
Fortinet FortiGate 901G FG-901G 1U Rackmount Firewall with 2x 480GB SSD
Overview
The Fortinet FortiGate 900G Series is a 1RU data-centre edge platform with Ultra Low Latency 25GE/10GE SFP28/SFP+ interfaces. The datasheet publishes firewall latency figures of 3.78 / 2.5 microseconds, with the latency measurement based on the Ultra Low Latency ports. The series uses SPU NP7 and CP9 acceleration, supports 28 million concurrent TCP sessions and 50,000 firewall policies, and is available in AC and DC power variants. Both the AC and DC models use dual hot-swappable power supplies. Two SFP SX transceivers are included. The FG-901G is the stored variant, adding two 480 GB SSDs so logging and reporting can stay on the appliance instead of depending on a collector; the FG-900G is the otherwise closely matched model without the SSDs. FortiOS forwards both IPv4 and IPv6 traffic; Fortinet does not publish a routing-protocol list for this appliance in the datasheet, which is why the specification table records the protocols as not published while stating IPv6 support.
Technical Details
The Fortinet FortiGate 901G FG-901G is a 1U rack-mount next-generation firewall with sixteen gigabit Ethernet copper ports, eight gigabit SFP slots, four 10 GE SFP+ slots and four Ultra Low Latency 25 GE SFP28 slots and two 480 GB SSDs, running FortiOS. Firewall throughput is 164 / 163 / 153 Gbps at 1518, 512 and 64-byte UDP, and threat protection throughput is 30 Gbps on the Enterprise Traffic Mix with logging enabled. IPsec VPN throughput is 55 Gbps at 512 bytes with AES256-SHA256, and SSL inspection throughput is 16.7 Gbps with IPS on average HTTPS. It holds 28 million concurrent TCP sessions and opens 720,000 new sessions per second. Power comes from dual hot-swappable AC power supplies. It operates from 0 to 45 degrees Celsius and is used at a data-centre edge for north-south inspection, DMZ segmentation and high-throughput VPN aggregation.
Best For
The FG-901G suits a data-centre edge that needs 30 Gbps of threat protection throughput with 28 million concurrent sessions behind it. Its sixteen gigabit Ethernet copper ports, eight gigabit SFP slots, four 10 GE SFP+ slots and four Ultra Low Latency 25 GE SFP28 slots cover the port requirement. Firewall throughput is 164 Gbps at 1518-byte UDP and 153 Gbps at 64 bytes, which is the headroom on uninspected traffic, while 30 Gbps is the figure to size against once inspection is on. Choose it over the FG-900G where logs need to be retained on the appliance itself.
Not suitable if:
- you already send all logging to FortiAnalyzer, FortiGate Cloud or a syslog collector, since the onboard storage would then go unused
- you need Power over Ethernet for cameras or access points, since this appliance provides none
- your inspected traffic exceeds 30 Gbps, since that is the published threat protection throughput
- you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only from 0 to 45 degrees Celsius
FG-901G Specifications
| Ports & Uplinks | |
|---|---|
| Fixed Interfaces | 16×1GbE RJ45, 8×1GbE SFP, 4×10GbE SFP+, 4×25GbE SFP28 |
| Max Port Speed | 25 GbE |
| Management & Console Ports | 1×1GbE RJ45 management, 1×2.5GbE RJ45 HA, 1×RJ45 console, 2×USB |
| Performance & Scale | |
| Firewall Throughput | 164 / 163 / 153 Gbps (1518 / 512 / 64-byte UDP) |
| Threat Prevention Throughput | 30 Gbps (Enterprise Traffic Mix, logging enabled) |
| TLS/SSL Inspection Throughput | 16.7 Gbps (IPS, average HTTPS) |
| IPsec VPN Throughput | 55 Gbps (512-byte, AES256-SHA256) |
| Hardware & Memory | |
| Onboard Storage | 2×480 GB SSD |
| Power & Thermal | |
| Power Supply | 100-240V AC input (50/60 Hz); dual hot-swappable power supplies, two fitted by default; maximum current 6A @100VAC |
| Redundant Power Supply | Yes |
| Maximum Power Consumption | 323 W (184 W average) |
| Cooling | Forced airflow, side and front to back |
| Physical & Environmental | |
| Operating System | FortiOS |
| Form Factor | 1U Rackmount |
