Listing Thumbnail

    Fortinet FortiSandbox Zero-Day Threat Protection (On-Demand)

     Info
    Deployed on AWS
    Zero-day Malware Protection for Your Cloud and Hybrid Workloads

    Overview

    FortiSandbox for AWS enables organizations to defend against Zero-day threats natively in the cloud, working alongside network, application, email, endpoint security, and other 3rd party security solutions, or as an extension to their on-premises security architectures to leverage cloud elasticity and scale.

    The number of Windows VMs used for behavior analysis for BYOL plan is based on the license. While, for PAYG plan, that is based on the CPU cores of the instance. 1 Core - maximum of 4 Windows VMs for behavior analysis 2 Cores - maximum of 8 Windows VMs for behavior analysis 4 Cores - maximum of 16 Windows VMs for behavior analysis 8 Cores - maximum of 32 Windows VMs for behavior analysis 16 Cores - maximum of 64 Windows VMs for behavior analysis Both BYOL and PAYG plan can use the Fortinet-hosted Windows Cloud VMs . Alternatively, the Custom VMs can be deployed within the cloud but will incur additional charges as per infrastructure instance price.

    Highlights

    • AI-powered sandbox malware analysis - Two-stage AI-based Static and Dynamic analysis for fast and reliable detection of Zero-day Malware.
    • Broad Coverage of the Attack Surface with Security Fabric - Effective defense against advanced targeted attacks through a cohesive and extensible architecture working to protect network, application layers and endpoint devices from campus to cloud.
    • Automated Zero-day, Advanced Malware Detection and Mitigation - Native integration and open APIs automate the submission of objects from Fortinet and third-party vendor protection points, and the sharing of threat intelligence in real time for immediate threat response.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    OtherLinux 5.0.2

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Fortinet FortiSandbox Zero-Day Threat Protection (On-Demand)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (13)

     Info
    Dimension
    Cost/hour
    c5.xlarge
    Recommended
    $0.98
    c4.xlarge
    $1.96
    m4.xlarge
    $1.96
    m5.xlarge
    $0.98
    m5.2xlarge
    $1.96
    m4.2xlarge
    $3.93
    m5.4xlarge
    $3.93
    m5zn.metal
    $3.93
    m4.large
    $0.98
    c5.4xlarge
    $3.93

    Vendor refund policy

    You may terminate the instance at anytime to stop incurring charges.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiSandbox-VM. Connect to the secured Web UI via the public DNS address: https://<public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiSandbox-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortisandbox-public-cloud/latest/fortisandbox-vm-on-aws/443751/overview 

    Support

    Vendor support

    https://support.fortinet.com  This product is intended for On-Demand subscription. Please contact Customer Support with the following information : 1. The serial number of your FortiSandbox-VM instance 2. The email ID of your Fortinet account. If you do not have an account yet, please sign up at https://support.fortinet.com/login/CreateAccount.aspx  .

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    3.5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    100%
    0%
    0%
    1 AWS reviews
    |
    33 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Mohammed Hattari

    Email scanning efficiency needs improvement alongside reliable file scanning

    Reviewed on Nov 20, 2024
    Review provided by PeerSpot

    What is our primary use case?

    The company came to us and provided a proof of concept (POC) for six or seven months for testing the machine and evaluating how we can use Fortinet FortiSandbox . Also, we use FortiSandbox  for scanning files, like attachments.

    What is most valuable?

    Currently, there isn't a standout feature. We use Fortinet FortiSandbox for scanning files such as attachments, and we have not faced any issues so far. Up to now, it is performing well.

    What needs improvement?

    We sometimes face a delay in email scanning due to not having multiple virtual machines. Improvements could be made in dynamic scanning, scanning all email components such as URLs and attachments, and analyzing the Sandbox response. Additionally, better integration with cloud solutions and enhanced performance would be beneficial.

    For how long have I used the solution?

    I have been using FortiSandbox for six months, specifically for testing purposes on the Alibaba Cloud  platform.

    What do I think about the stability of the solution?

    The solution is stable up to now because it is still new, just six months maximum.

    What do I think about the scalability of the solution?

    The solution's performance is fine and more improved compared to the last two months.

    How are customer service and support?

    As of now, I've primarily been in contact with the consultants for support and have only needed one ticket with Fortinet. I have no substantial experience with Fortinet's direct technical support.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I previously used Cisco, but Fortinet is much easier in terms of configuration and service time.

    How was the initial setup?

    The initial setup of Fortinet was easy, more so than other products. Even though I'm not directly involved, it has been very easy to work with Fortinet, especially compared to other solutions.

    What about the implementation team?

    It was a combined effort. A consultant from an external company worked alongside us on the implementation. Most of the integration and support involved consultants.

