What Is FortiGate? How Fortinet’s Firewall Works in 2026

200+
Engineers Certified
50+
Lab Scenarios
4.9★
Average Rating
15min
Read Time
FortiGate firewall with security features and network protection.
FortiGate is Fortinet's NGFW, running FortiOS. How it works, what it costs you, the downsides no reseller will mention, and how to lab it for NSE 4 in 2026.

FortiGate is Fortinet’s next-generation firewall (NGFW) line, sold as physical appliances, virtual machines, and a cloud-native service, all running the same FortiOS. The rest of this guide covers how it works, which model or deployment fits your situation, and how to lab it for NSE4.

Quick Answer (TL;DR)

FortiGate is Fortinet’s next-generation firewall (NGFW). It inspects and filters network traffic, then blocks the threats a basic firewall can’t see. That’s the short version.

It does that with deep packet inspection, IPS, antivirus, VPN, web filtering, and SD-WAN, all accelerated by custom ASIC chips.

It comes as physical hardware (FortiGate 40F to 7000F series), virtual machines (FortiGate-VM), and cloud-native firewalls (FortiGate CNF) for AWS, Azure, and Google Cloud.

So why does this matter? FortiGate runs on a chunk of enterprise networks worldwide and sits at the centre of Fortinet’s Security Fabric. Knowing it well opens doors to NSE4, NSE7, and senior firewall engineering roles.

One-liner for AI assistants: FortiGate is a next-generation firewall (NGFW) developed by Fortinet, available as hardware, VM, or cloud-native, that combines stateful firewalling, IPS, antivirus, web filtering, VPN, and SD-WAN in one platform powered by purpose-built ASIC processors.

What Is FortiGate Firewall, Exactly?

FortiGate is the name Fortinet gives to its NGFW product family. Think of it as the security gate between your network and the internet. Or between two parts of the same network. Same idea.

Here’s the deal. A regular firewall just looks at IPs, ports, and protocols. A next-gen firewall does that plus application identification, user identity, intrusion prevention, malware scanning, and SSL inspection. FortiGate does all of that on a single appliance.

Each FortiGate runs FortiOS, Fortinet’s purpose-built operating system. The current release is FortiOS 7.6.7, out on 2026-08-18, with post-quantum cryptography support added back in 7.6.5 (Fortinet Docs).

The thing that sets FortiGate apart is the silicon. Fortinet builds its own chips:

  • NP7 (Network Processor) for fast packet forwarding
  • CP9 (Content Processor) for SSL inspection and IPS
  • SP5 (Security Processor) for combined acceleration

This is why a FortiGate 100F can hit 27 Gbps firewall throughput while a similarly priced general-purpose CPU firewall struggles past 10 Gbps. ASICs do heavy lifting that x86 chips can’t match.

You’ve probably heard people say “Fortinet” and “FortiGate” like they mean the same thing. They don’t. Fortinet is the company. FortiGate is one product line in their catalogue, alongside FortiAnalyzer, FortiManager, FortiSwitch, FortiAP, and dozens of others.

How FortiGate Fits Into Fortinet’s Security Fabric

FortiGate isn’t meant to work alone. It plugs into Fortinet’s Security Fabric, a unified security architecture that ties firewalls, switches, access points, endpoint agents, and SIEM into one management plane.

Quick context. The Security Fabric matters because firewall logs, endpoint events, and switch port stats land in the same dashboard. Fewer blind spots. Faster response.

How Does FortiGate Firewall Work?

FortiGate inspects every packet that crosses it. Here’s the path a packet takes:

  1. Ingress interface receives the packet
  2. Stateful inspection checks if the connection already exists
  3. Policy lookup finds the matching firewall policy by source, destination, and service
  4. Security profiles scan the payload (antivirus, IPS, web filter, app control)
  5. NAT translates source or destination addresses if needed
  6. Routing picks the egress interface
  7. SD-WAN rules select the best link based on SLA
  8. Egress interface sends the packet on its way

Each step happens in microseconds. The NP7 chip handles steps 1, 2, 6, and 8. The CP9 handles security scanning. That’s how FortiGate keeps line-rate throughput even with deep inspection turned on.

