Fortinet
FG-3000F-DCFortinet FortiGate 3000F-DC
List PriceThe FortiGate 3000F Series is built for security-driven networking across the datacentre and hybrid IT estate, protecting network edges at scale. Powered by Fortinet's AI/ML-based FortiGuard Services and an integrated Security Fabric platform, it delivers coordinated, automated threat protection across all deployment use cases.
Built-in Zero Trust Network Access (ZTNA) enforcement controls and verifies user access to applications directly within the NGFW, giving consistent, converged access control without additional overlay hardware.
An optional perpetual Hyperscale Firewall License unlocks further performance by hardware-accelerating CGNAT features — including hardware session setup, session logging and NAT — using Fortinet's SPU NP7 processor. The FG-3000F-DC ships with two DC power supplies for telco and data-centre racks running DC power.
Key features
- SPU NP7 network processor and CP9 content processor hardware acceleration
- Zero Trust Network Access (ZTNA) enforcement built into the NGFW
- Trusted Platform Module (TPM) built in
- Two DC power supplies, 1+1 redundancy, hot-swappable
- Optional perpetual Hyperscale Firewall License for hardware-accelerated CGNAT
- Up to 500 virtual domains (VDOMs)
- Supports up to 300 FortiSwitches and 4,096 FortiAPs
- 6x 100GE QSFP28, 16x 25GE SFP28/10GE SFP+ and 16x 10GE RJ45 interfaces
Works with
Frequently asked questions
Hardware-only or a bundle?
The hardware-only SKU (FG-3000F-DC) is the appliance alone. The bundle SKUs add 1, 3 or 5 years of FortiCare Premium support plus either FortiGuard Unified Threat Protection (UTP) or Enterprise Protection, which most deployments need for ongoing IPS, antivirus and web/URL filtering updates.
3000F-DC vs 3000F — what's different?
The two share the same interfaces and performance figures in Fortinet's datasheet. The difference is power input: the FG-3000F-DC takes two DC power supplies for telco and data-centre racks running DC power, where the base FG-3000F takes AC.
How do I size the right model?
Check the enterprise-mix throughput figures (36 Gbps IPS, 34 Gbps NGFW, 33 Gbps Threat Protection) against expected inspected traffic, and the capacity figures — up to 230 million concurrent TCP sessions and 200,000 firewall policies — against session counts and policy complexity.
Sizing a FortiGate deployment? Call 0333 242 1314 or email sales@clisecure.com.
Interfaces and Modules
| Hardware Accelerated 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 |
|---|---|
| Hardware Accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 16 (include 2x HA Slots) |
| Hardware Accelerated 10 GE / 5 GE / 2.5 GE / GE RJ45 Ports | 16 |
| 10GE/ GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1/1 |
| Console Port | 1 |
| Onboard Storage | None |
| Trusted Platform Module (TPM) | Yes |
| Included Transceivers | 2x SFP+ (SR 10 GE) |
System Performance — Enterprise Traffic Mix
| IPS Throughput | 36 Gbps |
|---|---|
| NGFW Throughput | 34 Gbps |
| Threat Protection Throughput | 33 Gbps |
System Performance and Capacity
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 397 / 389 / 221 Gbps |
|---|---|
| IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) | 397 / 389 / 221 Gbps |
| Firewall Latency (64 byte, UDP) | 3.92 μs |
| Firewall Throughput (Packet per Second) | 331.5 Mpps |
| Concurrent Sessions (TCP) | 70 Million / 230 Million |
| New Sessions/Second (TCP) | 870,000 / 3 Million |
| Firewall Policies | 200,000 |
| IPsec VPN Throughput (512 byte) | 105 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| SSL-VPN Throughput | 11 Gbps |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 29 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 29,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 7.5 Million |
| Application Control Throughput (HTTP 64K) | 115 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4096 / 2048 |
| Maximum Number of FortiTokens | 20,000 |
| High Availability Configurations | Active-Active, Active-Passive, Clustering |
Dimensions and Power
| Height x Width x Length (inches) | 3.5 x 17.44 x 21.89 |
|---|---|
| Height x Width x Length (mm) | 88.9 x 443 x 556 |
| Weight | 37.3 lbs (16.9 kg) |
| Form Factor (supports EIA/non-EIA standards) | Rack Mount, 2 RU |
