A firewall that appears affordable at purchase can become expensive very quickly if it cannot inspect encrypted traffic, sustain VPN demand, or support a second internet service without slowing critical applications. This FortiGate sizing guide focuses on the figures that matter in a production environment, so your organisation can select protection that performs properly on day one and remains commercially sensible as demand grows.
The right FortiGate is not determined by headcount alone. A 50-person business with cloud backups, Microsoft 365, video conferencing, remote access and SSL inspection can require more capacity than a 150-user site with modest internet use. Good sizing starts with how your network actually operates, then applies enough performance headroom to protect availability without paying for capacity you will not use.
Start with the security services you will enable
FortiGate appliances publish several throughput figures. They are all useful, but they do not describe the same workload. Firewall throughput is typically the largest number because it measures straightforward packet handling. It should not be the primary sizing figure for an organisation planning to use next-generation security controls.
For most business deployments, assess threat protection throughput first. This is a more realistic indicator of performance when intrusion prevention, application control, antivirus and firewall policies are operating together. If you will decrypt and inspect HTTPS traffic, consider SSL inspection throughput as a separate and critical measure. Much of modern business traffic is encrypted, and bypassing inspection simply to preserve performance creates a security gap that should be consciously managed, not accidentally accepted.
Also confirm the subscriptions and protections required by your risk profile. A FortiGate can be configured as a capable firewall without every inspection service enabled, but sizing solely around a minimal policy set often leaves little room to improve your security posture later. For organisations handling sensitive customer information, payment environments, regulated workloads or distributed operations, it is usually wiser to size for the controls you intend to standardise.
FortiGate sizing guide: measure real traffic demand
Begin with your internet connections. Add the usable bandwidth for primary and secondary services, then consider whether both links may carry traffic during normal operation through SD-WAN. A site with two 1 Gbps services may need a firewall capable of inspecting close to 2 Gbps if it uses both links actively. Sizing only for the primary circuit can restrict performance precisely when you add the resilience you paid for.
Next, map the traffic that crosses the firewall. Internet-bound traffic is obvious, but internal segmentation can create substantial demand too. A FortiGate protecting separate user, server, guest, voice, OT and management networks may inspect east-west traffic as well as traffic leaving the site. This is often the right security design, particularly where compliance or business continuity requirements call for stronger separation, but it must be included in capacity planning.
Traffic patterns matter as much as link speed. Scheduled cloud backups, software updates, large file transfers, Teams or Zoom meetings, and synchronisation with SaaS platforms can all create peaks. Review utilisation from existing routers, switches or firewalls over at least several weeks where possible. Average bandwidth is useful, but peak demand and the duration of those peaks are more useful when selecting a security appliance.
A practical rule is to avoid designing for 100 per cent of the published inspected-throughput figure. Performance data is generated under defined test conditions. Your policy set, packet sizes, encrypted traffic mix, logging, IPS signatures and concurrent activity will differ. Allowing meaningful headroom supports stable performance during bursts, security updates and growth.
Count users, devices and sessions properly
User numbers are a starting point, not a result. A modern employee may use a laptop, mobile, tablet and voice device, while meeting room equipment, printers, cameras, access points and IoT devices add sessions without adding staff. Each device creates DNS requests, cloud connections, updates and background traffic.
Concurrent sessions are therefore an important FortiGate capacity measure. High session counts can arise in organisations using cloud applications, browser-based platforms, large guest networks or device-dense sites. New sessions per second also matter in environments with frequent connections, such as schools, hospitality venues, retail sites and busy branch offices.
Do not overlook branch connectivity. IPsec VPN throughput and tunnel capacity need to accommodate site-to-site links, cloud connections and remote-access users together. If a head office FortiGate acts as the hub for multiple branches, its VPN workload can be materially higher than its local user count suggests. Remote users can also generate demanding traffic when they access file services, use voice and video, or route all internet traffic through the corporate security stack.
Design for interfaces and physical architecture
Performance alone does not guarantee a suitable appliance. The port mix must match the network you are building. Confirm the number and type of copper, fibre, 1 GbE, 2.5 GbE, 10 GbE or higher-speed interfaces required for WAN services, core switching, DMZs and dedicated management connections.
A smaller FortiGate may provide enough inspection capacity for a site but lack the interfaces needed to separate services cleanly. Conversely, buying a larger model for port density alone can be poor value if a suitable switch design would achieve the same result. The right answer depends on whether the firewall is serving a compact branch, a campus edge, a data centre boundary or an SD-WAN hub.
High availability also changes the design. In an active-passive pair, both appliances must be able to carry the full expected load when one unit is unavailable. You do not size each member for half the traffic. Factor in compatible switching, redundant power where appropriate, link design and the operational process for failover testing. Resilience is an architecture outcome, not simply a second appliance in a rack.
Match the appliance to the site role
A small office with a modest broadband or fibre service, limited remote access and straightforward security policies may suit an entry-level desktop FortiGate. These models can deliver enterprise-grade controls at a cost appropriate for smaller teams, especially when the site does not need high-speed fibre interfaces or extensive segmentation.
A growing business or busy branch generally benefits from a mid-range appliance with more inspected throughput, stronger VPN capacity and greater interface flexibility. This is often the sensible range for organisations running dual WAN, SD-WAN, cloud applications, guest access and several network segments while expecting continued growth.
For headquarters, multi-site hubs, large campuses and data centre environments, sizing needs to account for aggregated branch traffic, high concurrent sessions, greater inspection depth and high-speed interfaces. Enterprise models can be justified when the firewall is a central security control rather than a single-site internet gateway. The aim is not to buy the biggest model available. It is to prevent the central point of protection from becoming the central point of constraint.
Avoid the common sizing shortcuts
The most frequent mistake is selecting by firewall throughput. That number looks compelling but can create a false sense of capacity once IPS, antivirus, application control and decryption are enabled. The second is sizing against current bandwidth only, with no allowance for internet upgrades, additional sites or growing cloud reliance.
Another shortcut is assuming every traffic type needs the same inspection treatment. Some organisations should decrypt most outbound web traffic. Others must exclude particular applications, privacy-sensitive categories or certificate-pinned services. A sound design documents these decisions and assesses the resulting performance impact rather than applying a generic policy everywhere.
Finally, do not treat subscriptions as an afterthought. FortiGuard security services, support coverage and hardware lifecycle planning should be evaluated as part of the total solution cost. An appliance that fits the initial hardware budget but lacks the right protection bundle or support model is not a best-value outcome.
Build a sizing brief before requesting a quote
A concise technical brief produces a more accurate recommendation and reduces rework. Include your internet speeds, expected growth, number of users and devices, remote users, branches, planned VPN tunnels, required interfaces, current and future segmentation, and whether SSL inspection will be enabled. Add any compliance requirements, critical applications and availability expectations.
This information lets a certified specialist distinguish between a cost-effective branch firewall and a model that needs additional capacity for high inspection loads, high-speed services or centralised SD-WAN. It also supports a cleaner comparison between hardware, FortiGuard bundles, support options and deployment services.
FortiSecure Store can help translate operational requirements into a properly scoped Fortinet solution, with genuine hardware and certified Australian guidance rather than a part-number-only recommendation. That matters when the appliance will protect revenue-critical applications, remote staff and customer data.
Choose the FortiGate that supports the security controls your business needs under peak conditions, not just the bandwidth figure that looks best on a specification sheet. A measured sizing exercise protects performance, avoids premature replacement and gives your network room to grow with confidence.

