Haink KnowledgeCase StudiesAbout Contact sales
Home / Knowledge / Brands / Fortinet

How to Choose Fortinet — FortiGate NGFW, FortiSwitch, FortiAP & the Security Fabric

Haink supplies Fortinet security and networking hardware to enterprises, service providers, and data centers in Hong Kong, Dubai, and Mainland China. Available product lines include Fortinet FortiGate next-generation firewalls and unified threat management appliances, FortiSwitch secure campus and data center switches, FortiAP wireless access points, FortiAnalyzer log management and analytics, FortiManager centralized policy and device management, FortiWeb web application firewalls, FortiMail email security gateways, and FortiSandbox advanced threat protection platforms.

Fortinet is the world's largest cybersecurity company by units shipped and is known for the FortiASIC custom security processing unit that delivers industry-leading firewall throughput in compact form factors. The Fortinet Security Fabric is Fortinet's integrated platform architecture that connects FortiGate firewalls, FortiSwitch, FortiAP, and supporting security products into a unified management and threat intelligence ecosystem. Haink sources Fortinet hardware through authorized distribution channels and delivers to enterprise and service provider facilities across the Asia-Pacific and Middle East regions.

Written and maintained by Haink's network infrastructure team · Updated July 2026 · authorized-channel, serial & FortiCare verified. We size and supply Fortinet across NGFW, switching, Wi-Fi and the Security Fabric — this guide is how we help buyers choose.

Which Fortinet for the Job — Selection by Role

Role / workloadRecommended FortinetWhy
Branch / small officeFortiGate 40F–90G (G-series, SP5)SD-WAN + full UTM in one box, high throughput-per-watt
Mid-enterprise edge / SD-WAN hubFortiGate 200F / 400FSSL inspection at scale, SD-WAN head-end
Campus / DC perimeterFortiGate 700G / 1000F / 1800FNP7/SP5 high inspected throughput
Hyperscale / service-provider coreFortiGate 4200F / 4400F / 7121FModular chassis, multi-Tbps security
LAN-edge switchingFortiSwitch (FortiLink)Managed from FortiGate — no separate console/WLC
Enterprise wirelessFortiAP 23xG (6E) / 441K, 443K (Wi-Fi 7)Security policy enforced at the wireless edge
Central managementFortiManagerConfig, policy and firmware orchestration
Logging / analytics / complianceFortiAnalyzerSOC visibility, long-term logs, reporting
WAF / email / identityFortiWeb / FortiMail / FortiAuthenticatorApp, email and MFA layers of the Fabric

How to Choose Fortinet — the Decision

  1. Start from the security role, not the model. Perimeter NGFW, branch SD-WAN, LAN edge, wireless, or WAF/email/identity — that fixes the product before you compare throughput numbers.
  2. Size to threat-protection throughput with SSL inspection ON. Never the raw "firewall throughput" number — that's large-packet, security-off marketing. The inspected figure is a fraction of it (see below).
  3. Decide the FortiGuard bundle. UTP vs Enterprise Protection gates the NGFW features and is the recurring cost — pick it deliberately, and co-term it across the estate.
  4. Consolidate the LAN edge with FortiLink if you want single-console wired + wireless from the FortiGate — or stay best-of-breed if that's your strategy.
  5. Confirm channel and FortiCare registration before payment. Authorized sourcing, serial and entitlement check, subscription quoted with the hardware.

How to Size a FortiGate — the Numbers

The single most common Fortinet buying mistake is sizing to the headline "firewall throughput." That figure is measured with large packets and security services off. What you actually run on is threat-protection throughput (IPS + application control + AV) with SSL/TLS inspection enabled — and that is a fraction of the firewall number. A FortiGate 700G, for example, is rated ~164 Gbps firewall but ~26 Gbps threat protection.