| Power Consumption (Average / Maximum) | 425 W / 680 W |
| DC Power Supply | 48–60VDC |
| Heat Dissipation | 2321 BTU/h |
| Redundant Power Supplies (Hot Swappable) | Yes (dual PSU, 1+1 redundancy) |
| Power Supply Efficiency Rating | 80Plus Compliant |
Operating Environment and Certifications
| Operating Temperature | 32–104°F (0–40°C) |
|---|---|
| Storage Temperature | -31–158°F (-35–70°C) |
| Humidity | 5% to 90% non-condensing |
| Noise Level | 69 dBA |
| Forced Airflow | Front to Back |
| Operating Altitude | Up to 10,000 ft (3048 m) |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-3000F-DC |
Interfaces and Modules
| Hardware Accelerated 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 |
|---|---|
| Hardware Accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 16 (include 2x HA Slots) |
| Hardware Accelerated 10 GE / 5 GE / 2.5 GE / GE RJ45 Ports | 16 |
| 10GE/ GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1/1 |
| Console Port | 1 |
| Onboard Storage | None |
| Trusted Platform Module (TPM) | Yes |
| Included Transceivers | 2x SFP+ (SR 10 GE) |
System Performance — Enterprise Traffic Mix
| IPS Throughput | 36 Gbps |
|---|---|
| NGFW Throughput | 34 Gbps |
| Threat Protection Throughput | 33 Gbps |
System Performance and Capacity
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 397 / 389 / 221 Gbps |
|---|---|
| IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) | 397 / 389 / 221 Gbps |
| Firewall Latency (64 byte, UDP) | 3.92 μs |
| Firewall Throughput (Packet per Second) | 331.5 Mpps |
| Concurrent Sessions (TCP) | 70 Million / 230 Million |
| New Sessions/Second (TCP) | 870,000 / 3 Million |
| Firewall Policies | 200,000 |
| IPsec VPN Throughput (512 byte) | 105 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| SSL-VPN Throughput | 11 Gbps |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 29 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 29,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 7.5 Million |
| Application Control Throughput (HTTP 64K) | 115 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4096 / 2048 |
| Maximum Number of FortiTokens | 20,000 |
| High Availability Configurations | Active-Active, Active-Passive, Clustering |
Dimensions and Power
| Height x Width x Length (inches) | 3.5 x 17.44 x 21.89 |
|---|---|
| Height x Width x Length (mm) | 88.9 x 443 x 556 |
| Weight | 37.3 lbs (16.9 kg) |
| Form Factor (supports EIA/non-EIA standards) | Rack Mount, 2 RU |
| Power Consumption (Average / Maximum) | 425 W / 680 W |
| DC Power Supply | 48–60VDC |
| Heat Dissipation | 2321 BTU/h |
| Redundant Power Supplies (Hot Swappable) | Yes (dual PSU, 1+1 redundancy) |
| Power Supply Efficiency Rating | 80Plus Compliant |
Operating Environment and Certifications
| Operating Temperature | 32–104°F (0–40°C) |
|---|---|
| Storage Temperature | -31–158°F (-35–70°C) |
| Humidity | 5% to 90% non-condensing |
| Noise Level | 69 dBA |
| Forced Airflow | Front to Back |
| Operating Altitude | Up to 10,000 ft (3048 m) |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-3000F-DC |
Customer reviews
Built for B2B buying
From product selection to deployment, this is made for real projects.
Get the hardware, licences and supporting kit you need without chasing multiple suppliers. CLI Secure helps trade buyers confirm fit, stock, delivery and project pricing before checkout.
Why choose us
Procurement that feels fast, clear and trade-ready.
Every product page is designed to help you move from shortlist to checkout with fewer unknowns.
Common questions
Product and order FAQs
Can I request trade or bulk pricing?
Yes. For multi-unit, reseller or project orders, contact CLI Secure and our team can review the basket for trade pricing.
How quickly can this be delivered?
Available delivery options are shown at checkout. Many in-stock products support next-day or timed UK delivery.
Can you help confirm compatibility?
Yes. Share the existing setup, model numbers or project requirement and we can help confirm suitable hardware, licences or accessories.
Do you supply renewals and supporting accessories?
CLI Secure supplies hardware, renewals, licences and related accessories across networking, CCTV, VoIP and IT support categories.





