Fortinet FG-601F FortiGate 601F Next Generation Firewall Secure SD-WAN Gateway With Built-in SSD

Fortinet FG-601F FortiGate 601F Next Generation Firewall Secure SD-WAN Gateway With Built-in SSD

The Fortinet FG-601F (FortiGate 601F) is a high-performance 1U rackmount next-generation firewall (NGFW) and secure SD-WAN gateway, identical to the FG-600F but with 2x 240GB SSDs for local logging/storage—ideal for mid-to-large enterprises and data centers. Powered by NP7 SPU and CP9 content processor, it delivers 139Gbps firewall throughput with ultra-low latency for encrypted traffic. Ports include 4x25G SFP28, 4x10G SFP+, 8xGE SFP, 18xGE RJ45, plus dual hot-swappable PSUs. As part of the Fortinet Security Fabric, it integrates AI/ML FortiGuard threat protection, ZTNA, and unified management—perfect for organizations needing high-speed security, local log retention, and scalable hybrid cloud connectivity.

Comprehensive Product Overview

The FortiGate 601F (FG-601F) is a flagship enterprise security appliance in Fortinet’s 600F series (paired with FG-600F), built on Security-Driven Networking architecture. It unifies NGFW, secure SD-WAN, ZTNA, SSL inspection, IPS, application control, and advanced malware protection into a single 1U platform—with the key difference of dual 240GB SSDs for onboard logging, reducing reliance on external servers.

Designed for 1U rackmount deployment, the FG-601F uses dedicated NP7 (network processing) and CP9 (content processing) SPUs to offload security tasks, ensuring wire-speed performance even with full security policies enabled. High-density 25G/10G fiber and GE copper ports support high-bandwidth enterprise backbones, data center interconnections, and large branch SD-WAN.

As part of the Fortinet Security Fabric, it integrates seamlessly with FortiAP, FortiSwitch, FortiNAC, and FortiGuard, delivering end-to-end security across on-premises, cloud, and edge environments. Certified for enterprise reliability, it features dual hot-swappable AC PSUs, TPM 2.0, and a rugged chassis for 24/7 operation—with local SSD storage for compliant log retention and faster troubleshooting.


Key Features & Business Benefits

Key Features

  • NP7 + CP9 Hardware Acceleration: Wire-speed performance for firewall, IPS, SSL inspection, and application control.
  • 2x 240GB Onboard SSDs: Local logging/storage for compliance, reduced external server dependency, and faster log access.
  • High-Density 25G/10G/GE Interfaces: 4x25G SFP28, 4x10G SFP+, 8xGE SFP, 18xGE RJ45 (16x switch, 1x MGMT, 1x HA), 2x USB, 1x Console.
  • AI/ML-Powered FortiGuard Services: Real-time protection against ransomware, zero-days, malware, phishing, and APTs.
  • Secure SD-WAN & ZTNA: Application-aware SD-WAN routing; Universal ZTNA for granular user-to-application access.
  • Ultra-High Throughput: 139Gbps IPv4 firewall, 14Gbps IPS, 11.5Gbps NGFW, 9Gbps SSL inspection.
  • Redundant & Reliable: Dual hot-swappable AC PSUs, 1U rackmount, TPM 2.0, 55dBA low noise.
  • FortiOS Unified Management: Single OS for firewall/SD-WAN/switching/wireless; GUI/CLI or cloud management via FortiManager.

Business Benefits

  • Simplify Compliance & Logging: Onboard SSDs enable local log retention for regulatory requirements (PCI DSS, HIPAA), reducing external logging costs.
  • Reduce Security Complexity: Consolidate 10+ security/networking functions into one appliance, cutting management overhead.
  • Boost Network Performance: Hardware acceleration ensures security doesn’t slow traffic—supporting video, cloud, and VoIP.
  • Strengthen Threat Protection: AI-driven FortiGuard Labs blocks emerging threats before they impact operations.
  • Enable Secure Hybrid Work: ZTNA/SSL VPN deliver safe remote access; SD-WAN optimizes cloud/data center connectivity.
  • Lower TCO: 1U design saves rack space; redundant components reduce downtime; unified management cuts training/maintenance costs.
  • Scale with Growth: High-density 25G/10G ports support future upgrades; VDOMs enable multi-tenant deployments.

