FortiNDR Cloud is a SaaS offering that enhances security teams' advanced detection capabilities by providing contextually rich insights while streamlining incident response. Through analysis of network metadata, FortiNDR Cloud contributes to a stronger and more proactive security posture without the need for endpoint agents. FortiNDR Cloud enables you to reduce attacker dwell time by analyzing network traffic from all devices, managed/unmanaged/IoT/WFH across hybrid or multi-cloud networks.
Through the power of AI-based detections and expert analysis, security teams can spot the evidence of attacker behavior early, enabling effective response across your environments.
AGENTLESS VISIBILITY ACROSS YOUR NETWORK - Network detection and response combine AI-based, human, and behavioral network traffic analysis to look for signs of malicious activity without the need for installed agents. Through this metadata analysis, FortiNDR Cloud creates high-fidelity detections that improve response efforts.
ORCHESTRATED INCIDENT RESPONSE - FortiNDR Cloud allows security teams to pivot from detection to investigation to response with a few clicks. Providing interactions with the Fortinet Security Fabric and third-party tools such as EDR, SOAR, SIEM, NGFW and XDR, FortiNDR ensures you can automate investigation, triage, and remediation.
365-DAY DATA RETENTION FOR RETROSPECTIVE ANALYSIS AND THREAT HUNTING - FortiNDR Cloud retains rich network metadata for 365 days, enabling a comprehensive investigation. This data ensures newly discovered tools, tactics, and procedures can be retroactively investigated to discover if and when threats may have infiltrated the customer's network. Contact AWSsales@fortinet.com with questions or additional platforming licensing via Private Offers.
Videos to Learn More:
Overview: Find Hidden Threats Using Fortinet Network Detection and Response - https://www.youtube.com/watch?v=v3Fdr-ajkmY&t=2s
Demo: FortiNDR Cloud Integrates with FortiGate NGFW -https://www.youtube.com/watch?v=ZxVX8iBE3tE
Highlights
Improved Visibility of Threats: Real-time, automated investigation of network security incidents and extended historical network visibility enable a faster, more comprehensive response to threats.
Reduced False Positives: Advanced analytics and machine learning help distinguish between legitimate and suspicious activities, reducing the number of false positives, easing the burden on analyst teams.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Annual Subscription license for FortiNDR Cloud Guided-SaaS Platform with Detections, Investigations, Playbooks, and Reports at 100Mbps of metered usage. Includes FortiCare premium. Does not include physical sensors.
You buy one annual subscription to the FortiNDR Cloud Guided-SaaS Platform. Pricing is set at a fixed bandwidth level of 100Mbps P95 metered usage over a one-year term. P95 means billing reflects your 95th-percentile bandwidth, ignoring brief usage spikes. The subscription covers Detections, Investigations, Playbooks, and Reports, plus FortiCare premium support. Physical sensors are not included and must be obtained separately. This is a single flat-rate option, so there are no tiers or add-ons to compare. Your cost stays the same for the term regardless of daily fluctuations within the metered bandwidth level.
Top-of-mind questions for buyers
What does the 100Mbps P95 bandwidth figure actually measure for billing?
P95 measures the throughput of network traffic your sensors send for analysis. The system records bandwidth continuously, then bills at the 95th-percentile level. This ignores the top 5% of usage spikes, so brief peaks do not raise your fixed rate within the 100Mbps level.
Since physical sensors are not included, how do I collect the network traffic this subscription analyzes?
The subscription covers the cloud analysis platform only. You deploy sensors separately to capture network traffic. Options include physical hardware sensors or virtual sensors that run on AWS or other virtualization environments. These sensors feed traffic to the cloud service for analysis.
What capabilities does the subscription include beyond raw detection?
Your subscription covers Detections, Investigations, Playbooks, and Reports on the Guided-SaaS Platform, plus FortiCare premium support. Investigations let analysts query network activity. Playbooks automate response steps. Data is analyzed in the cloud and retained for later inspection to support threat hunting.
www.fortinet.com+1
Helpful?