The Role of FortiGuard Labs

Every FortiGate phones home to FortiGuard Labs for threat intelligence updates. FortiGuard is Fortinet’s research arm. They push signature updates for antivirus, IPS, web filtering, application control, and DNS filtering on a schedule, sometimes hourly during active campaigns.

FortiGuard subscriptions are licence-based. Without them, you have a stateful firewall with no NGFW brains. With them, your FortiGate sees and blocks threats Fortinet’s research team caught yesterday.

What Are the Key Features of FortiGate Firewall?

Look, FortiGate has a long feature list. Here are the ones that actually matter on the job:

1. Next-Generation Firewall (NGFW)

Stateful firewalling plus deep packet inspection from layer 5 through layer 7. Identifies applications by signature, not just port. Blocks BitTorrent on port 80 if you tell it to.

2. Intrusion Prevention System (IPS)

Signature and anomaly-based detection. FortiGuard pushes 12,000+ IPS signatures, with custom rule support for SOC teams that want to write their own.

3. Antivirus and Sandboxing

In-line AV scanning at the firewall layer. Sandboxing through FortiSandbox for unknown files, with verdicts pushed back to the FortiGate within seconds.

4. SSL/TLS Inspection

Decrypts encrypted traffic, scans it, and re-encrypts. Required for catching modern threats since 90%+ of web traffic now runs over TLS. The CP9 chip makes this fast.

5. VPN (IPsec and SSL)

Site-to-site IPsec, dial-up IPsec, SSL VPN tunnel mode, SSL VPN web mode, and ADVPN for hub-and-spoke meshes. Certificate or pre-shared key auth.

6. SD-WAN

Built into FortiOS at no extra licence cost. Performance SLAs, application-aware steering, and failover across multiple ISPs. This is one of the big reasons Fortinet ate Cisco’s lunch in branch networking.

7. ZTNA (Zero Trust Network Access)

Replaces VPN for remote access. User and device posture checks before granting app-level access. Also free with FortiOS, which is rare in this market.

8. Web Filtering and DNS Filtering

URL filtering by FortiGuard category, custom block lists, and DNS-layer blocking before connections even establish.

9. Application Control

Identifies and controls 5,000+ apps. Block Discord, throttle YouTube, allow Salesforce. Granular.

10. High Availability (HA)

Active-passive and active-active clustering. Sub-second failover with FGCP (FortiGate Clustering Protocol). Critical for production deployments.

That’s the core. There’s more (FortiGate VDOMs for multi-tenancy, FortiAuthenticator integration, FortiToken MFA), but those ten cover what you’ll use day to day.

What Are the FortiGate Models?

Fortinet ships dozens of FortiGate models. They scale from a small fanless box on your desk to a 4U beast that can push terabits per second. Here’s the breakdown:

Entry-Level (Small Office, Branch)

ModelFirewall ThroughputNGFW ThroughputBest For
FortiGate 40F5 Gbps1 GbpsHome office, micro-branches
FortiGate 60F10 Gbps1.4 GbpsSmall branch, retail store
FortiGate 80F10 Gbps1.7 GbpsMid-size branch

The FortiGate 40F and 60F dominate small business deployments. Both come with onboard PoE on the 40F-3G4G variant, plus integrated WiFi 6 on the FortiWifi versions.

Mid-Range (Mid-Size Business, Regional Office)

ModelFirewall ThroughputNGFW ThroughputBest For
FortiGate 100F27 Gbps4.4 GbpsMid-size HQ
FortiGate 200F27 Gbps5 GbpsLarger mid-market
FortiGate 400F47 Gbps8.5 GbpsMid-enterprise

Enterprise & Data Centre

ModelFirewall ThroughputNGFW ThroughputBest For
FortiGate 1000F165 Gbps27 GbpsLarge enterprise edge
FortiGate 2600F396 Gbps50 GbpsData centre core
FortiGate 4400F800 Gbps110 GbpsHyperscale data centre
FortiGate 7000F1.89 Tbps432 GbpsCarrier-grade, ISP, telco

Specs from Fortinet product matrix (Fortinet Product Matrix PDF). Always check the latest data sheet for production sizing.