Worked example — a 2,000-user HQ with ~2–3 Gbps of internet traffic, mostly TLS: don't buy on a 40–60 Gbps firewall figure. Size to inspected throughput with SSL 1.3 inspection on (which carries real overhead), plus concurrent-session and new-connections-per-second headroom — a FortiGate 200F/400F-class NGFW with a UTP bundle covers it comfortably. Rules of thumb, not guarantees — we size the exact model to your inspected throughput, session counts and inspection profile.

FortiGate Next-Generation Firewalls

FortiGate is Fortinet's flagship NGFW product line covering deployments from small branch offices to hyperscale data center and carrier environments. All FortiGate models run FortiOS and are managed individually, through FortiManager, or via FortiCloud. FortiGate NGFWs deliver firewall, IPS, application control, SSL inspection, web filtering, and antivirus services in a single appliance, accelerated by FortiASIC NP and CP processors.

FortiGate Desktop and Branch (Entry)

FortiGate Mid-Range Enterprise

FortiGate High-End and Chassis

FortiGate Rugged Series

FortiSwitch Secure Access Switches

FortiSwitch is Fortinet's secure switching product line designed for enterprise campus and data center environments. FortiSwitch is tightly integrated with FortiGate through FortiLink, allowing FortiGate to manage FortiSwitch ports, VLANs, PoE, and security policies from a single pane of glass. This FortiGate + FortiSwitch integration is Fortinet's core LAN-edge architecture for unified wired and wireless security management.

FortiSwitch Access Layer

FortiSwitch Distribution and Aggregation

FortiAP Wireless Access Points

FortiAP is Fortinet's wireless access point product line, integrated with FortiGate NGFW and the Fortinet Security Fabric through FortiLink and FortiCloud wireless management. FortiAP applies FortiGate security policies at the wireless edge and provides unified management with wired switching, firewalling, and SD-WAN through a single FortiManager console.

FortiAP Indoor Access Points

FortiAP Outdoor Access Points

FortiAnalyzer — Log Management and Analytics

FortiAnalyzer is Fortinet's centralized log management, analytics, and compliance reporting platform for Fortinet Security Fabric environments. FortiAnalyzer collects logs from FortiGate, FortiSwitch, FortiAP, FortiMail, FortiWeb, and other Fortinet devices, providing enterprise-wide security visibility, threat detection, incident investigation, and regulatory compliance reporting.

FortiManager — Centralized Network Management

FortiManager is Fortinet's centralized network and security management platform for managing large deployments of FortiGate, FortiSwitch, and FortiAP devices. FortiManager provides policy management, device provisioning, firmware orchestration, and configuration automation across distributed enterprise and MSSP environments with hundreds or thousands of Fortinet devices.

FortiWeb — Web Application Firewall

FortiWeb is Fortinet's web application firewall (WAF) and API security platform, protecting web applications, APIs, and microservices from OWASP Top 10 threats, bot attacks, DDoS, and zero-day exploits using ML-based threat detection. FortiWeb is available as hardware appliances, virtual machines, and cloud instances on AWS, Azure, and GCP.

FortiMail — Email Security Gateway

FortiMail is Fortinet's secure email gateway providing advanced email threat protection including anti-spam, anti-phishing, anti-malware, sandboxing, email encryption, and DLP. FortiMail integrates with FortiSandbox for zero-day email attachment analysis and with FortiAnalyzer for unified security logging.

FortiSandbox — Advanced Threat Protection

FortiSandbox is Fortinet's advanced threat protection platform providing dynamic analysis of suspicious files and URLs in an isolated sandbox environment. FortiSandbox integrates with FortiGate, FortiMail, FortiProxy, and FortiWeb to provide zero-day threat detection, sharing verdicts back to the Fortinet Security Fabric in real time.

FortiAuthenticator and FortiToken — Identity and MFA

FortiAuthenticator is Fortinet's identity and access management appliance providing RADIUS, LDAP, SAML, and OAuth-based authentication with integrated multi-factor authentication (MFA) for Fortinet VPN, ZTNA, and network access. FortiToken is Fortinet's hardware and mobile OTP token for TOTP-based MFA.

