Fortinet FortiGate 3600LX2
Unified Threat Management Solutions
| Fortinet Products | ||
|---|---|---|
| FortiGate-3600LX2 | ||
| Fortinet FortiGate-3600LX2 Firewall - 1 10/100, 2 1000base-LX, 2 1000base-SX, 2 1000base-T ports |
#FG-3600LX2-US Our Price: $30,995.00 |
|
Click here to jump to more pricing!
Overview:
Best-of-Breed Network Antivirus Protection
FortiGate™ Antivirus Firewalls are dedicated, hardware based units that deliver complete, real-time network protection services at the network edge. Based on Fortinet’s revolutionary FortiASIC™ Content Processor chip, the FortiGate platforms are the only systems that can detect and eliminate viruses, worms, and other content-based threats without reducing network performance — even for real-time applications like Web browsing. FortiGate systems also include integrated firewall, content filtering, VPN, intrusion detection and prevention, and traffic shaping functions, making them the most cost effective, convenient, and powerful network protection solutions available.

The FortiGate-3600 Antivirus Firewall is a high performance system that delivers gigabit throughput with exceptional reliability for the most demanding large enterprise and service provider environments. Providing 6 gigabit interfaces, the FortiGate-3600 establishes new levels of price/performance, and offers a complete array of antivirus, firewall, web and email content filtering, VPN, network-based intrusion detection and prevention, and traffic shaping capabilities. The FortiGate-3600 deploys easily in existing networks and can be used for antivirus and content filtering only or can be deployed as a complete network protection solution. The FortiGate-3600 supports independent security zones and policies mapped to VLAN tags enabling granular security configurations unique to each group or department. High Availability (HA) operation and redundant hot-swappable power supplies ensure non-stop operation in mission-critical applications. The FortiGate-3600 is kept up to date automatically by Fortinet’s FortiProtect™ Network, which provides continuous updates that ensure protection against the latest viruses, worms, Trojans, and other threats – around the clock, and around the world.
Product Highlights:
- Optimal solution for Large Enterprise and Managed Security Service Providers (MSSPs)
- Eliminates viruses and worms from email, file transfer, and real-time (Web) traffic without degrading network performance
- Provides complete network protection functionality: network-based antivirus, web and email content filtering, firewall, VPN, network-based intrusion detection and prevention, and traffic shaping
- “Transparent mode” operation supports highly available architectures and deployments for antivirus and content filtering only in conjunction with existing firewall, VPN, intrusion detection and prevention, or other existing systems
- Real-time system status monitoring lowers the total cost of ownership by providing an easy graphical view of CPU and memory utilization, network and session status, virus and intrusion detection
- Reduces exposure to threats by detecting and preventing 1300 different intrusions, including DoS and DDoS attacks
- Active-active and active-passive high availability operation supports transparent failover for mission-critical applications and clustering of up to 32 units
- VLAN and virtual domain support provides for granular network segmentation into zones with independent security and access control policies
- Delivers superior performance and reliability from hardware accelerated, ASIC-based architecture and redundant, hotswappable power supplies
- Automatically downloads the latest virus and attack database and can accept instant “push” updates from the FortiProtect Network
- Underlying FortiOS™ is ICSA-certified for Antivirus, Firewall, IPSec VPN and Intrusion Detection
Fortinet Security Leadership.
FortiGateTM Multi-Threat security systems are dedicated ASIC-based appliances that deliver comprehensive network protection scalable to multi-gigabit speeds. Utilizing the industry’s first hardware-accelerated content inspection engines, Fortinet Complete Content Inspection and Reassembly technology provides the most advanced ASIC-accelerated network-based security products available today.
Powerful, Enterprise-Class Security in a Single Device.
The FortiGate-3600TM Security System is a high performance solution that delivers gigabit throughput with exceptional reliability for the most demanding large enterprise and service provider environments. The FortiGate-3600 deploys easily in existing networks and can be used for antivirus and content filtering only or can be deployed as a complete network protection solution. High Availability (HA) operation and redundant hot-swappable power supplies ensure non-stop operation in mission-critical applications. The FortiGate-3600 is kept up to date automatically by Fortinet’s FortiGuardTM network, which provides continuous updates for FortiGuard Subscription Services that ensure protection against the latest viruses, worms, trojans and other threats - around the clock.
Sophisticated Security Solution
The FortiGate-3600 delivers critical security functions in a hardened security platform that is tuned for reliability, usability, rapid deployment, low operational costs and most importantly, a superior detection rate against know and unknown anomalous threats. Backed by Fortinet’s proactive real-time subscription services, the FortiGate security systems are unbeatable for value, performance and functionality.