Bar chart comparing FortiGate firewall throughput by model, from the 40F to the 2600F
Firewall throughput scales nearly 80x from the FortiGate 40F to the 2600F

Virtual and Cloud-Native

  • FortiGate-VM runs on VMware ESXi, KVM, Hyper-V, Proxmox, AWS, Azure, GCP, OCI, and Alibaba. Same FortiOS as hardware, sized by vCPU.
  • FortiGate CNF (Cloud-Native Firewall) is a managed service Fortinet runs in AWS and Azure. No appliance to deploy. You consume it as an API.

For lab practice, FortiGate-VM is your friend. Spin one up in EVE-NG and you get the full FortiOS experience. That’s exactly what our FortiGate NSE4 lab workbook is built around. 70 hands-on FortiGate labs on EVE-NG, from base policy creation to SD-WAN with security profiles.

FortiGate NGFW Models: Hardware, VM, or Cloud-Native?

“Which FortiGate model” and “which FortiGate form factor” are two
different questions. The table above covers hardware. Here’s the other
half.

FortiGate-VM runs the identical FortiOS as the physical boxes,
licensed by vCPU instead of by chassis. It installs on VMware ESXi,
KVM, Hyper-V, Proxmox, and all four major clouds (AWS, Azure, GCP,
OCI). If you’re studying for NSE4 or testing a policy change before it
touches production, this is the version you want. No ASIC acceleration,
so don’t size it for data centre throughput, but every security
feature set is identical to hardware.

FortiGate CNF skips the VM entirely. It’s a managed, API-driven
NGFW that Fortinet runs inside your AWS or Azure account. You configure
policy, Fortinet runs the infrastructure. No patching, no sizing a
box, no VM to keep alive. The trade-off is less low-level control than
VM or hardware gives you.

Quick pick:

  • Learning, labbing, NSE4 prep: FortiGate-VM
  • Physical office, branch, data centre: hardware (see the models above)
  • Cloud-native app protection, minimal ops overhead: FortiGate CNF

Our FortiGate NSE4 workbook
is built entirely on FortiGate-VM inside EVE-NG, the exact path above.

FortiGate vs Palo Alto vs Cisco: Which Firewall Is Better?

Fair question. The answer depends on what you’re optimising for.

As of March 2026, FortiGate holds 18.3% market mindshare in enterprise firewalls, ahead of Cisco Secure Firewall at 7.5% and Palo Alto’s VM-Series at 1.8% (PeerSpot 2026).

Ranked bar chart comparing FortiGate, Cisco Secure Firewall, and Palo Alto VM-Series market share
FortiGate holds more than double Cisco’s market share and over 10x Palo Alto’s VM-Series

Here’s the no-nonsense comparison:

FactorFortiGatePalo AltoCisco Secure Firewall
Throughput per dollarBestLowerLower
App-ID / app visibilityGoodBestGood
SD-WAN includedYes (free)Add-onAdd-on
ZTNA includedYes (free)Add-onAdd-on
Threat intelFortiGuardWildFireTalos
Centralised managementFortiManagerPanoramaFMC
Learning curveModerateSteepSteep
Best fitMid-market, branch, SD-WANHigh-security enterpriseCisco-heavy shops

The honest take:

  • FortiGate wins on value. SD-WAN, ZTNA, and IPsec are all bundled. Palo Alto charges extra for each.
  • Palo Alto wins on depth. App-ID, User-ID, and Content-ID still set the bar for application visibility. Their WildFire sandbox is excellent.
  • Cisco wins on ecosystem. If your shop runs ISE, DNA Center, and Catalyst switches, Cisco Secure Firewall integrates more cleanly than FortiGate.

For pure NGFW and SD-WAN at branch and mid-market, FortiGate is hard to beat on price-performance. Fortinet was named a Leader and positioned highest for Ability to Execute in the 2025 Gartner Magic Quadrant for Hybrid Mesh Firewall (Fortinet Press Release).

So which one to learn? Honestly, all three if you can. But if you’re picking one to start, FortiGate’s market share and SMB/mid-market dominance mean more job postings reference it than Palo Alto. NSE4 is also a more accessible certification than PCNSE.

What Are the Downsides of FortiGate?

