Fortinet FortiGate 70G FG-70G-BDL-950-36 Desktop Firewall, 3-Year Unified Threat Protection (UTP)

Brand:
Fortinet
Part Number:
FG-70G-BDL-950-36
Desktop firewall, SP5 ASIC, 10x GE RJ45 (2 WAN/7 internal/1 DMZ), 2.5 Gbps IPS, SD-WAN, including 3 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP)
$3,644.78 $2,479.00 Instant Savings $1,165.78

Net 30 or as low as $—/month Apply Now

Quote

Overview

The Fortinet FortiGate 70G Series sits a step above the 50G in a fanless desktop chassis of the same dimensions, and the step is a real one: two WAN ports instead of one, ten gigabit ports instead of five, double the 1518-byte firewall throughput and nearly double the session capacity. That combination suits a branch that terminates two WAN links for SD-WAN path selection rather than a single circuit with a backup. It runs FortiOS with ten Virtual Domains, controller capacity for 24 FortiSwitches and 96 FortiAPs (48 in tunnel mode), and active-active, active-passive or clustered high availability. The main functional difference between the FG-70G-BDL-950-36 and FG-71G is onboard storage. The FG-70G-BDL-950-36 is the configuration without onboard storage, so logging goes to FortiAnalyzer, FortiGate Cloud or a syslog collector; the FG-71G is the otherwise closely matched model with a 64 GB SSD. FortiOS forwards both IPv4 and IPv6 traffic; Fortinet does not publish a routing-protocol list for this appliance in the datasheet, which is why the specification table records the protocols as not published while stating IPv6 support. This part number is the bundled configuration: the same appliance supplied with a prepaid FortiGuard Unified Threat Protection (UTP) subscription and FortiCare Premium support for 3 years (36 months). The appliance itself is the FG-70G as sold on its own; what the bundle adds is the FortiGuard service entitlement and 24x7x365 support with one-hour response for critical issues.

Technical Details

The Fortinet FortiGate 70G FG-70G-BDL-950-36 is a desktop next-generation firewall with ten gigabit Ethernet copper ports, two of them WAN ports, running FortiOS. Firewall throughput is 10 / 10 / 10 Gbps at 1518, 512 and 64-byte UDP, and threat protection throughput is 1.3 Gbps on the Enterprise Traffic Mix with logging enabled. IPsec VPN throughput is 7.1 Gbps at 512 bytes with AES256-SHA256, and SSL inspection throughput is 1.4 Gbps with IPS on average HTTPS. It holds 1.4 million concurrent TCP sessions and opens 100,000 new sessions per second. It operates from 0 to 40 degrees Celsius and is used at a small office or branch site for internet-edge protection, site-to-site VPN, and secure SD-WAN.

Best For

The FG-70G suits a branch office or small site that needs 1.3 Gbps of threat protection throughput with 1.4 million concurrent sessions behind it. Its ten gigabit Ethernet copper ports, two of them WAN ports cover the port requirement. Firewall throughput is 10 Gbps at 1518-byte UDP and 10 Gbps at 64 bytes, which is the headroom on uninspected traffic, while 1.3 Gbps is the figure to size against once inspection is on. Choose it over the FG-71G where logging already goes to FortiAnalyzer, FortiGate Cloud or a syslog collector. As a bundled part number it arrives with 3 years (36 months) of FortiGuard Unified Threat Protection (UTP) and FortiCare Premium support already attached, so the services do not need ordering separately.

Not suitable if:

  • you need logs and reports retained on the appliance itself, since this configuration has no onboard storage
  • you need Power over Ethernet for cameras or access points, since this appliance provides none
  • your inspected traffic exceeds 1.3 Gbps, since that is the published threat protection throughput
  • you need SSL-VPN, since the datasheet lists SSL-VPN throughput and concurrent SSL-VPN users as N/A on this model
  • you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only from 0 to 40 degrees Celsius
  • you want a different subscription term or bundle tier, since this part number is fixed at 3 years of Unified Threat Protection (UTP)

