Fortinet FortiGate 90G FG-90G 8-Port Desktop Firewall with 2x 10GE SFP+

Brand:
Fortinet
Part Number:
FG-90G
Firewall, desktop, 8x GE RJ45, 2x 10GE/GE shared media WAN, up to 28 Gbps firewall, SD-WAN
$3,638.00 $2,474.00 Instant Savings $1,164.00

Net 30 or as low as $—/month Apply Now

Quote

Overview

The Fortinet FortiGate 90G Series is the point in Fortinet's G-series range where 10 gigabit connectivity arrives in a desktop chassis rather than a rack unit. Fortinet positions the line for distributed enterprise sites and branch locations, and builds it on the Secure SD-WAN ASIC SP5, which combines a RISC-based CPU with Fortinet's own content and network processors so that application identification, IPsec and deep SSL inspection run in silicon rather than software. The FG-90G is the variant without an SSD; the otherwise closely matched FG-91G adds a 120 GB drive for on-box logging. Resiliency comes from active-active, active-passive or clustered high availability formed over a data port, since this family has no dedicated HA interface, and power redundancy is optional: the appliance accepts up to two external DC power adapters and one is included. FortiOS forwards both IPv4 and IPv6 traffic; Fortinet does not publish a routing-protocol list for this appliance in the datasheet, which is why the specification table records the protocols as not published while stating IPv6 support.

Technical Details

The Fortinet FortiGate 90G FG-90G is a desktop NGFW with eight GE RJ45 ports and two 10/5/2.5/GE RJ45 or 10GE/GE SFP+/SFP shared-media pairs, running FortiOS on the Secure SD-WAN ASIC SP5. Firewall throughput is 28 / 28 / 27.9 Gbps at 1518, 512 and 64-byte UDP, and threat protection throughput is 2.2 Gbps on the Enterprise Traffic Mix with logging enabled. IPsec VPN throughput is 25 Gbps at 512 bytes with AES256-SHA256, and SSL inspection throughput is 2.6 Gbps with IPS on average HTTPS. It holds 3 million concurrent TCP sessions and opens 124,000 new sessions per second. It operates from 0 to 40 degrees Celsius and is used at distributed enterprise sites for internet-edge protection, site-to-site VPN, and secure SD-WAN.

Best For

The FG-90G suits a distributed enterprise site or branch office that needs an internet edge with 10 gigabit uplink headroom in a unit that sits on a shelf rather than in a rack. Its eight GE access ports, two shared-media 10GE WAN ports and 3 million concurrent sessions fit a site terminating multiple WAN links and running site-to-site VPN back to headquarters, and its FortiSwitch and FortiAP controller capacity of 24 switches and 128 access points (64 in tunnel mode) covers an SD-Branch deployment from the same box. Choose it over the FG-91G where logging already goes to FortiAnalyzer, FortiGate Cloud or a syslog collector.

Not suitable if:

  • you need on-box logging or local reporting stored on the appliance, since this configuration has no internal SSD
  • you need a dedicated high-availability interface, since HA on this family is formed over a data port
  • you need more than two 10 gigabit ports, since the two shared-media WAN pairs are the only ports above 1 gigabit
  • you need Power over Ethernet for cameras or access points, since this appliance provides none
  • you need a rack-mount appliance with internal redundant supplies, since this is a desktop unit whose redundancy comes from a second external adapter
  • you need a hardened appliance for a plant floor or outdoor cabinet, since this unit is rated only from 0 to 40 degrees Celsius

FG-90G Specifications

Ports & Uplinks
Fixed Interfaces8×1GbE RJ45, 2×10GbE RJ45/SFP+ shared-media combo
Max Port Speed10 GbE
Management & Console Ports1×RJ45 console, 1×USB
Performance & Scale
Firewall Throughput28 / 28 / 27.9 Gbps (1518 / 512 / 64-byte UDP)
Threat Prevention Throughput2.2 Gbps (Enterprise Traffic Mix, logging enabled)
TLS/SSL Inspection Throughput2.6 Gbps (IPS, average HTTPS)
IPsec VPN Throughput25 Gbps (512-byte, AES256-SHA256)
Power & Thermal
Power Supply100-240V AC input (50/60 Hz); 12V DC, 3A rating; maximum current 115Vac/0.4A, 230Vac/0.2A
Redundant Power SupplyOptional
Maximum Power Consumption20.53 W (19.9 W average)
Physical & Environmental
Operating SystemFortiOS
Form FactorDesktop
Dimensions (H x W x D)1.65 × 8.5 × 7.0 in (4.2 × 21.6 × 17.8 cm)
Weight2.47 lb (1.12 kg)
Operating Temperature32°F to 104°F (0°C to 40°C)
Software
Central Management PlatformFortiManager, FortiGate Cloud
Routing Protocols & IPv6Routing protocols not published; IPv6 supported
Other
Maximum Concurrent Sessions3,000,000 (TCP)
New Sessions per Second124,000 (TCP)
Maximum IPsec VPN Tunnels200 gateway-to-gateway, 2,500 client-to-gateway
High AvailabilityActive/Active, Active/Passive, Clustering

