
Entry-Level · branches and offices
FortiGate 90G
Next-generation firewall for branches and offices
Models in the series: FortiGate 90G, FortiGate 91G
- Threat Protection
- 2.2 Gbps
- IPS
- 4.5 Gbps
- NGFW
- 2.5 Gbps
Price on request — we reply within 24 hours.
Overview
The FortiGate 90G series integrates firewalling, SD-WAN, network controller, and security in one appliance, making them perfect for building secure networks at distributed enterprise sites and transforming WAN architecture at any scale.
The 90G series runs on FortiOS, a converged networking and security platform with secure AI controls and quantum-safe protection. This single OS approach enables businesses to gain benefits of operational efficiency and unified protection from the seamless integration of Fortinet solutions within a hybrid mesh firewall architecture.
As a cornerstone of the Fortinet Security Fabric platform, the FortiGate NGFW works seamlessly with FortiGuard AI-Powered Security Services to deliver coordinated, automated, end-to-end threat protection in real time.
The 90G family is built on the patented SD-WAN-based ASIC, which delivers unmatched performance over traditional CPUs with lower cost and reduced power consumption. This application-specific design and embedded multi-core processor further accelerate the convergence of networking and security functions in the 90G family to optimize secure connections and deliver a robust user experience at branch locations.
Use cases
- Perimeter Protection • Protect networks from malicious traffic, guard against file-based threats, block web-based attacks, and secure applications and data with natively integrated FortiGuard AI-Powered Security Services • Inspect and control incoming and outgoing traffic based on defined security policies • Perform real-time SSL inspection (including TLS 1.3) with full visibility into users, devices, and applications across the attack surface • Accelerate performance, protection, and energy efficiency with Fortinet’s patented SPU with converged security and networking technologies
- Secure SD-WAN • FortiGate enables best-of-breed WAN edge with integrated SD-WAN, WAN optimization, security, and unified management from a single FortiOS operating system • FortiGate, built on a patented SD-WAN-based ASIC, delivers faster application identification to avoid delays in accessing applications and accelerates overlay performance regardless of location • Enhances hybrid working with a comprehensive SASE solution by integrating cloud-delivered SD-WAN with security service edge (SSE) • Achieves operational efficiencies at any scale through automation, deep analytics, and self-healing
- Secure Branch • The Fortinet Security Fabric platform enables FortiGate NGFWs to automatically discover and secure IoT devices for faster branch onboarding • Fully integrated with FortiSwitch secure Ethernet switches and FortiAP access points, FortiGate easily extends security to WAN, LAN, and WLAN at branch offices for unified protection and reliable connectivity • FortiGate and Fortinet products work seamlessly with FortiManager to centralize visibility and simplify management across locations for IT teams • FortiGate HA support ensures continuous network protection and minimizes downtime in the event of hardware failures or network disruptions
- Universal ZTNA Control access to applications no matter where the user is and no matter where the application is hosted for universal application of access policies. • Provide extensive authentications, checks, and enforce policy prior to granting application access every time • Agent-based access with FortiClient or agentless access via proxy portal for guest or BYOD
Variants
91G — FortiGate 91G — with a 120 GB SSD for on-device logging
Hardware


Rear panel — Ports and LEDs · 90G / 91G
- 1Signed Firmware Switch — Part Numbers: P28786-12 (FG-90G) / P28792-12 (FG-91G) and up
- 2Power Input 12VDC 3A, 100-240VAC 50/60Hz — (optional redundant power adapter and cable available for purchase)
Front panel — Ports and LEDs · 90G / 91G
- 1BLE — Flashing Blue: Discovery mode; Blue: BLE on; Off: BLE off
- 2Reset/BLE Press to enable BLE; press and hold for system reset
- 3HA — Green: HA enabled (normal); Amber: HA enabled (failover); Off: HA disabled; POWER — Green: Both PSUs functioning; Amber: One PSU functioning; Off: Power is off; STATUS — Flashing Green: Booting up; Green: Operating normally; Off: Device is off
- 4CONSOLE (RJ45) CLI management; USB (USB A) USB 3.0 server port
- 5SFP+ Ports 1 & 2 shared with X1 & X2 — Green: Link established at 10/5/2.5/1 Gbps; Flashing Green: Data activity; Off: No link established
- 6FortiLink Ports X1 & X2 shared with SFP+1 & SFP+2 — LINK/ACT (Left LED) — Green: Connected; Flashing Green: Data Activity; Off: No activity; SPEED (Right LED) — Green: 10 Gbps; Amber: 5/2.5/1 Gbps; Off: 100 Mbps or off
- 7Ethernet Ports 1 to 6 and Ports A & B — LINK/ACT (Left LED) — Green: Connected; Flashing Green: Data Activity; Off: No activity; SPEED (Right LED) — Green: 1 Gbps; Amber: 100 Mbps; Off: 10 Mbps or off
- 8SIGNED FIRMWARE BIOS Security Level — Controlled by Signed Firmware Switch, see Admin Guide at https://docs.fortinet.com; High: Unsigned firmware blocked (default); Low: Unsigned firmware allowed with a warning
Hardware features
- Trusted Platform Module (TPM) — The FortiGate 90G series features a dedicated module that hardens physical networking appliances by generating, storing, and authenticating cryptographic keys. Hardware-based security mechanisms protect against malicious software and phishing attacks.
