Fortinet FortiDDoS
Fortinet FortiDDoS. Behavioral DDoS mitigation. Built into hardware.
Fortinet FortiDDoS appliances identify and suppress volumetric, protocol, and application layer attacks in real time using custom ASIC processing and behavior-based detection. No signature updates to manage. No scrubbing center to route traffic through. Clean traffic keeps moving, and attack traffic stops at the perimeter. Firewalls.com is an authorized Fortinet Expert partner with same-day shipping and certified engineers on staff.
Shop by Series
FortiDDoS-600B
The 600B brings ASIC-accelerated DDoS mitigation to smaller environments and data center edge deployments. Behavioral detection runs at line rate with no signature database to update or license separately.
Shop FortiDDoS-600B →
FortiDDoS-800B
The 800B adds throughput headroom for regional ISPs and mid-market hosting environments under sustained attack. Adaptive baselines learn your traffic mix and tighten suppression as attack volume grows.
Shop FortiDDoS-800B →
FortiDDoS-900B
The 900B handles enterprise-scale DDoS campaigns and multi-vector attacks at high throughput. Granular per-source rate controls let your engineers tune suppression without touching legitimate traffic.
Shop FortiDDoS-900B →
FortiDDoS-2000E
The 2000E runs on Fortinet's next-generation ASIC platform and handles carrier-class traffic volumes under sustained attack. If your upstream bandwidth is measured in tens of gigabits, the 2000E is your mitigation layer.
Shop FortiDDoS-2000E →
Licenses & Renewals
Keep your FortiDDoS appliance supported and current with FortiCare plans and FortiGuard DDoS subscription services. Available in one, three, and five year terms for every model in the lineup.
Shop All Licenses →Fortinet FortiDDoS Appliances at a Glance
| Series | Best For | Throughput | Form Factor | Key Feature |
|---|---|---|---|---|
| FortiDDoS-600B | SMB & Edge Data Centers | Up to 6 Gbps | 1U Rackmount | ASIC-based behavioral detection |
| FortiDDoS-800B | Regional ISP & Mid-Market | Up to 8 Gbps | 1U Rackmount | Adaptive traffic baselines |
| FortiDDoS-900B | Enterprise & Hosting Providers | Up to 12 Gbps | 1U Rackmount | Granular per-source rate controls |
| FortiDDoS-2000E | Large Enterprise & Carrier | Up to 24 Gbps | 2U Rackmount | Next-generation ASIC platform |
Fortinet FortiDDoS FAQ
FortiDDoS is Fortinet's purpose-built DDoS mitigation appliance line. It uses custom ASICs to process traffic at line rate and behavioral analysis to separate attack traffic from legitimate traffic. The appliance tracks traffic baselines over time, then detects and suppresses anomalies in real time when an attack begins, without requiring signature updates.
Yes. Because FortiDDoS uses behavior-based detection rather than signature matching, it identifies and blocks novel attack vectors that have never been seen before. Any traffic that deviates from established baselines triggers mitigation, whether or not the attack type appears in a known-attacks database.
FortiDDoS stops volumetric attacks such as UDP floods and ICMP floods, protocol-layer attacks including SYN floods and TCP fragmentation, and application-layer attacks like HTTP GET floods and DNS amplification. All three attack categories are handled in hardware for fast, low-latency mitigation.
The right model depends on your traffic volume and deployment environment. The 600B suits smaller data centers and SMB networks. The 800B fits regional ISPs and mid-market data centers. The 900B handles enterprise and hosting provider scale. The 2000E is Fortinet's highest-capacity platform for large enterprises and carriers. Tell us your peak bandwidth and we can confirm sizing.
FortiDDoS is an on-premises hardware appliance. It sits inline or in detection mode within your network perimeter and scrubs attack traffic before it reaches downstream systems. On-premises mitigation means you are not dependent on redirecting traffic to a third-party scrubbing center, and latency added to clean traffic stays near zero.
The B-series models, which include the 600B, 800B, and 900B, are the proven platform that has protected enterprise networks for years. The 2000E represents Fortinet's next-generation ASIC architecture with higher throughput and added capacity for large-scale attacks. If you need carrier-class scale, the 2000E is the right starting point. The B-series covers most enterprise requirements at a lower entry price.
Yes. Our certified Fortinet engineers offer pre-deployment configuration, including baseline policy setup, interface configuration, and integration with your upstream network. We also offer ongoing managed services if you want a team watching your FortiDDoS and handling change requests. Contact us for a quote.
Not sure which Fortinet FortiDDoS is right for you?
Tell us your peak traffic volume, your uplink capacity, and whether you need inline or out-of-path deployment, and our certified Fortinet engineers will size the right FortiDDoS model for your environment.
Get a Sizing Recommendation
Login and Registration Form
Existing User