Management for all FortiGate platforms is easily performed with a policy based Web UI or via Fortinet’s FortiManager for central management. FortiManager can manage hundreds of FortiGate devices for configuration and policy changes via a single console. Fortinet’s management ensures consistent policy enforcement across all FortiGate platforms. FortiLogTM provides a central logging facility that aggregates and analysis logs from all centrally managed FortiGate platforms. Together FortiManager and FortiLog provide a unified architecture for complete network management.
Automated Security Services
FortiGate security systems are proactive against the latest threats. With the FortiGuard Subscription Services options, each FortiGate system is automatically updated with the latest detection methods within minutes of their availability from Fortinet.
FortiGate Subscription Services are provided through Fortinet’s global FortiGuard Distribution Network (FDN). FDN provides guaranteed 24 x 7 customer access with ten redundant high-speed centers around the world. Critical updates for attack signatures and detection engines can be obtained in several ways to best suit the needs of every customer:
- Automatically updates “pushed” from the FDN network to Fortinet products
- Scheduled updates “pulled” from the FDN network based on the customer’s customized schedule
- Immediate updates through “update now” function
FortiGuard security filtering services for Web Filtering and Antispam provide fully managed solutions to secure networks and users from non-authorized web sites and spam mail. With Fortinet’s award-winning graphical user interface, setting up web filtering and antispam services couldn’t be easier. Within minutes, customers can create sophisticated security policies leveraging Fortinet’s rich knowledge base to quickly reduce and eliminate non-business and potentially harmful web browsing and email messages.

Features and Benefits:
| Feature | Description | Benefit |
|---|---|---|
| Network-based Antivirus (ICSA Certified) |
Detects and eliminates viruses and worms in real-time. Scans incoming and outgoing email attachments (SMTP, POP3, IMAP) and all FTP and HTTP traffic including web-based email — without degrading Web performance | Closes the vulnerability window by stopping viruses and worms before they enter the network |
| Dynamic Intrusion Detection & Prevention (ICSA Certified) |
Detection and prevention of over 1300 intrusions and attacks, based on user-configurable thresholds. Automatic update of IPS signatures from FortiProtect Network | Stops attacks that evade conventional antivirus products, with real-time response to fast spreading threats |
| Firewall (ICSA Certified) |
Powerful stateful inspection firewall | Certified protection, maximum performance and scalability |
| Web Content Filtering | Processes all Web content to block inappropriate material and malicious scripts via URL blocking and keyword/phrase blocking | Assures improved productivity for enterprise and regulatory compliance for CIPA-compliant educational institutions |
| VPN (ICSA Certified) |
Industry standard IPSec, PPTP, and L2TP VPN support | Provide secure communication tunnels between networks and clients |
| Transparent Mode | FortiGate units can be deployed in conjunction with existing firewall and other devices to provide antivirus, content filtering, and other content-intensive applications | Easy integration/investment protection of legacy systems. |
| Remote Access | Supports secure remote access from any PC equipped with FortiClient Host Security software | Low cost, anytime, anywhere access for mobile and remote workers and telecommuters |
| Key Features | Benefits |
|---|---|
| Industry proven multi-threat security architecture | Tightly integrated application security is ideal for protecting against complex blended threats, worms, viruses, trojans, spyware and identity theft attacks plaguing today’s organizations |
| Automated updates of Antivirus and IPS signatures | Around the clock protection against the latest threats |
| Easy to deploy and manage, network-based, ASIC appliance | Delivers gigabit performance to ensure the firewall does not become a network bottleneck |
| Inspection of VPN (IPSec and SSL) content | Prevents virus outbreaks and vulnerability attacks from propagating through VPNs |
| Lower deployment and management costs | Security zones and Virtual domains allows management of multiple customer and internal networks from a single easy-to-manage platform |
| Support for emerging technologies, H323, SIP, IM, P2P | Flexible OS offers granular control of IM and VOIP applications |
| Detailed logging and reporting tools | FortiLog and FortiManager turn-key offer extensive reporting and data archiving options |
| Flexible and scalable deployment modes, HA, NAT, Route, Transparent (bridge) mode | Allows for integration of network security into any network environment |
| Robust dynamic routing protocol support, RIP, OSPF, BGP4 | The FortiGate-3600 easily integrates into fully-meshed network designs |
Deployments:
High performance multi-threat security for the Enterprise and Managed Security Service Providers (MSSPs)

The security landscape has evolved. Traditional point-based Firewall, Antivirus and IPS security solutions are inadequately equipped to protect your network from today’s complex blended threats such as NetSky and SoBig which utilize multiple methods to attack and infect computer systems.
To effectively protect organizations from these new generation of attacks requires a comprehensive security strategy that contains multiple layers of network-based defenses at the edge and at the core of your network. The FortiGate-3600 delivers a high performance appliance that tightly integrates multiple security solutions to combat blended attacks. Integrated antivirus and antispyware engines inspects email, HTTP and FTP downloads for malicious content, dynamic IPS detects and blocks attacks aimed at exploiting application vulnerabilities, antispam filtering blocks the transport of malicious files, comprehensive web content filtering blocks access to offensive and malicious internet sites and a stateful firewall is used as a first line of defense.
