Short answer
A FortiGate firewall is Fortinet's next-generation firewall appliance. As well as filtering traffic by port and address, it inspects encrypted traffic, identifies applications and users, blocks intrusions and malware, and provides secure remote access and SD-WAN from the same box.
Updated 2026-09-21 · 4 min read

What it does beyond a basic firewall
- Application control — allow or block by app, not just by port
- Intrusion prevention against known exploits
- Web filtering and DNS filtering for staff browsing
- Antivirus and sandboxing on files crossing the boundary
- SSL inspection for the encrypted traffic that is now most of it
- IPsec and SSL VPN, ZTNA, and SD-WAN across multiple lines
How the models scale
| Model | Typical site | Notes |
|---|---|---|
| FortiGate 40F | Very small office, home worker | Desktop unit, no fan |
| FortiGate 60F | Small office up to ~50 users | The most common UK small-business choice |
| FortiGate 80F | Busier small office | More ports, higher throughput |
| FortiGate 100F | Mid-size site or HQ | Rack mount, higher inspection throughput |
The licences matter as much as the hardware
The appliance enforces policy; the subscription bundle supplies the threat intelligence. Without an active UTP or Enterprise bundle, features such as IPS, web filtering and antivirus stop receiving updates. We always quote hardware and the right bundle together so there is no surprise at renewal.
Related questions
- Is FortiGate better than a router's built-in firewall?
- For a business, yes. A router firewall filters ports; a FortiGate inspects content, applications and encrypted traffic, and reports on what it blocked.
- What happens when the licence expires?
- The firewall keeps passing traffic and enforcing policy, but threat feeds stop updating, so protection ages quickly.
Hardware for this
The ranges below cover what this article describes, supplied in the UK with lead times confirmed before you commit.


