Fortinet FGR-50G-5G-BDL-809-36 DIN-Rail Firewall, 3-Year Enterprise Protection

Brand:
Fortinet
Part Number:
FGR-50G-5G-BDL-809-36
Rugged next-generation firewall, integrated 5G WWAN with dual SIM, 6× Gigabit Ethernet RJ45 ports, 2× GE SFP slots, fanless DIN-rail industrial design, including 3 year FortiCare Premium and FortiGuard Enterprise Protection.
$16,261.96 $11,059.00 Instant Savings $5,202.96

Net 30 or as low as $—/month Apply Now

Quote

Overview

The Fortinet FortiGate Rugged Series brings FortiOS to the plant floor: fanless, DIN-rail mounted, IP40-rated appliances that run from -40 to 75 degrees Celsius on redundant DC inputs, certified to IEC 61850-3 and IEEE 1613 for electric power substations and to EN 50155 and EN 50121 for rail. The constraint to know before specifying one is SSL-VPN: the datasheet lists SSL-VPN throughput and concurrent users as N/A for this model and notes that SSL-VPN is not supported on FortiOS 7.6.0 and above for models with 2 GB of RAM, so plan remote access on IPsec VPN. The FGR-50G-5G-BDL-809-36 is the configuration without onboard storage, so logging goes to FortiAnalyzer, FortiGate Cloud or a syslog collector; the FGR-70G is a higher-throughput platform with a bypass port pair and a MicroSD slot but no cellular modem, on a 12 to 125V DC input rather than 12 to 54V. FortiOS forwards both IPv4 and IPv6 traffic; Fortinet does not publish a routing-protocol list for this appliance in the datasheet, which is why the specification table records the protocols as not published while stating IPv6 support. This part number is the bundled configuration: the same appliance supplied with a prepaid FortiGuard Enterprise Protection subscription and FortiCare Premium support for 3 years (36 months). The appliance itself is the FGR-50G-5G as sold on its own; what the bundle adds is the FortiGuard service entitlement and 24x7x365 support with one-hour response for critical issues.

Technical Details

The Fortinet FortiGate Rugged 50G-5G FGR-50G-5G-BDL-809-36 is a DIN-rail industrial next-generation firewall with six gigabit Ethernet copper ports, two gigabit SFP slots and one embedded 5G cellular module with two SIM slots, running FortiOS on the FortiSP5 processor. Firewall throughput is 6 / 6 / 6 Gbps at 1518, 512 and 64-byte UDP, and threat protection throughput is 1.1 Gbps on the Enterprise Traffic Mix with logging enabled. IPsec VPN throughput is 5.3 Gbps at 512 bytes with AES256-SHA256, and SSL inspection throughput is 1.3 Gbps with IPS on average HTTPS. It holds 700,000 concurrent TCP sessions and opens 85,000 new sessions per second. It operates from -40 to 75 degrees Celsius on redundant DC inputs and is used in OT and industrial networks to segment PLC and SCADA traffic at the plant floor, in a substation, or in a remote cabinet.

Best For

The FGR-50G-5G suits an OT or industrial network that needs 1.1 Gbps of threat protection throughput with 700,000 concurrent sessions behind it. Its six gigabit Ethernet copper ports, two gigabit SFP slots and one embedded 5G cellular module with two SIM slots cover the port requirement. Firewall throughput is 6 Gbps at 1518-byte UDP and 6 Gbps at 64 bytes, which is the headroom on uninspected traffic, while 1.1 Gbps is the figure to size against once inspection is on. Choose it over the FGR-70G where the site needs an embedded 5G cellular WAN link. As a bundled part number it arrives with 3 years (36 months) of FortiGuard Enterprise Protection and FortiCare Premium support already attached, so the services do not need ordering separately.

Not suitable if:

  • you need logs and reports retained on the appliance itself, since this configuration has no onboard storage
  • you need Power over Ethernet for cameras or access points, since this appliance provides none
  • your inspected traffic exceeds 1.1 Gbps, since that is the published threat protection throughput
  • you need SSL-VPN remote access, since the datasheet lists SSL-VPN as N/A for this model
  • you want a different subscription term or bundle tier, since this part number is fixed at 3 years of Enterprise Protection

FGR-50G-5G-BDL-809-36 Specifications

Ports & Uplinks
Fixed Interfaces6×1GbE RJ45, 2×1GbE SFP, 1×embedded 5G WWAN module (2 SIM slots)
Max Port Speed1 GbE
Management & Console Ports1×RJ45 console, 1×RJ45 serial, 1×USB
Performance & Scale
Firewall Throughput6 / 6 / 6 Gbps (1518 / 512 / 64-byte UDP)
Threat Prevention Throughput1.1 Gbps (Enterprise Traffic Mix, logging enabled)
TLS/SSL Inspection Throughput1.3 Gbps (IPS, average HTTPS)
IPsec VPN Throughput5.3 Gbps (512-byte, AES256-SHA256)
Power & Thermal
Power Supply12V to 54V DC redundant dual inputs, 2 pins per terminal block, negative or positive ground; DC cables not included
Redundant Power SupplyYes
Maximum Power Consumption24 W (16 W average)
CoolingFanless
Physical & Environmental
Operating SystemFortiOS
Form FactorDIN-rail
Dimensions (H x W x D)5.47 × 3.52 × 4.8 in (13.9 × 8.95 × 12.2 cm)
Weight3.97 lb (1.8 kg)
Operating Temperature-40°F to 167°F (-40°C to 75°C)
Software
Central Management PlatformFortiManager, FortiGate Cloud
Routing Protocols & IPv6Routing protocols not published; IPv6 supported
Other
Maximum Concurrent Sessions700,000 (TCP)
New Sessions per Second85,000 (TCP)
Maximum IPsec VPN Tunnels200 gateway-to-gateway, 250 client-to-gateway
High AvailabilityActive/Active, Active/Passive, Clustering