Fortinet Security Fabric

The Fortinet Security Fabric is Fortinet's platform architecture that connects FortiGate firewalls, FortiSwitch LAN switches, FortiAP wireless access points, FortiAnalyzer, FortiManager, FortiClient endpoint security, FortiSandbox, FortiWeb, and FortiMail into an integrated ecosystem with shared threat intelligence, unified management, and automated orchestration.

Key Security Fabric capabilities relevant to enterprise procurement:

Where Haink Supplies Fortinet Equipment

Lifecycle — What to Buy Now vs From Stock

SegmentCurrent (buy now)Still fine from stockLegacy / EOL → successor
Branch NGFW70G / 90G / 120G (SP5/NP7)60F / 70F / 100Folder 60E-class → G-series
Mid / edge NGFW200F / 400F / 700G600F / 800F2200E / 3300E / 3600E → F/G-series
Chassis / hyperscale4200F / 4400F / 7121F1800F6000F (NP6) / 7030–7060E → 4400F / 7121F
SwitchingFortiSwitch 6xxF / 1xxF548D2xxE / 4xxE → 6xx-series
Wi-Fi231G/431G (6E) · 441K/443K (Wi-Fi 7)231F / 431F222E / 223E (Wi-Fi 5) → 43xF / 44xK

Buying Genuine Fortinet — Serial & FortiCare Verification

Gray-market Fortinet is a real risk: a FortiGate sold outside authorized distribution may arrive with no valid FortiCare contract, or with entitlement already registered to another company — either of which blocks FortiGuard updates and Fortinet support, leaving you with an expensive stateful router. Before payment we source through authorized channels, verify each serial and its FortiCare registration/entitlement with Fortinet, and confirm the unit is clean to register to you. Refurbished EOL chassis (E-series) are fine when that's what you're buying — but we label them as such. A price far below market usually means a FortiCare or gray-market problem; ask us to verify before you commit.

When Fortinet Isn't the Answer

We stay neutral, because Fortinet isn't always the right call:

Why Organizations Choose Fortinet

Need pricing on Fortinet hardware?

Get firm pricing, availability and lead times on Fortinet — export-screened, OEM-warranted.

Get a quote   Prefer email? sales@haink.org

Related Resources

Frequently Asked Questions

How do I size a FortiGate — firewall throughput vs threat-protection throughput?

Size to threat-protection throughput with SSL inspection on, not the headline "firewall throughput." The firewall number is measured with large packets and security services off; in production you run IPS, application control and AV with TLS inspection, and that inspected figure is a fraction of the firewall one — a FortiGate 700G is rated ~164 Gbps firewall but ~26 Gbps threat protection. Add concurrent-session and new-connections-per-second headroom and allowance for TLS 1.3 inspection overhead. We size the exact model to your real inspected throughput and session profile rather than the datasheet headline.

F-series or G-series FortiGate — which should I buy now?

The G-series (70G/90G/120G/700G/900G) runs Fortinet's newer SP5/NP7 ASICs — much higher inspected throughput per watt, and post-quantum and FortiAI ready — so it's the right choice for new multi-year deployments. The F-series (60F/200F/400F and up) is fully supported, is often available faster from stock, and remains a sound pick when you need units immediately or are matching an existing F-series estate. For a fresh rollout we lean G-series; for immediate branch stock or estate consistency, F-series.

How do I make sure a FortiGate is genuine and FortiCare-registered?

Gray-market FortiGate may arrive with no valid FortiCare contract or with entitlement already registered to another company — either of which blocks FortiGuard updates and Fortinet support. Before payment we source through authorized distribution, verify each serial and its FortiCare registration and entitlement status with Fortinet, and confirm the unit is clean to register to you. If you're knowingly buying refurbished EOL chassis we label them as such. A price far below market usually signals a FortiCare or gray-market issue — we check before you commit.

What is the difference between FortiGate 200F, 400F, and 600F?

