Overview:
The FortiGate 3500G Series enables organizations to build security-driven networks, forming the foundation of a robust Hybrid Mesh Firewall architecture. This approach weaves security deep into their datacenter and across their hybrid IT environment, protecting any edge at any scale.
Powered by a rich set of AI/ML-based FortiGuard Services and an integrated security fabric platform, the FortiGate 3500G Series delivers coordinated, automated, end-to-end threat protection across all use cases. The industry's first integrated Zero Trust Network Access (ZTNA) enforcement within an NGFW solution, FortiGate 3500G automatically controls, verifies, and facilitates user access to applications, delivering consistent convergence with a seamless user experience across your distributed network.
The industry's first integrated zero-trust network access (ZTNA) enforcement within an NGFW solution, the FortiGate 3500G automatically controls, verifies, and facilitates user access to applications, reducing lateral threats by providing access only to validated users for seamless user experience.
| IPS |
NGFW |
Threat Protection |
Interfaces |
| 125 Gbps |
115 Gbps |
105 Gbps |
Multiple 400 GE QSFP-DD, 100 GE QSFP28, 25 GE SFP28, and 10 GE / GE RJ45 port |
Highlights:
- Gartner Magic Quadrant Leader for Hybrid Mesh Firewall.
- Secure Networking with FortiOS for converged networking and security
- Unparalleled Performance with Fortinet's patented SPU and vSPU processors.
- Enterprise Security with consolidated AI / ML-powered FortiGuard Services.
- Hyperscale security to secure any edge at any scale.
Use Cases:
Next Generation Firewall (NGFW)
- FortiGuard Labs' suite of AI-Powered Security Services, natively integrated with your NGFW, secures web, content, and devices and protects networks from ransomware, malware, zero days, and sophisticated AI-powered cyberattacks
- Real-time SSL inspection (including TLS 1.3) provides full visibility into users, devices, and applications across the attack surface
- Fortinet's patented SPU technology provides industry-leading high-performance protection
Segmentation
- Dynamic segmentation adapts to any network topology to deliver true end-to-end security from the branch to the data center and across multi-cloud environments
- Ultra-scalable, low latency, VXLAN segmentation bridges physical and virtual domains with Layer 4 firewall rules
- Prevents lateral movement across the network with advanced, coordinated protection from FortiGuard Security Services, detects and prevents known, zero-day, and unknown attacks
Secure SD-WAN
- FortiGate WAN Edge powered by one OS and unified security and management framework and systems transforms and secures WANs
- Delivers superior quality of experience and effective security posture for hybrid working models, SD-Branch, and cloud-first WAN use cases
- Achieves operational efficiencies at any scale through automation, deep analytics, and selfhealing
Mobile Security for 4G, 5G, and IoT
- SPU-accelerated, high-performance CGNAT and IPv6 migration options, including: NAT44, NAT444, NAT64/DNS64, NAT46 for 4G Gi/sGi, and 5G N6 connectivity and security
- Radio access network security with highly scalable and highest-performing IPsec aggregation and control security gateway
- User plane security enabled by full threat protection and visibility into GTP-U inspection
FortiOS Everywhere
FortiOS, Fortinet's Real-Time Quantum-Safe Network Security Operating System
FortiOS is Fortinet's natively AI-powered and quantum-safe operating system (OS) that powers the Fortinet Security Fabric platform, enabling enforcement of security policies and holistic visibility across the entire attack surface. It provides a unified framework for securing networks across on-premises, cloud, hybrid environments, and the convergence of IT, OT, and IoT.
By converging networking and security functions into a single operating system, organizations can manage network and security more effectively to detect, investigate, and respond to incidents faster. This unified architecture simplifies operations, eliminates security silos, and allows organizations to scale securely without multiple tools or management complexity.
FortiOS also incorporates AI-driven capabilities that enhance threat detection, automate network activity analysis, and deliver more precise remediation guidance. Together, FortiGate firewalls and FortiOS provide intelligent, adaptive protection that reduces complexity, improves operational efficiency, and strengthens security across modern hybrid environments.
FortiGuard AI-Powered Security Services
FortiGuard AI-Powered Security Services is part of Fortinet's layered defense and tightly integrated into our FortiGate NGFWs and other products. Powered by real-time AI enhanced threat intelligence from FortiGuard Labs, these services protect organizations against modern attack vectors and threats, including zero days and evasive, sophisticated AI-powered attacks.
Network and file security
Network and file security services protect against network and file-based threats. Consists of intrusion prevention system (IPS) which uses AI/ML models for deep packet/SSL inspection, detecting and blocking malicious content, uncovers hidden command-and-control activity, and applies virtual patches for newly discovered vulnerabilities. Application control improves security compliance and provides real-time visibility into applications and usage including generative AI (GenAI) applications.
Web/DNS security
Web/DNS security services protect against DNS-based attacks, malicious URLs (including those in emails), and botnet communications. DNS filtering blocks the full spectrum of DNS-based attacks while URL filtering uses a database of millions of URLs to identify and block malicious links. Meanwhile, IP reputation and anti-botnet services guard against botnet activity and DDoS attacks.
