Two mistakes account for most of the money wasted on firewall projects in Pakistan. The first is buying too small — a 60-user company puts in an entry-level box, switches on SSL inspection eighteen months later, and watches Zoom calls stutter. The second is buying too big — a procurement team specifies a rack-mount appliance rated for a data centre, then pays five years of licence renewals on capacity the business will never touch.
Both failures usually trace back to the same root cause: choosing a model from the firewall throughput number on the datasheet, which is the one number that almost never reflects real-world performance.
This guide explains how FortiGate models are actually structured, which specifications matter when sizing, and what separates a genuine Fortinet partner in Pakistan from a reseller who simply forwards your enquiry to a distributor.
Quick Answer: FortiGate Model by Business Size
| Business profile | Typical FortiGate model | Why |
| Small office, single site, up to ~25 staff | FortiGate 50G | Desktop form factor, 1.1 Gbps threat protection |
| Growing SME, 25–75 staff, moderate cloud use | FortiGate 70G | 1.3 Gbps threat protection, more session capacity |
| Established SME or large branch, 75–200 staff | FortiGate 90G | 2.2 Gbps threat protection, 10 GE uplinks |
| Mid-market head office, 200–500 staff | FortiGate 120G / 200G | Rack-mount, higher port density, dual PSU options |
| Large campus or multi-site HQ, 500–1,500 staff | FortiGate 400G / 700G | 13–26 Gbps threat protection, 25 GE uplinks |
| Enterprise data centre edge | FortiGate 900G / 1200G | 30–40 Gbps threat protection, 100 GE connectivity |
Important caveat: Fortinet does not publish user counts per model, and neither should any honest reseller present them as fact. The staff ranges above are a planning rule of thumb derived from typical bandwidth per user. Your actual requirement depends on internet link speed, encrypted traffic volume and how many security services you intend to run. The sizing method further down replaces the guesswork.
Understanding the FortiGate Naming System
Every FortiGate model number carries two pieces of information.
The number indicates the performance tier — 50, 90, 200, 900 and so on. Higher means more throughput, more sessions and more ports.
The letter suffix indicates the hardware generation. G-series is the current generation; F-series is the previous one. The difference is not cosmetic. Entry and mid-range G-series appliances consolidate the CPU, network processor and content processor into a single FortiSP5 security processor, whereas F-series models pass packets between separate network and content chips.
That architectural change shows up exactly where it matters. A FortiGate 70G delivers 1.3 Gbps of threat protection against roughly 700 Mbps on the 60F it replaces, and it roughly doubles SSL inspection capacity. Raw firewall throughput barely moves between generations — which is why comparing an F-series and a G-series appliance on the headline number will actively mislead you.
A suffix of 1 on the model number (FG-91G, FG-201G, FG-401G) denotes the same appliance with onboard SSD storage for local logging. If you are not sending logs to a FortiAnalyzer, you probably want the storage variant.
The Three Numbers That Actually Matter
Fortinet publishes several throughput figures for every appliance. They are measured under different conditions, and only two of them are useful for sizing.
| Metric | What it measures | Use it for sizing? |
| Firewall throughput | Large-packet (1518-byte) UDP with no inspection | No — best-case lab figure |
| IPS throughput | Firewall plus intrusion prevention, enterprise traffic mix | Partially |
| NGFW throughput | Firewall, IPS and application control | Partially |
| Threat protection throughput | Firewall, IPS, application control, malware protection and logging | Yes — primary sizing metric |
| SSL inspection throughput | Decryption and inspection of HTTPS traffic | Yes — second sizing metric |
The gap between the first and last rows is enormous. A FortiGate 120G is rated at 39 Gbps of firewall throughput and 2.8 Gbps of threat protection. That is not a defect — it is what happens when a device stops forwarding packets and starts inspecting them.
Since the overwhelming majority of business traffic is now encrypted, SSL inspection throughput is the figure that determines whether your firewall can see modern threats at all. A firewall that cannot decrypt at your link speed is inspecting a fraction of what crosses it. Any network security design that skips this calculation is building in a blind spot on day one.
FortiGate Model Comparison by Tier
All figures below are taken from Fortinet’s published NGFW Ordering Guide and Product Matrix. Threat protection and NGFW values are measured with enterprise-mix traffic and logging enabled.
Small Business and Branch Office (30G – 90G)
| Model | Firewall (1518B) | Threat Protection | SSL Inspection | IPsec VPN |
| FortiGate 30G | 4 Gbps | 500 Mbps | 400 Mbps | — |
| FortiGate 50G | 5 Gbps | 1.1 Gbps | 1.3 Gbps | — |
| FortiGate 70G | 10 Gbps | 1.3 Gbps | 1.4 Gbps | — |
| FortiGate 90G | 28 Gbps | 2.2 Gbps | 2.6 Gbps | 25 Gbps |
These are fanless desktop units. The 90G adds two 10 GE shared-media ports and supports 3 million concurrent sessions with 124,000 new sessions per second — comfortable headroom for a busy branch or a small head office.
