FortiSandbox VM
100 – 1,000 files per hour, up to 40 – 1,600 users
- Files per hour
- 100 – 1,000
- Users
- 40 – 1,600
- Local VMs
- up to 8
The FortiSandbox VM detonates suspicious files in instrumented virtual machines and reports what they actually do, at 100 – 1,000 files per hour. Verdicts feed back automatically to every FortiGate, FortiMail and FortiClient in the Fabric.
100 to 1,000 files an hour on your own infrastructure, with up to 8 local analysis VMs. It keeps samples on your premises without a dedicated appliance, which is the right compromise for organisations that have a regulatory constraint but not the volume to justify hardware. Detonation is CPU-intensive, so give it real resources.
Highlights
- 100 – 1,000 files per hour
- Verdicts shared automatically across the Security Fabric
- Catches targeted malware no signature has seen
- Samples never leave your premises
Typical deployments
- Regulated organisations with moderate sample volume
- Keeping samples on-premises without dedicated hardware
- Environments already running everything virtually
What this includes
Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
Capacity
Effective sandboxing throughput is tested on files that are 80% documents and 20% executables, including both static and dynamic analysis, with pre-filtering enabled. User counts assume a ratio of one user per 25 emails.
| Effective sandboxing throughput (files/hour) | 100 – 1,000 |
|---|---|
| Number of users | 40 – 1,600 |
| Number of local VMs | up to 8 |
Sources
- Fortinet Product Matrix (July 2026) — retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.