Fortigate 5000 Series: Data Sheet
Fortigate 5000 Series: Data Sheet
Fortigate 5000 Series: Data Sheet
Refer to specification table for details. * Each Security Blade. ** With FG-5001E security blades
1
DATA SHEET | FortiGate® 5000 Series
DEPLOYMENT
Next Generation Firewall (NGFW) IPS
§ Reduce the complexity and maximize your ROI by § Purpose-built security processors delivering industry
integrating threat protection security capabilities into validated IPS performance with high throughput and low
a single high-performance network security appliance, latency
powered by Fortinet’s Security Processing Unit (SPU)
§ Deploy virtual patches at the network level to protect
§ Full visibility into users, devices, applications across against network exploitable vulnerabilities and optimize
the entire attack surface and consistent security policy network protection time
enforcement irrespective of asset location
§ Deep packet inspection at wire speeds offers unparalleled
§ Protect against network exploitable vulnerabilities with threat visibility into network traffic including traffic
Industry-validated IPS security effectiveness, low latency encrypted with the latest TLS 1.3
and optimized network performance
§ Proactively block newly discovered sophisticated attacks in
§ Automatically block threats on decrypted traffic using the real-time with advanced threat protection provided by the
Industry’s highest SSL inspection performance, including intelligence services of the Fortinet Security Fabric
the latest TLS 1.3 standard with mandated ciphers
§ Proactively block newly discovered sophisticated attacks in
real-time with AI-powered FortiGuard Labs and advanced
threat protection services included in the Fortinet Security Mobile Security for 4G, 5G, and IOT
Fabric
§ SPU accelerated, high performance CGNAT and IPv4 and
IPv6 traffic, for 4G SGi LAN and 5G N6 security
FortiSandbox
CAMPUS Advanced Threat
Protection
FortiAP
FortiClient Secure Access
VPN Client Point
DATA
CENTER FortiGate
FortiGate FortiClient FortiSwitch
Switching
FortiGate
NGFW Endpoint Protection NGFW
Segmentation IPS
FortiGate
FortiManager Segmentation
Single pane-of-Glass FortiManager
Management Single Pane-of-Glass
Management
FortiAnalyzer FortiAnalyzer
Analytics-powered Analytics-powered
Security & Log Management Security & Log Management
2
DATA SHEET | FortiGate® 5000 Series
ARCHITECTURE
3
DATA SHEET | FortiGate® 5000 Series
CHASSIS
FortiGate 5144C
Next Generation 14U 19-inch rack mount ATCA chassis with 40 Gbps Backplane and capable of Dual-Dual-Star topology. It can
install up to 14 FortiGate 5000 series blades.
FortiController 5903C
Boards
Slots 1 and 2
FortiGate 5001D FortiGate 5001D
Boards Boards
Slots 3, 5, 7, 9, Slots 4, 6, 8, 10, H/S
ACT
! H/S
ACT
!
12, and 14
H/S H/S
11, and 13
OOS OOS
RTM
Slot Slot Numbers
Numbers
RTM
Air Baffle
Slot Covers
Air Filter
ESD Frame
Socket
FG-5144C FG-5144C
Hardware Specifications Power and Environment
Available Slots 14 Power Required DC/AC 1
High Availability Backplane Fabric Built-in Chassis Only Power Consumption (Maximum) *** 960 W
40 Gbps Backplane Support Yes Heat Dissipation (Maximum) *** 3,276 BTU/h
Shelf Manager (Default / Maximum) 1/2 Operating Temperature 32–104°F (0–40°C)
Dual Networking Blade Support Yes Storage Temperature -13–158°F (-35–70°C)
Humidity 5–90% non-condensing
Dimensions
Height x Width x Length (inches) 24.44 x 19.06 x 21.63 Compliance
Height x Width x Length (cm) 62.1 x 48.4 x 55.0 Certifications FCC Part 15 Class A, RCM,
VCCI, CE, BSMI, UL/cUL
Weight 108 lbs (50 kg)
NEBS Certified Yes
Form Factor (supports EIA/non-EIA standards) 14 RU
1
Optional FortiGate 5053B Power Supply Shelf used to provide AC power to the FortiGate
Maximum Capacity** ** Based on fully-populated FortiGate 5001D
*** Please refer to respective Chassis Guide for computation of total power requirement.
Firewall Throughput 1.12 Tbps
AdvancedTCA™-compliant Chassis
§ Based on industry-conforming standards assuring § Highly scalable with minimum service disruptions
carrier-grade performance, reliability, 99.999% as hot-swapped blades may be added to increase
availability, and serviceability capacity with ease
§ Redundant fans, power modules, self managers, and § Comprehensive management and monitoring
alarm modules options facilities via shelf managers and alarm modules
4
DATA SHEET | FortiGate® 5000 Series
SECURITY BLADES
FortiGate 5001E/5001E1
MGMT 1 and MGMT 2 3 and 4
10/100/1000 Copper 10 G ig
Management Interfaces SFP+ Network
1 and 2 Interfaces
RJ-45 IPM
Latest purpose-built FortiGate security blade with carrier- Console
40 Gig
QSFP+ Network
LED
(board
Interfaces
class capacity and protection.
