
Fortinet FortiGate 31G FG-31G 4-Port Desktop Firewall
Overview
The Fortinet FortiGate 30G Series is a compact desktop appliance of 1.3 lb with four gigabit copper ports, no SFP cage and no USB port, built for a small office or retail site that needs a next-generation firewall rather than a router with filtering bolted on. It runs FortiOS with integrated Secure SD-WAN and Security Fabric support. What the platform does not carry is as important as what it does: Virtual Domains are not supported, no SSL-VPN throughput or concurrent-user figures are published, and high availability is limited to active-active and active-passive without clustering. The FG-31G is the stored variant, adding 30 GB of onboard storage so logging and reporting can stay on the appliance instead of depending on a collector; the FG-30G is the otherwise closely matched model without onboard storage. FortiOS forwards both IPv4 and IPv6 traffic; Fortinet does not publish a routing-protocol list for this appliance in the datasheet, which is why the specification table records the protocols as not published while stating IPv6 support.
Technical Details
The Fortinet FortiGate 31G FG-31G is a desktop next-generation firewall with one gigabit RJ45 WAN port, two gigabit RJ45 ports and a gigabit RJ45 FortiLink port and 30 GB of onboard storage, running FortiOS. Firewall throughput is 4 / 4 / 3.9 Gbps at 1518, 512 and 64-byte UDP, and threat protection throughput is 0.5 Gbps on the Enterprise Traffic Mix with logging enabled. IPsec VPN throughput is 3.5 Gbps at 512 bytes with AES256-SHA256, and SSL inspection throughput is 0.4 Gbps with IPS on average HTTPS. It holds 600,000 concurrent TCP sessions and opens 30,000 new sessions per second. It operates from 0 to 40 degrees Celsius and is used at a small office or branch site for internet-edge protection, site-to-site VPN, and secure SD-WAN.
Best For
The FG-31G suits a branch office or small site that needs 0.5 Gbps of threat protection throughput with 600,000 concurrent sessions behind it. Its one gigabit RJ45 WAN port, two gigabit RJ45 ports and a gigabit RJ45 FortiLink port cover the port requirement. Firewall throughput is 4 Gbps at 1518-byte UDP and 3.9 Gbps at 64 bytes, which is the headroom on uninspected traffic, while 0.5 Gbps is the figure to size against once inspection is on. Choose it over the FG-30G where logs need to be retained on the appliance itself.
Not suitable if:
- you already send all logging to FortiAnalyzer, FortiGate Cloud or a syslog collector, since the onboard storage would then go unused
- you need Power over Ethernet for cameras or access points, since this appliance provides none
- your inspected traffic exceeds 0.5 Gbps, since that is the published threat protection throughput
- you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only from 0 to 40 degrees Celsius
- you need Virtual Domains, since they are not supported on this platform
- you need SSL-VPN, since no SSL-VPN throughput or concurrent-user figures are published for this model
- you need clustered high availability, since this model supports only active-active and active-passive modes
- you need a USB port for provisioning or an external modem, since this model has none
FG-31G Specifications
| Ports & Uplinks | |
|---|---|
| Fixed Interfaces | 4×1GbE RJ45 |
| Max Port Speed | 1 GbE |
| Management & Console Ports | 1×RJ45 console |
| Performance & Scale | |
| Firewall Throughput | 4 / 4 / 3.9 Gbps (1518 / 512 / 64-byte UDP) |
| Threat Prevention Throughput | 0.5 Gbps (Enterprise Traffic Mix, logging enabled) |
| TLS/SSL Inspection Throughput | 0.4 Gbps (IPS, average HTTPS) |
| IPsec VPN Throughput | 3.5 Gbps (512-byte, AES256-SHA256) |
| Hardware & Memory | |
| Onboard Storage | 30 GB |
| Power & Thermal | |
| Power Supply | Powered by external DC power adapter, 100-240V AC, 50/60 Hz; 12V DC, 2A rating; maximum current 110V/0.17A, 240V/0.085A |
| Redundant Power Supply | No |