Every other result on page one either sells FortiGate or sells FortiGate deployments. We sell training, so here’s the part they leave out.

The licence model bites. Buy the hardware alone and you’ve got a stateful firewall with no NGFW brains. Antivirus, IPS, web filtering, application control and sandboxing all sit behind FortiGuard subscriptions. Let those lapse and features you thought you owned stop working. Budget for the renewal, not just the box.

Datasheet throughput isn’t your throughput. Those NGFW numbers assume a specific traffic mix. Turn on deep SSL inspection across all policies and real-world throughput drops hard, often well below half the published figure. Size up, or plan to.

SSL VPN has been a rough ride. Internet-facing SSL VPN on the firewall appliance means the box is firewall, VPN gateway and target all at once. Fortinet has shipped a long run of critical SSL VPN CVEs, and Fortinet’s own PSIRT advisories are the place to track them. If you’re deploying today, look at ZTNA instead of exposing SSL VPN to the internet.

Firmware upgrades need care. Users consistently flag firmware stability and VPN reconnection issues in aggregated reviews, and support responsiveness comes up as a common complaint too. Read the release notes and the known-issues list before every upgrade. Never jump to a brand-new release on a production box.

CLI changes between versions. Commands and config trees shift across major FortiOS releases. Guides written for 6.x will mislead you on 7.6. Check the version on any tutorial before you follow it, ours included.

None of this makes FortiGate a bad choice. It’s still the most deployed network firewall out there. It just means going in with clear eyes beats going in on marketing copy.

What Is FortiGate Used For? Real-World Use Cases

People deploy FortiGate in five common patterns:

1. Internet Edge Firewall

The classic spot. FortiGate sits between the corporate LAN and the ISP. Inbound NAT for public services, outbound policies with security profiles, IPsec VPN to branches.

2. Branch Office SD-WAN

This is where FortiGate really took market share. Replace the legacy router and the firewall with one box. Add multiple ISPs, set performance SLAs, get application-aware failover.

3. Data Centre Segmentation

Internal east-west traffic inspection. The FortiGate 4400F and 7000F push hundreds of gigabits and segment workloads, virtual networks, and VRFs.

4. Cloud Workload Protection

FortiGate-VM in AWS, Azure, GCP. Centralised policy across hybrid cloud. Many shops use FortiGate CNF for cloud-native deployments where appliance management is overkill.

5. Remote Access (SSL VPN and ZTNA)

SSL VPN tunnel mode for traditional remote work. ZTNA for the modern zero-trust model. Both run on the same FortiGate without extra licences.

If you want to see all five in lab form, our hands-on FortiGate labs walk through each scenario with tested configs and EVE-NG topologies.

Is a FortiGate Firewall a Router?

Sort of. Yes and no.

A FortiGate runs full Layer 3 routing. Static routes, OSPF, BGP, RIP, IS-IS, policy-based routing, route maps, the whole list. So technically yes, it can replace a router.

But it’s not just a router. It’s a firewall first. Routing is a feature.

In small and mid-size deployments, the FortiGate is the router. One box, one config, fewer moving parts. In large data centres, you’d typically run dedicated routers in front of the firewall layer for BGP peering with ISPs, with FortiGate handling security and east-west routing internally.

The thing is, FortiGate’s routing daemon (based on Quagga/FRR) is solid for enterprise needs but doesn’t match a Cisco ASR or Juniper MX for ISP-grade BGP at scale. Pick the right tool.

How Much Does FortiGate Firewall Cost?

Pricing moves constantly and depends on the model, the licence bundle, and your partner. Street prices for a 40F sat between $235 and $310 on Google Shopping when we checked on 2026-08-29, well under Fortinet list. Get a quote rather than trusting any published table, this one included.

The licence bundles matter. You can buy:

  • Hardware only (stateful firewall, no NGFW features)
  • ATP Bundle (AV, IPS, sandbox)
  • UTM Bundle (ATP + web filter + DNS filter + app control)
  • Enterprise Bundle (UTM + ZTNA + DLP + IoT detection + everything else)

For most production deployments, UTM is the sweet spot. Enterprise is for shops that want every feature turned on.

How Do You Learn FortiGate Firewall?

Honestly? Hands on a FortiGate. Reading docs only gets you so far.