USB po s ition)
Hardware Features
Retention Retention
Factory Use
/
Screw OOS S TA Base and Fabric Screw
Extraction LED LED network activity NMI Switch Extraction
Lever LEDs Lever
PWR ACC
LED LED
Forti
NP6 CP9 40GE Carrier 480GB
FG-5001E/5001E1
Interfaces and Storage
40 GE QSFP+ Ports 2
10 GE SFP+ Ports 2
GE RJ45 Ports 2
RJ45 Console Port 1
Included Transceivers 2x 10 GE SFP+ SR
Local Storage 1x 480 GB SSD (5001E1)
System Performance
Firewall Throughput (1518 / 512 / 64 byte UDP packets) 80 / 80 / 50 Gbps
Firewall Latency (64 byte UDP packets) 3 μs
Firewall Throughput (Packets Per Second) 75 Mpps
Concurrent Sessions (TCP) 40 Million
New Sessions/Second (TCP) 640,000
Maximum Firewall Policies 200,000
IPsec VPN Throughput (512 byte packets) 45 Gbps
Gateway-to-Gateway IPsec VPN Tunnels 40,000
Client-to-Gateway IPsec VPN Tunnels 64,000
SSL-VPN Throughput 9 Gbps
Concurrent SSL-VPN Users (Recommended Maximum) 25,000
IPS Throughput (HTTP / Enterprise Mix) 1 25 / 18 Gbps
SSL Inspection Throughput 2 15 Gbps
SSL Inspection CPS (IPS, avg. HTTPS) 3 8,805
SSL Inspection Concurrent Session (IPS, avg. HTTPS) 3 3.97 Million
Application Control Throughput 3 36 Gbps
NGFW Throughput 4 15 Gbps
Threat Protection Throughput 5 13.5 Gbps
CAPWAP Throughput 15 Gbps
Virtual Domains (Default / Maximum) 10 / 500
Maximum Number of FortiTokens 20,000
Maximum Number of Registered FortiClients 20,000
Maximum Number of FortiAPs (Total / Tunnel) 4,096 / 1,024
Compliance
Certifications FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB, ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN
NEBS Certified –
Note: A
ll performance values are “up to” and vary depending on system configuration. IPsec VPN performance is based on 512 byte UDP packets using AES-256+SHA1. 1. IPS performance is measured
using 1 Mbyte HTTP and Enterprise Traffic Mix. 2. SSL Inspection is measured with IPS enabled and HTTP traffic, using TLS v1.2 with AES256-SHA. 3. Application Control performance is measured
with 64 Kbytes HTTP traffic. 4. NGFW performance is measured with IPS and Application Control enabled, based on Enterprise Traffic Mix. 5. Threat Protection performance is measured with IPS
and Application Control and Malware protection enabled, based on Enterprise Traffic Mix. 6. CAPWAP performance is based on 1444 byte UDP packets.
5
DATA SHEET | FortiGate® 5000 Series
NETWORKING BLADES
FortiController 5903C/5913C
High Performance networking blade that provides 10/40-gigabit fabric and 1-gigabit base backplane channel layer-2 switching
in a dual star architecture.
Base Network
Activity LEDs B1 and B2
F1 and F2 10 Gig Base Channel
Fabric Network RJ-45 40 GE QSFP+ RJ-45 100 Gig Fabric Channel SFP+ Interfaces IPM
Activity LEDs Console Network 10 GE SFP+ Console CFP2 Network (heartbeat and LED
Interface Slots Base Channel Interface Slots Interfaces (data) management) (board
USB position)
Retention Retention
Screw OOS STA Screw
GE Copper Extraction LED LED MGMT Extraction
Management Interface Lever 10/100/1000 Copper Lever
PWR Management Interface
LED
Maximum Concurrent Sessions 135 Million 135 Million NEBS Certified Yes Yes
AC POWER SUPPLIES
FortiGate 5053B and Power Supply Unit 5000B
The FortiGate 5053B is a 1U 19-inch rack mount power supply shelf with PSU-5000B hot swappable power supplies to convert
AC power to DC power and to supply power to a FortiGate 5000 series chassis.