    What's my experience with pricing, setup cost, and licensing?

    I think it's affordable. For the six to seven months of usage, the cost has been reasonable.

    What other advice do I have?

    FortiSandbox is rated five out of ten. It meets the requirements but still has room for growth and improvements.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Alibaba
    Abdelhamid Saber

    Enhanced network security with adaptable integration and really good support

    Reviewed on Oct 23, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We use FortiSandbox  for scanning files and images that pass through our networks. It integrates with different devices, such as five adapters and other Fortinet devices.

    How has it helped my organization?

    It is time-saving and more secure. It saves us from a lot of antivirus and anti-malware issues.

    What is most valuable?

    The adapter is beneficial as it allows integration with various devices, not just Fortinet.

    What needs improvement?

    It would be better if we could integrate FortiSandbox  with endpoint security solutions. This would allow us to scan files opened by the endpoint user and not just over the network.

    For how long have I used the solution?

    I have about one year of experience working with FortiSandbox.

    What do I think about the stability of the solution?

    I would rate the stability of FortiSandbox as eight out of ten.

    What do I think about the scalability of the solution?

    I would rate the scalability of FortiSandbox as eight out of ten.

    How are customer service and support?

    Fortinet provides really good technical support. They introduce high-level support for us.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial configuration is straightforward and not difficult. We have an ID for port one and can assign port three for ID two for the device.

    What's my experience with pricing, setup cost, and licensing?

    I am not familiar with the pricing because my role is strictly technical.

    What other advice do I have?

    I recommend using FortiSandbox, especially if your environment relies on FortiGate  devices or is integrated with Fortinet. It ensures better compatibility.

    I'd rate the solution nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    reviewer1721355

    Used for malware analysis and easily integrate with various solutions

    Reviewed on Apr 18, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We use Fortinet FortiSandbox for malware analysis, seamlessly integrating with various solutions such as FortiGate, FortiMail for Mail Security, FortiWeb, and other endpoints. FortiSandbox also supports ICAP integration with FortiWeb, enhancing its capabilities. These integrations can be configured within FortiSandbox, either internally or externally. Additionally, FortiSandbox offers integration with Exchange as an adapter.

    What is most valuable?

    The integration is easy with other Fortinet products like FortiMail. The technology of sandboxing FortiSandbox can cover it.

    Fortinet FortiSandbox has the capability for manual analysis' Unlike its competitors, FortiSandbox offers functionalities such as banning, sniffing, and analyzing traffic in the network. It can connect as a bandwidth analyzer and provide analytics on the network traffic. It's not limited to just sandboxing; it can also operate at the endpoint, firewall, or gateway levels to submit files for analysis and monitor network traffic for analysts.

    What needs improvement?

    The solution must focus on API integration with other vendors.

    For how long have I used the solution?

    I have been using Fortinet FortiSandbox as an integrator since 2017.

    What do I think about the stability of the solution?

    The solution is stable on dedicated appliances like virtual machines. It also depends on the capabilities of the host system, including CPU and RAM.

    What do I think about the scalability of the solution?

    The solution is scalable. You can configure up to one hundred nodes as workers. Additionally, you can include up to ninety-eight worker nodes in other models, allowing them to function as a cluster.

    It has a defense line from zero-day attacks and sophisticated attacks. You will need an EDR solution and the endpoint.

    Six persons are using this solution.

    How are customer service and support?

    Customer support is friendly and has a good team.

    How was the initial setup?

    A network security engineer can deploy the solution. The organization's IT department manages administration, including application and network security. Multiple administrators may use FortiSandbox, each with their front-end interface for managing it.

    What was our ROI?

    The solution provide zero-day attacks which benefitted a lot.

    What other advice do I have?

    If the customer's operating system is supported, there's no need for a custom package. It's straightforward. If a custom operating system is required, it will take longer due to the need for package customization.

    Overall, I rate the solution an eight out of ten.

    reviewer1810833

    Real-time analysis capability of FortiSandbox is beneficial for email analysis and is scalable for enterprise companies

    Reviewed on Mar 20, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We implemented FortiSandbox in three main steps: planning the infrastructure and topology, setting up dedicated Internet access for the sandbox, and configuring manual uploading and email forwarding. For email communication, we used either FortiMail or BCC/force mirroring solutions. FortiSandbox has successfully identified and blocked email attachments containing threats. 

    What is most valuable?

    The real-time analysis capability of FortiSandbox is beneficial for email analysis, but it's not practical for real-time web traffic analysis because users won't wait for the FortiSandbox to complete its analysis before accessing content.

    What needs improvement?


    For how long have I used the solution?

    I have experience working with Fortinet FortiSandbox, but it's been about one year since the first implementation.

