FortiGate-601F-BDL-950-12

Key Hardware / Physical Specs
  • Form factor: 1U rackmount (desktop style racks)
  • Size & weight: ~ 44.45 mm × 432 mm × 380 mm and about 7.1–7.5 kg depending on configuration.
  • Power: Dual AC power supplies (hot‑swappable) for redundancy. Power consumption in typical mode ~ ~170‑180 W, peak higher.
  • Operating conditions: Temperature etc typical for datacenter / enterprise deployment; compliance certifications like CE, FCC, UL, etc.

Fortinet FortiGate FG-601F-BDL-950-12 Hardware + 1 year FortiCare Premium UTP

Description

This is a bundle that includes the FortiGate 601F hardware plus a 1‑year license for FortiCare Premium and FortiGuard Unified Threat Protection (UTP). Unified Threat Protection (UTP) typically includes services such as intrusion prevention (IPS), antivirus/anti-malware, web filtering, application control, sandboxing, and other advanced security features. FortiCare Premium gives you a higher tier of support (24×7, faster response, etc.). This is a next‑generation firewall (NGFW) appliance, part of Fortinet’s 600F series. The model “601F” is one of the variants. It’s designed for mid‑sized to large enterprises, campus networks, or distributed branch/core networks. It supports advanced threat protection, SD‑WAN, VPN, Zero‑Trust / ZTNA, SSL inspection, intrusion prevention, etc. It runs on Fortinet’s FortiOS and uses Fortinet’s hardware‑accelerated SPU chips, particularly NP7 (network) and CP9 (content) processors, to offload heavy traffic/inspection workloads.

Key Features

  • Purpose‑built hardware acceleration via Fortinet ASIC / SPU processors — NP7 (network processor) + CP9 (content/inspection processor) — to offload and accelerate firewall, VPN, SSL/TLS inspection, IPS etc.
  • Strong throughput numbers for real‑world / enterprise mixed traffic:
      • IPS throughput up to ≈ 14 Gbps 
      • NGFW (Next‑Gen Firewall) throughput around 11.5 Gbps
      • Threat Protection throughput ≈ 10.5 Gbps (includes AV, sandboxing etc.)
  • Very high raw firewall throughput (UDP traffic, large packets etc.): ~139 Gbps for large UDP packets, ~70 Gbps for small packet loads.
  • Low latency (for small packets) due to the SPU acceleration.
  • Supports large numbers of concurrent sessions, high session startup rates:
      • Concurrent TCP sessions ~ 8 million 
      • New sessions per second ~ ≈ 550,000
  • Solid VPN performance:
      • IPsec VPN throughput ~ 55 Gbps 
      • SSL‑VPN throughput ~ 4.3 Gbps
  • SSL Inspection capability:
      • Inspection throughput (HTTPS etc.) ~ 9 Gbps for average SSL/HTTPS traffic with IPS etc. 
      • Large numbers of concurrent SSL inspection sessions (~840,000)
  • Flexible interfaces / port types:
      • 16 × 1 Gb RJ45 ports 
      • 8 × 1 Gb SFP slots
      • 4 × 10 Gb SFP+ slots 
      • 4 × 25 Gb SFP28 slots (also compatible with 10Gb) for ultra low latency/high bandwidth uplinks.
  • On‑board storage: Dual SSDs (2 × 240 GB) for logs, etc.
  • Redundant / high‑availability features: hot‑swappable power supplies, support for Active‑Active or Active‑Passive HA / clustering.
  • Virtualization / multi‑tenancy: multiple Virtual Domains (VDOMs) supported (default/max ~10) allowing segmentation or logical firewall slices.
  • Integration with Fortinet’s broader Security Fabric: FortiGuard services (threat intelligence, malware, web filtering, etc.), SD‑WAN, management through FortiManager / FortiCloud etc.

Security

  • Identifies thousands of applications inside network traffic for deep inspection and granular policy enforcement
  • Protects against malware, exploits, and malicious websites in both encrypted and non-encrypted traffic
  • Prevent and detect against known and unknown attacks using continuous threat intelligence from AI-powered FortiGuard Labs security services

Performance

  • Delivers industry’s best threat protection performance and ultra-low latency using purpose-built security processor (SPU) technology
  • Provides industry-leading performance and protection for SSL encrypted traffic

Certification

  • Independently tested and validated best security effectiveness and performance
  • Received unparalleled third-party certifications from NSS Labs

Networking

  • Delivers advanced networking capabilities that seamlessly integrate with advanced layer 7 security and virtual domains (VDOMs) to offer extensive deployment flexibility, multi-tenancy and effective utilization of resources
  • Delivers high-density, flexible combination of various high-speed interfaces to enable best TCO for customers for data center and WAN deployments

Management

  • Includes a management console that is effective, simple to use, and provides comprehensive network automation and visibility
  • Provides Zero Touch Integration with Security Fabric’s Single Pane of Glass Management
  • Predefined compliance checklist analyzes the deployment and highlights best practices to improve overall security posture

Security Fabric

  • Enables Fortinet and Fabric-ready partners’ products to provide broader visibility, integrated end-to-end detection, threat intelligence sharing, and automated remediation

Strengths

  • High throughput even with advanced security features enabled, because of SPU acceleration.
  • A large number of ports, including high‑speed ones (25G etc.) for backbone / aggregation purposes.
  • Onboard storage in 601F helps for logging / reporting chores without needing external devices immediately.
  • Good scalability: able to handle many simultaneous sessions, VPNs, etc.
  • Strong feature set: SSL inspection, threat protection, intrusion prevention, etc., plus SD‑WAN, ZTNA etc via FortiOS services.
  • Redundant power supplies, rackable, designed for enterprise usage.

Use Cases / Where It Fits

This bundle is intended for:

  • Large enterprises, data centers, or environments needing high throughput and advanced threat protection
  • Deployments where you want “all in one” — hardware + license + support for an initial period
  • Situations where you plan to scale in future and want headroom (i.e. you don’t want to buy something that barely meets your current load)

Less suitable when:

  • For small branch offices with few users or low traffic, simpler / lower cost appliances may suffice.
  • If budget is constrained (both CAPEX & OPEX) and features won’t be used to capacity.