Watch the port count. The 90G provides eight GE RJ45 ports plus two 10 GE. If you need to terminate more devices directly without a downstream switch, a higher model or a companion FortiSwitch is required. Getting this wrong is one of the most common reasons a firewall has to be swapped within a year, and it is a solved problem if the network infrastructure design is done before the purchase order.
Mid-Market and Campus (120G – 400G)
| Model | Firewall (1518B) | Threat Protection | SSL Inspection | Concurrent Sessions | New Sessions/Sec |
| FortiGate 120G | 39 Gbps | 2.8 Gbps | 3 Gbps | 3 million | 140,000 |
| FortiGate 200G | 39 Gbps | 6 Gbps | 7 Gbps | 11 million | 400,000 |
| FortiGate 400G | 164 Gbps | 13 Gbps | 11.5 Gbps | 28 million | 580,000 |
Note the jump between the 120G and the 200G. Firewall throughput is identical at 39 Gbps, but threat protection more than doubles and SSL inspection more than doubles. Two appliances with the same headline number are a full performance class apart once inspection is switched on — which is precisely why the headline number is the wrong basis for a decision.
The 400G is the point at which 25 GE uplinks, 28 million concurrent sessions and serious VDOM segmentation become available. It suits a multi-building campus, a regional headquarters or an organisation consolidating several older firewalls onto one platform.
Large Enterprise and Data Centre (700G – 1200G)
| Model | Firewall (1518B) | Threat Protection | SSL Inspection | IPS | New Sessions/Sec |
| FortiGate 700G | 164 Gbps | 26 Gbps | 14 Gbps | 38 Gbps | 700,000 |
| FortiGate 900G | 164 Gbps | 30 Gbps | 16.7 Gbps | 42 Gbps | 720,000 |
| FortiGate 1200G | 397 Gbps | 40 Gbps | Not yet published | 54 Gbps | 1,000,000 |
At this tier you are buying redundancy as much as throughput: dual hot-swappable power supplies, onboard SSD pairs, high-availability clustering and the port density to segment a data centre internally.
The 1200G is the newest addition to the range and introduces FortiSASE Outpost, which lets the appliance act as an on-premises SASE point of presence — relevant for any Pakistani bank, telecom operator or government body facing data residency requirements. We compared it against rival platforms in detail in our guide to the FortiGate 1200G versus competing enterprise firewalls, and Trubyte’s technical breakdown of the 1200G SKUs is worth reading before you place an order, since the FG-1200G and FG-1201G are not differentiated clearly in Fortinet’s public documentation.
How to Size Correctly: A Practical Method
Skip the user-count shortcut. Work through these five steps instead.
- Measure peak throughput, not average. Pull 95th-percentile utilisation from your existing router or firewall over a full month. Month-end and payroll days matter more than a Tuesday afternoon.
- Estimate your encrypted share. Assume the large majority of your traffic is HTTPS unless you have data saying otherwise. That figure is your SSL inspection requirement.
- Decide which services you will actually run. If you plan to enable IPS, application control, web filtering and antivirus, size on threat protection throughput. If you genuinely only need stateful firewalling and VPN, you can size higher up the table.
- Add 40–50% headroom. Signature databases grow, policy tables grow, and your bandwidth will grow. A firewall sized exactly to today’s peak is already undersized.
- Count your ports and your tunnels. Site-to-site VPN count, number of VLANs, PoE requirements and FortiAP or FortiSwitch management all constrain the model independently of throughput.
A worked example: a Karachi manufacturer with 250 staff, a 500 Mbps internet link peaking at 400 Mbps, heavy Microsoft 365 use and four branch VPN tunnels needs roughly 400 Mbps of inspected throughput plus growth headroom. The 90G covers it on paper; the 120G or 200G covers it with room to enable full SSL inspection and add sites without a forklift upgrade in year two.
Five Model-Selection Mistakes Worth Avoiding
1. Assuming SSL VPN will be there. This is the single most disruptive change of the current FortiOS generation. From FortiOS 7.6.3, SSL VPN tunnel mode has been removed from every FortiGate model and replaced with IPsec VPN, which can be configured on TCP port 443. Existing configurations are not carried across during an upgrade. Separately, Agentless VPN (formerly SSL VPN web mode) is unavailable on the 40F, 50G, 60F, 61F, 70G, 90G and 91G. If your remote-access plan depends on FortiClient SSL VPN, that plan needs rewriting before you buy, not after.
2. Ignoring power supply redundancy. Desktop models have a single external PSU. In a country where power quality is a genuine operational risk, a head-office firewall without dual hot-swappable supplies is a single point of failure — and it should sit inside a broader disaster recovery plan, not stand alone.
3. Licensing only the primary unit in an HA pair. Fortinet requires every member of a high-availability cluster to hold a valid support contract and matching FortiGuard licences. Any cluster member can become primary, and an unlicensed secondary cannot receive updates or open a support ticket.