FGR-50G-5G-BDL-809-36 Accessories

Included in the boxEmbedded 5G WWAN module, 4 × external SMA WWAN antennas, 1 × external SMA GPS antenna
Optional SFP ModulesFN-TRAN-GC, FN-TRAN-LX, FR-TRAN-SX, FR-TRAN-ZX, FN-TRAN-FX
Optional Power SupplyFortiPSU Rugged DIN Rail 240W (SP-RGDIN-240-PS)

FAQ

Does the Fortinet FortiGate Rugged 50G-5G FGR-50G-5G-BDL-809-36 support PoE?

No. The FGR-50G-5G-BDL-809-36 provides no Power over Ethernet on any port, so cameras, access points and IP phones need their own power source or a PoE switch between them and the firewall. Its interfaces are six gigabit Ethernet copper ports, two gigabit SFP slots and one embedded 5G cellular module with two SIM slots, all data-only. Within the FortiGate G series PoE appears on separate part numbers, not on this one.

What transceivers do the SFP slots on the FGR-50G-5G-BDL-809-36 use?

The appliance has two dedicated GE SFP slots alongside its six gigabit RJ45 ports. Fortinet lists the compatible transceiver modules, including extended-temperature variants, in the ordering information. Transceivers are sold separately.

How does high availability work on the Fortinet FortiGate Rugged 50G-5G FGR-50G-5G-BDL-809-36?

The FGR-50G-5G-BDL-809-36 supports Active-Active, Active-Passive and Clustering high-availability modes. An HA pair should be two identical models running the same FortiOS build, and the units synchronise configuration and session state over the HA link. This model has no dedicated HA port, so the HA link runs over a data port.

What are the environmental ratings of the FGR-50G-5G-BDL-809-36?

The FGR-50G-5G-BDL-809-36 operates from -40 to 75 degrees Celsius and is rated IP40. It is fanless, mounts on a DIN rail, and takes redundant dual DC inputs on a two-pin terminal block with either negative or positive ground; DC cables are not supplied. It is certified to IEC 61850-3 and IEEE 1613 for electric power substations, and to EN 50155 for rail. It is built on the FortiSP5 processor and includes a Digital I/O Module (DIO); it does not have a MicroSD card slot.

What is the difference between the FGR-50G-5G-BDL-809-36 and the FGR-70G?

The FGR-50G-5G-BDL-809-36 and FGR-70G are different Rugged Series platforms. The FGR-70G provides higher published throughput and session capacity, adds a bypass GE port pair and a MicroSD card slot, and uses a different DC input range, but has no cellular modem. Their physical and power specifications also differ.

What is included in the FGR-50G-5G-BDL-809-36 bundle?

The FGR-50G-5G-BDL-809-36 is the appliance plus a prepaid FortiGuard Enterprise Protection subscription and FortiCare Premium support, both for a term of 3 years (36 months). Enterprise Protection covers IPS, anti-malware, URL and DNS filtering, anti-spam, AI-based inline malware prevention, data loss prevention (full features when running FortiOS 7.4.1, per Fortinet) and Attack Surface Security, along with the FortiConverter configuration-conversion service. OT Security and the SD-WAN and SASE services are not part of this bundle. Fortinet's footnote excludes video filtering and some other services on the FortiGate 30G and 50G series; confirm with Fortinet whether that exclusion applies to this Rugged 50G model. FortiCare Premium provides 24x7x365 availability with one-hour response for critical issues and next-business-day response for everything else.

Does the FGR-50G-5G-BDL-809-36 require a subscription to operate?

No. Core firewall, routing and networking functions can continue to operate without an active FortiGuard subscription, while subscription-based security intelligence, updates and services require an active subscription. The FGR-50G-5G-BDL-809-36 ships with a prepaid FortiGuard Enterprise Protection subscription and FortiCare Premium support for 3 years (36 months); when that term ends, the FortiGuard intelligence and the support entitlement lapse and can be renewed.

What condition is the FGR-50G-5G-BDL-809-36 sold in, and what warranty applies?

Network Devices Inc. supplies the FGR-50G-5G-BDL-809-36 new and factory sealed, in original Fortinet packaging with the standard accessories. It is covered by a one-year Network Devices Inc. warranty and a 30-day return window. Because the unit is new rather than renewed, it is eligible for Fortinet registration and for FortiCare and FortiGuard entitlements ordered against it, which is not always the case with refurbished stock. Orders ship from our New Jersey and Texas warehouses.

Reviews