FortiNDR
Behavioural detection of the attacker already inside
- Licensing
- By inspected throughput and deployment model
- Deployment
- Physical or virtual sensor, requires SPAN/TAP
- Detection
- Behavioural modelling of east-west traffic
FortiNDR models normal east-west traffic and flags the deviation: lateral movement, command-and-control beaconing, staging before exfiltration. Because it is behavioural rather than signature-based it catches novel tooling, and because it inspects internal traffic it sees activity that never crosses the firewall.
Where it fits, and where it stops fitting
The practical constraint is traffic access, NDR needs a SPAN, mirror or TAP at the right points, and that is a network engineering exercise we work through before quoting. Its strongest case is alongside EDR, because it sees the unmanaged devices EDR cannot be installed on.
Highlights
- Sees the devices EDR cannot be installed on
- Catches lateral movement and C2 beaconing
- Behavioural, not dependent on signatures
- Feeds FortiSIEM and FortiSOAR for response
Typical deployments
- Detecting an intruder who already has valid credentials
- Visibility across an OT or IoT segment with no agents
- Confirming or ruling out lateral movement during an incident
What to work out first
FortiNDR watches east-west traffic and models normal behaviour, then flags the deviation: lateral movement, beaconing to command and control, staging before exfiltration. It is aimed at the phase after initial access, which perimeter controls by definition have already missed.
Because it is behavioural rather than signature-based, it catches novel tooling, and because it inspects internal traffic, it sees activity that never crosses the firewall at all.
Questions worth answering before you order
Can you actually get the traffic?
NDR needs a SPAN, mirror or TAP at the right points. This is the practical constraint that decides whether a deployment succeeds, and it is a network engineering question we work through before quoting.
Do you have EDR already?
NDR and EDR overlap deliberately. NDR sees the unmanaged devices EDR cannot be installed on, which in an OT or IoT-heavy environment is most of them.
Who investigates the detections?
Behavioural detections need a human to adjudicate. Without SOC capacity, this generates alerts nobody closes.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | By inspected throughput and deployment model |
|---|---|
| Deployment | Physical or virtual sensor, requires SPAN/TAP |
| Detection | Behavioural modelling of east-west traffic |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | By inspected throughput and deployment model |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.