4. Forgetting VDOM limits. If you intend to segment departments, tenants or subsidiaries into virtual domains, check the included and maximum VDOM count for the model. Additional VDOMs are a separately purchased licence.
5. Buying F-series to save money without checking the inspected figures. Sometimes an F-series appliance genuinely is the right call — usually for port density at a given price. But make that comparison on threat protection and SSL inspection, never on raw firewall throughput.
What Actually Makes a Good Fortinet Partner in Pakistan
Fortinet sells entirely through the channel, so the partner you choose determines your experience of the product far more than most buyers expect.
Verify the partnership independently
Fortinet’s Engage Partner Program has four engagement levels — Advocate, Select, Advanced and Expert — with requirements tied to revenue and to staff certifications. Partners at Select level and above can hold formal specialisations, including Secure Networking Firewall, SD-WAN, SASE, Secure Networking LAN, Operational Technology and Security Operations.
You can confirm any company’s status yourself through the official Fortinet Partner Locator. Do it. It takes two minutes and it is the fastest way to separate a real integrator from a broker.
Ask about certifications, by name
Fortinet’s certification ladder runs FCF (Fundamentals), FCA (Associate), FCP (Professional), FCSS (Solution Specialist) and FCX (Expert, formerly NSE 8). A partner should be able to tell you how many certified engineers they employ and at which levels — not how many years they have “worked with Fortinet”.
Understand the FortiCare level being quoted
| Service level | Response commitment | Hardware replacement | Availability |
| FortiCare Essential | Next business day, web only | Return-and-replace | Entry-level models only (FortiGate 9x and below) |
| FortiCare Premium | 24×7×365, one hour for critical issues | Next-business-day RMA included | Full product range |
| FortiCare Elite | 15 minutes for Priority 1 and 2 | Next-business-day RMA included, plus Elite portal and extended engineering support | FortiGate, FortiWiFi, FortiManager, FortiAnalyzer, FortiAP, FortiSwitch |
The detail that matters most in Pakistan: Fortinet’s Priority RMA add-ons — next-calendar-day delivery, four-hour hardware delivery, and four-hour delivery with an onsite engineer — are add-ons to Premium or Elite contracts, and availability depends on geographic location. Fortinet states plainly that these services are not offered everywhere. Before you sign, ask your partner to confirm in writing what replacement SLA is genuinely deliverable to your site in Karachi, Lahore or Islamabad, and what their own local spares position is if the vendor SLA does not reach you. A partner who answers this precisely is worth more than one offering a bigger discount.
Check who registers the licence
Products should be registered to the end customer’s FortiCloud account, not held under the reseller’s. If the reseller controls registration, you cannot open support tickets directly and you are dependent on them for every renewal. This is a recurring problem in the regional market and it is entirely avoidable by asking one question at the point of order.
Look for design and migration capability
Anyone can quote a part number. Fewer can run a policy audit on your existing firewall, plan a cutover window, migrate rule sets without carrying over a decade of dead rules, and hand you documentation afterwards. If you are consolidating firewalls, adding centralised Wi-Fi under Security Fabric management, or protecting on-premises virtualisation, that engineering capability is the whole value of the partner.
Licensing: UTP or Enterprise?
Hardware is roughly half the story. The FortiGuard bundle you attach determines what the appliance can actually do.
The Unified Threat Protection (UTP) bundle covers IPS, advanced malware protection, application control, botnet database, mobile malware, outbreak prevention, web and video filtering, cloud sandbox, secure DNS filtering, antispam and 24×7 support. For most Pakistani SMEs this is the sensible default.
The Enterprise bundle adds services aimed at larger or more regulated environments. Fortinet’s own ordering guide lists Enterprise as the recommended bundle across the current G-series lineup, but “recommended” is not “required” — the correct answer depends on which services you will operationalise rather than merely license.
Budget on a three-to-five-year view. Across that horizon, subscription renewals typically exceed the original hardware cost, which is why an ongoing IT support contract with clearly defined renewal handling matters as much as the initial discount.
Conclusion
Choosing the right FortiGate is a sizing exercise, not a shopping exercise. Size on threat protection and SSL inspection throughput, add real headroom, count your ports and tunnels, and verify that the remote-access architecture you are planning still exists in the FortiOS version you will run. Do those four things and the model almost selects itself.
Choosing the right Fortinet partner in Pakistan is a due-diligence exercise. Verify the partnership on Fortinet’s own locator, ask for named certifications, get the achievable RMA SLA in writing for your city, and insist that licences are registered to your organisation. A partner who welcomes those questions is the one you want.
If you are sizing a FortiGate now — or inherited one that no longer fits — Maxicon Solutions’ IT consultancy team can run a vendor-neutral assessment of your actual traffic, encryption ratio and growth plans before anyone quotes a part number. Request a consultation and we will help you specify it correctly the first time.