Fortinet FortiGate 3960E-DC
Data Center Firewall with 100 GE Interfaces
Click here to jump to more pricing!
Please Note: All Prices are Inclusive of GST
Overview:
The FortiGate 3900E series delivers high performance threat protection for mid-sized to large enterprises and service providers, with the flexibility to be deployed at the Internet or cloud edge, in the data center core or internal segments. The multiple high-speed interfaces, high port density, industry-leading security efficacy and high throughput of the 3900E series keeps your network connected and secure.
Security
- Protects against known exploits, malware and malicious URLs using continuous threat intelligence provided by FortiGuard Labs security services
- Protects against unknown attacks using dynamic analysis and provides automated mitigation to stop targeted attacks
Performance
- Delivers industry’s best threat protection performance and ultra-low latency using purpose-built security processor (SPU) technology
- Unprecedented 1 Terabit/second network firewall throughput in an appliance form factor for FortiGate 3980E
- Provides industry-leading performance and protection for SSL encrypted traffic
Certification
- Independently tested and validated best security effectiveness and performance
- Received unparalleled third-party certifications from NSS Labs, ICSA, Virus Bulletin and AV Comparatives
Networking
- Delivers extensive routing, high-speed interfaces, and high performance VPN capabilities to address performance and connectivity needs of large-scale data center and cloud applications
- Enables flexible deployment such as Next Generation Firewall and Secure SD-WAN
Management
- Single Pane of Glass with Network Operations Center (NOC) view provides 360° visibility to identify issues quickly and intuitively
- Predefined compliance checklist analyzes the deployment and highlights best practices to improve overall security posture
Security Fabric
- Enables Fortinet and Fabric-ready partners’ products to collaboratively integrate and provide end-to-end security across the entire attack surface
Features:
Security Fabric
The Security Fabric allows security to dynamically expand and adapt as more and more workloads and data are added. Security seamlessly follows and protects data, users, and applications as they move between IoT, devices, and cloud environments throughout the network.
FortiGates are the foundation of Security Fabric, expanding security via visibility and control by tightly integrating with other Fortinet security products and Fabric-Ready Partner solutions.
FortiOS
Control all the security and networking capabilities across the entire FortiGate platform with one intuitive operating system. Reduce operating expenses and save time with a truly consolidated nextgeneration security platform.
- A truly consolidated platform with one OS for all security and networking services for all FortiGate platforms
- Industry-leading protection: NSS Labs Recommended, VB100, AV Comparatives, and ICSA validated security and performance.
- Control thousands of applications, block the latest exploits, and filter web traffic based on millions of real-time URL ratings.
- Prevent, detect, and mitigate advanced attacks automatically in minutes with integrated advanced threat protection.
- Fulfill your networking needs with extensive routing, switching, and SD-WAN capabilities.
- Ultilize SPU hardware acceleration to boost security capability performance.
SERVICES
FortiGuard™ Security Services
FortiGuard Labs offers real-time intelligence on the threat landscape, delivering comprehensive security updates across the full range of Fortinet’s solutions. Comprised of security threat researchers, engineers, and forensic specialists, the team collaborates with the world’s leading threat monitoring organizations and other network and security vendors, as well as law enforcement agencies.
FortiCare™ Support Services
Our FortiCare customer support team provides global technical support for all Fortinet products. With support staff in the Americas, Europe, Middle East, and Asia, FortiCare offers services to meet the needs of enterprises of all sizes.
