Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FortiSandbox (FSA-500G / 1500G / 3000G / VM / Cloud)

FortiSandbox Advanced Threat Protection

Detonate the unknown — files no signature has seen yet

Compare all 5 models

Figures are Fortinet’s own — sortable, cited on every product page
FortiSandbox Advanced Threat Protection model comparison
Modelfiles/hourActions
FortiSandbox Cloud (PaaS)FSA-CLOUD20 – 4,0008 – 1,600Details
FortiSandbox VMFSA-VM100 – 1,00040 – 1,600up to 8Details
FortiSandbox 500GFSA-500G10,0001,4002 + 12 optionalDetails
FortiSandbox 1500GFSA-1500G32,0004,0002 + 26 optionalDetails
FortiSandbox 3000GFSA-3000G160,00020,0008 + 142 optionalDetails

How to read these numbers

FortiSandbox executes suspicious files in instrumented virtual machines and watches what they actually do. It is the answer to targeted and zero-day malware, which by definition no signature matches, and its verdicts feed back to every FortiGate, FortiMail and FortiClient in the Fabric automatically.

More on choosing within this range

Capacity is measured in files per hour, tested at 80% documents and 20% executables with pre-filtering enabled: the cloud PaaS tier covers 20–4,000, the FSA-VM 100–1,000, and the appliances 10,000 (500G), 32,000 (1500G) and 160,000 (3000G).

Before you order

How many files per hour?

Count what actually reaches the sandbox after pre-filtering, not total email volume. The published figures already assume that pre-filter is on.

Can the samples leave your premises?

The cloud tier is cheaper and simpler, but the files leave your control. For regulated data that decision is usually made for you and points at an appliance.

Which Fabric products will submit to it?

FortiSandbox is worth far more when FortiGate, FortiMail and FortiClient all submit and all consume its verdicts. A sandbox fed by one product is a fraction of the value.

All FortiSandbox Advanced Threat Protection