Fortinet
FG-401FFortinet FortiGate 401F
List PriceThe FortiGate 400F series is a next-generation firewall (NGFW) that combines AI- and machine-learning-based threat protection with deep visibility into the applications, users and devices on the network.
It delivers IPS throughput of 12 Gbps, NGFW throughput of 10 Gbps and Threat Protection throughput of 9 Gbps on an enterprise traffic mix, accelerated by Fortinet's SPU NP7 network processor and CP9 content processor. Connectivity is provided over 18x GE RJ45 ports, 8x GE SFP slots and 8x 10GE SFP+ slots.
Universal ZTNA verifies and controls user access to applications to reduce lateral threats, and FortiOS unifies networking and security policy across physical, virtual, container and cloud FortiGate deployments as part of the Fortinet Security Fabric.
Key features
- SPU NP7 network processor and CP9 content processor hardware acceleration
- Universal ZTNA for verified application access
- Secure SD-WAN and network segmentation
- 18x GE RJ45, 8x GE SFP and 8x 10GE SFP+ ports
- Trusted Platform Module (TPM) built in
- Dual AC power supplies, 1+1 redundancy
- Up to 10 virtual domains (VDOMs)
- Supports up to 72 FortiSwitches and 512 FortiAPs
- 2x 480GB onboard SSD storage
Works with
Frequently asked questions
Hardware only or a bundle?
The hardware-only SKU is the appliance alone. The bundle SKUs add 1, 3 or 5 years of FortiCare Premium support plus either the FortiGuard Unified Threat Protection (UTP) or Enterprise Protection subscription, which most deployments need for ongoing IPS, antivirus and web/URL filtering updates.
401F vs 400F — what's different?
The 401F adds 2x 480GB onboard SSD storage; the 400F has no onboard SSD storage. The 401F weighs 14.33 lbs (6.5 kg) with average/maximum power consumption of 161.1 W / 196.9 W; the 400F weighs 14.11 lbs (6.4 kg) and draws 154.8 W / 189.2 W. IPS, NGFW and Threat Protection throughput are the same across both models.
How do I size the right model?
Check the enterprise-mix throughput figures (12 Gbps IPS, 10 Gbps NGFW, 9 Gbps Threat Protection) against your expected inspected traffic, and the capacity figures — 7.8 million concurrent TCP sessions, 500,000 new sessions per second and 10,000 firewall policies — against session counts and policy complexity.
Sizing a FortiGate deployment? Call 0333 242 1314 or email sales@clisecure.com.
Interfaces and Modules
| Hardware Accelerated GE RJ45 Interfaces | 16 |
|---|---|
| Hardware Accelerated GE SFP Slots | 8 |
| Hardware Accelerated 10GE SFP+ Slots | 4 |
| Hardware Accelerated 10GE SFP+ Ultra Low Latency Slots | 4 |
| GE RJ45 Management Ports | 2 |
| USB Ports | 1 |
| RJ45 Console Port | 1 |
| Onboard Storage | 2x 480 GB SSD |
| Trusted Platform Module (TPM) | Yes |
| Included Transceivers | 2x SFP (SX 1 GE) |
System Performance — Enterprise Traffic Mix
| IPS Throughput | 12 Gbps |
|---|---|
| NGFW Throughput | 10 Gbps |
| Threat Protection Throughput | 9 Gbps |
System Performance and Capacity
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 79.5 / 78.5 / 70 Gbps |
|---|---|
| IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 79.5 / 78.5 / 70 Gbps |
| Firewall Latency (64 byte, UDP) | 4.19 μs / 2.5 μs |
| Firewall Throughput (Packet per Second) | 105 Mpps |
| Concurrent Sessions (TCP) | 7.8 Million |
| New Sessions/Second (TCP) | 500,000 |
| Firewall Policies | 10,000 |
| IPsec VPN Throughput (512 byte) | 55 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 2,000 |
| Client-to-Gateway IPsec VPN Tunnels | 50,000 |
| SSL-VPN Throughput | 3.6 Gbps |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 5,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 8 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 6,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 800,000 |
| Application Control Throughput (HTTP 64K) | 28 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 10 |
| Maximum Number of FortiSwitches Supported | 72 |
| Maximum Number of FortiAPs (Total / Tunnel) | 512 / 256 |
| Maximum Number of FortiTokens | 5,000 |
| High Availability Configurations | Active-Active, Active-Passive, Clustering |
Dimensions and Power
| Height x Width x Length (inches) | 1.75 x 17.0 x 15.0 |
|---|---|
| Height x Width x Length (mm) | 44.45 x 432 x 380 |
| Weight | 14.33 lbs (6.5 kg) |
| Form Factor | Rack Mount, 1 RU |
| Power Consumption (Average / Maximum) | 161.1 W / 196.9 W |
| Power Source | 100–240V AC, 50/60Hz |
| Current (Maximum) | 6A |
| Heat Dissipation | 671.85 BTU/h |
