FortiSandbox 1500G
32,000 files per hour, up to 4,000 users
- Files per hour
- 32,000
- Users
- 4,000
- Local VMs
- 2 + 26 optional
The FortiSandbox 1500G detonates suspicious files in instrumented virtual machines and reports what they actually do, at 32,000 files per hour. Verdicts feed back automatically to every FortiGate, FortiMail and FortiClient in the Fabric.
32,000 files an hour, 4,000 users, and 2 VMs expandable by 26 — the VM count matters as much as the file rate, because concurrent detonation capacity is what stops a queue forming during a campaign. If your worry is a burst rather than a steady average, that expansion headroom is what you are buying.
Highlights
- 32,000 files per hour
- Verdicts shared automatically across the Security Fabric
- Catches targeted malware no signature has seen
- Samples never leave your premises
Typical deployments
- Large organisations with heavy attachment and download volume
- Environments subject to targeted phishing campaigns
- Deployments where analysis latency must stay low under burst
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Effective sandboxing throughput is tested on files that are 80% documents and 20% executables, including both static and dynamic analysis, with pre-filtering enabled. User counts assume a ratio of one user per 25 emails.
| Effective sandboxing throughput (files/hour) | 32,000 |
|---|---|
| Number of users | 4,000 |
| Number of local VMs | 2 + 26 optional |
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.