A fortinet firewall is rarely bought in isolation. Most buyers are replacing an ageing edge appliance, standardising across multiple sites, or trying to close a security gap without blowing the quarter’s hardware budget. That changes how you should evaluate the range. Raw throughput matters, but so do licensing, port layout, VPN capacity, support terms and whether the box fits your actual traffic profile rather than a vendor datasheet.
For IT teams and procurement buyers, Fortinet remains a frequent shortlist brand because it covers a wide spread of use cases. Small office appliances, branch deployments, campus edge security and larger data centre roles are all represented in the portfolio. The practical question is not whether a FortiGate unit is capable. It is which model gives you the right balance of inspection performance, subscriptions, lifespan and purchase cost.
What a fortinet firewall is really buying you
At base level, you are buying a security appliance that combines firewall policy control with additional services such as intrusion prevention, application control, VPN, web filtering and anti-malware inspection. In many environments, that consolidation is the appeal. Instead of stacking separate products for routing, filtering and remote access, a single platform can handle several functions with centralised management.
That said, consolidation has trade-offs. Turning on more security services affects performance, and the headline figures on a spec sheet often look strongest with minimal features enabled. If your deployment requires deep inspection, SSL inspection, site-to-site VPN and heavy east-west traffic, you should size for the real workload, not the marketing number.
Fortinet’s own advantage in the market is that its appliances are widely deployed and familiar to administrators. That lowers operational friction when replacing like-for-like units, expanding an existing estate or adding branch hardware under a known management model. Businesses sourcing Fortinet solutions may also find our Fortinet Authorised Partner UK: What to Check guide useful when evaluating suppliers, product availability, support options, and procurement considerations. For buyers, that familiarity also helps with sourcing replacements, spare units and previous-generation models where value matters more than having the newest release.
Fortinet firewall models and where they fit
The most common buying mistake is choosing by price band alone. A cheaper appliance can become expensive quickly if it forces compromises on interfaces, sessions, VPN users or enabled security features.
Small office and entry-level deployments
For small businesses, retail branches and simple edge protection, entry-level FortiGate appliances are often enough. These models suit organisations with modest internet circuits, a limited number of VLANs and straightforward policy sets. They are usually selected for branch connectivity, secure internet breakout and basic remote access rather than heavy inspection at scale. Businesses looking for a proven branch security solution may also consider the Fortinet FortiGate 60F Firewall, which delivers advanced threat protection, secure VPN connectivity, and integrated SD-WAN capabilities for small office and branch environments.
Where buyers need to be careful is growth. If the site is likely to add guest wireless, cloud-managed VoIP, more cameras or always-on VPN tunnels, an entry model can reach its comfort limit sooner than expected. Buying one step up can be better value than replacing the unit a year later.
Mid-range appliances for growing networks
This is where many SMBs and managed service providers land. Mid-range models typically offer stronger threat inspection performance, more ports, better concurrent session handling and enough headroom for multi-site VPN. Organisations requiring additional performance and scalability may also consider the Fortinet FortiGate 100F Firewall, which delivers enhanced security inspection, higher throughput, and support for growing multi-site deployments. They fit schools, multi-floor offices, warehouse networks and mixed-use environments with a blend of users, servers, SaaS applications and remote access.
For this bracket, port density and interface type start to matter more. If you need multiple WAN links, DMZ segmentation, fibre uplinks or link aggregation to the switching stack, a low-end box may be too restrictive even if the throughput looks acceptable.
Higher-end and data centre roles
Larger Fortinet appliances target enterprises with heavier traffic loads, higher availability requirements and more complex security policies. These deployments often involve redundant power, HA pairs, larger VPN estates, advanced segmentation and greater inspection demand. Here the buying conversation shifts from simple sizing to architecture. You are not just choosing a firewall. You are choosing a platform that has to fit failover design, rack space, support expectations and future bandwidth growth.
How to size a fortinet firewall properly
The right starting point is not user count on its own. A fifty-user office with VoIP, CCTV backhaul, cloud applications, SSL inspection and IPsec tunnels may place more demand on a firewall than a larger site with lighter traffic and fewer controls enabled.
Start with internet bandwidth and expected growth. Then look at how much security inspection you actually intend to enable. IPS, antivirus, web filtering, application control and SSL inspection all consume resources. If those services are mandatory, the relevant performance figures are threat protection and SSL inspection throughput, not just firewall throughput.