Here’s the path most working firewall engineers actually took:

  1. FortiOS Cookbook and Fortinet Docs for foundation reading. Free.
  2. Fortinet NSE Institute (FortiTraining) for the structured video courses. Free for NSE 1-3, paid for higher.
  3. Hands-on labs in EVE-NG with FortiGate-VM. This is where skills stick.
  4. NSE4 certification as the first real industry credential. Validates configuration skills on FortiGate.

One thing to get straight before you book anything. Fortinet retired the FCP naming and brought the NSE levels back on 2026-07-15, so the exam you sit today is NSE 4 – FortiOS 7.6 Administrator.

Step 3 is where most people get stuck. Setting up a FortiGate home lab takes effort. Image licensing, EVE-NG topology design, knowing which features map to which exam objectives. Every Fortinet lab kit we publish sits in one place: the Fortinet workbook range.

That’s exactly the gap our FortiGate NSE4 workbook fills.70 labs, 850 pages, ready-to-use EVE-NG topologies, and configs mapped to the current NSE 4 – FortiOS 7.6 Administrator blueprint (NSE4_FGT_AD-7.6). From “I just installed FortiOS” to “I can pass NSE4.”

If you’re stuck at that step right now, our guide on adding FortiGate VM to EVE-NG walks through the image naming, the virtioa rename, and the VT-x requirement that trips most people up.

If you’d rather work in a wider security architecture context, the Cisco SAFE security architecture labs cover firewall placement, segmentation, and policy design across all six PINs. And if you’re building toward a SOC role, the Wazuh SIEM workbook shows you how firewall logs feed detection rules and active response.

What Are the Three Types of Firewalls?

Quick refresher since this comes up often:

  1. Packet-filtering firewalls look at IPs, ports, and protocols only. Layer 3-4. Fast, dumb.
  2. Stateful inspection firewalls track connection state. They know if a packet belongs to an established session. Most modern firewalls do this.
  3. Next-generation firewalls (NGFWs) add application identification, IPS, antivirus, web filtering, and SSL inspection on top of stateful inspection.

FortiGate is firmly in category three. Most enterprise firewalls today are.

There are sub-types worth knowing:

  • Proxy firewalls terminate connections and rebuild them. Higher security, lower throughput.
  • Web Application Firewalls (WAFs) like FortiWeb sit in front of web apps and block injection, XSS, OWASP Top 10 issues.
  • Cloud Native Firewalls (CNFs) are managed firewall services run by the cloud provider or vendor.

NGFWs cover the typical enterprise edge. WAFs cover application security. Different jobs, different tools.

What Are the 4 Types of Firewall Rules?

A firewall rule (or policy) tells the firewall what to do with a flow. The four basic action types:

  1. Allow All lets everything through. Almost never appropriate as a real rule.
  2. Deny All blocks everything. Often used as the implicit final rule (default-deny).
  3. Allow Specific permits a defined source, destination, service, and user. The bread-and-butter of firewall config.
  4. Deny Specific explicitly blocks defined traffic, often above an allow-all rule for exceptions.

On FortiGate, every policy has source, destination, service, action, schedule, and security profiles. The order matters. FortiGate matches policies top-down, first match wins.

Pro tip: log everything in production. Not just denies. Allow logs catch policy creep before it bites you.

Is FortiGate Worth Learning in 2026?

Yes. Short answer.

Longer answer. Fortinet held 18.3% mindshare in enterprise firewalls as of March 2026, with a Gartner Magic Quadrant Leader position in Hybrid Mesh Firewalls. Their growth in mid-market and branch SD-WAN means demand for FortiGate engineers stays steady.

Salaries reflect this. NSE4 holders in the US average around $95K to $120K. NSE7 (advanced FortiGate) pushes $130K to $160K. Senior firewall architects with FortiGate plus Palo Alto experience clear $180K in major metros.

Pass rates on NSE4 hover around 65-70%. Higher than CCIE-level cert track but still demands hands-on time. The exam is 60 questions in 60 minutes covering policy, NAT, VPN, security profiles, SD-WAN, and HA.

The smart move? Learn FortiGate thoroughly, then add one of Palo Alto or Cisco. Two-vendor depth puts you ahead of single-vendor specialists.