NON-REDUNDANT REDUNDANT
Number of PSUs 1 2 3 4 1+1 2+1 3+1
5053B with PSU-5000B 2,725 W 5,450 W 8,175 W 10,900 W 2,725 W 5,450 W 8,175 W
(185–307V AC High Line Input)
5053B with PSU-5000B 1,200 W 2,400 W 3,600 W 4,800 W 1,200 W 2,400 W 3,600 W
(100–184V AC Low Line Input, North America, Mexico, Japan)
6
DATA SHEET | FortiGate® 5000 Series
Chassis
FG-5060 FG-5060
Hardware Specifications Power and Environment
Available Slots 6 Power Required DC/AC 1
High Availability Backplane Fabric Built-in Chassis-Only Power Consumption 350 W
(Maximum) ***
40 Gbps Backplane Support –
Heat Dissipation (Maximum) *** 1194 BTU/h
Shelf Manager (Default / Maximum) 1/2
Operating Temperature 41–104°F (5–40°C)
Dual Networking Blade Support Yes
Storage Temperature 23–131°F (-5–55°C)
Dimensions
Humidity 5–85% non-condensing
Height x Width x Length (inches) 8.86 x 17.64 x 18.82
Compliance
Height x Width x Length (cm) 22 x 44.8 x 47.8
Certifications FCC Part 15 Class A, RCM, VCCI, CE, BSMI,
Weight 38 (17.3 kg) UL/cUL
7
DATA SHEET | FortiGate® 5000 Series
Security Fabric
The industry’s highest-performing cybersecurity platform,
powered by FortiOS, with a rich ecosystem designed to Fabric Management Fabric Security
Center Operations
span the extended digital attack surface, delivering fully
automated, self-healing network security. NOC SOC
FortiOS™
Operating System
FortiOS, Fortinet’s leading operating system enable the The release of FortiOS 7 dramatically expands the Fortinet
convergence of high performing networking and security Security Fabric’s ability to deliver consistent security across
across the Fortinet Security Fabric delivering consistent and hybrid deployment models consisting on appliances, software
context-aware security posture across network endpoint, and and As-a-Service with SASE, ZTNA and other emerging
clouds. The organically built best of breed capabilities and cybersecurity solutions.
unified approach allows organizations to run their businesses
without compromising performance or protection, supports
seamless scalability, and simplifies innovation consumption.
SERVICES
FortiGuard™ FortiCare™
Security Services Services
FortiGuard Labs offers real-time intelligence on the threat Fortinet is dedicated to helping our customers succeed, and
landscape, delivering comprehensive security updates across every year FortiCare services help thousands of organizations
the full range of Fortinet’s solutions. Comprised of security get the most from their Fortinet Security Fabric solution. We
threat researchers, engineers, and forensic specialists, the have more than 1,000 experts to help accelerate technology
team collaborates with the world’s leading threat monitoring implementation, provide reliable assistance through advanced
organizations and other network and security vendors, as well support, and offer proactive care to maximize security and
as law enforcement agencies. performance of Fortinet deployments.
8
DATA SHEET | FortiGate® 5000 Series
ORDER INFORMATION
PRODUCT SKU DESCRIPTION
Chassis
FortiGate 5144C Chassis FG-5144C-DC 14U 14-slot chassis with 40G Dual Dual Star fabric backplane, 4 PEMs, 4 fan units, 2 shelf FRU data modules, 1
shelf manager, front and RTM air baffles, and 4 pairs DC cables for connecting to FG-5053B power shelves
FortiGate 5144C-DC Chassis FG-5144C-DC-NEBS 14U 14-slot chassis with 40G Dual Dual Star fabric backplane, 4 PEMs, 4 fan units, 2 shelf FRU data modules, 1
shelf manager, front and RTM air baffles, and 4 pairs DC cables for connecting to FG-5053B power shelves, NEBS
certified
FortiGate 5144C Shelf Manager FG-5144C-SM 5144C shelf manager with ShMM-700R mezzanine card and radial IPMB bus
FortiGate 5144C Fan Tray FG-5144C-FAN-F FG-5144C fan tray front
FortiGate 5144C Fan Tray FG-5144C-FAN-R FG-5144C fan tray rear
FortiGate 5144C Shelf FRU Data Module FG-5144C-SFRU FG-5144C shelf FRU data module
FortiGate 5144C Power Entry Module FG-5144C-PEM FG-5144C PEM, power entry module
FortiGate 5144C Air Filter FG-5144C-AF FG-5144C air filter
