Fortinet FortiGate 30G / 31G
The Fortinet FortiGate 30G and 31G are next-generation firewalls designed for small businesses and branch offices. It combines advanced security features with SD-WAN capabilities to protect your network and optimize performance. Powered by FortiOS, the FortiGate 30G firewall delivers fast and efficient protection against cyber threats using AI-powered FortiGuard services. Key features include real-time SSL inspection, intrusion prevention, and simplified management all in a compact, energy-efficient device. 30 GB of SSD onboard storage is included in the 31G model only.
You'll always get our best prices when you're signed in!
Fortinet FortiGate 30G Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP) - 1 Year simple - FG-30G-BDL-950-12
- Recommended for Teleworker, SOHO
- ISP Connection Speeds up to 400 Mbps*
- Content Filtering to control access to Internet content
- Gateway Antivirus to protect you from viruses & ransomware
- Intrusion Prevention Services to detect network attacks
- 24x7 Technical Services for support, firmware, and warranty
- Zero Day Protection from unknown threats
- AI-based Inline Malware Prevention for emerging AI-based threats
- Optional Configuration Support to get you secure
- Optional Hassle-Free Management to keep you secure
For Pricing, request a quote.
All orders placed after 3pm EST will ship on the next business dayFortinet FortiGate 31G Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP) - 1 Year simple - FG-31G-BDL-950-12
- Recommended for Teleworker, SOHO
- ISP Connection Speeds up to 400 Mbps*
- Content Filtering to control access to Internet content
- Gateway Antivirus to protect you from viruses & ransomware
- Intrusion Prevention Services to detect network attacks
- 24x7 Technical Services for support, firmware, and warranty
- Zero Day Protection from unknown threats
- AI-based Inline Malware Prevention for emerging AI-based threats
- Optional Configuration Support to get you secure
- Optional Hassle-Free Management to keep you secure
For Pricing, request a quote.
All orders placed after 3pm EST will ship on the next business day
Fortinet FortiGate 30G Product Overview
The Fortinet FortiGate 30G firewall is your reliable, subscription-enhanced Next-Generation Firewall (NGFW) designed for remote worker, SOHO, branch offices, and IoT environments. It delivers a firewall throughput of 400 Mbps and supports up to 600,000 concurrent sessions (TCP). The hardware features four Gigabit Ethernet ports (three internal and one WAN port). Designed for top security efficacy at a low TCO, the FG 30G provides advanced threat prevention, including Capture ATP sandboxing, IPS, and SSL VPN capabilities, while integrating with FortiGuard AI-Powered Security Services to deliver coordinated, automated, end-to-end threat protection in real time.
Fortinet FortiGate 30G Review
The Fortinet FortiGate 30G was released in Q2 of 2025 to great success. It replaced the FG 30F and improved on its technical specs in almost every way. The Fortinet FortiGate-30G has a max throughput of 400 Mbps SSL Inspection Throughput (IPS, avg. HTTPS), 500 Mbps Threat Protection throughput, 600,000 max sessions (TCP), 500 FortiTokens, and much more.
Check out our video or written review of the Fortinet FG-30G.
Fortinet FortiGate 30G Technical Specs
- Max Firewall Throughput: 4.0 Gbps
- Threat Prevention Throughput: 500 Mbps
- Application Control Throughput: 830 Mbps
- Max SSL Inspection Throughput HTPPS: 400 Mbps
- Network Interface Ports: 4x1GbE Cu (3x1GbE, 1xGbE WAN), 1 Console
- TCP Maximum Sessions: 600,000
- New Sessions: 30,000
- Firewall Policies: 2,000
- Gateway-to-Gateway IPsec VPN Tunnels: 200
FortiGate NGFW Security Features
- Gateway AV, IPS, & App Control: FortiGate 30G integrates an advanced Intrusion Prevention System (IPS) with signature-based detection, protocol decoders, and behavioral heuristics to identify and block malicious traffic, including worms, buffer overflows, and remote code execution (RCE) attempts. By performing deep packet inspection (DPI), the 30G can inspect encrypted traffic flows—a necessity given that the vast majority of modern web traffic is protected by TLS/SSL—to ensure that threats are not hidden within encrypted payloads. Furthermore, the 30G facilitates network segmentation, which is a foundational principle of Zero Trust architecture. By dividing the network into distinct security zones, the 30G prevents the lateral movement of threats, ensuring that if a single device is compromised, the infection cannot easily propagate across the entire infrastructure.
- Content Filtering: Content filtering on the FortiGate 30G is designed to enforce organizational acceptable use policies (AUP) and mitigate risks associated with web-borne threats. Administrators can configure granular policies that deny access to illegal, unproductive, or malicious websites based on user identity, device type, group membership, or specific time-of-day constraints. This functionality is supported by real-time threat intelligence feeds that categorize millions of URLs, ensuring that the 30G remains effective against newly registered domains and evolving phishing campaigns.
- 24x7 Support: To maintain the efficacy of the FortiGate 30G, the device relies on continuous updates from FortiGuard Labs. These updates include the latest firmware, signature databases for IPS and antivirus, and updated threat intelligence definitions. Users are provided with 24x7 support through an intuitive web portal, ensuring that security teams have immediate access to technical assistance and the latest security patches to defend against zero-day vulnerabilities
- Capture ATP Sandbox: The Fortinet Capture Advanced Threat Protection (ATP) service functions as a cloud-based, multi-engine sandbox environment. When the FortiGate 30G encounters a suspicious file that does not match known threat signatures, it can offload the file to the sandbox for detonation and behavioral analysis. This process is critical for identifying zero-day exploits, ransomware, and encrypted malware that attempt to hide their malicious intent. Upon confirming a threat, the system can trigger automated remediation workflows, which may include blocking the file across the network and initiating damage rollback procedures to restore affected systems to a known-good state.
- RTDMI Technology: Real-Time Deep Memory Inspection (RTDMI) represents a specialized advancement in the FortiGate 30G’s security stack. Traditional sandboxing often relies on file execution, which sophisticated malware can detect to remain dormant. RTDMI bypasses this by inspecting the memory space of the CPU during the execution phase, identifying malicious patterns at the instruction level. By analyzing traffic in real-time within the memory, the 30G can detect zero-day threats without the latency penalty typically associated with full-file emulation, ensuring that high-speed network performance is maintained alongside rigorous security.
- DNS Security: Domain Name System (DNS) security is a vital component of the 30G’s defense-in-depth strategy. By authenticating the origin of DNS responses, the appliance prevents DNS spoofing and cache poisoning attacks that redirect users to malicious infrastructure. Plus, the 30G applies DNS filtering to block requests to known command-and-control (C2) servers and phishing domains, effectively creating a protective barrier between internal users and the public internet before a connection is even established.
- Cloud Management: FortiGate 30G supports centralized orchestration through cloud-based management platforms such as FortiManager or the FortiCloud portal. This allows administrators to push consistent security policies across distributed environments from a single pane of glass. The inclusion of Network Security Manager Essentials provides critical visibility through seven days of cloud-based reporting. This telemetry allows security teams to analyze traffic patterns, identify anomalies, and optimize network performance, ensuring that the security infrastructure remains aligned with organizational operational requirements.
Optional Remote Installation and Support For Fortinet FG-30G Firewalls
Firewalls.com offers remote installation services. These include configuring the FortiGate-30G Firewall before it ships to the customer or doing remote installation if the device is already connected to the customers network.
Ongoing support is always available to clients who lack the necessary skill-set to manage technology of this complexity or who don’t have the time.