VPN is another sizing factor that gets underestimated. Site-to-site tunnels, remote worker access and branch overlays all affect CPU and session handling. If secure connectivity is central to the design, review tunnel counts and concurrent user expectations carefully.
Session volume also matters in cloud-heavy environments. Modern users generate a high number of short-lived connections through browsers, SaaS tools, Teams-style collaboration platforms and endpoint security traffic. Even without huge bandwidth, that can stress undersized hardware.
Licensing, subscriptions and total cost
Hardware price is only part of the spend. With Fortinet, subscriptions and support can materially change total cost of ownership. Some buyers are only after core firewalling and VPN, while others need the full security stack with unified threat protection or more advanced bundles.
This is where procurement discipline matters. If the site only needs stable edge security with tightly managed traffic, paying for services that will never be enabled makes little sense. On the other hand, buying the appliance without the subscriptions your security policy requires is a false economy.
There is also a practical resale and replacement angle. Used or surplus Fortinet units can make good commercial sense for lab use, non-critical roles, temporary deployments or cost-sensitive branch refreshes, provided you verify hardware condition, support status, licensing implications and software compatibility. Buyers who know the exact model they need can often cut procurement costs sharply by sourcing previous-generation stock instead of defaulting to the latest release.
New versus used: where value shows up
Not every environment needs factory-sealed current-generation inventory. For replacement projects, test environments and compatible branch rollouts, used enterprise hardware can be the smarter buy. The key is knowing where compromise is acceptable.
If you are deploying into a high-risk production edge with strict support requirements, new stock with warranty coverage is usually the cleaner option. If you are extending an existing estate, holding a spare, replacing a failed branch unit or building a non-production lab, used hardware can reduce spend without hurting the outcome.
Green Code UK sits well with this type of buyer because the decision is often about availability and price as much as model preference. When a specific FortiGate SKU is needed quickly, stock depth and replacement options matter more than polished marketing copy.
Features worth checking before you buy
A Fortinet appliance can look right on paper and still be awkward in deployment. Interface mix is one example. Check whether the unit offers the copper and fibre combinations your site needs today, not after you add media converters and workarounds.
High availability is another. If uptime matters, confirm the chosen model suits your HA design and that you are budgeting for a pair rather than a single appliance. It sounds obvious, but many buyers begin with a resilience requirement and then price only one unit.
Management approach should also be considered early. If the firewall will sit inside a broader Fortinet estate, there may be operational advantages in standardising. If it will be a standalone box managed by a small internal team, ease of administration and policy clarity may matter more than advanced feature depth.
Finally, check rack form factor, power requirements, fan noise and branch suitability. Those details get ignored until installation day, when they become purchase problems.
When Fortinet is the right fit, and when it is not
Fortinet is a strong fit for organisations that want broad security functionality in one appliance, especially where there is already in-house familiarity with FortiGate management or a need to scale from branch to larger sites within one vendor family. It also suits buyers who value broad model availability and clear upgrade paths.
It may be a less tidy fit where the environment has very niche requirements, a strict multi-vendor standard or internal teams that prefer a different policy model. Pricing can also shift once subscriptions and support are added, so the cheapest box on day one is not always the cheapest platform over three to five years.
The smart buy is the one that matches your traffic, security policy, support expectation and budget at the same time. If you start there, choosing a fortinet firewall becomes less about brand reputation and more about getting the right hardware in the rack, at the right price, before a delay turns into downtime.
The best purchasing decisions in network security are usually the least dramatic – accurate sizing, clean compatibility and stock you can actually get when you need it.
FAQ
What is the best Fortinet firewall for a small business?
The best model depends on user count, internet bandwidth, VPN requirements, and security needs. The FortiGate 60F is a popular option for small business environments.
How do I choose the right Fortinet firewall?
Consider inspected throughput, VPN usage, interface requirements, security services, and expected business growth rather than relying solely on headline firewall throughput.
Are Fortinet firewalls suitable for multi-site businesses?
Yes. Many Fortinet models support site-to-site VPNs, SD-WAN functionality, and centralised management, making them suitable for distributed environments.
Should I buy a new or used Fortinet firewall?
New appliances provide longer support lifecycles and warranty coverage, while used hardware can be a cost-effective option for replacement, lab, or non-critical deployments.
What should I check before buying a Fortinet firewall?
Review throughput ratings, licensing requirements, support options, interface configuration, VPN capacity, and future scalability before making a purchase.













