FortiSandbox 500G
10,000 files per hour, up to 1,400 users
- Files per hour
- 10,000
- Users
- 1,400
- Local VMs
- 2 + 12 optional
The FortiSandbox 500G detonates suspicious files in instrumented virtual machines and reports what they actually do, at 10,000 files per hour. Verdicts feed back automatically to every FortiGate, FortiMail and FortiClient in the Fabric.
10,000 files an hour and 1,400 users, with 2 local VMs expandable by 12. Remember the published figures already assume pre-filtering is on and are tested at 80% documents to 20% executables — so size on what actually reaches the sandbox after filtering, not on total email and download volume. That distinction routinely changes the model.
Highlights
- 10,000 files per hour
- Verdicts shared automatically across the Security Fabric
- Catches targeted malware no signature has seen
- Samples never leave your premises
Typical deployments
- Mid-size organisations with on-premises analysis requirements
- Estates where FortiMail and FortiGate both submit samples
- Deployments needing verdicts without leaving the network
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Effective sandboxing throughput is tested on files that are 80% documents and 20% executables, including both static and dynamic analysis, with pre-filtering enabled. User counts assume a ratio of one user per 25 emails.
| Effective sandboxing throughput (files/hour) | 10,000 |
|---|---|
| Number of users | 1,400 |
| Number of local VMs | 2 + 12 optional |
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.