Technical Specifications (FG-601F)

System Performance

  • IPv4 Firewall Throughput (1518/512/64 byte UDP): 139 / 137.5 / 70 Gbps
  • IPv6 Firewall Throughput: 139 Gbps
  • IPS Throughput (Enterprise Mix): 14 Gbps
  • NGFW Throughput (Enterprise Mix): 11.5 Gbps
  • Threat Protection Throughput: 10.5 Gbps
  • SSL Inspection Throughput (HTTPS): 9 Gbps
  • Application Control Throughput: 32 Gbps
  • Concurrent TCP Sessions: 8 Million
  • New TCP Sessions/Second: 550,000
  • IPsec VPN Throughput (512 byte): 55 Gbps
  • SSL VPN Throughput: 4.3 Gbps
  • Virtual Domains (Default/Max): 10 / 10

Interfaces & Ports

  • 4x 25GE SFP28 (ultra-low latency)
  • 4x 10GE SFP+
  • 8x GE SFP
  • 18x GE RJ45 (16x switch ports, 1x MGMT, 1x HA)
  • 2x USB 3.0
  • 1x RJ45 Console (9600 baud)

Hardware & Physical

  • Form Factor: 1U Rackmount
  • Dimensions (H×W×D): 1.75 × 17.0 × 15.0 in (44.45 × 432 × 380 mm)
  • Weight: 15.6 lbs (7.1 kg)
  • Power Supply: Dual Hot-Swappable AC (100–240V AC, 50/60Hz)
  • Power Consumption: 169W (avg) / 255W (max)
  • Heat Dissipation: 871 BTU/h
  • Operating Temperature: 32°–104°F (0°–40°C)
  • Humidity: 5%–90% non-condensing
  • Noise Level: 55 dBA
  • Security: TPM 2.0, secure boot, encrypted storage support
  • Onboard Storage: 2x 240 GB SSD (FG-601F only; FG-600F has no storage)

Licensing & Management

  • Supported FortiOS Versions: 7.0+
  • Management: FortiManager (on-prem/cloud), FortiGate GUI/CLI, FortiCloud
  • Security Subscriptions: FortiGuard Enterprise (IPS, malware, URL/DNS filtering, CASB, DLP), FortiCare Premium (24/7 support, NBD replacement)

Ideal Application Scenarios

  • Enterprise Campus Networks: High-speed backbone security for large university, corporate, or government campuses.
  • Large Enterprise Branches: Secure SD-WAN gateway for regional HQ or 500+ user branches needing local log storage.
  • Data Center Edge Security: Perimeter firewall for data centers, protecting servers/storage/cloud interconnections with compliant logging.
  • Hybrid & Multi-Cloud Security: Secure on-prem/cloud connectivity via IPsec/SSL VPN; local SSDs log cloud traffic for audits.
  • Zero Trust Network Access (ZTNA): Granular access control for remote/on-site employees; logs track access for compliance.
  • High-Bandwidth Application Environments: Networks running video conferencing, big data, VoIP, or e-commerce needing low-lat security.
  • Regulated Industries: Finance, healthcare, and government requiring local log retention (PCI DSS, HIPAA, GDPR).

Supported Accessories & Modules

Transceiver Modules (Compatible)

  • 25G SFP28: SR (multimode), LR (single-mode), ER (extended reach)
  • 10G SFP+: SR, LR, ER, ZR, DAC (direct attach copper)
  • GE SFP: SX (multimode), LX (single-mode), BX (bidirectional)

Power Supplies

  • FG-601F AC Power Supply (hot-swappable replacement)

Mounting & Cabling

  • 1U Rackmount Kit (included)
  • Console Cable (RJ45-to-USB, included)
  • Ethernet Cables (CAT5e/CAT6 for RJ45 ports)

Management & Security

  • FortiManager VM/Appliance (centralized management)
  • FortiGuard Enterprise Protection License (1/3/5-year terms)
  • FortiCare Premium Support Contract (24/7 support, NBD replacement)

Frequently Asked Questions (FAQ)

Q1: What is the main difference between FG-601F and FG-600F?

A: The FG-601F includes 2x 240GB SSDs for local logging/storage, while the FG-600F has no onboard storage. All other hardware (interfaces, performance, processors) is identical.

Q2: Why choose FG-601F over FG-600F?

A: The FG-601F’s dual SSDs enable local log retention for compliance (PCI DSS, HIPAA), reduce external logging server costs, and speed up log access/troubleshooting—ideal for regulated industries or data centers.

Q3: Does the FG-601F support secure SD-WAN?

A: Yes. It includes FortiGate SD-WAN with application-aware routing, ZTP, and FortiCloud integration for centralized management.

Q4: Can the FG-601F be deployed in HA mode?

A: Yes. It supports Active-Active and Active-Passive HA, plus clustering for scalability/redundancy.

Q5: What is the maximum SSL VPN user count?

A: The FG-601F supports up to 10,000 recommended concurrent SSL VPN users (tunnel mode).

Q6: Is the FG-601F certified for enterprise standards?

A: Yes. It complies with FIPS 140-2, Common Criteria (EAL4+), and PCI DSS—suitable for government, finance, and regulated industries.

Q7: How is data stored on the FG-601F’s SSDs secured?

A: The SSDs support encrypted storage with TPM 2.0 and secure boot, ensuring log data remains tamper-proof and compliant with data security regulations.