Description
FortiGate 3300E Series — High-Performance Data Centre NGFW with NP6 and CP9 ASICs
The FortiGate 3300E series is a 2RU data centre NGFW delivering 27 Gbps IPS and 17 Gbps threat protection throughput — powered by Fortinet's NP6 and CP9 ASICs with 40GE QSFP+ and 25GE SFP28 connectivity, offering greater session capacity and policy scale than the 2200E for large enterprise and service provider core deployments.
Key Performance
- 27 Gbps IPS throughput
- 23 Gbps NGFW throughput
- 17 Gbps Threat Protection throughput
- 160 Gbps firewall throughput (1518 byte)
- 98 Gbps IPsec VPN throughput
- 21 Gbps SSL inspection throughput
- 10 Gbps SSL-VPN throughput
- 50 million concurrent sessions
- 700,000 new sessions per second
- 3.17 Ç?¶æs firewall latency
- 200,000 firewall policies
Interfaces & Hardware
- 4x 40GE QSFP+ slots
- 14x 25GE SFP28/10GE SFP+/GE SFP slots
- 2x 25GE SFP28/10GE SFP+/GE SFP HA slots
- 4x 10GE RJ45 ports
- 12x GE RJ45 ports
- 2x GE RJ45 Management ports
- 1x USB, 1x Console port
- Dual hot-swappable redundant AC PSUs
- 2x SFP+ SR 10GE transceivers included
- 2RU rack mount form factor
FortiGate 3301E Additions
- 2x 1TB onboard SSD (2TB total)
- All other specs identical to 3300E
Capacity
- Up to 300 FortiSwitches
- Up to 4,096 FortiAPs (2,048 tunnel mode)
- Up to 20,000 FortiTokens
- Up to 500 virtual domains (VDOMs)
- 40,000 gateway-to-gateway IPsec VPN tunnels
- 200,000 client-to-gateway IPsec VPN tunnels
- 30,000 concurrent SSL-VPN users
Security Features
- FortiGuard AI-powered IPS with 18,000+ signatures and virtual patching
- Anti-malware: AV, sandboxing, AI-based heuristics, Content Disarm and Reconstruct
- Web/DNS/video filtering across 300M+ URL database
- AI-based inline malware prevention — sub-second zero-day blocking
- Data Loss Prevention (DLP) and inline CASB
- OT security with 1,000+ virtual patches and 3,300+ protocol rules
- Real-time SSL/TLS 1.3 deep inspection
Mobile & Carrier Security
- SPU-accelerated CGNAT and IPv6 migration: NAT44, NAT444, NAT64/DNS64, NAT46
- 4G Gi/sGi and 5G N6 connectivity and security
- Scalable IPsec aggregation for radio access network security
- GTP-U inspection for user plane security and visibility
Networking & SD-WAN
- Full SD-WAN built into FortiOS at no extra cost
- NP6 ASIC for superior firewall performance, VPN, CAPWAP, and IP tunnel acceleration
- CP9 ASIC for accelerated SSL/TLS 1.3 decryption and IPS pre-scan
- Universal ZTNA — agent-based via FortiClient or agentless via proxy portal
- VXLAN segmentation bridging physical and virtual domains
- Active-Active, Active-Passive, and Clustering HA
Management
- Managed via FortiManager (enterprise) or FortiGate Cloud
- FortiAnalyzer Cloud and FortiManager Cloud available
- GenAI-assisted configuration and troubleshooting via FortiAI
- FortiConverter Service for migration from legacy firewalls
Environment
- Operating temperature: 0°C to 40°C
- Power consumption: 492W average / 610W max (3300E)
- Noise: 70 dBA, front-to-back airflow
- Operating altitude: up to 2,250m
View data sheet:FortiGate 3300E Series Datasheet

