Fortinet
FG-3500FFortinet FortiGate 3500F
List PriceThe FortiGate 3500F series delivers high-performance next-generation firewall (NGFW) capabilities for large enterprises and service providers. Multiple high-speed interfaces, high port density and high throughput make it suited to the enterprise edge, the hybrid data-centre core, and internal network segmentation, backed by industry-leading IPS, SSL inspection and advanced threat protection.
Fortinet's SPU NP6 network processor works inline with FortiOS functions to accelerate traffic processing, while the ninth-generation SPU CP9 content processor works outside the direct flow of traffic to accelerate content inspection.
An optional perpetual Hyperscale Firewall License unlocks further performance by hardware-accelerating CGNAT features — including hardware session setup, session logging and NAT — using Fortinet's latest SPU NP7 processor.
Key features
- SPU NP7 network processor and CP9 content processor hardware acceleration
- 6x 100GE QSFP28/40GE QSFP+ slots and 32x 25GE SFP28/10GE SFP+/GE SFP slots
- Trusted Platform Module (TPM) built in
- Two AC power supplies, hot-swappable
- Optional perpetual Hyperscale Firewall License for hardware-accelerated CGNAT
- Up to 500 virtual domains (VDOMs)
- Supports up to 300 FortiSwitches and 4,096 FortiAPs
Works with
Frequently asked questions
Hardware-only or a bundle?
The hardware-only SKU (FG-3500F) is the appliance alone. The bundle SKUs add 1, 3 or 5 years of FortiCare Premium support plus either FortiGuard Unified Threat Protection (UTP) or Enterprise Protection, which most deployments need for ongoing IPS, antivirus and web/URL filtering updates.
What does the Hyperscale Firewall License add?
It's an optional perpetual licence for the FG-3500F/3501F series that unlocks hardware-accelerated CGNAT on the SPU NP7 processor, covering hardware session setup, firewall session logging and NAT — useful for service-provider and large-scale NAT deployments.
How do I size the right model?
Check the enterprise-mix throughput figures (72 Gbps IPS, 65 Gbps NGFW, 63 Gbps Threat Protection) against expected inspected traffic, and the capacity figures — up to 348 million concurrent TCP sessions and 200,000 firewall policies — against session counts and policy complexity.
Sizing a FortiGate deployment? Call 0333 242 1314 or email sales@clisecure.com.
Interfaces and Modules
| Hardware Accelerated 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 |
|---|---|
| Hardware Accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 32 |
| 10GE/ GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1 / 1 |
| Console Port | 1 |
| Onboard Storage | None |
| Trusted Platform Module (TPM) | Yes |
| Included Transceivers | 2x SFP+ (SR 10 GE) |
System Performance — Enterprise Traffic Mix
| IPS Throughput | 72 Gbps |
|---|---|
| NGFW Throughput | 65 Gbps |
| Threat Protection Throughput | 63 Gbps |
System Performance and Capacity
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 595 / 590 / 420 Gbps |
|---|---|
| IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 595 / 590 / 420 Gbps |
| Firewall Latency (64 byte, UDP) | 2.98 μs |
| Firewall Throughput (Packet per Second) | 630 Mpps |
| Concurrent Sessions (TCP) | 140 Million / 348 Million |
| New Sessions/Second (TCP) | 1 Million / 5 Million |
| Firewall Policies | 200,000 |
| IPsec VPN Throughput (512 byte) | 165 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| SSL-VPN Throughput | 16 Gbps |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 55 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 60,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 15 Million |
| Application Control Throughput (HTTP 64K) | 135 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4,096 / 2,048 |
| Maximum Number of FortiTokens | 40,000 |
| High Availability Configurations | Active / Active, Active / Passive, Clustering |
Dimensions and Power
| Height x Width x Length (inches) | 3.5 x 17.4 x 21.9 |
|---|---|
| Height x Width x Length (mm) | 89 x 443 x 556 |
| Weight | 43.8 lbs (19.9 kg) |
| Form Factor | Rack Mount, 2 RU |
| AC Power Supply | 100–240V AC, 50–60 Hz |
| Power Consumption (Average / Maximum) | 760 W / 1174 W |