FortiGate 5144C Blank Panel FG-5144C-ABF 5000 front slot blank panel with air baffle (aluminum/plastic)
FortiGate 5144C Blank Panel FG-5144C-ABR 5000 RTM slot blank panel with air baffle (aluminum/plastic)
FortiGate 5060 Chassis FG-5060-DC 5U 6-slot chassis with Dual Star fabric backplane, 2 PEMs, 2 fan units, 2 shelf FRU data modules, 1 shelf manager,
front and RTM air baffles, and 2 pairs DC cables for connecting to FG-5053B power shelves
FortiGate 5060 Fan Tray FG-5060FA Fan tray for FG-5060 chassis
FortiGate 5060 Shelf Manager FG-5060SM Shelf manager for FG-5060 chassis
FortiGate 5060 Shelf Alarm Panel FG-5060SAP Shelf alarm panel for FG-5060 chassis
FortiGate 5053B Power Converter Tray FG-5053B AC power converter shelf for high capacity 5000 chassis, supports up to 4 PSU-5000B power supply units,
unpopulated
FortiGate 5000 Series Power Supply Unit PSU-5000B Power supply unit for FG-5000 series, AC power supply unit, 1,200 Watts maximum, requires FortiGate 5053B shelf
Security Blades
FortiGate 5001E FG-5001E Security blade with 2x 40 GE QSFP+ ports, 2x 10 GE SFP+ ports, 2x GE RJ45 management ports, FortiASIC NP6
and CP9 hardware accelerated
FortiGate 5001E1 FG-5001E1 Security blade with 2x 40 GE QSFP+ ports, 2x 10 GE SFP+ ports, 2x GE RJ45 management ports, FortiASIC NP6
and CP9 hardware accelerated, 480 GB SSD onboard storage
Networking Blades
FortiController 5903C FCTRL-5903C Networking blade with 4x 40 GE SFP+ fabric slots, 2x 10 GE SFP+ base slots, 1x GE RJ45 management port
FortiController 5913C FCTRL-5913C Networking blade with 2x 100 GE CFP2 fabric slots, 2x 10 GE SFP+ base slots, includes 2 SR SFP+
Optional Accessories
1 GE SFP LX Transceiver Module FN-TRAN-LX 1 GE SFP LX transceiver module for all systems with SFP and SFP/SFP+ slots.
1 GE SFP RJ45 Transceiver Module FN-TRAN-GC 1 GE SFP RJ45 transceiver module for all systems with SFP and SFP/SFP+slots.
1 GE SFP SX Transceiver Module FN-TRAN-SX 1 GE SFP SX transceiver module for all systems with SFP and SFP/SFP+ slots.
10 GE SFP+ RJ45 Transceiver Module FN-TRAN-SFP+GC 10 GE SFP+ RJ45 transceiver module for systems with SFP+ slots.
10 GE SFP+ Transceiver Module, Short FN-TRAN-SFP+SR 10 GE SFP+ transceiver module, short range for all systems with SFP+ and SFP/SFP+ slots.
Range
10 GE SFP+ Transceiver Module, Long FN-TRAN-SFP+LR 10 GE SFP+ transceiver module, long range for all systems with SFP+ and SFP/SFP+ slots.
Range
10 GE SFP+ Transceiver Module, Extended FN-TRAN-SFP+ER 10 GE SFP+ transceiver module, extended range for all systems with SFP+ and SFP/SFP+ slots.
Range
10 GE SFP+ Active Direct Attach Cable SP-CABLE-ADASFP+ 10 GE SFP+ active direct attach cable, 10m / 32.8 ft for all systems with SFP+ and SFP/SFP+ slots
40 GE QSFP+ Transceiver Module, Short
FN-TRAN-QSFP+SR 40 GE QSFP+ transceiver module, short range for all systems with QSFP+ slots.
Range
40 GE QSFP+ Transceiver Module, Long
FN-TRAN-QSFP+LR 40 GE QSFP+ transceiver module, long range for all systems with QSFP+ slots.
Range
100 GE CFP2 Transceivers, Long Range FG-TRAN-CFP2-LR4 100 GE CFP2 transceivers, long range, over single mode fiber, for all systems with CFP2 slots
100 GE CFP2 Transceivers, Short Range FG-TRAN-CFP2-SR10 100 GE CFP2 transceivers, 10 channel parallel fiber, short range for all systems with CFP2 slots
9
DATA SHEET | FortiGate® 5000 Series
BUNDLES
360 Enterprise Unified Threat Advanced Threat
Bundles
Protection Protection Protection Protection
1. 24x7 plus Advanced Services Ticket Handling 2. Available when running FortiOS 7.0
www.fortinet.com
Copyright © 2021 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product
or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other
conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser
that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any
such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise
revise this publication without notice, and the most current version of the publication shall be applicable.
FG-5000E-DAT-R44-20210312