Fortinet
FG-4201F-DCFortinet FortiGate 4201F-DC
List PriceThe FortiGate 4201F-DC is the storage-equipped member of the 4200F series, a high-end next-generation firewall (NGFW) built for large enterprises and service providers. It adds 2x 2TB SSD onboard storage to the same hardware platform, which is used for local logging and analytics on the appliance itself. It runs on DC power, making it suited to telecom and data-centre racks that use -48V to -60V DC feeds instead of mains AC.
On the Enterprise traffic mix, the series delivers 52 Gbps of IPS throughput, 47 Gbps of NGFW throughput and 45 Gbps of threat protection throughput, with firewall throughput reaching up to 800 Gbps (1518-byte UDP) at 600 Mpps. It supports up to 450 million concurrent TCP sessions, 7 million new sessions per second, 210 Gbps of IPsec VPN throughput and 50 Gbps of SSL inspection throughput.
Connectivity is provided by 8x 100GE QSFP28/40GE QSFP+ slots and 16x 25GE SFP28/10GE SFP+/GE SFP slots (plus 2 HA and 2 AUX slots), with 2x GE RJ45 management ports and a console port. The unit ships as a 3U rack-mount chassis with dual redundant, hot-swappable DC power supplies (-48V to -60V DC, 25-32A per PSU) and supports Active/Active, Active/Passive and clustering HA configurations.
Key features
- SPU NP7 and CP9 hardware-accelerated processing
- 2x 2TB SSD onboard storage for local logging and analytics
- 8x 100GE QSFP28/40GE QSFP+ slots and 16x 25GE SFP28/10GE SFP+/GE SFP slots (plus 2 HA and 2 AUX slots)
- Up to 800 Gbps firewall throughput and 600 Mpps
- Up to 450 million concurrent TCP sessions and 7 million new sessions/second
- IPsec VPN throughput of 210 Gbps across up to 40,000 gateway-to-gateway tunnels
- SSL inspection throughput of 50 Gbps with 9 million concurrent inspected sessions
- Active/Active, Active/Passive and clustering HA configurations
- 3 RU rack-mount chassis with dual redundant, hot-swappable power supplies
- -48V to -60V DC power input for telecom and data-centre racks
Works with
Frequently asked questions
Do I need the bundle, or can I buy hardware only?
Hardware-only gets you the appliance with SPU NP7/CP9 acceleration and no FortiGuard subscription active. The bundle variants add FortiCare Premium support plus either FortiGuard Unified Threat Protection (UTP) or Enterprise Protection for a fixed 1, 3 or 5 year term, which is the simpler route if the firewall needs to be licensed from day one.
What does the -DC in 4201F-DC mean?
The 4201F-DC is the DC-powered version of the 4201F. It takes -48V to -60V DC input instead of mains AC, which is the standard feed in telecom and data-centre racks, and is otherwise built to the same specification as the AC model.
How do I size a deployment against these numbers?
Real-world throughput depends on the security profile enabled (IPS, SSL inspection, application control) and average packet size, so the Enterprise traffic mix figures above are the most realistic planning baseline. The 4200F series ships with 8x 100/40GE QSFP28 slots and 16x 25/10GE SFP28/SFP+ slots plus dedicated HA and AUX slots, and supports Active/Active, Active/Passive and clustering HA configurations. Talk to us with your expected traffic mix and port requirements before committing to a model.
Sizing a FortiGate deployment? Call 0333 242 1314 or email sales@clisecure.com.