    What do I think about the stability of the solution?

    It is stable

    What do I think about the scalability of the solution?

    The solution is scalable especially suitable for enterprise businesses.

    How are customer service and support?

    I haven't needed technical support, and while the pricing can be expensive, the performance and security it offers are commendable.

    How was the initial setup?

    I rate the initial setup of Fortinet FortiSandbox as a little bit difficult due to licensing issues,

    What other advice do I have?

    I would recommend FortiSandbox for high-security environments like financial or government sectors. Overall, I rate it an eight out of ten.

    ImranShaikh

    An easy-to-maintain tool with a satisfactory support team

    Reviewed on Feb 12, 2024
    Review from a verified AWS customer

    What is most valuable?

    The most valuable features of the product include components like CDR, greylisting, sandboxing, attachment detection in sandboxing, DLP  fingerprinting, and the redirect option.

    What needs improvement?

    For the MSSPs, it would be great if the product could display all the threat chains on a dashboard since it is an area where the tool is currently lacking.

    For how long have I used the solution?

    I have been using Fortinet FortiSandbox  for around two years. My company has a partnership with Fortinet. My company also operates as an MSP for Fortinet.

    What do I think about the stability of the solution?

    It is a stable solution with no issues at all. The product is scalable and stable since it is compatible with cloud solutions like AWS  and Azure . The product can be deployed on the cloud services offered by Amazon AWS  or Microsoft Azure .

    What do I think about the scalability of the solution?

    It is an easily scalable solution.

    My company caters to the needs of small, medium, and large-sized businesses where the solution is used.

    How are customer service and support?

    The solution's technical support is satisfactory. I rate the technical support a seven to eight out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have worked with other solutions in the past.

    How was the initial setup?

    The product is easy to deploy.

    The product can be deployed in 15 days.

    Two or three people from our company are involved in the deployment, implementation, and configuration process.

    What was our ROI?

    Fortinet FortiSandbox  saves a lot of money for its users since if an attack happens in your environment, the loss is infinite, especially in terms of the brand value and laws of data. In terms of ROI, the tools safeguard the data and brand value of the company. The percentage of the ROI can vary from company to company. If the product prevents an attack on a small or medium-sized business, then the ROI part will have a different implication in terms of numbers. If the product prevents an attack on an enterprise-sized company, the ROI part will have a different implication in terms of numbers.

    What's my experience with pricing, setup cost, and licensing?

    Fortinet FortiSandbox is a nominally priced product, so I would not say that it is a very cheap tool. It is one of the best solutions in the market with a competitive pricing model, similar to the prices offered by products from Cisco.

    What other advice do I have?

    I would describe Fortinet FortiSandbox, which has been deployed within our company's network for threat detection, as a proactive solution with multiple functionalities. A few of the functionalities of the product include areas like sandboxing, CDR, pattern-reading, and detection ratio, which are very good.

    I rate the product's effectiveness in dealing with zero-day threats a seven to eight out of ten, where ten means it is the most effective product for dealing with zero-day threats.

    As of now, Fortinet FortiSandbox is not integrated with other Fortinet solutions to improve our company's security posture. The tool is integrated with our own existing email security gateway to use anti-spam and anti-virus features.

    The tool should have more ability to customize from the reporting point of view. The tool should be able to provide more slicing and dicing in data. The users of the product should try to know about threat chains t with the help of the tool's MSPs so that they know the outcome of a threat that may enter their networks. In the MSP model, it would be good if the aforementioned area gets integrated.

    The reporting and alerting capabilities of the product have helped our company's security area since the tool provides good and deep-dive reports, which include proper reasoning for certain actions that were taken. The report will explain why it blocked or did not block certain aspects. There are detailed reports in terms of the logs that the tool provides its users. The tools also provide details on the areas that were quarantined. In general, the tool provides a very detailed report.

    The product is easy to maintain since my company gets proper support from Fortinet.

    In my company, there are many use cases to describe scenarios where the product prevented or mitigated a breach or an attack. My company operates as a managed service provider for Fortinet, and many of our customers use Fortinet FortiSandbox. When my company receives any attacks via links or attachments, FortiMail  blocks such emails.

    I suggest others consider whether they plan to buy a solution from a security company. I will see whether the tool I use for sandboxing is from a security company or not. I will consider the catch rate of the product. I will also consider the other solutions that the vendor can bring in for me that can improve and secure my company's security posture while being easy to use and implement.

    I will consider whether the vendor who offers our company sandboxing features has a security background. I will look into whether the solution is interoperable or not. There should be interoperability if I need to deploy some other solution as well, like a DLP  or a firewall.

    I rate the overall tool a seven out of ten.

    View all reviews