Fortinet has expanded its family of next-generation firewalls with FortiGate 1200G, a device aimed at large enterprises, data centers, and artificial intelligence infrastructures that can also function as a local presence point for FortiSASE. This approach allows deploying security services in on-premise facilities that are typically offered from the cloud, catering to organizations with strict latency, data sovereignty, or compliance requirements.
The key features of FortiGate 1200G in 20 seconds
- The new firewall delivers up to 397 Gbps of performance and supports 10, 25, and 100 Gbps connections.
- FortiSASE Outpost enables deploying a SASE presence point within the customer-controlled environment.
- Sensitive traffic can be inspected locally without being sent to an external data center.
- Fortinet plans to commercialize the FortiGate 1200G in Q3 2026.
- Performance figures are provided by the manufacturer and may vary based on configuration.
The launch reflects an evolution in network security models. In recent years, companies have shifted some of their controls to SASE platforms, acronym for Security Access Service Edge, which combine connectivity and security via distributed cloud services. However, not all traffic can leave the organization’s premises for inspection at an external point of presence.
Industrial applications, financial platforms, public infrastructure, or AI systems may require very low latency response times. Additionally, organizations may need to keep certain data within a specific jurisdiction, region, or under their physical control.
FortiSASE Outpost aims to fill this intermediate space. The customer maintains management and policies synchronized with Fortinet’s cloud service but can process locally the traffic deemed sensitive or dependent on reduced latency.
A firewall for high-capacity networks and AI infrastructures
FortiGate 1200G utilizes Fortinet’s new architecture based on specialized integrated circuits, known as FortiASIC. These processors are designed to accelerate networking and security functions without offloading all work to general-purpose processors.
According to the company’s specifications, this model achieves up to 397 Gbps firewall performance, 102 Gbps VPN (IPsec), and 40 Gbps threat protection.
The latest measurement includes firewall, intrusion prevention system, application control, malware protection, and activity logging. While closer to real-world usage, these figures are still provided by the manufacturer and may differ in actual deployment.
The device supports up to 40 million concurrent sessions and can process a million new connections per second. Its interfaces of 10, 25, and 100 Gbps allow integration with large corporate networks or data center environments.
Fortinet compares these figures with several models from Palo Alto Networks, Cisco, Check Point, and Juniper. The company claims its device offers 4.5 times the average firewall performance of these competitors and 2.8 times the average VPN IPsec throughput.
These comparisons should be taken with caution. Fortinet acknowledges that testing methodologies, enabled features, and conditions can vary among vendors. Not all equipment listed occupy the same position within their respective product lines.
Fortinet’s argument is that the growth of AI and encrypted traffic necessitates inspecting larger volumes without creating bottlenecks. Compute clusters, inter-data-center links, and training or inference platforms can generate loads that quickly surpass older equipment’s capacity.
What FortiSASE Outpost adds
The most distinctive innovation isn’t only in hardware. FortiGate 1200G can be configured as a FortiSASE Outpost, turning it into a locally accelerated SASE presence point via ASIC.
In a conventional SASE architecture, traffic from employees, branches, or remote devices is directed to a cloud point of presence. There, features like web filtering, zero-trust access, application control, and threat prevention are applied before granting Internet or internal resource access.
This simplifies protecting a distributed workforce but adds an extra path. If the point of presence is far from the user or application, latency can increase, and sensitive information might need to leave the controlled environment.
With FortiSASE Outpost, some of these functions run locally on the FortiGate installed within the data center, headquarters, or near the users.
Organizations can choose which traffic to inspect locally and which to send to Fortinet’s cloud points of presence. Latency-sensitive applications, regulatory data, or bandwidth-heavy loads can stay within their facilities.
This setup is also beneficial in regions where Fortinet lacks a nearby point of presence. Instead of routing traffic internationally, customers can deploy the service close to their users.
The manufacturer also notes that local processing can reduce bandwidth costs. The actual savings depend on network design, traffic volume, and licensing models.
Shared policies between local firewall and cloud
FortiGate and FortiSASE run on FortiOS, Fortinet’s security operating system. This common foundation enables reusing policies, threat intelligence, security context, and zero-trust access decisions across both on-premise and cloud environments.