Vendor refund policy
This is a BYOL product - there're no refund and cancellation policy applied.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Fortinet FortiCare support offerings provide global support and deliver best-in-class support services. With FortiCare support, customers can be assured that their Fortinet security products are performing optimally and protecting their corporate assets.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FortiNDR is Fortinet's Network Detection and Response technology. FortiNDR has extended and added features to detect Network Anomalies with auto and manual mitigation techniques
Fortinet offers a unified set of intelligent detection and response solutions to help organizations identify, investigate, and respond to sophisticated cyber threats across hybrid IT and OT environments. These include:
• FortiNDR – AI-driven Network Detection & Response
• FortiSIEM – Unified Security Information & Event Management
• FortiXDR – Extended Detection & Response with automation and context correlation
Together, they empower SOC teams to detect threats faster, reduce alert fatigue, and respond more effectively through Fortinet’s integrated Security Fabric.
Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
Fortinet professional design and implementation services for network, application, and cloud-native (CNAPP) security for AWS, hybrid, and multi-cloud environments.
FortiAuthenticator is a centralized user Identity Management solution to transparently identify network users and enforce identity-driven access policy in a Fortinet fabric. It supports FortiToken Two-factor authentication, Certificate and Wireless Guest management and Single Sign On capability.
The Fortinet FortiManager provides easy centralized configuration, policy-based provisioning, update management and end-to-end network monitoring for your Fortinet installed environment.
The FortiWeb web application firewall (WAF) defends web-based applications from known and zero-day threats. Its AI-based machine learning identifies threats with virtually no false positive detections.
Network detection enhances security while seamless integration boosts utility
Reviewed on Mar 18, 2025
Review provided by PeerSpot
What is our primary use case?
I use Fortinet FortiNDR for its Network Detection features, primarily with FortiGate on-premises. However, I do not handle day-to-day operations myself; my team manages the tools. In general, there is no issue with FortiGate in our company.
What is most valuable?
Some of the valuable features include FortiGate's Network Detection and SD-WAN capabilities. Additionally, using it as a bundle is cost-effective, providing comprehensive tools for security. Fortinet also integrates seamlessly with our SIEM, using QRadar, which enhances its utility.
What needs improvement?
I would like to see the inclusion of sandboxing in the bundling. Currently, sandbox is not included in our package.
For how long have I used the solution?
I have been using Fortinet tools since 2018.
What was my experience with deployment of the solution?
We have not encountered any deployment issues as we implemented it with a vendor who took care of it.
What do I think about the stability of the solution?
There is no issue with the stability of Fortinet FortiNDR in our company.
What do I think about the scalability of the solution?
We have not faced any issues with scaling Fortinet FortiNDR in our environment.
How are customer service and support?
So far, I have not had to contact customer service, as I haven't faced any issues requiring support.
How was the initial setup?
The initial setup was straightforward because I implemented it with a vendor who managed the entire process.
What about the implementation team?
The vendor handled the setup, and it took about three days.
What was our ROI?
The Fortinet tools provide a good return on investment by being cost-effective and offering comprehensive security features in a bundled package.
What's my experience with pricing, setup cost, and licensing?
Using Fortinet FortiNDR as a bundle is cost-effective, providing a complete package of tools.
What other advice do I have?
I rate Fortinet FortiNDR a nine out of ten. The only reason it is not rated a ten is due to the absence of sandbox in the bundle. Overall, I am satisfied with the solution.
Don Chanaka Chanaka Chanaka Shehan Marasinghe
Informative dashboards and enhanced threat intelligence lead to proactive network monitoring
Reviewed on Nov 05, 2024
Review provided by PeerSpot
What is our primary use case?
We deploy Fortinet FortiNDR to monitor customer networks and proactively identify any bottlenecks or issues that may arise. This involves analyzing network traffic to detect anomalies and threats, which enhances network performance and security.
How has it helped my organization?
Customers benefit from proactive network monitoring and anomaly-based threat detection, which ensures high performance and security of their networks. It provides significant insights into understanding network threats.
What is most valuable?