SaaS and data security
SaaS and data security services cover key security needs for application use and data protection. This service includes data loss/leakage prevention in files, GenAI applications and Images via OCR (optical character recognition). This ensures visibility, management, and protection (blocking exfiltration) of data in motion across networks, clouds, and users. The inline CASB service secures SaaS applications in use, providing broad visibility and granular control over SaaS access, usage, and data.
Zero-Day threat prevention
Zero-day threat prevention is achieved through AI-powered inline malware prevention to analyze file content to identify and block unknown and zero-day malware in real time, delivering sub-second protection across all NGFWs. Integrated into FortiGate NGFWs, the service provides comprehensive defense by blocking unknown threats, streamlining incident response, and reducing security overhead.
Attack surface visibility and compliance
The FortiGuard Attack Surface Security Service provides continuous, compliance-ready monitoring of your Fortinet Security Fabric infrastructure. It calculates your overall security posture rating by scoring controls against vulnerabilities, misconfigurations, and sub-optimal settings, while offering specific remediation guidelines for devices found out of configuration. It maintains continuous compliance with PCI DSS, CIS Controls, and Fortinet security best practices.
OT security
With over 2,400 virtual patches, 1,600+ OT applications, and 3,500+ protocol rules, integrated OT security capabilities detect threats targeting OT infrastructure, perform vulnerability correlation, apply virtual patching, and utilize industry-specific protocol decoders for robust defense of OT environments and devices.
Fortinet ASICs: Unrivaled Security, Unprecedented Performance
Powered by the only purpose-built SPU
Traditional firewalls cannot protect against today's content and connection-based threats because they rely on off-the-shelf general-purpose central processing units (CPUs), leaving a dangerous security gap. Fortinet's custom SPUs deliver the power you need to radically increase speed, scale, and efficiency while greatly improving user experience and reducing footprint and power requirements. Fortinet's SPUs deliver up to 520 Gbps of protected throughput to detect emerging threats and block malicious content while ensuring your network security solution does not become a performance bottleneck.
Fortinet ASICs are designed to be energy-efficient, leading to lower power consumption and improved TCO. They deliver industry-leading throughput, handle more traffic and perform security inspections faster, reduce latency for quicker packet processing and minimize network delays.
Fortinet SPUs are designed with integrated security functions like zero trust, SSL, IPS, and VXLAN to name but a few, dramatically improving the performance of these functions that competitors traditionally implement in software.
Network processor NP7
Network processors operate in line to deliver unmatched performance and scalability for critical network functions. Fortinet's breakthrough SPU NP7 works in line with FortiOS functions to deliver:
- Hyperscale firewall, accelerated session setup, and ultra-low latency
- Industry-leading performance for VPN, VXLAN termination, hardware logging, and elephant flows
Content processor CP10
Content processors act as co-processors to offload resource-intensive processing of security functions. The tenth generation of the Fortinet Content Processor, the CP10, accelerates resource-intensive SSL (including TLS 1.3) decryption and security functions while delivering:
- Pattern matching acceleration and fast inspection of real-time traffic for application identification
- IPS pre-scan/pre-match, signature correlation offload, and accelerated antivirus processing
FortiManager
AI-Powered, Automation-Driven, Enterprise-Class Centralized Management at Scale
FortiManager, powered by FortiAI-Assist, provides centralized, single-pane management for the Fortinet Security Fabric, unifying configuration, policy, and responses across thousands of devices. It converges networking and security management, enabling consistent policy enforcement across SD-WAN, ZTNA, SASE, and branch environments while delivering real-time visibility and automated network operations.
FortiAI-Assist helps with Day 0–1 provisioning and Day N troubleshooting and maintenance. AI agents collaborating via a unified Model Context Protocol (MCP) framework automates goal-driven tasks toward a self-healing operation.
FortiManager integrates with FortiSOC for contextual insights and fabric-wise response. It also supports ecosystem integrations, and open APIs for extended automation. ADOM-based administration and FortiManager clusters enables resilient control across distributed networks.
FortiConverter Service
Migration to FortiGate NGFW made easy
The FortiConverter Service provides hassle-free migration to help organizations transition quickly and easily from a wide range of legacy firewalls to FortiGate NGFWs. The service eliminates errors and redundancy by employing best practices with advanced methodologies and automated processes. Organizations can accelerate their network protection with the latest FortiOS technology.
FortiCare Services
Expertise at your service
Fortinet prioritizes customer success through FortiCare Services, optimizing the Fortinet Security Fabric solution. Our comprehensive life-cycle services include Design, Deploy, Operate, Optimize, and Evolve. The FortiCare Elite, one of the service offerings, provides heightened SLAs and swift issue resolution with a dedicated support team. This advanced support option includes an extended end-of-engineering support of 18 months, providing flexibility and access to the intuitive FortiCare Elite portal for a unified view of device and security health, streamlining operational efficiency and maximizing Fortinet deployment performance.