FG-70G-BDL-950-36 Specifications

Ports & Uplinks
Fixed Interfaces10×1GbE RJ45
Max Port Speed1 GbE
Management & Console Ports1×RJ45 console, 1×USB
Performance & Scale
Firewall Throughput10 / 10 / 10 Gbps (1518 / 512 / 64-byte UDP)
Threat Prevention Throughput1.3 Gbps (Enterprise Traffic Mix, logging enabled)
TLS/SSL Inspection Throughput1.4 Gbps (IPS, average HTTPS)
IPsec VPN Throughput7.1 Gbps (512-byte, AES256-SHA256)
Power & Thermal
Power SupplyPowered by external DC power adapter, 100-240V AC, 50/60 Hz; 12V DC, 3A rating; maximum current 100V/0.4A, 240V/0.2A
Redundant Power SupplyNo
Maximum Power Consumption12.8 W (12.3 W average)
CoolingFanless
Physical & Environmental
Operating SystemFortiOS
Form FactorDesktop
Dimensions (H x W x D)1.6 × 8.5 × 6.3 in (4.05 × 21.6 × 16.0 cm)
Weight2.01 lb (0.91 kg)
Operating Temperature32°F to 104°F (0°C to 40°C)
Software
Central Management PlatformFortiManager, FortiGate Cloud
Routing Protocols & IPv6Routing protocols not published; IPv6 supported
Other
Maximum Concurrent Sessions1,400,000 (TCP)
New Sessions per Second100,000 (TCP)
Maximum IPsec VPN Tunnels200 gateway-to-gateway, 500 client-to-gateway
High AvailabilityActive/Active, Active/Passive, Clustering

FG-70G-BDL-950-36 Accessories

Accessory TypeDescription
OptionalRack Mount Tray (SP-RACKTRAY-02), Wall Mount Kit (SP-FG60F-MOUNT-20), Mounting Ear Brackets (SP-EAR-FG90G-10), AC Power Adaptor (SP-FG60E-PDC-5, pack of 5; power cable SP-FG60CPCOR-XX sold separately). For PoE models: AC Power Adaptor (SP-FG50G-POE-PDC-5, pack of 5; power cable SP-FGPCOR-XX sold separately).

FAQ

Does the Fortinet FortiGate 70G FG-70G-BDL-950-36 support PoE?

No. The FG-70G-BDL-950-36 provides no Power over Ethernet on any port, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are ten gigabit Ethernet copper ports, two of them WAN ports, all data-only. Within the FortiGate G series PoE appears on separate part numbers, not on this one.

What ports does the FG-70G-BDL-950-36 have?

The FG-70G-BDL-950-36 provides ten gigabit Ethernet copper ports, two of them WAN ports, plus one RJ45 console port. There are no pluggable transceiver slots on this configuration, so every interface is fixed copper and no optics are ordered against it. It also has one USB port.

How does high availability work on the Fortinet FortiGate 70G FG-70G-BDL-950-36?

The FG-70G-BDL-950-36 supports Active-Active, Active-Passive and Clustering high-availability modes. An HA pair should be two identical models running the same FortiOS build, and the units synchronise configuration and session state over the HA link. This model has no dedicated HA port, so the HA link runs over a data port.

How much traffic can the FG-70G-BDL-950-36 handle?

Fortinet publishes no user count for the FG-70G-BDL-950-36, so size it on the capacity figures. Firewall throughput is 10 / 10 / 10 Gbps at 1518, 512 and 64-byte UDP. Threat protection throughput is 1.3 Gbps once IPS, application control and malware protection are enabled, and SSL inspection throughput is 1.4 Gbps; size against those. It holds 1.4 million concurrent TCP sessions and opens 100,000 new sessions per second. All values are stated as up to.

What is the difference between the FG-70G-BDL-950-36 and the FG-71G?

Their interface layout and published performance specifications are the same: the FG-71G is the otherwise closely matched model with a 64 GB SSD. Weight and power consumption differ between the two models, so read each model's own rows in the specification table. Both run the same FortiOS build and take the same FortiGuard subscriptions.

What is included in the FG-70G-BDL-950-36 bundle?

The FG-70G-BDL-950-36 is the appliance plus a prepaid FortiGuard Unified Threat Protection (UTP) subscription and FortiCare Premium support, both for a term of 3 years (36 months). Unified Threat Protection (UTP) covers IPS, anti-malware, URL, DNS and video filtering, and anti-spam. AI-based inline malware prevention, data loss prevention and Attack Surface Security are Enterprise Protection services, not UTP ones. FortiCare Premium provides 24x7x365 availability with one-hour response for critical issues and next-business-day response for everything else.

Does the FG-70G-BDL-950-36 require a subscription to operate?

No. Core firewall, routing and networking functions can continue to operate without an active FortiGuard subscription, while subscription-based security intelligence, updates and services require an active subscription. The FG-70G-BDL-950-36 ships with a prepaid FortiGuard Unified Threat Protection (UTP) subscription and FortiCare Premium support for 3 years (36 months); when that term ends, the FortiGuard intelligence and the support entitlement lapse and can be renewed.

What condition is the FG-70G-BDL-950-36 sold in, and what warranty applies?

Network Devices Inc. supplies the FG-70G-BDL-950-36 new and factory sealed, in original Fortinet packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Because the unit is new rather than renewed, it is eligible for Fortinet registration and for FortiCare and FortiGuard entitlements ordered against it, which is not always the case with refurbished stock. Orders ship from our New Jersey and Texas warehouses.

Reviews