45 management
- VPN Performance: IPsec VPN (512 byte) 165 Gbps; SSL-VPN 16 Gbps
- SSL Inspection: 63 Gbps throughput (IPS, avg. HTTPS); 60,000 CPS; 15 million concurrent sessions
- Session Capacity: 140 million / 348 million concurrent TCP sessions; 1 million / 5 million new sessions/sec (*requires Hyperscale Firewall License)
- Power and Form Factor: 2 RU rack mount; redundant hot-swappable dual AC PSU; power consumption 760 W average / 1174 W maximum
Upgrade Your Network Security
Secure your hyperscale environment with the FortiGate 3500F today.