| Power Supply Efficiency Rating | 80Plus Compliant |
| Redundant Power Supplies (Hot Swappable) | (Default dual AC PSU for 1+1 Redundancy) |
Operating Environment and Certifications
| Operating Temperature | 32–104°F (0–40°C) |
|---|---|
| Storage Temperature | -31–158°F (-35–70°C) |
| Humidity | 5–90% non-condensing |
| Noise Level | LPA 48 dBA / LWA 55 dBA |
| Operating Altitude | Up to 10 000 ft (3048 m) |
| Airflow | Side and Front to Back |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN, USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-401F |
Interfaces and Modules
| Hardware Accelerated GE RJ45 Interfaces | 16 |
|---|---|
| Hardware Accelerated GE SFP Slots | 8 |
| Hardware Accelerated 10GE SFP+ Slots | 4 |
| Hardware Accelerated 10GE SFP+ Ultra Low Latency Slots | 4 |
| GE RJ45 Management Ports | 2 |
| USB Ports | 1 |
| RJ45 Console Port | 1 |
| Onboard Storage | 2x 480 GB SSD |
| Trusted Platform Module (TPM) | Yes |
| Included Transceivers | 2x SFP (SX 1 GE) |
System Performance — Enterprise Traffic Mix
| IPS Throughput | 12 Gbps |
|---|---|
| NGFW Throughput | 10 Gbps |
| Threat Protection Throughput | 9 Gbps |
System Performance and Capacity
| IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 79.5 / 78.5 / 70 Gbps |
|---|---|
| IPv6 Firewall Throughput (1518 / 512 / 64 byte, UDP) | 79.5 / 78.5 / 70 Gbps |
| Firewall Latency (64 byte, UDP) | 4.19 μs / 2.5 μs |
| Firewall Throughput (Packet per Second) | 105 Mpps |
| Concurrent Sessions (TCP) | 7.8 Million |
| New Sessions/Second (TCP) | 500,000 |
| Firewall Policies | 10,000 |
| IPsec VPN Throughput (512 byte) | 55 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels | 2,000 |
| Client-to-Gateway IPsec VPN Tunnels | 50,000 |
| SSL-VPN Throughput | 3.6 Gbps |
| Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) | 5,000 |
| SSL Inspection Throughput (IPS, avg. HTTPS) | 8 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) | 6,000 |
| SSL Inspection Concurrent Session (IPS, avg. HTTPS) | 800,000 |
| Application Control Throughput (HTTP 64K) | 28 Gbps |
| CAPWAP Throughput (HTTP 64K) | 65 Gbps |
| Virtual Domains (Default / Maximum) | 10 / 10 |
| Maximum Number of FortiSwitches Supported | 72 |
| Maximum Number of FortiAPs (Total / Tunnel) | 512 / 256 |
| Maximum Number of FortiTokens | 5,000 |
| High Availability Configurations | Active-Active, Active-Passive, Clustering |
Dimensions and Power
| Height x Width x Length (inches) | 1.75 x 17.0 x 15.0 |
|---|---|
| Height x Width x Length (mm) | 44.45 x 432 x 380 |
| Weight | 14.33 lbs (6.5 kg) |
| Form Factor | Rack Mount, 1 RU |
| Power Consumption (Average / Maximum) | 161.1 W / 196.9 W |
| Power Source | 100–240V AC, 50/60Hz |
| Current (Maximum) | 6A |
| Heat Dissipation | 671.85 BTU/h |
| Power Supply Efficiency Rating | 80Plus Compliant |
| Redundant Power Supplies (Hot Swappable) | (Default dual AC PSU for 1+1 Redundancy) |
Operating Environment and Certifications
| Operating Temperature | 32–104°F (0–40°C) |
|---|---|
| Storage Temperature | -31–158°F (-35–70°C) |
| Humidity | 5–90% non-condensing |
| Noise Level | LPA 48 dBA / LWA 55 dBA |
| Operating Altitude | Up to 10 000 ft (3048 m) |
| Airflow | Side and Front to Back |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN, USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-401F |
Customer reviews
Built for B2B buying
From product selection to deployment, this is made for real projects.
Get the hardware, licences and supporting kit you need without chasing multiple suppliers. CLI Secure helps trade buyers confirm fit, stock, delivery and project pricing before checkout.
Why choose us
Procurement that feels fast, clear and trade-ready.
Every product page is designed to help you move from shortlist to checkout with fewer unknowns.
Common questions
Product and order FAQs
Can I request trade or bulk pricing?
Yes. For multi-unit, reseller or project orders, contact CLI Secure and our team can review the basket for trade pricing.
How quickly can this be delivered?
Available delivery options are shown at checkout. Many in-stock products support next-day or timed UK delivery.
Can you help confirm compatibility?
Yes. Share the existing setup, model numbers or project requirement and we can help confirm suitable hardware, licences or accessories.
Do you supply renewals and supporting accessories?
CLI Secure supplies hardware, renewals, licences and related accessories across networking, CCTV, VoIP and IT support categories.





