Fortinet
FG-4400FFortinet FortiGate 4400F
List PriceThe FortiGate 4400F is a compact hyperscale next-generation firewall (NGFW) built for large enterprises and service providers. It is designed to secure the network edge, the hybrid and hyperscale datacentre core, and internal network segments from a single 4U chassis, and includes a dedicated TPM module that hardens the appliance by generating, storing and authenticating cryptographic keys in hardware. A perpetual Hyperscale Firewall License is available separately to unlock hardware-accelerated CGNAT features, including hardware session setup, firewall session logging and NAT, via the SPU NP7.
On the Enterprise traffic mix, the series delivers 94 Gbps of IPS throughput, 82 Gbps of NGFW throughput and 75 Gbps of threat protection throughput, with firewall throughput reaching up to 1.2 Tbps (1.15 Tbps at 1518-byte UDP) at 750 Mpps. It supports up to 700 million concurrent TCP sessions, 10 million new sessions per second, 310 Gbps of IPsec VPN throughput and 86 Gbps of SSL inspection throughput.
Connectivity is provided by 12x 100GE QSFP28/40GE QSFP+ slots and 16x 25GE SFP28/10GE SFP+/GE SFP slots (plus 2 HA and 2 AUX slots), with 2x GE RJ45 management ports, a USB 3.0 port and a console port. The unit ships as a 4U rack-mount chassis with a hot-swappable fan tray and hot-swappable AC power supplies (2+2 redundant), and supports Active, Active-Active, Passive and clustering HA configurations.
Key features
- SPU NP7 and CP9 hardware-accelerated processing
- 12x 100GE QSFP28/40GE QSFP+ slots and 16x 25GE SFP28/10GE SFP+/GE SFP slots (plus 2 HA and 2 AUX slots)
- Up to 1.2 Tbps firewall throughput and 750 Mpps
- Hardware-accelerated VXLAN and DDoS protection for high-throughput “elephant flows”
- Up to 700 million concurrent TCP sessions and 10 million new sessions/second
- IPsec VPN throughput of 310 Gbps across up to 40,000 gateway-to-gateway tunnels
- SSL inspection throughput of 86 Gbps with 9 million concurrent inspected sessions
- Dedicated TPM module for hardware-based key generation, storage and authentication
- Hot-swappable fan tray and redundant power supplies
- 4 RU rack-mount chassis
Works with
Frequently asked questions
Do I need the bundle, or can I buy hardware only?
Hardware-only gets you the appliance with SPU NP7/CP9 acceleration and no FortiGuard subscription active. The bundle variants add FortiCare Premium support plus either FortiGuard Unified Threat Protection (UTP) or Enterprise Protection for a fixed 1, 3 or 5 year term, which is the simpler route if the firewall needs to be licensed from day one.
Is there a DC-powered version of the 4400F?
Yes. The 4400F-DC is otherwise identical to the 4400F but takes -48V to -60V DC input instead of mains AC, for deployment in telecom and data-centre racks that run on DC power.
How do I size a deployment against these numbers?
Real-world throughput depends on the security profile enabled (IPS, SSL inspection, application control) and average packet size, so the Enterprise traffic mix figures above are the most realistic planning baseline. The 4400F series ships with 12x 100/40GE QSFP28 slots and 16x 25/10GE SFP28/SFP+ slots plus dedicated HA and AUX slots, and supports Active, Active-Active, Passive and clustering HA configurations. Talk to us with your expected traffic mix and port requirements before committing to a model.
Sizing a FortiGate deployment? Call 0333 242 1314 or email sales@clisecure.com.