Hardware specifications
| 100 GE QSFP28 / 40 GE QSFP+ slots | 8 |
|---|---|
| 25 GE SFP28 / 10 GE SFP+ / GE SFP slots | 16 |
| 25 GE SFP28 / 10 GE SFP+ / GE SFP HA slots | 2 |
| 25 GE SFP28 / 10 GE SFP+ / GE SFP AUX slots | 2 |
| GE RJ45 management ports | 2 |
| USB ports | 1 |
| Console port | 1 |
| Internal storage | 2x 2TB SSD |
| Included transceivers | 2x SFP+ (SR 10GE) |
System performance — enterprise traffic mix
| IPS throughput | 52 Gbps |
|---|---|
| NGFW throughput | 47 Gbps |
| Threat protection throughput | 45 Gbps |
System performance and capacity
| Firewall throughput (1518 / 512 / 64 byte, UDP) | 800 / 788 / 400 Gbps |
|---|---|
| IPv6 firewall throughput (1518 / 512 / 86 byte, UDP) | 800 / 788 / 400 Gbps |
| Firewall latency (64 byte, UDP) | 3.02 µs |
| Firewall throughput (packets per second) | 600 Mpps |
| Concurrent sessions (TCP) | 210 million / 450 million |
| New sessions/second (TCP) | 1 million / 7 million |
| Firewall policies | 200,000 |
| IPsec VPN throughput (512 byte) | 210 Gbps |
| Gateway-to-gateway IPsec VPN tunnels | 40,000 |
| Client-to-gateway IPsec VPN tunnels | 200,000 |
| SSL-VPN throughput | 16 Gbps |
| Concurrent SSL-VPN users (recommended max, tunnel mode) | 30,000 |
| SSL inspection throughput (IPS, avg. HTTPS) | 50 Gbps |
| SSL inspection CPS (IPS, avg. HTTPS) | 23,000 |
| SSL inspection concurrent sessions (IPS, avg. HTTPS) | 9 million |
| Application control throughput (HTTP 64K) | 135 Gbps |
| CAPWAP throughput (HTTP 64K) | 47 Gbps |
| Virtual domains (default / maximum) | 10 / 500 |
| Maximum FortiSwitches supported | 300 |
| Maximum FortiAPs (total / tunnel mode) | 8,192 / 4,096 |
| Maximum FortiTokens | 20,000 |
| Maximum registered FortiClients | 50,000 |
| High availability configurations | Active/Active, Active/Passive, Clustering |
Dimensions and power
| Height x width x length (inches) | 5.22 x 17.20 x 26.17 |
|---|---|
| Height x width x length (mm) | 132.5 x 437 x 664.8 |
| Weight | 61.07 lbs (27.7 kg) |
| Form factor | Rack mount, 3 RU |
| DC power supply | -48V to -60V DC |
| DC current (maximum rated) | 25A to 32A per PSU |
| Power consumption (average / maximum) | 940 W / 1306 W |
| Heat dissipation | 4456 BTU/h |
| Redundant power supplies | Default 1+1 redundant, hot-swappable |
Operating environment
| Operating temperature | 32-104°F (0-40°C) |
|---|---|
| Storage temperature | -31-158°F (-35-70°C) |
| Humidity | 20-90% non-condensing |
| Noise level | 57 dBA |
| Operating altitude | Up to 7,400 ft (2,250 m) |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-4201F-DC |
Customer reviews
Built for B2B buying
From product selection to deployment, this is made for real projects.
Get the hardware, licences and supporting kit you need without chasing multiple suppliers. CLI Secure helps trade buyers confirm fit, stock, delivery and project pricing before checkout.
Why choose us
Procurement that feels fast, clear and trade-ready.
Every product page is designed to help you move from shortlist to checkout with fewer unknowns.
Common questions
Product and order FAQs
Can I request trade or bulk pricing?
Yes. For multi-unit, reseller or project orders, contact CLI Secure and our team can review the basket for trade pricing.
How quickly can this be delivered?
Available delivery options are shown at checkout. Many in-stock products support next-day or timed UK delivery.
Can you help confirm compatibility?
Yes. Share the existing setup, model numbers or project requirement and we can help confirm suitable hardware, licences or accessories.
Do you supply renewals and supporting accessories?
CLI Secure supplies hardware, renewals, licences and related accessories across networking, CCTV, VoIP and IT support categories.