Flexible security for emerging technologies and network architectures

The FortiGate-3600’s flexible architecture allows it to quickly adapt to emerging technologies and threats such as IM, P2P and VOIP applications and Identity theft methods such as Spyware, Phishing and Pharming attacks.
Flexible deployment options such as NAT, Route and Transparent modes allow the FortiGate-3600 to be easily deployed into most network designs. Core networking features such as High Availability (HA) and support for dynamic routing protocols RIP, OSPF and BGP allow the FortiGate-3600 to be deployed into complex full mesh network environments that require maximum network availability.
To reduce deployment costs, The FortiGate-3600 appliance supports security zones and virtual security domains to secure multiple internal networks or external customers on a single, easy to manage platform.
Technical Specifications:

| Feature List | FortiGate-3600 | FortiGate-3600LX2 | FortiGate-3600LX4 |
|---|---|---|---|
| Interfaces | |||
| 10/100 Ethernet Ports | 1 | 1 | 1 |
| Gigabit Ethernet Ports (Copper / Fiber) | 2C/4F | 2C/4F (2-LX, 2-SX) | 2C/4F (4-LX) |
| High Availability Port | |||
| WLAN | |||
| DMZ Port | |||
| USB Ports | |||
| System Performance | |||
| Concurrent sessions | 1,000,000 | 1,000,000 | 1,000,000 |
| New sessions/second | 25,000 | 25,000 | 25,000 |
| Firewall throughput (Mbps) | 4Gbps | 4Gbps | 4Gbps |
| 168-bit Triple-DES throughput (Mbps) | 600 | 600 | 600 |
| Unlimited concurrent users | |||
| Policies | 50,000 | 50,000 | 50,000 |
| Schedules | 256 | 256 | 256 |
| Antivirus, Worm Detection & Removal (ICSA Certified) | |||
| Scans HTTP,FTP,SMTP,POP3,IMAP, and encrypted VPN Tunnels | |||
| Automatic "push" Virus Database Update | |||
| Quarantine infected messages | |||
| Block by file size | |||
| Firewall Modes and Features | |||
| NAT, PAT,Transparent (bridge) | |||
| Routing mode (RIP v1, v2) | |||
| Virtual domains | |||
| 802.1q VLAN Support | |||
| User Group-based authentication | |||
| H.323 NAT Traversal | |||
| Protection Profiles | 32 | 32 | 32 |
| VPN | |||
| Dedicated tunnels | 5,000 | 5,000 | 5,000 |
| Encryption (DES, 3DES, AES) | |||
| PPTP,L2TP,VPN client pass though | |||
| Hub and Spoke Architecture | |||
| IKE certificate authentication (X.959) | |||
| IPSec NAT Traversal | |||
| Content Filtering | |||
| URL block, Keyword Block, Exempt List | |||
| Block Java Applet, Cookies, Active X | |||
| Email filtering (keyword, exempt list, RBL/ORDB support) | |||
| Mime Header Check | |||
| Cerberian web filtering support | |||
| FortiGuard™ web filtering support | |||
| Dynamic Intrusion Detection and Prevention | |||
| Prevention for over 1300 attacks | |||
| Customizable dynamic detection signature list | |||
| Automatic attack database update | |||
| Anti-Spam | |||
| Real-time Blacklist/Open Relay Database Server | |||
| MIME header check | |||
| Keyword/phrase filtering | |||
| IP address blacklist/exempt list | |||
| Logging/Monitoring | |||
| Internal logging capacity | 20G | 20G | 20G |
| Syslog, SNMP | |||
| Email notification of viruses and attacks | |||
| High Availability (HA) | |||
| Active-active, Active-passive | |||
| Stateful failover (FW and VPN) | |||
| Device failure detection & notification | |||
| Redundant Power Supplies | |||
| Link status monitor | |||
| Networking | |||
| Multiple WAN link support | |||
| PPPoE client | |||
| DHCP client/server | |||
| Policy-based routing | |||
| System Management | |||
| Console interface (RS-232) | |||
| WebUI (HTTPS) | |||
| Multi-language support | |||
| Command line interface | |||
| Secure Command Shell (SSH) | |||
| FortiManager System | |||
| Administration | |||
| Multiple administrators and user levels | |||
| Upgrades & changes via TFTP &WebUI | |||
| System software rollback | |||
| User Authentication | |||
| Internal database | |||
| LDAP support | |||
| External RADIUS | |||
| RSA SecurID | |||
| Xauth over RADIUS for IPSec VPN | |||
| IP/MAC address binding | |||
