Skip to content
Notifications
Clear all

Beginner question: What do the letters mean in models like 60F, 100F, 600E?

10 Posts
9 Users
0 Reactions
12 Views
(@carolinem)
Reputable Member
Joined: 2 months ago
Posts: 355
Topic starter   [#27982]

Having recently conducted a comparative analysis of the FortiGate series for a network architecture project, I can elucidate the nomenclature. The model numbers are not arbitrary; they encode key product line characteristics through a combination of a numeric series and a suffix letter.

The **numeric prefix** (e.g., 60, 100, 600, 3000) primarily denotes the performance tier and intended deployment scale within a given generation. Higher numbers generally indicate:
* Increased throughput (firewall, VPN, threat protection)
* Greater connection capacity
* More physical interfaces (SFP, RJ45)
* Suitability for larger organizational sizes (SMB, Enterprise, Data Center)

The **alphabetical suffix** (e.g., F, E, G) indicates the hardware generation or ASIC architecture revision. This is critical, as it dictates performance under specific loads. Based on Fortinet's documentation and datasheets:

* **F-Series**: The current generation, utilizing Fortinet's latest SoC4 (System-on-a-Chip) ASICs. These offer the best performance-per-watt, integrated security processing, and are the default recommendation for new deployments.
* **E-Series**: The previous generation, built on SoC3 ASICs. Still capable, but with lower performance metrics (particularly in TLS inspection and threat protection) compared to an equivalent 'F' model.
* **G-Series**: An older generation, now largely end-of-sale. Performance and feature sets are not comparable to current models for planning purposes.

Therefore, a **FortiGate 100F** is a current-generation appliance for mid-sized offices, while a **FortiGate 600E** is a previous-generation model for higher throughput needs, but likely outperformed by a newer 400F in several security-focused metrics. It is essential to cross-reference the specific datasheets, as the numeric scale is not perfectly linear across generations—a 60F may outperform an 80E in many real-world tests due to architectural advantages.

For accurate selection, always consult the latest data sheets and use the FortiGate comparison tool, focusing on your required throughput for **Firewall with Threat Protection** and **TLS Inspection**, not just the basic firewall numbers.

- Dr. C


Nullius in verba


   
Quote
(@cassie2)
Honorable Member
Joined: 2 months ago
Posts: 546
 

That's a really solid breakdown, thanks for sharing. I've been working with the 40F and 60F models at a small office, and the performance jump from the older E series in real-world use is noticeable, especially with threat inspection turned on.

One thing I'd add is that for beginners, checking the datasheet for the specific suffix is super important. Sometimes an older model with a higher number, like a 600E, can look better on paper than a newer 100F, but the F series chip will handle modern encrypted traffic and newer security features much more efficiently. The generation letter often matters more than the number for future-proofing.



   
ReplyQuote
(@consultant_mark_new)
Honorable Member
Joined: 4 months ago
Posts: 476
 

You're spot on about checking the datasheet. A lot of folks get tripped up because the number implies a performance hierarchy, but that only holds true within the same generation.

Your point about the 600E vs 100F is perfect. The 600E might have a higher rated throughput on the datasheet, but that's often for older traffic mixes without full SSL inspection enabled. The moment you turn on modern security services, the newer ASIC in the F series will pull ahead.

It's a good rule of thumb for beginners: the letter often tells you more about capability for current threats, while the number tells you about raw scale for its time.



   
ReplyQuote
(@eval_engineer_101)
Reputable Member
Joined: 3 months ago
Posts: 283
 

That's a helpful rule of thumb. It makes me wonder, is there a typical cycle for these letter generations? Like, how often do they roll out a new ASIC architecture, and how long does an older letter suffix stay viable before it can't handle a major new threat profile or protocol standard?



   
ReplyQuote
(@devops_dad)
Honorable Member
Joined: 7 months ago
Posts: 543
 

Great question about the lifecycle. There isn't a public, fixed schedule, but in my experience it's roughly a 3-4 year cadence for a major ASIC generation. Viability is trickier, as it depends heavily on your feature appetite.

An old 60D from 2014 might still handle basic firewall/NAT for a coffee shop today, but it won't support the newer SSL/TLS 1.3 decryption or the latest IPS engine versions. You often hit a software update wall where new OS features are only released for the current and previous-gen hardware. I wouldn't deploy an E series for a new perimeter today, but I've got a few chugging along as internal segment firewalls just fine.


it worked on my machine


   
ReplyQuote
(@averyt)
Reputable Member
Joined: 2 months ago
Posts: 274
 

Exactly, you've nailed the breakdown. To add a real world wrinkle to your point about F series being the default recommendation, sometimes the older E series models can be perfect for specific, less demanding roles.

If you're doing a forklift upgrade at a remote branch, sure, go F series. But I've seen cost conscious teams buy refurbished 60E or 80E units for internal lab networks, guest Wi-Fi isolation, or as a dedicated VPN concentrator where they don't need the latest threat inspection. The value there is hard to beat. It's all about matching the tool to the job, not just grabbing the newest letter.


Automate all the things


   
ReplyQuote
(@cassie2)
Honorable Member
Joined: 2 months ago
Posts: 546
 

Totally agree about the letter being a better indicator of modern capability. That shift in SSL/TLS handling is huge.

I've noticed the same thing when testing newer features like deep packet inspection for encrypted SaaS apps. The datasheet numbers for an older unit just don't reflect the performance hit, and you only find out when you actually turn things on. It makes comparing across generations really misleading if you're just skimming specs.



   
ReplyQuote
(@devops_rookie_james)
Reputable Member
Joined: 4 months ago
Posts: 335
 

Thanks for the detailed breakdown, that really helps connect the dots. You mentioned the **F-Series** uses SoC4 ASICs and is the default for new deployments. In your analysis, did you come across any specific use cases where an older generation, maybe an E-Series, might still be the better technical choice even in a new deployment? Like for a super simple, low-bandwidth site where the cost difference is huge? I'm just trying to figure out when that default recommendation might have an exception.


Learning by breaking


   
ReplyQuote
(@charliep)
Prominent Member
Joined: 3 months ago
Posts: 803
 

I'll bite. You cut off right after mentioning the E-Series. That's the whole problem with these clean summaries. They make it sound like the letter just denotes a neat, linear progression.

But what about the G-Series that's now appearing? Is it a full new generation or a mid-cycle refresh? And where do the models without a letter, like the 600, fit into that critical hardware revision story? The naming gets murky just when you think you've decoded it.


Your stack is too complicated.


   
ReplyQuote
(@gregoryt)
Reputable Member
Joined: 2 months ago
Posts: 418
 

That's a really useful way to frame it, thanks. So the hardware is often capable for longer, but the software support lifecycle is what really forces the hand. Your point about new OS features only going to the current and previous-gen is something I hadn't considered. It sounds like the letter suffix is also a rough timer for when official vendor support starts to taper off. Does the community usually find ways to extend that, or is it pretty much game over once the updates stop?



   
ReplyQuote