
Fortinet FortiGate 200G FG-200G-BDL-809-12 1U Rackmount Firewall, 1-Year Enterprise Protection
Overview
The Fortinet FortiGate 200G Series takes the campus-edge role of the 120G onto a substantially larger platform, with NP7Lite and CP10 hardware acceleration, eight multigigabit copper ports alongside eight gigabit ones, four GE SFP slots and eight separate 10GE SFP+/SFP FortiLink slots. Its largest step over the 120G is session capacity: 11 million concurrent sessions and 400,000 new sessions per second, against 3 million and 140,000 on the 120G at similar firewall throughput. Its Virtual Domain ceiling also rises above its default, from ten to twenty-five, where the 120G stays at ten. The FG-200G-BDL-809-12 is the configuration without onboard storage, so logging goes to FortiAnalyzer, FortiGate Cloud or a syslog collector; the FG-201G is the otherwise closely matched model with a 480 GB SSD. FortiOS forwards both IPv4 and IPv6 traffic; Fortinet does not publish a routing-protocol list for this appliance in the datasheet, which is why the specification table records the protocols as not published while stating IPv6 support. This part number is the bundled configuration: the same appliance supplied with a prepaid FortiGuard Enterprise Protection subscription and FortiCare Premium support for 1 year (12 months). The appliance itself is the FG-200G as sold on its own; what the bundle adds is the FortiGuard service entitlement and 24x7x365 support with one-hour response for critical issues.
Technical Details
The Fortinet FortiGate 200G FG-200G-BDL-809-12 is a 1U rack-mount next-generation firewall with eight gigabit and eight 5 GE multigigabit copper ports, four gigabit SFP slots and eight 10 GE SFP+ FortiLink slots, running FortiOS. Firewall throughput is 39 / 39 / 26.5 Gbps at 1518, 512 and 64-byte UDP, and threat protection throughput is 6 Gbps on the Enterprise Traffic Mix with logging enabled. IPsec VPN throughput is 36 Gbps at 512 bytes with AES256-SHA256, and SSL inspection throughput is 7 Gbps with IPS on average HTTPS. It holds 11 million concurrent TCP sessions and opens 400,000 new sessions per second. It operates from 0 to 40 degrees Celsius and is used at a campus or main-office internet edge, in the DMZ and for segmentation.
Best For
The FG-200G suits a campus or main-office internet edge that needs 6 Gbps of threat protection throughput with 11 million concurrent sessions behind it. Its eight gigabit and eight 5 GE multigigabit copper ports, four gigabit SFP slots and eight 10 GE SFP+ FortiLink slots cover the port requirement. Firewall throughput is 39 Gbps at 1518-byte UDP and 26.5 Gbps at 64 bytes, which is the headroom on uninspected traffic, while 6 Gbps is the figure to size against once inspection is on. Choose it over the FG-201G where logging already goes to FortiAnalyzer, FortiGate Cloud or a syslog collector. As a bundled part number it arrives with 1 year (12 months) of FortiGuard Enterprise Protection and FortiCare Premium support already attached, so the services do not need ordering separately.
Not suitable if:
- you need logs and reports retained on the appliance itself, since this configuration has no onboard storage
- you need Power over Ethernet for cameras or access points, since this appliance provides none
- your inspected traffic exceeds 6 Gbps, since that is the published threat protection throughput
- you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only from 0 to 40 degrees Celsius
- you want a different subscription term or bundle tier, since this part number is fixed at 1 year of Enterprise Protection
FG-200G-BDL-809-12 Specifications
| Ports & Uplinks | |
|---|---|
| Fixed Interfaces | 8×1GbE RJ45, 8×5GbE RJ45, 4×1GbE SFP, 8×10GbE SFP+ |
| Max Port Speed | 10 GbE |
| Management & Console Ports | 1×1GbE RJ45 management, 1×1GbE RJ45 HA, 1×RJ45 console, 1×USB |
| Performance & Scale | |
| Firewall Throughput | 39 / 39 / 26.5 Gbps (1518 / 512 / 64-byte UDP) |
| Threat Prevention Throughput | 6 Gbps (Enterprise Traffic Mix, logging enabled) |
| TLS/SSL Inspection Throughput | 7 Gbps (IPS, average HTTPS) |
| IPsec VPN Throughput | 36 Gbps (512-byte, AES256-SHA256) |
| Power & Thermal | |
| Power Supply | 100-240V AC input (50/60 Hz); dual non-swappable AC power supplies for 1+1 redundancy; maximum current 2A @100VAC, 1.2A @240VAC |
| Redundant Power Supply | Yes |
| Maximum Power Consumption | 175 W (145 W average) |
| Cooling | Forced airflow, side and front to back |
| Physical & Environmental | |
| Operating System | FortiOS |
| Form Factor | 1U Rackmount |
| Dimensions (H x W x D) | 1.75 × 17.0 × 15.0 in (4.445 × 43.2 × 38.0 cm) |
| Weight | 14.11 lb (6.4 kg) |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) |