Hardware:
FortiGate 3500G Series

Trusted Platform Module (TPM)
The FortiGate 3500G Series features a dedicated module that hardens physical networking appliances by generating, storing, and authenticating cryptographic keys. Hardware-based security mechanisms protect against malicious software and phishing attacks.
FortiSentry
FortiSentry is an innovative out-of-band hardware module designed to enhance system integrity by continuously monitoring the FortiOS file system integrity. FortiSentry proactively detects and prevents unauthorized modifications to FortiOS system-level files, reinforcing the overall security posture of the platform.
Unlike traditional in-line software-based solutions, the FortiSentry hardware module is physically isolated from the FortiGate OS but monitors the filesystem to detect potential malicious activity, providing robust protection against targeted attacks.
Specifications:
|
FG-3500G |
FG-3501G |
| Hardware Accelerated 400GE QSFP-DD/ 200GE QSFP56/ 100GE QSFP28/ 40GE QSFP+ Ports |
2 |
| Hardware Accelerated 100GE QSFP28/ 40GE QSFP+ Slots |
4 |
| Hardware Accelerated 25GE SFP28/ 10GE SFP+/ GE SFP Slots |
30 |
| 10GE/ GE RJ45 Management Ports |
2 |
| USB Ports (Client / Server) |
1 |
| Console Port |
1 |
| Onboard Storage |
— |
2x 1.92TB SSD |
| Trusted Platform Module (TPM) |
Yes |
| Bluetooth Low Energy (BLE) |
— |
| Signed Firmware Hardware Switch |
Yes |
| FortiSentry |
Yes |
| Included Transceivers |
2x SFP+ (SR 10 GE) |
| IPS Throughput |
125 Gbps |
| NGFW Throughput |
115 Gbps |
| Threat Protection Throughput |
105 Gbps |
IPv4 Firewall Throughput (1518 / 512 / 64 byte, UDP) |
595 / 590 / 420 Gbps |
IPv6 Firewall Throughput (1518 / 512 / 86 byte, UDP) |
595 / 590 / 420 Gbps |
| Firewall Latency (64 byte, UDP) |
2.96 μs |
| Firewall Throughput (Packet per Second) |
630 Mpps |
| Concurrent Sessions (TCP) |
179 Million |
| New Sessions/Second (TCP) |
1.1 Million |
| Firewall Policies |
200,000 |
| IPsec VPN Throughput (512 byte) |
163 Gbps |
| Gateway-to-Gateway IPsec VPN Tunnels |
40,000 |
| Client-to-Gateway IPsec VPN Tunnels |
200,000 |
| SSL-VPN Throughput |
9.8 Gbps |
Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) |
30,000 |
SSL Inspection Throughput (IPS, avg. HTTPS) |
112 Gbps |
| SSL Inspection CPS (IPS, avg. HTTPS) |
112,345 |
SSL Inspection Concurrent Session (IPS, avg. HTTPS) |
18 Million |
| Application Control Throughput (HTTP 64K) |
197 Gbps |
| CAPWAP Throughput (HTTP 64K) |
TBA |
| Virtual Domains (Default / Maximum) |
10 / 500 |
| Maximum Number of FortiSwitches Supported |
300 |
| Maximum Number of FortiAPs (Total / Tunnel) |
4096 / 2048 |
| Maximum Number of FortiTokens |
20,000 |
| Maximum Number of FortiClients |
50,000 |
| High Availability Configurations |
Active-Active, Active-Passive, Clustering |
| Height x Width x Length (inches) |
3.5 x 17.4 x 20.8 |
| Height x Width x Length (mm) |
88.5 x 442.5 x 529.3 |
| Weight |
36.7 lbs (16.65 kg) |
37 lbs (16.8 kg) |
Form Factor (supports EIA/non-EIA standards) |
Rack Mount, 2U |
| AC Power Supply |
100-240 VAC, 60-50 Hz |
| AC Current (Maximum) |
12A@100V, 9A@240V |
| Power Consumption (Average / Maximum) |
678 W / 973 W |
688 W / 993 W |
| Heat Dissipation |
3318 BTU/h |
3386 BTU/h |
| Redundant Power Supplies |
Hot Swappable, Default dual AC PSU for 1+1 Redundancy |
| Power Supply Efficiency Rating |
80+ Compliant |
| Operating Temperature |
32°F to 113°F (0°C to 45°C) |
| Storage Temperature |
-31°F to 158°F (-35°C to 70°C) |
| Humidity |
5% to 90% non-condensing |
| Noise Level |
70.4 dBA |
| Forced Airflow |
Front to Back |
| Operating Altitude |
Up to 10,000 ft (3048 m) |
| Compliance |
FCC Part 15 Class A, ISED, CE, VCCI, PSE, BSMI, ANATEL, UL/cUL |
| Certifications |
USGv6/IPv6 |