- Compact and reliable form factor — Designed for small environments, the FortiGate can be on a desktop or wall-mounted. It is small, lightweight, yet highly reliable with superior meantime between failures, minimizing the chance of network disruption.
- Third-party verified Environmental Product Declaration — The FortiGate 90G/91G is EPD compliant with ISO 14025 Type III (externally verified), ensuring data accuracy and full transparency on the product environmental impacts throughout its life cycle. For more information please visit https://www.environdec.com/library/epd21562
Specifications
| Parameter | FortiGate 90G | FortiGate 91G |
|---|---|---|
| Interfaces and modules | ||
| GE RJ45 internal ports | 8 | |
| 10/5/2.5/GE RJ45 or 10GE/GE SFP+/SFP shared media pairs | 2 | |
| Wireless interface (Wi-Fi) | None | |
| USB ports | 1 | |
| Console port (RJ45) | 1 | |
| Internal storage | — | 1 x 120 GB SSD |
| Trusted Platform Module (TPM) | ✓ | |
| Bluetooth Low Energy (BLE) | ✓ | |
| Signed firmware hardware switch | — | |
| System performance — Enterprise Traffic Mix | ||
| IPS throughput | 4.5 Gbps | |
| NGFW throughput | 2.5 Gbps | |
| Threat Protection throughput | 2.2 Gbps | |
| System performance and capacity | ||
| IPv4 firewall throughput (1518 / 512 / 64 byte, UDP) | 28 / 28 / 27.9 Gbps | |
| Firewall latency (64 byte, UDP) | 3.23 μs | |
| Firewall throughput (packets per second) | 41.85 Mpps | |
| Concurrent sessions (TCP) | 3 M | |
| New sessions/second (TCP) | 124 000 | |
| Firewall policies | 5000 | |
| IPsec VPN throughput (512 byte) | 25 Gbps | |
| Gateway-to-gateway IPsec VPN tunnels | 200 | |
| Client-to-gateway IPsec VPN tunnels | 2500 | |
| SSL-VPN throughputSSL VPN only supported between 7.0.12 and 7.0.15 | 1.4 Gbps | |
| Concurrent SSL-VPN users (recommended maximum, tunnel mode) | 200 | |
| SSL inspection throughput (IPS, avg. HTTPS) | 2.6 Gbps | |
| SSL inspection CPS (IPS, avg. HTTPS) | 1400 | |
| SSL inspection concurrent sessions (IPS, avg. HTTPS) | 300 000 | |
| Application control throughput (HTTP 64K) | 6.7 Gbps | |
| CAPWAP throughput (HTTP 64K) | 23.6 Gbps | |
| Virtual domains (default / maximum) | 10 / 10 | |
| Maximum number of FortiSwitches supported | 24 | |
| Maximum number of FortiAPs (total / tunnel mode) | 128 / 64 | |
| Maximum number of FortiTokens | 500 | |
| High availability configurations | Active-Active, Active-Passive, Clustering | |
| Dimensions and mounting | ||
| Height × width × length (inches) | 1.65 x 8.5 x 7.0 | |
| Height × width × length (mm) | 42 x 216 x 178 | |
| Weight | 1.12 kg | |
| Form factor | Desktop | |
| Power | ||
| Input rating | 12V DC, 3A (dual redundancy optional) | |
| Power supply | Up to two external DC power adapters (one included), 100–240 V AC, 50/60 Hz | |
| Maximum current | 115Vac/0.4A, 230Vac/0.2A | |
| Power consumption (average / maximum) | 19.9 W / 20.53 W | 22.4 W / 23.5 W |
| Heat dissipation | 70.0 BTU/hr | 80.1 BTU/hr |
| Power supply efficiency rating | 80 PLUS compliant | |
| Operating environment and certifications | ||
| Operating temperature | 0 to 40 °C | |
| Storage temperature | -35 to 70 °C | |
| Humidity | 10–90%, non-condensing | |
| Noise level | 21.73 dBA | |
| Operating altitude | up to 3,048 m | |
| Compliance | FCC, ICES, CE, RCM, VCCI, BSMI, UL/cUL, CB | |
| Certifications | USGv6/IPv6 | |
Manufacturer data, updated 08.10.2026. Performance measured by Fortinet in lab conditions. Official datasheet (PDF)
Notes
- Note All performance values are “up to” and vary depending on system configuration.
- 1 IPsec VPN performance test uses AES256-SHA256.
- 2 IPS (Enterprise Mix), Application Control, NGFW and Threat Protection are measured with Logging enabled.
- 3 SSL Inspection performance values use an average of HTTPS sessions of different cipher suites.