| AC Current (Maximum) | 12A@120V, 9A@240V |
| Heat Dissipation | 4,006 BTU/h |
| Redundant Power Supplies (Hot Swappable) | Yes, Hot Swappable |
Operating Environment and Certifications
| Operating Temperature | 32–104°F (0–40°C) |
|---|---|
| Storage Temperature | -31–158°F (-35–70°C) |
| Humidity | 20–90% non-condensing |
| Noise Level | 53.5 dBA |
| Operating Altitude | Up to 7,400 ft (2,250 m) |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-3500F |
Interfaces and Modules
| Hardware Accelerated 100 GE QSFP28 / 40 GE QSFP+ Slots | 6 |
|---|---|
| Hardware Accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP Slots | 32 |
| 10GE/ GE RJ45 Management Ports | 2 |
| USB Ports (Client / Server) | 1 / 1 |
| Console Port | 1 |
| Onboard Storage | None |
| Trusted Platform Module (TPM) | Yes |
| Included Transceivers | 2x SFP+ (SR 10 GE) |
System Performance — Enterprise Traffic Mix
| IPS Throughput | 72 Gbps |
|---|---|
| NGFW Throughput | 65 Gbps |
| Threat Protection Throughput | 63 Gbps |
System Performance and Capacity
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 595 / 590 / 420 Gbps |
|---|---|
| IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 595 / 590 / 420 Gbps |
| Firewall Latency (64 byte, UDP) | 2.98 μs |
| Firewall Throughput (Packet per Second) | 630 Mpps |
| Concurrent Sessions (TCP) | 140 Million / 348 Million |
| New Sessions/Second (TCP) | 1 Million / 5 Million |
| Firewall Policies | 200,000 |
| IPsec VPN Throughput (512 byte) | 165 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 40,000 |
| Client-to-Gateway IPsec VPN Tunnels | 200,000 |
| SSL-VPN Throughput | 16 Gbps |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 30,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 55 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 60,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 15 Million |
| Application Control Throughput (HTTP 64K) | 135 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 500 |
| Maximum Number of FortiSwitches Supported | 300 |
| Maximum Number of FortiAPs (Total / Tunnel) | 4,096 / 2,048 |
| Maximum Number of FortiTokens | 40,000 |
| High Availability Configurations | Active / Active, Active / Passive, Clustering |
Dimensions and Power
| Height x Width x Length (inches) | 3.5 x 17.4 x 21.9 |
|---|---|
| Height x Width x Length (mm) | 89 x 443 x 556 |
| Weight | 43.8 lbs (19.9 kg) |
| Form Factor | Rack Mount, 2 RU |
| AC Power Supply | 100–240V AC, 50–60 Hz |
| Power Consumption (Average / Maximum) | 760 W / 1174 W |
| AC Current (Maximum) | 12A@120V, 9A@240V |
| Heat Dissipation | 4,006 BTU/h |
| Redundant Power Supplies (Hot Swappable) | Yes, Hot Swappable |
Operating Environment and Certifications
| Operating Temperature | 32–104°F (0–40°C) |
|---|---|
| Storage Temperature | -31–158°F (-35–70°C) |
| Humidity | 20–90% non-condensing |
| Noise Level | 53.5 dBA |
| Operating Altitude | Up to 7,400 ft (2,250 m) |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-3500F |
Customer reviews
Built for B2B buying
From product selection to deployment, this is made for real projects.
Get the hardware, licences and supporting kit you need without chasing multiple suppliers. CLI Secure helps trade buyers confirm fit, stock, delivery and project pricing before checkout.
Why choose us
Procurement that feels fast, clear and trade-ready.
Every product page is designed to help you move from shortlist to checkout with fewer unknowns.
Common questions
Product and order FAQs
Can I request trade or bulk pricing?
Yes. For multi-unit, reseller or project orders, contact CLI Secure and our team can review the basket for trade pricing.
How quickly can this be delivered?
Available delivery options are shown at checkout. Many in-stock products support next-day or timed UK delivery.
Can you help confirm compatibility?
Yes. Share the existing setup, model numbers or project requirement and we can help confirm suitable hardware, licences or accessories.
Do you supply renewals and supporting accessories?
CLI Secure supplies hardware, renewals, licences and related accessories across networking, CCTV, VoIP and IT support categories.