| Maximum Power Consumption | 9.3 W (8.1 W average) |
| Physical & Environmental | |
| Operating System | FortiOS |
| Form Factor | Desktop |
| Dimensions (H x W x D) | 1.6 × 5.6 × 6.3 in (4.05 × 14.2 × 16.0 cm) |
| Weight | 1.3 lb (0.6 kg) |
| Operating Temperature | 32°F to 104°F (0°C to 40°C) |
| Software | |
| Central Management Platform | FortiManager, FortiGate Cloud |
| Routing Protocols & IPv6 | Routing protocols not published; IPv6 supported |
| Other | |
| Maximum Concurrent Sessions | 600,000 (TCP) |
| New Sessions per Second | 30,000 (TCP) |
| Maximum IPsec VPN Tunnels | 200 gateway-to-gateway, 250 client-to-gateway |
| High Availability | Active/Active, Active/Passive |
FG-31G Accessories
| Accessory Type | Description |
| Optional | Wall Mount Kit (SP-FG60F-MOUNT-20, pack of 20), AC Power Adaptor (SP-FG-30G-PA-10(-XX), pack of 10; -XX = country code) |
FAQ
Does the Fortinet FortiGate 31G FG-31G support PoE?
No. The FG-31G provides no Power over Ethernet on any port, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are one gigabit RJ45 WAN port, two gigabit RJ45 ports and a gigabit RJ45 FortiLink port, all data-only. Within the FortiGate G series PoE appears on separate part numbers, not on this one.
What ports does the FG-31G have?
The FG-31G provides one gigabit RJ45 WAN port, two gigabit RJ45 ports and a gigabit RJ45 FortiLink port, plus one RJ45 console port. There are no pluggable transceiver slots on this configuration, so every interface is fixed copper and no optics are ordered against it. This model has no USB port.
How does high availability work on the Fortinet FortiGate 31G FG-31G?
The FG-31G supports Active-Active and Active-Passive high-availability modes. An HA pair should be two identical models running the same FortiOS build, and the units synchronise configuration and session state over the HA link. This model has no dedicated HA port, so the HA link runs over a data port.
How much traffic can the FG-31G handle?
Fortinet publishes no user count for the FG-31G, so size it on the capacity figures. Firewall throughput is 4 / 4 / 3.9 Gbps at 1518, 512 and 64-byte UDP. Small packets cost throughput. Threat protection throughput is 0.5 Gbps once IPS, application control and malware protection are enabled, and SSL inspection throughput is 0.4 Gbps; size against those. It holds 600,000 concurrent TCP sessions and opens 30,000 new sessions per second. All values are stated as up to.
What is the difference between the FG-31G and the FG-30G?
Their interface layout and published performance specifications are the same: the FG-30G is the otherwise closely matched model without onboard storage. Power consumption differs between the two models while the published weight is the same, so read each model's own row in the specification table. Both run the same FortiOS build and take the same FortiGuard subscriptions.
Does the FG-31G require a subscription to operate?
No. Core firewall, routing and networking functions can continue to operate without an active FortiGuard subscription, while subscription-based security intelligence, updates and services require an active subscription. A FortiGuard subscription supplies IPS signatures, anti-malware, URL and DNS filtering and the rest of the catalogue, along with FortiCare support. This plain part number is the appliance on its own, with FortiGuard services and FortiCare sold separately. The FG-31G-BDL part numbers bundle a prepaid subscription for one, three or five years.
What condition is the FG-31G sold in, and what warranty applies?
Network Devices Inc. supplies the FG-31G new and factory sealed, in original Fortinet packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Because the unit is new rather than renewed, it is eligible for Fortinet registration and for FortiCare and FortiGuard entitlements ordered against it, which is not always the case with refurbished stock. Orders ship from our New Jersey and Texas warehouses.