- 4 NGFW performance is measured with Firewall, IPS and Application Control enabled.
- 5 Threat Protection performance is measured with Firewall, IPS, Application Control and Malware Protection enabled.
- 6 SSL VPN only supported between 7.0.12 and 7.0.15
Box contents and ordering
Sold separately
- Power cable SP-FG60CPCOR-XX sold separately.
Protection needs a subscription
IPS, antivirus and web filtering are updated through a FortiGuard subscription. Bundles: Unified Threat Protection, Enterprise Protection, Advanced Threat Protection — for 1, 3 or 5 years.
Compare bundles
| Enterprise Protection | Unified Threat Protection | Advanced Threat Protection | SD-WAN | |
|---|---|---|---|---|
| IPS — intrusion prevention | ✓ | ✓ | ✓ | — |
| Antivirus and cloud sandbox | ✓ | ✓ | ✓ | — |
| Inline AI sandbox | ✓ | — | — | — |
| Web and DNS filtering | ✓ | ✓ | — | — |
| Botnet and C2 protection | ✓ | ✓ | — | — |
| Antispam | ✓ | ✓ | — | — |
| Data loss prevention (DLP) | ✓ | — | — | — |
| Security Rating | ✓ | — | — | ✓ |
| SD-WAN monitoring and orchestration | — | — | — | ✓ |
| FortiCare Premium 24×7 support | ✓ | ✓ | ✓ | ✓ |
Application control and basic services come with any FortiCare contract. Terms: 1, 3 or 5 years. Most customers choose Unified Threat Protection; Enterprise Protection adds inline sandboxing and data loss prevention (DLP).
Accessories and modules
| SKU | Description | For models |
|---|---|---|
| FG-90G | 8x GE RJ45 ports, 2x 10GE RJ45/SFP+ shared media WAN ports. | FG-90G |
| FG-91G | 8x GE RJ45 ports, 2x 10GE RJ45/SFP+ shared media WAN ports with 120GB SSD. | FG-91G |
| SP-FG60E-PDC-5 | Pack of 5 AC power adaptors for FG/FWF 60E/61E, 60F/61F, 70/71F, 70/71G, 80E/81E, 80/81F, 90/91G and FDC-100G. Power cable SP-FG60CPCOR-XX sold separately. | FG-90G, FG-91G |
| SP-FG60F-MOUNT-20 | Pack of 20 wall mount kits for FG/FWF-60F, FG-90G/91G and FG/FWF-80F series. | FG-90G, FG-91G |
| SP-RACKTRAY-02 | Rack mount tray for all FortiGate E, F, and G series desktop models. | FG-90G, FG-91G |
| SP-EAR-FG90G-10 | Mounting Ear brackets for FG-90/91G 10 pairs pack. | FG-90G, FG-91G |
| FN-TRAN-EX | 1 GE SFP EX transceiver module for all systems with SFP and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-GC | 1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP+slots. | FG-90G, FG-91G |
| FN-TRAN-SFP-1BD40 | 1 GE SFP transceiver module, 40km long range single BiDi for systems with SFP slots (connects to FN-TRAN-1BU40, ordered separately). | FG-90G, FG-91G |
| FN-TRAN-SFP-1BU40 | 1 GE SFP transceiver module, 40km long range single BiDi for systems with SFP slots (connects to FN-TRAN-1BD40, ordered separately). | FG-90G, FG-91G |
| FN-TRAN-SX | 1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-LX | 1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP+ slots. | FG-90G, FG-91G |
| FR-TRAN-ZX | 1 GE SFP transceiver module, long range 90km, LC connector, SMF, 1550nm, -40°C to 85°C, for systems with SFP slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+GC-T80 | 10 GE copper SFP+ RJ45 transceiver module (80m range) for systems with SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+GC | 10 GE SFP+ RJ45 transceiver module for systems with SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+SR | 10 GE SFP+ transceiver module, short range for all systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+LR | 10 GE SFP+ transceiver module, long range for all systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+ER | 10 GE SFP+ transceiver module, extended range for all systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+ZR | 10 GE SFP+ transceiver module, 80km extreme long range, for systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-TRAN-SFP+BD27 | 10 GE SFP+ transceiver module, 30km long range single BiDi for systems with SFP+ and SFP/SFP+ slots (connects to FN-TRAN-SFP+BD33, ordered separately). | FG-90G, FG-91G |
| FN-TRAN-SFP+BD33 | 10 GE SFP+ transceiver module, 30km long range single BiDi for systems with SFP+ and SFP/SFP+ slots (connects to FN-TRAN-SFP+BD27, ordered separately). | FG-90G, FG-91G |
| FN-CABLE-SFP+1 | 10 GE SFP+ passive direct attach cable, 1m for systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-CABLE-SFP+3 | 10 GE SFP+ passive direct attach cable, 3m for systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |
| FN-CABLE-SFP+5 | 10 GE SFP+ passive direct attach cable, 5m for systems with SFP+ and SFP/SFP+ slots. | FG-90G, FG-91G |