Description
FortiGate VM16-S 16 vCPU Virtual NGFW for Private and Public Cloud Deployments
The FortiGate VM16-S is an annual subscription virtual NGFW supporting up to 16 vCPU cores delivering full FortiOS security capabilities with vSPU-accelerated performance across private hypervisors and major public cloud platforms, suited for large-scale virtualised data centre and multi-cloud environments.
License & vCPU
- Supports 1 to 16 vCPU cores
- Annual subscription licensing model
- SKU: FC5-10-FGVVS-<Support Bundle>-02-DD
- No RAM restrictions
- Unlimited user license included
- Managed by FortiManager 6.4.0+ and 7.x+
Capacity
- 200,000 firewall policies
- Up to 500 virtual domains (VDOMs requires separate VDOM subscription license; each seat = 5 VDOMs, max 100 seats / 500 VDOMs)
- Up to 4,096 wireless access points (1,024 tunnel mode)
- Up to 300 FortiSwitches
- Up to 20,000 registered endpoints
- Storage: 32GB minimum / 2TB maximum
- Up to 24 network interfaces (FortiOS 6.4.0+)
Private Cloud / Hypervisor Support
- VMware ESXi v6.7 / v7.0 / v8.0
- VMware NSX-T v3.2 / v4.0
- Microsoft Hyper-V Server 2008 R2 through 2019
- Microsoft AzureStack
- Red Hat OpenShift Virtualization 4.17.13 (FortiOS 7.6.0+)
- Citrix XenServer v5.6 SP2 and later
- Open source Xen v3.4.3 and later
- KVM (RHEL/CentOS, Ubuntu, SuSE)
- Nutanix AHV 7.3 (FortiOS 7.6.3+)
- CSP 5000 Series
Public Cloud / Marketplace Support
- Amazon AWS (including GovCloud and AWS China)
- VMware Cloud on AWS
- Microsoft Azure (including US Gov, Germany, China) and AzureStack
- Google GCP
- Oracle OCI
- Alibaba Cloud
- IBM Cloud (Gen1/Gen2)
Performance Acceleration
- vSPU technology offloads packet processing to user space with kernel bypass delivers 3x+ UDP firewall throughput
- Intel QuickAssist Technology (QAT) support for IPsec VPN 23x throughput improvement
- First NGFW vendor to support AWS C5n instances for compute-heavy cloud applications
Security Features
- FortiGuard AI-powered IPS with virtual patching
- Anti-malware: AV, sandboxing, AI-based heuristics, Content Disarm and Reconstruct
- Web/DNS/video filtering across 300M+ URL database
- AI-based inline malware prevention sub-second zero-day blocking
- Data Loss Prevention (DLP) and inline CASB
- OT security: detection, vulnerability correlation, virtual patching, protocol decoders
- Real-time SSL/TLS 1.3 deep inspection
- Universal ZTNA agent-based or agentless
- Full SD-WAN built into FortiOS
Cloud Integration & Automation
- Terraform modules, AWS CloudFormation, Ansible playbooks, REST API
- Native integrations with cloud-native tools, serverless functions, and auto-scaling
- Log forwarding and event correlation into cloud SIEM and SOAR platforms
- Cloud identity, tagging, and networking service integration for unified policy enforcement
Management
- Centralised management via FortiManager or FortiManager Cloud
- FortiAnalyzer Cloud available
- FortiConverter Service for legacy firewall migration
- Cloud marketplace deployments include UTP bundle by default
View data sheet: FortiGate Virtual Appliances Data Sheet