Hardware specifications
| Hardware accelerated 100 GE QSFP28 / 40 GE QSFP+ slots | 12 |
|---|---|
| Hardware accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP slots | 16 |
| Hardware accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP HA slots | 2 |
| Hardware accelerated 25 GE SFP28 / 10 GE SFP+ / GE SFP AUX slots | 2 |
| GE RJ45 management ports | 2 |
| USB port (3.0) | 1 |
| Console port | 1 |
| Onboard storage | - |
| Included transceivers | 2x SFP+ (SR 10GE) |
System performance — enterprise traffic mix
| IPS throughput | 94 Gbps |
|---|---|
| NGFW throughput | 82 Gbps |
| Threat protection throughput | 75 Gbps |
System performance and capacity
| IPv4 firewall throughput (1518 / 512 / 64 byte, UDP) | 1.15 / 1.14 / 0.50 Tbps |
|---|---|
| IPv6 firewall throughput (1518 / 512 / 86 byte, UDP) | 1.15 / 1.14 / 0.50 Tbps |
| Firewall latency (64 byte, UDP) | 2.98 µs |
| Firewall throughput (packets per second) | 750 Mpps |
| Concurrent sessions (TCP) | 210 million / 700 million* |
| New sessions/second (TCP) | 1 million / 10 million* |
| Firewall policies | 200,000 |
| IPsec VPN throughput (512 byte) | 310 Gbps |
| Gateway-to-gateway IPsec VPN tunnels | 40,000 |
| Client-to-gateway IPsec VPN tunnels | 200,000 |
| SSL-VPN throughput | 16 Gbps |
| Concurrent SSL-VPN users (recommended max, tunnel mode) | 30,000 |
| SSL inspection throughput (IPS, avg. HTTPS) | 86 Gbps |
| SSL inspection CPS (IPS, avg. HTTPS) | 70,000 |
| SSL inspection concurrent sessions (IPS, avg. HTTPS) | 9 million |
| Application control throughput (HTTP 64K) | 140 Gbps |
| CAPWAP throughput (HTTP 64K) | 63 Gbps |
| Virtual domains (default / maximum) | 10 / 500 |
| Maximum FortiSwitches supported | 300 |
| Maximum FortiAPs (total / tunnel mode) | 8,192 / 4,096 |
| Maximum FortiTokens | 20,000 |
| Maximum registered FortiClients | 20,000 |
| High availability configurations | Active, Active-Active, Passive, Clustering |
Dimensions and power
| Height x width x length (inches) | 6.97 x 17.20 x 26.17 |
|---|---|
| Height x width x length (mm) | 177 x 437 x 665 |
| Weight | 81.8 lbs (37.1 kg) |
| Form factor | Rack mount, 4 RU |
| AC power supply | 100-240V AC, 50/60 Hz |
| AC current (maximum) | 20A@100V, 9A@240V |
| Power consumption (average / maximum) | 1533 W / 1875 W |
| Heat dissipation | 6397.77 BTU/h |
| Redundant power supplies | Hot-swappable, 2+2 (AC), 1+1 (DC) |
| Fan tray | Hot-swappable |
Operating environment
| Operating temperature | 32-104°F (0-40°C) |
|---|---|
| Storage temperature | -31-158°F (-35-70°C) |
| Humidity | 20-90% non-condensing |
| Noise level | 68.9 dBA |
| Forced airflow | Front to back |
| Operating altitude | Up to 7,400 ft (2,250 m) |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN, USGv6/IPv6 |
Product details
| Brand | Fortinet |
|---|---|
| Part number | FG-4400F |
Customer reviews
Built for B2B buying
From product selection to deployment, this is made for real projects.
Get the hardware, licences and supporting kit you need without chasing multiple suppliers. CLI Secure helps trade buyers confirm fit, stock, delivery and project pricing before checkout.
Why choose us
Procurement that feels fast, clear and trade-ready.
Every product page is designed to help you move from shortlist to checkout with fewer unknowns.
Common questions
Product and order FAQs
Can I request trade or bulk pricing?
Yes. For multi-unit, reseller or project orders, contact CLI Secure and our team can review the basket for trade pricing.
How quickly can this be delivered?
Available delivery options are shown at checkout. Many in-stock products support next-day or timed UK delivery.
Can you help confirm compatibility?
Yes. Share the existing setup, model numbers or project requirement and we can help confirm suitable hardware, licences or accessories.
Do you supply renewals and supporting accessories?
CLI Secure supplies hardware, renewals, licences and related accessories across networking, CCTV, VoIP and IT support categories.





