Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FSA-VM

FortiSandbox VM

100 – 1,000 files per hour, up to 40 – 1,600 users

Files per hour
100 – 1,000
Users
40 – 1,600
Local VMs
up to 8

The FortiSandbox VM detonates suspicious files in instrumented virtual machines and reports what they actually do, at 100 – 1,000 files per hour. Verdicts feed back automatically to every FortiGate, FortiMail and FortiClient in the Fabric.

Is this the right model?

Where it fits, and where it stops fitting

Compare the whole range

100 to 1,000 files an hour on your own infrastructure, with up to 8 local analysis VMs. It keeps samples on your premises without a dedicated appliance, which is the right compromise for organisations that have a regulatory constraint but not the volume to justify hardware. Detonation is CPU-intensive, so give it real resources.

Sizing this model

How to work out whether it fits

The arithmetic a datasheet leaves out. If any of it does not match your situation, that is worth a call rather than a guess.

Detonation is CPU-bound and the analysis VMs are what consume it, so allocate host resources against the VM count rather than the file rate. Eight local VMs running Windows images with realistic dwell time is a meaningful compute load, and starving it shows up as a queue rather than an error. If you are running this on shared virtualisation alongside production workloads, reserve the resources explicitly rather than relying on the scheduler.

Highlights

  • 100 – 1,000 files per hour
  • Verdicts shared automatically across the Security Fabric
  • Catches targeted malware no signature has seen
  • Samples never leave your premises

Typical deployments

  • Regulated organisations with moderate sample volume
  • Keeping samples on-premises without dedicated hardware
  • Environments already running everything virtually
Specifications

What this includes

Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.

Capacity

Effective sandboxing throughput is tested on files that are 80% documents and 20% executables, including both static and dynamic analysis, with pre-filtering enabled. User counts assume a ratio of one user per 25 emails.

Capacity
Effective sandboxing throughput (files/hour)100 – 1,000
Number of users40 – 1,600
Number of local VMsup to 8

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.

Buyers also compare