| Dimensions (H x W x D) | 1.75 × 17.0 × 15.0 in (4.445 × 43.2 × 38.0 cm) |
| Weight | 16.53 lb (7.5 kg) |
| Operating Temperature | 32°F to 113°F (0°C to 45°C) |
| Software | |
| Central Management Platform | FortiManager, FortiGate Cloud |
| Routing Protocols & IPv6 | Routing protocols not published; IPv6 supported |
| Other | |
| Maximum Concurrent Sessions | 28,000,000 (TCP) |
| New Sessions per Second | 720,000 (TCP) |
| Maximum IPsec VPN Tunnels | 2,000 gateway-to-gateway, 50,000 client-to-gateway |
| High Availability | Active/Active, Active/Passive, Clustering |
FG-901G Accessories
| Included Accessories | 2x SFP SX Transceivers, Dual Hot Swappable Power Supplies |
| Optional Accessories | AC Power Supply (SP-FG400F-PS), 1 GE SFP Transceivers (LX, RJ45, SX), 10 GE SFP+ Transceivers (RJ45, SR, LR, ER, ZR, BiDi), 25 GE SFP28 Transceivers (SR, LR), DAC Cables (10 GE SFP+, 25 GE SFP28) |
FAQ
Does the Fortinet FortiGate 901G FG-901G support PoE?
No. The FG-901G provides no Power over Ethernet on any port, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are sixteen gigabit Ethernet copper ports, eight gigabit SFP slots, four 10 GE SFP+ slots and four Ultra Low Latency 25 GE SFP28 slots, all data-only. Within the FortiGate G series PoE appears on separate part numbers, not on this one.
What transceivers do the SFP slots on the FG-901G use?
The appliance has eight GE SFP slots, four 10GE/GE SFP+/SFP slots, and four separate 25GE/10GE SFP28/SFP+ Ultra Low Latency slots. Fortinet lists the compatible transceiver modules in the ordering information. Two SFP SX transceivers are included. Other transceivers are sold separately.
How does high availability work on the Fortinet FortiGate 901G FG-901G?
The FG-901G supports Active-Active, Active-Passive and Clustering high-availability modes. An HA pair should be two identical models running the same FortiOS build, and the units synchronise configuration and session state over the HA link. This model has a dedicated HA port.
How much traffic can the FG-901G handle?
Fortinet publishes no user count for the FG-901G, so size it on the capacity figures. Firewall throughput is 164 / 163 / 153 Gbps at 1518, 512 and 64-byte UDP. Small packets cost throughput. Threat protection throughput is 30 Gbps once IPS, application control and malware protection are enabled, and SSL inspection throughput is 16.7 Gbps; size against those. It holds 28 million concurrent TCP sessions and opens 720,000 new sessions per second. All values are stated as up to.
What is the difference between the FG-901G and the FG-900G?
Their interface layout and published performance specifications are the same: the FG-900G is the otherwise closely matched model without the SSDs. Weight and power consumption differ between the two models, so read each model's own rows in the specification table. Both run the same FortiOS build and take the same FortiGuard subscriptions.
Does the FG-901G require a subscription to operate?
No. Core firewall, routing and networking functions can continue to operate without an active FortiGuard subscription, while subscription-based security intelligence, updates and services require an active subscription. A FortiGuard subscription supplies IPS signatures, anti-malware, URL and DNS filtering and the rest of the catalogue, along with FortiCare support. This plain part number is the appliance on its own, with FortiGuard services and FortiCare sold separately. The FG-901G-BDL part numbers bundle a prepaid subscription for one, three or five years.
What condition is the FG-901G sold in, and what warranty applies?
Network Devices Inc. supplies the FG-901G new and factory sealed, in original Fortinet packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Because the unit is new rather than renewed, it is eligible for Fortinet registration and for FortiCare and FortiGuard entitlements ordered against it, which is not always the case with refurbished stock. Orders ship from our New Jersey and Texas warehouses.