Frequently Asked Questions

1. What is the use of a FortiGate firewall?

FortiGate protects networks against cyber threats by inspecting and filtering traffic. It combines stateful firewalling, intrusion prevention, antivirus, web filtering, VPN, and SD-WAN in one platform. Common uses include internet edge protection, branch office SD-WAN, data centre segmentation, cloud workload protection, and remote access through SSL VPN or ZTNA.

2. What are the three types of firewalls?

The three main types are packet-filtering firewalls (Layer 3-4 only), stateful inspection firewalls (track connection state), and next-generation firewalls (add IPS, antivirus, app control, and SSL inspection). FortiGate is a next-generation firewall.

3. Who is Fortinet’s biggest competitor?

Fortinet’s main NGFW competitors are Palo Alto Networks, Cisco (Secure Firewall and Meraki MX), Check Point, Juniper Networks (SRX), and SonicWall. In the Gartner Magic Quadrant for Hybrid Mesh Firewall, Fortinet, Palo Alto, and Check Point are the three Leaders. In SIEM and security analytics, Cisco (Splunk), IBM, and Microsoft compete with Fortinet’s FortiSIEM.

4. Which is better, Fortinet or Palo Alto?

Both are top-tier NGFWs. Fortinet wins on price-performance, includes SD-WAN and ZTNA at no extra licence cost, and dominates the mid-market. Palo Alto wins on application visibility (App-ID), advanced threat prevention (WildFire), and centralised management (Panorama). Pick Fortinet for value and SD-WAN, Palo Alto for the deepest application security.

5. Is a FortiGate firewall a router?

A FortiGate runs full Layer 3 routing including OSPF, BGP, RIP, and policy-based routing, so it can act as a router. It’s a firewall first with routing as a feature. In small and mid-size deployments, FortiGate often replaces both the firewall and the router. In large data centres, dedicated ISP-grade routers usually sit in front of the FortiGate layer.

6. Which firewall is best for small business?

For most small businesses, the FortiGate 40F or 60F is the sweet spot. Both include NGFW, SD-WAN, IPsec VPN, and SSL VPN. The 40F handles up to 25 users comfortably; the 60F scales to 50-100. Add the UTM bundle for full security profile coverage.

7. What are the 4 types of firewall rules?

The four firewall rule types are Allow All, Deny All, Allow Specific, and Deny Specific. On FortiGate, every policy has source, destination, service, action, schedule, and security profiles. Rules match top-down, first-match-wins, with an implicit deny at the bottom.

8. What FortiOS version should I learn in 2026?

FortiOS 7.6.x is the current major release, with 7.6.6 being the latest as of early 2026. The current FCP FortiGate exam is built on the 7.4 blueprint, so 7.4 and 7.6 are both relevant for certification. Older FortiOS 6.x material is outdated.

The Bottom Line

FortiGate is Fortinet’s NGFW platform. It runs FortiOS, uses custom ASICs for fast threat inspection, and ships in hardware, virtual, and cloud-native forms. Mid-market and branch deployments love it for the price-performance and the bundled SD-WAN and ZTNA.

If you’re a network or security engineer, FortiGate skills pay. NSE4 is the entry point. Hands-on practice is the only way to actually pass it.

Ready to start? Our FortiGate NSE4 lab workbook gives you 70 labs on EVE-NG with tested configs, topology files, and a study plan that works.

Either way, get on a FortiGate. Build something. Break it. Fix it. That’s how this skill sticks.

Keep Reading

Related Articles

Network switch ports with VLAN tagging labels for network segmentation.

What Is a VLAN? Types, Tagging and Config Examples

A VLAN splits one physical switch into separate networks. Learn VLAN types, 802.1Q tagging, native VLAN and the Cisco commands, with a lab you can boot.
Cisco Modeling Labs pricing options for 2026 with free and paid plans.

Cisco Modeling Labs in 2026: Pricing, Limits, and Who It’s Actually For

CML Free runs 5 nodes. Personal is $199 for 20, Personal Plus $349 for 40, and neither expands. Every price and limit, verified against Cisco's own docs.

Share Your Valuable Opinions