The dashboards are very informative compared to other solutions like Cisco, providing valuable insights into network threats. FortiGuard has a strong threat intelligence database.
What needs improvement?
There is room for improvement in third-party integrations, particularly with other vendors like Check Point and Palo Alto. The integration with third-party firewalls is limited, and expanding this pool would be beneficial.
For how long have I used the solution?
We have been working with Fortinet FortiNDR for about a month.
What do I think about the stability of the solution?
Fortinet FortiNDR is rated around eight or nine out of ten in terms of stability. The solution has some limitations compared to Cisco NDR yet remains a robust and stable product.
What do I think about the scalability of the solution?
Fortinet FortiNDR is scalable and can handle high demands, rated around nine out of ten. However, there are not enough small appliances for small to medium-sized customers, and more intermediate solutions would be beneficial.
How are customer service and support?
Customer support is excellent, rated ten out of ten. They are quick to assist and provide comprehensive documentation for reference.
Which solution did I use previously and why did I switch?
We also work with Cisco Secure Network Analytics; however, Fortinet FortiNDR offers a more affordable solution with similar capabilities.
How was the initial setup?
The initial setup is very easy and straightforward, allowing for quick deployment within two to three hours.
What about the implementation team?
The implementation is typically handled within our team, leveraging the deployment guides provided by Fortinet.
What's my experience with pricing, setup cost, and licensing?
Fortinet FortiNDR is considered very affordable compared to Cisco solutions, making it an attractive option for our customers.
Which other solutions did I evaluate?
We evaluated Cisco Secure Network Analytics.
What other advice do I have?
Fortinet offers free training materials, which are beneficial for those evaluating the solution for the first time. Prospective users should utilize these resources to fully understand the capabilities of FortiNDR.
I'd rate the solution ten out of ten.
A K.
FortiGate Cloud Review
Reviewed on Dec 21, 2023
Review provided by G2
What do you like best about the product?
FortiGate cloud is mostly used by my organization and it provides complete security to our network and insfrstructure. We are glad to have fortigate cloud and firewall solutions in my infrastructure.
What do you dislike about the product?
Personally I do not feel anything to dislike about this product. Pricing is somthing can be considered and reduced.
What problems is the product solving and how is that benefiting you?
Best network and infrastructure management and security features and solutions of forigate firewall. I have been using it since 6 years and it works very well for my network.
Amar Y.
Excellent Security Solution- FortiGate Cloud
Reviewed on Dec 17, 2023
Review provided by G2
What do you like best about the product?
FortiGate Cloud provide complete firewall security management solutions over cloud. I have deploye FortiGate Firewall FG-100F along with FortiGate Cloud. They provide completely easy to manage and dashboard is pretty easy, simple and user friendly.
What do you dislike about the product?
from my personal point of view I never felt anything to dislike about FortiGate Cloud, they are improving their services on daily basis. There is nothing to dislike.
What problems is the product solving and how is that benefiting you?
Being an IT manager & IT Administrator we always look for easy to manage business security and policies as well as security network and infrastructure and FortiGate cloud provides complete solutions for these requirements. Provides complete bundle of services such as logs records, reporting and fortigate analytics.
Sneha P.
Review for Fortigate Cloud
Reviewed on Dec 14, 2023
Review provided by G2
What do you like best about the product?
The application Fortinet Fortigate Cloud is easy to use and has security features to secure the network of the Infra along with various integrated tools which enhances the scability of the application.
What do you dislike about the product?
The application is good but sometimes during applying or enforcing the policies in configuration needs little of excel and during IOS upgradation there will be some challenges while importing the firmware as the application won't allow the pro-active upgrades unless there is some bug or vulnerability found.
What problems is the product solving and how is that benefiting you?
The FortiGate Cloud has benefited in securing the network by providing the reports on Daily basis specailly of the VPN tunnels merged with Firewall. Also, the application is ease of GUI which is Web based firewall which gives more visibility with DDOS attack protection and allows to integrate the Wireless AP's. Also, we get good response from the support team during any issues.