| Traffic Shaping | |||
| DiffServ setting | |||
| Policy-based traffic shaping | |||
| Guarantee/Max/Priority Bandwidth | |||
| Dimensions | |||
| Height (inches) | 3.5 | 3.5 | 3.5 |
| Width (inches) | 16.95 | 16.95 | 16.95 |
| Length (inches) | 13.5 | 13.5 | 13.5 |
| Weight | 17.5 lb (8 kg) | 17.5 lb (8 kg) | 17.5 lb (8 kg) |
| Power | |||
| AC input voltage | 100 to 240VAC | 100 to 240VAC | 100 to 240VAC |
| AC input current | 6A | 6A | 6A |
| Environmental | |||
| Operating Temperature | 32 to 104°F (0 to 40°C) | 32 to 104°F (0 to 40°C) | 32 to 104°F (0 to 40°C) |
| Storage Temperature | -13 to 158°F (-25 to 70°C) | -13 to 158°F (-25 to 70°C) | -13 to 158°F (-25 to 70°C) |
| Humidity | 5 to 95% non-condensing | 5 to 95% non-condensing | 5 to 95% non-condensing |
| Compliance | |||
| FCC Class A Part 15 | |||
| CSA/CUS | |||
| CE | |||
| UL | |||
| ICSA Antivirus | |||
| ICSA Firewall | |||
| ICSA IPSec | |||
| ICSA Intrusion Detection | |||
Services & Support:
FortiGuard Security Subscription Services
FortiGuard Security Subscription Services deliver dynamic, automated updates for Fortinet products. The Fortinet Global Security Research Team creates these updates to ensure up-to-date protection against sophisticated threats. Subscriptions include antivirus, intrusion prevention, web filtering, antispam, vulnerability and compliance management, application control, and database security services.
FortiCare Support Services
FortiCare Support Services provide global support for all Fortinet products and services. FortiCare support enables your Fortinet products to perform optimally. Support plans start with 8x5 Enhanced Support with "return and replace" hardware replacement or 24x7 Comprehensive Support with advanced replacement. Options include Premium Support, Premium RMA, and Professional Services. All hardware products include a 1-year limited hardware warranty and 90-day limited software warranty.
Documentation:
![]()
Download the Fortinet
FortiGate 3600 Datasheet (.PDF)
| Fortinet Products | ||
|---|---|---|
| FortiGate-3600LX2 | ||
| Fortinet FortiGate-3600LX2 Firewall - 1 10/100, 2 1000base-LX, 2 1000base-SX, 2 1000base-T ports |
#FG-3600LX2-US Our Price: $30,995.00 |
|
| Fortinet FortiGuard Subscriptions Renewal | ||
| FortiGuard Subscriptions 1-Year Renewal | ||
| AntiVirus (AV) Service for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-100-02-12 Our Price: $7,499.00 |
|
| IPS Service for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-108-02-12 Our Price: $5,999.00 |
|
| Web Service for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-112-02-12 Our Price: $11,998.00 |
|
| AntiSpam (AS) Service for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-114-02-12 Our Price: $5,399.00 |
|
| AV, IPS, Web, and AS Service for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-107-02-12 Our Price: $21,626.00 |
|
| Fortinet FortiCare 8x5 Subscriptions | ||
| FortiGate-3600LX2 FortiCare 8x5, Renewals | ||
| The FortiCare 8x5 Renewal includes 8x5 Enhanced Support, Return and Replace, Firmware Upgrades, VPN, Traffic Management | ||
| 8x5 FortiCare for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-311-02-12 Our Price: $4,649.00 |
|
| 8x5 FortiCare for FortiGate-3600LX2, 2-Year Renewal | #FCX2-10-03600-311-02-24 Our Price: $8,717.00 |
|
| 8x5 FortiCare for FortiGate-3600LX2, 3-Year Renewal | #FCX2-10-03600-311-02-36 Our Price: $12,204.00 |
|
| Fortinet FortiCare 24x7 Subscriptions | ||
| FortiGate-3600LX2 FortiCare 24x7, Renewals | ||
| The FortiCare 24x7 Renewal includes 24x7 Comprehensive Support, Advanced Hardware Replacement (NBD), Firmware Upgrades, VPN, and Traffic Management | ||
| 24x7 FortiCare for FortiGate-3600LX2, 1-Year Renewal | #FCX2-10-03600-247-02-12 Our Price: $7,749.00 |
|
| 24x7 FortiCare for FortiGate-3600LX2, 2-Year Renewal | #FCX2-10-03600-247-02-24 Our Price: $14,529.00 |
|
| 24x7 FortiCare for FortiGate-3600LX2, 3-Year Renewal | #FCX2-10-03600-247-02-36 Our Price: $20,340.00 |
|