FortiGate 200F delivers 27 Gbps firewall throughput in 1U for medium-sized enterprises. FortiGate 400F delivers 65 Gbps firewall throughput for large enterprise internet edge and WAN aggregation. FortiGate 600F delivers 100 Gbps for very large enterprise and SP WAN aggregation. All three run the same FortiOS and support SD-WAN, ZTNA, and full UTM services; the primary differentiator is throughput capacity, interface density, and connection table size appropriate for the scale of deployment.

What FortiGate models does Haink supply?

Haink supplies Fortinet FortiGate 40F, 60F, 70F, 80F, 90G, 100F, 120G, 200F, 201F, 400F, 401F, 600F, 601F, 800F, 1000F, 1800F, 2200E, 2600F, 3300E, 3400E, 3600E, 3700F, 4200F, 4400F, and FortiGate 6000F and 7000F series chassis. Branch ruggedized models (FortiGate Rugged 30D, 60F, 70F) are also available.

What is FortiLink and why does it matter?

FortiLink is Fortinet's proprietary protocol that allows a FortiGate firewall to directly manage FortiSwitch and FortiAP access points — including port configuration, VLANs, PoE, and wireless profiles — from the FortiGate management interface rather than requiring separate switch management software or a wireless controller. This integration eliminates the cost of a dedicated wireless LAN controller (WLC) and switch management platform, and allows firewall security policies to be enforced at the access layer on both wired and wireless ports simultaneously.

What is the difference between FortiAnalyzer and FortiManager?

FortiAnalyzer handles log collection, long-term storage, security analytics, threat investigation, and compliance reporting for Fortinet Security Fabric deployments. FortiManager handles centralized configuration management, policy deployment, firmware orchestration, and provisioning automation for FortiGate, FortiSwitch, and FortiAP devices. Large enterprises typically deploy both: FortiManager to manage device configurations and FortiAnalyzer to manage security visibility and reporting. Both are available as hardware appliances and virtual machines.

What Fortinet FortiSwitch models does Haink supply?

Haink supplies Fortinet FortiSwitch 108F, 124F, 148F, 224E, 248E, 424E, 448E (all with PoE and full-PoE options), FortiSwitch 524D, 548D, 624F, 648F distribution switches, FortiSwitch 1024E, 1048E aggregation switches, and FortiSwitch 3032E 100G data center spine switches.

Does Haink supply FortiAP Wi-Fi 6 and Wi-Fi 6E access points?

Yes. Haink supplies Fortinet FortiAP 231F, 233G, 234F, 431F, 433F, 441K, 443K indoor APs and FortiAP 432F and 434F outdoor APs. The 233G and 443K support Wi-Fi 6E (6 GHz band) for next-generation high-density wireless deployments. The 441K and 443K support Wi-Fi 7.

What is FortiGuard and do I need a subscription?

FortiGuard is Fortinet's threat intelligence and content security subscription service. Without a FortiGuard subscription, FortiGate provides stateful firewall and basic routing functionality. With FortiGuard, FortiGate activates IPS signatures, antivirus, URL filtering, application control, DNS filtering, and sandbox integration updated continuously from Fortinet's global threat intelligence network. Enterprise deployments typically require the Unified Threat Protection (UTP) or Enterprise Protection (ENT) FortiGuard bundle for full NGFW functionality. Haink assists with FortiGuard subscription procurement alongside hardware orders.

Is Fortinet hardware available from stock for fast delivery?

Yes. Haink maintains access to FortiGate branch and enterprise firewalls, FortiSwitch access layer switches, and FortiAP wireless access points from regional distributor stock in Asia and the Middle East. Contact Haink for current availability and delivery timelines for specific Fortinet models in Hong Kong, Dubai, or Mainland China.

Haink
info@haink.org

Winning House
72–76 Wing Lok Street
Sheung Wan, Hong Kong

© 2026 Haink. All rights reserved.  ·  Privacy Policy  ·  TermsHong Kong · Dubai · Singapore · Mainland China · Delaware (USA)