We deployed a FortiGate 600E to replace an aging ASA. Vendor spec sheet claimed 10Gbps threat protection. Real numbers were different.
**Environment:**
* 500 users, mix of on-prem and VPN
* UTM profiles enabled (AV, IPS, App Control)
* ~1500 Mbps internet circuit
* Policy-based routing for internal segmentation
**Measured throughput (Spirent test):**
* HTTP traffic (no UTM): ~8 Gbps
* HTTPS with SSL inspection: 2.1 Gbps
* IPS-enabled traffic: 1.8 Gbps
* Concurrent sessions: 1.2 million (close to spec)
**Key findings:**
* SSL inspection is the biggest hit. Factor 4x reduction.
* Throughput drops ~30% under maximum policy count (we hit 400 policies).
* CPU was the bottleneck, not memory.
* HA failover took 9 seconds. Not sub-second as some claim.
If you're sizing, ignore the marketing "up to" numbers. Test with your own traffic profiles. The hardware is capable, but realistic throughput depends entirely on which features you enable.