FortiDDoS
Behavioural volumetric DDoS mitigation on purpose-built silicon
- Licensing
- By appliance model and mitigation capacity
- Detection
- Behavioural baselining, not signatures
- Deployment
- Inline or out-of-path, upstream of the firewall
FortiDDoS learns what your traffic normally looks like and treats deviation as the signal, rather than matching signatures that never keep up with an attack changing shape mid-flight. It runs on purpose-built silicon so mitigation happens at line rate.
Where it fits, and where it stops fitting
An on-premises appliance cannot mitigate an attack larger than the pipe it arrives on. If your exposure is to multi-hundred-gigabit floods you need upstream scrubbing as well, and we will say so rather than sell you a box that cannot help. It sits in front of the firewall, a flood that reaches the firewall has already consumed its session table.
Highlights
- Behavioural detection adapts to attacks that change shape
- Purpose-built silicon, mitigates at line rate
- Deployed upstream of the firewall where it can actually help
- Inline or out-of-path deployment options
Typical deployments
- Protecting a public-facing payments or gaming service
- Preventing session-table exhaustion on the perimeter firewall
- Meeting an availability SLA with a contractual penalty attached
What to work out first
FortiDDoS defends against volumetric and application-layer denial of service by learning what your traffic normally looks like and treating deviation as the signal, rather than matching signatures, which never keep up with an attack that changes shape mid-flight.
It sits in front of the firewall, because a DDoS flood that reaches the firewall has already succeeded at consuming the firewall's session table. That placement is the entire architectural point.
It is purpose-built silicon rather than software on a general-purpose CPU, which is what allows mitigation to run at line rate without becoming the bottleneck it was deployed to prevent.
Questions worth answering before you order
What is your circuit capacity?
An on-premises appliance cannot mitigate an attack larger than the pipe it arrives on. If your exposure is to multi-hundred-gigabit floods, you need upstream scrubbing as well; we will say so rather than sell you a box that cannot help.
Volumetric or application-layer?
They are different attacks with different defences. Application-layer attacks against web properties are often better addressed by FortiWeb. Many organisations need both.
Inline or out-of-path?
Inline gives the fastest mitigation and the simplest failure mode to reason about. Out-of-path avoids adding a device to the critical path. This decision should be made with your network team, not from a datasheet.
What is the actual risk?
DDoS protection is insurance. If an hour of downtime costs little, an appliance is hard to justify. If you are a payments, gaming or public-facing service, it is straightforward.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | By appliance model and mitigation capacity |
|---|---|
| Detection | Behavioural baselining, not signatures |
| Deployment | Inline or out-of-path, upstream of the firewall |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | By appliance model and mitigation capacity |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.