FortiGate 400E-BYPASS has reached end of sale and is no longer available. Current alternatives are listed on our FortiGate page.
1U rackmount next-generation firewall with hardware fail-to-wire bypass interface pairs, built on Fortinet's NP6 and CP9 SPUs, with 16 GE RJ45 ports, 16 GE SFP slots, 32 Gbps firewall throughput, 5 Gbps of threat protection, 4 million concurrent sessions and integrated SD-WAN. The bypass segments keep traffic flowing on power loss, making it ideal for inline IPS and transparent-mode deployment at the enterprise edge.


The 400E-BYPASS sits in the upper-mid range of the FortiGate E-series. Step down to the 200E for smaller sites, or move to the current-generation FortiGate 400F for roughly 2.5x the firewall throughput and higher session capacity. Same FortiOS and FortiGuard services across the range.
| Firewall throughput (1518 / 512 / 64 byte, UDP) | 32 / 32 / 24 Gbps |
| IPv6 firewall throughput (1518 / 512 / 64 byte, UDP) | 32 / 32 / 24 Gbps |
| Firewall latency (64 byte, UDP) | 2.14 µs |
| Firewall throughput (packets/sec) | 36 Mpps |
| Concurrent sessions (TCP) | 4,000,000 |
| New sessions/second (TCP) | 450,000 |
| Firewall policies | 10,000 |
| IPS throughput (Enterprise mix) | 7.8 Gbps |
| NGFW throughput | 6 Gbps |
| Threat protection throughput | 5 Gbps |
| IPsec VPN throughput (512 byte) | 20 Gbps |
| Gateway-to-gateway IPsec VPN tunnels | 2,000 |
| Client-to-gateway IPsec VPN tunnels | 50,000 |
| SSL-VPN throughput | 4.5 Gbps |
| Concurrent SSL-VPN users (tunnel mode, rec. max) | 5,000 |
| SSL inspection throughput (IPS, avg. HTTPS) | 4.8 Gbps |
| SSL inspection CPS (IPS, avg. HTTPS) | 4,000 |
| SSL inspection concurrent sessions | 300,000 |
| Application control throughput (HTTP 64K) | 12 Gbps |
| CAPWAP throughput (HTTP 64K) | 14.8 Gbps |
| Virtual domains (default / max) | 10 / 10 |
| Managed FortiAPs (total / tunnel) | 512 / 256 |
| Managed FortiSwitches | 72 |
| Maximum FortiTokens | 5,000 |
| High availability | Active-Active, Active-Passive, Clustering |
| Hardware acceleration | Fortinet SPU (NP6 + CP9) |
| Interfaces | 16x GE RJ45, 16x GE SFP slots, 2x GE RJ45 management, 2x USB, 1x console (RJ45); the BYPASS model adds hardware fail-to-wire (bypass) interface pairs for inline deployment; 2x SFP (1 GE SX) transceivers included |
| Hardware bypass | Yes - fail-to-wire (fail-open) bypass port pairs for inline IPS / transparent mode |
| Onboard storage | None (FortiGate 401E adds 2x 240 GB SSD) |
| Form factor | Rack mount, 1 RU |
| Dimensions (H x W x L) | 1.75 x 17 x 15 in (44.45 x 432 x 380 mm) |
| Weight | 16.4 lbs (7.4 kg) |
| Power supply | Dual AC, 100-240V AC, 50/60 Hz; optional redundant (hot-swappable) PSU, 80 Plus compliant |
| Power consumption (avg / max) | 109 W / 214 W |
| Heat dissipation | 730 BTU/h |
| Operating temperature | 32°F to 104°F (0°C to 40°C) |
| Humidity | 10% to 90% non-condensing |
| Forced airflow | Side and front to back |
| Operating altitude | Up to 7,400 ft (2,250 m) |
| Noise level | 48 dBA |
| Compliance | FCC Part 15 Class A, RCM, VCCI, CE, UL/cUL, CB |
| Certifications | USGv6 / IPv6 |
| Product lifecycle | Legacy (end of order 2025) — in stock, supported and renewable to 2030; successor generation: FortiGate 400F |
Source: official Fortinet FortiGate 400E Series datasheet (FG-400E column). The BYPASS model shares 400E system performance and adds hardware fail-to-wire interface pairs.
Download the full datasheetThe FortiGate 400E family shares the same NP6 + CP9 platform, ports and 400E-class performance. The 400E-BYPASS adds hardware fail-to-wire bypass port pairs; the 401E / 401E-DC add two 240 GB SSDs for local logging (AC or -48V DC power).
FortiGuard and FortiCare renewal subscriptions for installed FortiGate 400E-BYPASS units. Licensing is electronic and delivered worldwide.
Renewal subscriptions for the FortiGate 400E-BYPASS may still be available. Request a quote for current options.
Yes. The FortiGate 400E generation reached end of order, but the 400E-BYPASS (FG-400E-BYPASS) is still in stock, brand new, and fully supported. FortiGuard, FortiCare and RMA renewals run through 2030. For the current generation, the FortiGate 400F is the direct successor.
The 400E-BYPASS adds hardware fail-to-wire (fail-open) bypass interface pairs. If the appliance loses power, reboots or fails, those port pairs short together so traffic keeps flowing through the link — essential for inline IPS and transparent-mode deployments that cannot tolerate a network drop.
It delivers 32 Gbps firewall throughput, 7.8 Gbps IPS, 6 Gbps NGFW, 5 Gbps threat protection and 4.8 Gbps SSL inspection, with 4 million concurrent sessions and 450,000 new sessions per second, on Fortinet’s NP6 and CP9 SPUs.
The 400E line is end-of-order but remains fully serviceable: FortiGuard security subscriptions, FortiCare support and Secure RMA can be renewed through to end of support in 2030. We can quote any remaining term, or scope a migration to the FortiGate 400F.
In-stock units ship from Canada with fast shipping, usually delivered in 0-1 business days. FortiGuard and FortiCare licensing is delivered electronically worldwide.