| Software | |
| Central Management Platform | FortiManager, FortiGate Cloud |
| Routing Protocols & IPv6 | Routing protocols not published; IPv6 supported |
| Other | |
| Maximum Concurrent Sessions | 11,000,000 (TCP) |
| New Sessions per Second | 400,000 (TCP) |
| Maximum IPsec VPN Tunnels | 2,000 gateway-to-gateway, 16,000 client-to-gateway |
| High Availability | Active/Active, Active/Passive, Clustering |
FG-200G-BDL-809-12 Accessories
| Optional Accessories (Sold Separately) | |
|---|---|
| Transceivers | 1 GE SFP SX (FN-TRAN-SX), 1 GE SFP LX (FN-TRAN-LX), 10 GE SFP+ RJ45 (FN-TRAN-SFP+GC), 10 GE SFP+ SR (FN-TRAN-SFP+SR), 10 GE SFP+ LR (FN-TRAN-SFP+LR), 10 GE SFP+ ER (FN-TRAN-SFP+ER), 10 GE SFP+ ZR 80km (FN-TRAN-SFP+ZR), 10 GE SFP+ BiDi 30km (FN-TRAN-SFP+BD27 and FN-TRAN-SFP+BD33), 25 GE SFP28 SR (FN-TRAN-SFP28-SR) |
| Cables | 10 GE SFP+ Passive Direct Attach Cable 1m (FN-CABLE-SFP+1), 3m (FN-CABLE-SFP+3), 5m (FN-CABLE-SFP+5) |
FAQ
Does the Fortinet FortiGate 200G FG-200G-BDL-809-12 support PoE?
No. The FG-200G-BDL-809-12 provides no Power over Ethernet on any port, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are eight gigabit and eight 5 GE multigigabit copper ports, four gigabit SFP slots and eight 10 GE SFP+ FortiLink slots, all data-only. Within the FortiGate G series PoE appears on separate part numbers, not on this one.
What transceivers do the SFP slots on the FG-200G-BDL-809-12 use?
The appliance has four GE SFP slots and eight separate 10GE SFP+/SFP FortiLink slots. Fortinet lists compatible 1 GE SFP and 10 GE SFP+ transceiver modules in the ordering information. Transceivers are sold separately.
How does high availability work on the Fortinet FortiGate 200G FG-200G-BDL-809-12?
The FG-200G-BDL-809-12 supports Active-Active, Active-Passive and Clustering high-availability modes. An HA pair should be two identical models running the same FortiOS build, and the units synchronise configuration and session state over the HA link. This model has a dedicated HA port.
How much traffic can the FG-200G-BDL-809-12 handle?
Fortinet publishes no user count for the FG-200G-BDL-809-12, so size it on the capacity figures. Firewall throughput is 39 / 39 / 26.5 Gbps at 1518, 512 and 64-byte UDP. Small packets cost throughput. Threat protection throughput is 6 Gbps once IPS, application control and malware protection are enabled, and SSL inspection throughput is 7 Gbps; size against those. It holds 11 million concurrent TCP sessions and opens 400,000 new sessions per second. All values are stated as up to.
What is the difference between the FG-200G-BDL-809-12 and the FG-201G?
Their interface layout and published performance specifications are the same: the FG-201G is the otherwise closely matched model with a 480 GB SSD. Weight and power consumption differ between the two models, so read each model's own rows in the specification table. Both run the same FortiOS build and take the same FortiGuard subscriptions.
What is included in the FG-200G-BDL-809-12 bundle?
The FG-200G-BDL-809-12 is the appliance plus a prepaid FortiGuard Enterprise Protection subscription and FortiCare Premium support, both for a term of 1 year (12 months). Enterprise Protection covers IPS, anti-malware, URL, DNS and video filtering, anti-spam, AI-based inline malware prevention, data loss prevention (full features when running FortiOS 7.4.1, per Fortinet) and Attack Surface Security, along with the FortiConverter configuration-conversion service. OT Security and the SD-WAN and SASE services are not part of this bundle. FortiCare Premium provides 24x7x365 availability with one-hour response for critical issues and next-business-day response for everything else.
Does the FG-200G-BDL-809-12 require a subscription to operate?
No. Core firewall, routing and networking functions can continue to operate without an active FortiGuard subscription, while subscription-based security intelligence, updates and services require an active subscription. The FG-200G-BDL-809-12 ships with a prepaid FortiGuard Enterprise Protection subscription and FortiCare Premium support for 1 year (12 months); when that term ends, the FortiGuard intelligence and the support entitlement lapse and can be renewed.
What condition is the FG-200G-BDL-809-12 sold in, and what warranty applies?
Network Devices Inc. supplies the FG-200G-BDL-809-12 new and factory sealed, in original Fortinet packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Because the unit is new rather than renewed, it is eligible for Fortinet registration and for FortiCare and FortiGuard entitlements ordered against it, which is not always the case with refurbished stock. Orders ship from our New Jersey and Texas warehouses.