Hardware:
FortiGate 3980E/-DC Interfaces
- Console Port
- USB Port
- 2x GE RJ45 Management Ports
- 16x 1/10 G SFP/SFP+ Slots
- 10x 100 GE QSFP28 Slots
FortiGate 3960E/-DC Interfaces
- Console Port
- USB Port
- 2x GE RJ45 Management Ports
- 16x 1/10 G SFP/SFP+ Slots
- 6x 40/100 GE QSFP+/QSFP28 Slots
Powered by SPU
- Custom SPU processors deliver the power you need to detect malicious content at multi-Gigabit speeds
- Other security technologies cannot protect against today’s wide range of content- and connection-based threats because they rely on general-purpose CPUs, causing a dangerous performance gap
- SPU processors provide the performance needed to block emerging threats, meet rigorous third-party certifications, and ensure that your network security solution does not become a network bottleneck
Network Processor
Fortinet’s new, breakthrough SPU NP6 network processor works inline with FortiOS functions delivering:
- Superior firewall performance for IPv4/IPv6, SCTP and multicast traffic with ultra-low latency down to 2 microseconds
- VPN, CAPWAP and IP tunnel acceleration
- Anomaly-based intrusion prevention, checksum offload and packet defragmentation
- Traffic shaping and priority queuing
Content Processor
Fortinet’s new, breakthrough SPU CP9 content processor works outside of the direct flow of traffic and accelerates the inspection of computationally intensive security features:
- Enhanced IPS performance with unique capability of full signature matching at ASIC
- SSL Inspection capabilities based on the latest industry mandated cipher suites
- Encryption and decryption offloading
Deployment:
Next Generation Firewall (NGFW)
- Security gateway to the Internet for enterprises
- Enforce security policies with granular control and visibility of users and devices for thousands of discrete applications
- Identify and stop threats with powerful intrusion prevention beyond port and protocol that examines the actual content of your network traffic
Internal Segmentation Firewall (ISFW)
- Segmentation solution for end-to-end protection against threats while meeting compliance requirements
- High port density and accelerated traffic processing capacity, to protect multiple segments without compromising performance
- Deploy transparently and rapidly into existing environments with minimal disruption
Data Center Firewall and IPS (DCFW-IPS)
- High availability, high throughput and low latency firewall for data center edge and core
- High session scale for accommodating large network and user traffic for Internet and cloud-facing data centers
- High-speed interfaces for future-proof connectivity while compact size contributes to greener data centers
- Performance optimized IPS engine to detect and deter latest known and zero day threats
Carrier-Class Firewall (CCFW)
- Reliable high capacity firewall designed for service providers
- Powered by multiple SPU Network Processors that accelerate processing for both IPv4 and IPv6 traffic
- Supports Carrier License upgrade that unlocks features and protocol support for mobile networks such as GTP and SCTP
- High-speed interfaces for future-proof connectivity
Specifications:
FortiGate 3980E-DC | FortiGate 3960E-DC | ||
---|---|---|---|
Interfaces & Modules | |||
40/100 GE QSFP+/QSFP28 Slots | 10 | 6 | |
10 GE SFP+ Slots | 16 | ||
GE RJ45 Management Ports | 2 | ||
USB Ports | 1 | ||
Console Port | 1 | ||
Internal Storage | - | ||
Included Transceivers | 2x SFP+ (SR 10 GE) | ||
System Performance & Capacity | |||
Firewall Throughput (1518 / 512 / 64 byte, UDP) |
1.05 Tbps / 1.05 Tbps / 680 Gbps | 620 / 610 / 370 Gbps | |
Firewall Latency (64 byte, UDP) | 3 μs | ||
Firewall Throughput (Packet per Second) | 1,020 Mpps | 555 Mpps | |
Concurrent Sessions (TCP) | 160 Million | ||
New Sessions/Sec (TCP) | 550,000 | ||
Firewall Policies | 200,000 | ||
IPsec VPN Throughput (512 byte) | 400 Gbps | 280 Gbps | |
Gateway-to-Gateway IPsec VPN Tunnels | 40,000 | ||
Client-to-Gateway IPsec VPN Tunnels | 200,000 | ||
SSL-VPN Throughput | 9.5 Gbps | 9 Gbps | |
Concurrent SSL-VPN Users (Recommended Maximum, Tunnel Mode) |
30,000 | 30,000 | |
SSL Inspection Throughput (IPS, HTTP) | 32 Gbps | 30 Gbps | |
Application Control Throughput (HTTP 64K) | 55 Gbps | 40 Gbps | |
Virtual Domains (Default / Maximum) | 10 / 500 | ||
Maximum Number of Switches Supported | 256 | ||
