Fortinet, SonicWall or Cisco at the UAE Office Edge

You cannot compare these three appliances on their published headline throughput, because the three vendors do not measure the same thing. Fortinet rates firewall throughput on UDP packets of 1518, 512 and 64 bytes. SonicWall rates it under RFC 2544. Cisco rates ASA stateful inspection with 1500 byte UDP under what its data sheet calls ideal test conditions, and its Threat Defense figures at 1024 bytes. Put the entry models side by side on the numbers that use roughly the same definition, and the ranking changes.

Everything below comes from the three current data sheets, read on 19 September 2026: the FortiGate and FortiWiFi 70G Series data sheet, the SonicWall TZ Series Gen 8 data sheet, and the Cisco Secure Firewall 1200 Series data sheet updated 9 July 2025.

Three entry appliances, the figures as published

MetricFortiGate 70GSonicWall TZ280Cisco Secure Firewall 1210
Headline firewall throughput10 Gbps2.5 Gbps6.5 Gbps (ASA software)
Full inspection throughput1.3 Gbps threat protection1 Gbps threat prevention6.0 Gbps firewall with AVC and IPS
TLS inspection1.4 Gbps430 Mbps1.0 Gbps
IPsec VPN7.1 Gbps1.2 Gbps5.0 Gbps
New connections per second100,000 TCP sessions12,00035,000 with AVC
Copper ports2 GE WAN plus 6 GE RJ458 x 1GbE8 x 1000BASE-T
Fibre slotsNone2 x 1G SFPNone on the 1210

Read the first row and the FortiGate looks four times the firewall of the TZ280. Read the third row and that gap narrows to roughly three times, with Cisco between them. The rows do not measure the same traffic, so treat the table as a map of what each vendor publishes rather than a league table.

The inspected figure is the one that survives contact with a real office

Each vendor states what it switched on. Fortinet's threat protection figure of 1.3 Gbps is measured with firewall, IPS, application control and malware protection all running, and the data sheet says logging is enabled during the test. SonicWall's 1 Gbps threat prevention figure on the TZ280 is measured with Gateway Anti-Virus, Anti-Spyware, IPS and Application Control enabled, using Keysight HTTP test tools. Cisco publishes 6.0 Gbps for firewall with AVC and IPS on the 1210 at 1024 byte packets.

That last number deserves a pause. Cisco's inspected figure for its smallest 1200 Series model is about four and a half times Fortinet's on the 70G, and six times SonicWall's on the TZ280. The 1210 is a different class of appliance: it draws 32 W typical against 12.3 W for the FortiGate 70G. If your circuit and your inspection needs are modest, paying for that headroom is waste. We covered the sizing arithmetic in sizing a firewall for a UAE SME without overpaying.

TLS is the real ceiling, and it is far lower than the brochure

Almost all of your office traffic is encrypted, so the decryption figure is the one that governs a busy Tuesday afternoon. On the TZ280 that figure is 430 Mbps. On the FortiGate 70G it is 1.4 Gbps, measured across an average of HTTPS sessions using different cipher suites. On the Cisco 1210 it is 1.0 Gbps, measured with 50 percent TLS 1.2 traffic using AES256-SHA with RSA 2048 bit keys.

A 500 Mbps business fibre circuit in Business Bay or JLT will therefore saturate a TZ280 doing full decryption before the circuit itself is full. That is not a fault in the appliance. It is the predictable consequence of asking a 12 W desktop box to terminate and re-encrypt every session. The same pattern across three vendors is set out in why firewall throughput drops when you turn inspection on.

Connection ceilings run out before gigabits do

SonicWall is unusually open here, and the detail is worth copying into your evaluation sheet. The TZ280 publishes three separate connection ceilings: 1,000,000 stateful packet inspection connections, 200,000 deep packet inspection connections, and 35,000 TLS connections. The connection that matters to a browser is the TLS one, and it is 3.5 percent of the headline figure.

Fortinet publishes 1.4 million concurrent TCP sessions and 100,000 new sessions per second on the 70G, which reads as enormous headroom. The same data sheet then gives SSL inspection concurrent sessions as 140,000 and SSL inspection connections per second as 715. Seven hundred and fifteen new inspected sessions a second is a specific, published limit, and it is the number to hold in mind when someone quotes you 10 Gbps. Cisco's equivalent constraint on the 1210 is 35,000 new connections per second with AVC.