The goal is to prevent security teams from managing two separate rule sets. A policy applied to users or applications remains consistent whether inspected locally or in the cloud.
Fortinet also offers FortiGuard security services, which provide threat intelligence and updated protections, and FortiAI, its artificial intelligence suite for incident investigation and response.
This convergence supports a hybrid security model. The firewall no longer is solely a perimeter device, and SASE no longer is exclusively dependent on an external cloud infrastructure.
For existing FortiGate users, this approach can ease extending policies to remote users and branches. Organizations using other vendors’ products will need to evaluate the cost and dependency implications of adopting a more integrated platform.
Data sovereignty and security under customer control
Fortinet positions FortiSASE Outpost as a solution to the rising need for digital sovereignty.
Physical deployment of inspection points can be crucial when traffic contains sensitive health, financial, industrial, or public sector data. Keeping processing within a controlled infrastructure aids compliance with internal policies and contractual obligations.
However, deploying a presence point onsite doesn’t automatically ensure regulatory compliance. Organizations must review configurations, telemetry data transfers, logs, data storage, and external services integrated with the platform.
Operational responsibilities also include ensuring physical availability, power supply, connectivity, and hardware security. Cloud services reduce some of these tasks but rely on a different set of controls, while local deployment offers greater control at the expense of managing infrastructure.
FortiGate 1200G incorporates hardware-based protections, secure credential storage, and redundant components. Fortinet has not disclosed all the technical details of this trust anchor, so referencing official product documentation will be necessary to understand its implementation.
Fortinet aims to bridge two previously separate markets
Next-generation firewalls and SASE platforms have evolved largely as separate markets.
Firewalls typically protect data centers, headquarters, and internal networks via physical or virtual devices. SASE services are cloud-based, designed for distributed users, remote work, SaaS apps, and secure access from anywhere.
The rise of hybrid infrastructure blurs this boundary. Employees access applications hosted in public clouds, private data centers, and external services, with security policies needing to adapt regardless of resource location.
Fortinet calls this evolution the SASE Firewall market. It’s a marketing term, not an industry-standard category, but it captures the convergence: a single device capable of high-performance firewalling and local extension of a SASE platform.
This approach competes with other major security providers combining firewalls, zero-trust access, and cloud services. Its success will depend on real integration, geographic coverage of points of presence, performance with features enabled, pricing, and ease of managing hybrid environments.
Performance and power consumption
Fortinet also emphasizes energy efficiency.
The company estimates that the FortiGate 1200G consumes about 1.9 watts per Gbps of firewall throughput and 7.3 watts per Gbps on IPsec VPN. They claim these figures improve upon the average of comparable models by factors of 5.6 and 4.4 respectively.
These figures are based on maximum power consumption data from datasheets and external hardware guides. While useful as initial benchmarks, they are not independent tests under load.
Real consumption will depend on the number of active interfaces, inspection features enabled, session volume, temperature, redundancy, and sustained load.
In data centers, higher efficiency can reduce operational costs through lower power and cooling requirements. A high-performance wattage ratio can be advantageous, but buying decisions should also consider licensing, support, and overall security capabilities.
Fortinet anticipates FortiGate 1200G availability in Q3 2026. Pricing, licensing options for FortiSASE Outpost, and specific configurations have not yet been announced.
Frequently Asked Questions
What performance does FortiGate 1200G offer?
Fortinet states it can provide up to 397 Gbps in firewall performance, 102 Gbps in VPN (IPsec), and 40 Gbps with threat protection features enabled. These figures are manufacturer estimates and may vary with actual deployment.
What is FortiSASE Outpost?
It is a configuration that allows using a FortiGate as a local SASE presence point within the customer’s infrastructure. This enables certain inspections to be performed locally.
Why would a company run SASE on-premises?
To reduce latency, keep sensitive data within a specific location, comply with sovereignty policies, or avoid sending large volumes of traffic to external points of presence.
When will the FortiGate 1200G be available?
Fortinet plans to start selling in Q3 2026. The final pricing has not been publicly disclosed yet.
via: fortinet