Maximum Number of FortiAPs (Total / Tunnel Mode) |
4,096 / 1,024 | ||
Maximum Number of FortiTokens | 5,000 | ||
Maximum Number of Registered FortiClients | 100,000 | ||
High Availability Configurations | Active / Active, Active / Passive, Clustering | ||
System Performance — Optimal Traffic Mix | |||
IPS Throughput | 82 Gbps | 80 Gbps | |
System Performance — Enterprise Traffic Mix | |||
IPS Throughput | 32 Gbps | 30 Gbps | |
NGFW Throughput | 28 Gbps | 22 Gbps | |
Threat Protection Throughput | 18.5 Gbps | 13.5 Gbps | |
Dimensions and Power | |||
Height x Width x Length (inches) | 8.8 x 17.2 x 27.3 | ||
Height x Width x Length (mm) | 222 x 437 x 695 | ||
Weight | 106.3 lbs (48.2 kg) | 100.8 lbs (45.8 kg) | |
Form Factor | 5 RU | ||
AC Power Supply | 100–240V AC, 50–60 Hz | ||
DC Power Supply (FG-3980E-DC, FG-3960E-DC) | -48–60V | ||
Power Consumption (Average / Maximum) | 1172 / 2350 W | 960 / 2110 W | |
Current (Maximum) | 23.5A@100V, 9.8A@240V | 21.1A@100V, 8.8A@240V | |
Heat Dissipation | 8,019 BTU/h | 7,200 BTU/h | |
Redundant Power Supplies | Yes, Hot Swappable | ||
Operating Environment and Certifications | |||
Operating Temperature | 32–104°F (0–40°C) | ||
Storage Temperature | -31–158°F (-35–70°C) | ||
Humidity | 10–90% non-condensing | ||
Noise Level | 63 dBA | ||
Operating Altitude | Up to 7,400 ft (2,250 m) | ||
Compliance | FCC Part 15 Class A, C-Tick, VCCI, CE, UL/cUL, CB | ||
Certifications | ICSA Labs: Firewall, IPsec, IPS, Antivirus, SSL-VPN; USGv6/IPv6 | ||
NEBS Certified | - |
Documentation:
Download the Fortinet FortiGate 3960E-DC Datasheet (PDF).
Pricing Notes:
- All Prices are Inclusive of GST
- Hardware plus FortiCare Premium and FortiGuard Enterprise Protection
Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Enterprise Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering, Antispam, Security Rating, Industrial Security and FortiConverter Service) plus term of contract - Hardware plus FortiCare Premium and FortiGuard SMB Protection
Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, SMB Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering , Antispam and FortiGate Cloud subscription service) plus term of contract - Hardware plus FortiCare Premium and FortiGuard Unified Threat Protection (UTP)
Hardware Unit, FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering and Antispam Service) plus term of contract - Enterprise Protection (IPS, Advanced Malware Protection, Application Control, Web & Video Filtering, Antispam, Security Rating, IoT Detection, Industrial Security, FortiConverter Svc, and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Enterprise Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering, Antispam, Security Rating, Industrial Security and FortiConverter Service) - SMB Protection (IPS, Advanced Malware Protection, Application Control, Web & Video Filtering, Antispam, plus FortiGate Cloud subscription and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, SMB Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering, Antispam and FortiGate Cloud subscription service) - Unified Threat Protection (UTP) (IPS, Advanced Malware Protection, Application Control, Web & Video Filtering, Antispam Service, and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, UTP Services Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct, Application Control, Web & Video Filtering and Antispam Service) - Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control, and FortiCare Premium)
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Advanced Threat Protection Bundle (IPS, AV, Botnet IP/Domain, Mobile Malware, FortiGate Cloud Sandbox including Virus Outbreak and Content Disarm & Reconstruct Service, Application Control) - FortiCare Essential Support
FortiCare Essential Ticket Handling, Hardware Replacement, Firmware and General Upgrades, Application Control - FortiCare Premium Support
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, Application Control - FortiCare Elite Support
FortiCare Premium Support with FortiCare Elite Ticket Handling. - Prices are for one year of Premium RMA support. Usual discounts can be applied.
- Annual contracts only. No multi-year SKUs are available for these services.
- Contact Fortinet Renewals team for upgrade quotations for existing FortiCare contracts.
- Pricing and product availability subject to change without notice.