You do not have to guess where your office sits against these ceilings. Your existing firewall reports concurrent sessions and new sessions per second in its own dashboard. Pull a week of that data at your busiest hour before anyone quotes a model number.

On Cisco, the software image changes the answer

The same 1210 chassis ships with two different operating systems and two different performance tables. With ASA software it does 6.5 Gbps stateful inspection, 6.0 Gbps multiprotocol, and 175,000 new connections per second. With Threat Defense software it does 6.0 Gbps with AVC and IPS, but 35,000 new connections per second with AVC. That is a five times difference in connection rate on one piece of hardware, decided by the part number you order: the product codes differ only by ASA-K9 or TD-K9.

Cisco defines multiprotocol as a traffic profile made up mainly of TCP protocols such as HTTP, SMTP, FTP, IMAPv4, BitTorrent and DNS. Ask which image a quotation assumes. A quote that does not say is not a quote you can size against.

Ports, fibre and power over Ethernet

The FortiGate 70G has no SFP slot at all. Neither does the Cisco 1210 in either compact variant. The TZ280 has two 1G SFP slots, and the TZ380 upgrades those to SFP+ running at 5G, 2.5G or 1G, while the TZ680 carries two 10G SFP. If your building presents the circuit as fibre, which is common in JLT and DIFC towers, a copper only appliance means a media converter, which means another box and another power supply in a cupboard that is already full. Cisco's answer is to move up to the 1220CX for two SFP+ slots, or the 1230 for four.

PoE budgets on these boxes are small. The FortiGate 70G PoE model gives 4 PoE ports with a 60 W total budget and a 30 W per port maximum under 802.3at. The Cisco 1210CP gives 4 ports with 120 W total. The Gen 8 TZ table lists no PoE models. Either budget will run two or three access points, not a floor of them, and the class arithmetic is in PoE standards explained for UAE office networks.

Heat and noise, which matter more here than elsewhere

All three appliances are rated for 0 to 40 degrees Celsius operating temperature. That is the whole of the specification, and in a Dubai comms cupboard in July it is a live constraint rather than a formality. A cupboard off a corridor with no dedicated cooling sits above ambient, and the fanless FortiGate 70G relies entirely on the air around it. Measure that cupboard at 3 pm in August before choosing a fanless box.

Noise decides where the appliance can live. Cisco's compact 1210 is rated 23.5 dBA at 27 degrees and 42.7 dBA at maximum fan speed. Its rack mount siblings are rated 52.1 dBA on the 1230 and 57.8 dBA on the 1240 and 1250. Those two cannot sit in an open plan office. The TZ280 draws a maximum of 12.36 W and the FortiGate 70G averages 12.3 W, so neither adds meaningfully to a cupboard's heat load. A 1U Cisco at 57 W to 88 W does.

TDRA type approval applies to the wireless variants

Radio and telecommunications terminal equipment has to be registered with the TDRA before it can be used, sold or distributed in the UAE, and the authority splits equipment into three risk levels, with technical inspection required at the highest. The wireless models matter here: the FortiWiFi 70G carries dual radio 802.11ax, and the TZ380W carries 2x2 802.11ax. Their data sheets list FCC, CE, RCM, VCCI and similar approvals, and none of those is a UAE approval. Check the model against the TDRA approved equipment register, and check that whoever imports it holds a valid TDRA registration, which runs for five years.

What to send with the quote request

  • Your circuit speed and provider, and whether the handover is copper or fibre.
  • Peak concurrent sessions and peak new sessions per second from your current firewall, not a user count.
  • Whether you will decrypt TLS, and for which user groups, since that single decision moves the required model more than headcount does.
  • For Cisco, whether you want ASA or Threat Defense software.
  • How many PoE devices the firewall itself needs to power, if any.
  • Your comms room temperature at its worst, and whether the appliance sits in an occupied space.

Codeeo Tech stocks Fortinet, SonicWall and Cisco security platforms, and every item on the store is quoted rather than priced, because the subscription bundle and the support term usually cost more over three years than the appliance does. Browse Fortinet or SonicWall, or send the six answers above to us through the contact page and we will come back with options at two sizes rather than one.

Cover photo: Server Cabinet (25680506307) by Simeon W from Wellington, New Zealand, via Wikimedia Commons (CC BY 2.0).