FG-90G Accessories

Included AccessoriesExternal DC Power Adapter (1 adapter included)
Optional AccessoriesRack Mount Tray (SP-RACKTRAY-02) Wall Mount Kit, pack of 20 (SP-FG60F-MOUNT-20) Mounting Ear Bracket, 10 pairs pack (SP-EAR-FG90G-10) AC Power Adaptor, pack of 5 (SP-FG60E-PDC-5) 1 GE SFP RJ45 Transceiver Module (FN-TRAN-GC) 1 GE SFP SX Transceiver Module (FN-TRAN-SX) 1 GE SFP LX Transceiver Module (FN-TRAN-LX) 1 GE SFP Transceiver Module, 90km range (FR-TRAN-ZX) 10 GE SFP+ RJ45 Transceiver Module (FN-TRAN-SFP+GC) 10 GE SFP+ Transceiver Module, Short Range (FN-TRAN-SFP+SR) 10 GE SFP+ Transceiver Module, Long Range (FN-TRAN-SFP+LR) 10 GE SFP+ Transceiver Module, Extended Range (FN-TRAN-SFP+ER) 10 GE SFP+ Transceiver Module, 30km Long Range Single BiDi (FN-TRAN-SFP+BD27) 10 GE SFP+ Transceiver Module, 30km Long Range Single BiDi (FN-TRAN-SFP+BD33) 10 GE SFP+ Passive Direct Attach Cable, 1m (FN-CABLE-SFP+1) 10 GE SFP+ Passive Direct Attach Cable, 3m (FN-CABLE-SFP+3) 10 GE SFP+ Passive Direct Attach Cable, 5m (FN-CABLE-SFP+5)

FAQ

Does the Fortinet FortiGate FG-90G support PoE?

No. The FG-90G provides no Power over Ethernet on any port, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its eight GE RJ45 ports and two 10/5/2.5/GE RJ45 or 10GE/GE SFP+/SFP shared-media pairs are all data-only. Input rating is 12V DC, 3A from an external adapter. Within the G series PoE appears on separate part numbers such as the 70G-POE models.

What transceivers do the shared-media ports on the FG-90G use?

The FG-90G has two shared-media pairs, each operating as either a 10/5/2.5/GE RJ45 port or a 10GE/GE SFP+/SFP slot. A pair is one port with two physical options rather than two ports, so the copper and pluggable sides cannot be used at once. The pluggable side takes Fortinet 1 GE SFP and 10 GE SFP+ transceiver modules, listed in the ordering information. Transceivers are sold separately.

How does high availability work on the FG-90G?

The FG-90G supports Active-Active, Active-Passive and Clustering high-availability modes. This model has no dedicated HA port, so the heartbeat and synchronisation link runs over one of the data ports, which reduces the ports left for traffic. An HA pair should be two identical models on the same FortiOS build. Optional power redundancy is supported using up to two external DC power adapters; one adapter is included.

How many users can the FG-90G handle?

Fortinet publishes no user count for the FG-90G, so size it on the capacity figures. The appliance holds 3 million concurrent TCP sessions and opens 124,000 new sessions per second, which is usually what runs out first at a branch site. Threat protection throughput is 2.2 Gbps and SSL inspection throughput is 2.6 Gbps; size against those, not the 28 / 28 / 27.9 Gbps firewall throughput. All values are stated as up to.

What is the difference between the FG-90G and the FG-91G?

The two appliances are closely matched: the datasheet publishes the same performance figures, port layout, dimensions, weight and operating range for both. The difference that matters is storage: the FG-91G carries one 120 GB SSD and the FG-90G carries none. The FG-91G also has a higher power consumption. That drive is what makes on-box logging and local reporting possible, so the FG-91G suits a site needing log retention on the appliance, while the FG-90G suits one already sending logs to FortiAnalyzer, FortiGate Cloud or syslog.

Does the FG-90G require a subscription to operate?

No. Core firewall, routing and networking functions can continue to operate without an active FortiGuard subscription, while subscription-based security intelligence, updates and services require an active subscription. A FortiGuard subscription supplies IPS signatures, anti-malware, URL and DNS filtering and the rest of the catalogue, along with FortiCare support. This plain part number is the appliance on its own, with FortiGuard services and FortiCare sold separately.

Does the FG-90G support SSL-VPN?

The datasheet lists SSL-VPN throughput of 1.4 Gbps and a recommended maximum of 200 concurrent SSL-VPN users in tunnel mode, with SSL-VPN support limited to FortiOS versions 7.0.12 through 7.0.15. On a FortiOS build outside that range, remote access on the FG-90G means IPsec VPN, for which the datasheet publishes 25 Gbps of throughput and up to 2,500 client-to-gateway tunnels.

What condition is the FG-90G sold in, and what warranty applies?

Network Devices Inc. supplies the FG-90G new and factory sealed, in original Fortinet packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Because the unit is new rather than renewed, it is eligible for Fortinet registration and for FortiCare and FortiGuard entitlements ordered against it, which is not always the case with refurbished stock. Orders ship from our New Jersey and Texas warehouses.

Reviews