FortiSandbox for AWS enables organizations to defend against Zero-day threats natively in the cloud, working alongside network, application, email, endpoint security, and other 3rd party security solutions, or as an extension to their on-premises security architectures to leverage cloud elasticity and scale.
The number of Windows VMs used for behavior analysis for BYOL plan is based on the license. While, for PAYG plan, that is based on the CPU cores of the instance.
1 Core - maximum of 4 Windows VMs for behavior analysis
2 Cores - maximum of 8 Windows VMs for behavior analysis
4 Cores - maximum of 16 Windows VMs for behavior analysis
8 Cores - maximum of 32 Windows VMs for behavior analysis
16 Cores - maximum of 64 Windows VMs for behavior analysis
Both BYOL and PAYG plan can use the Fortinet-hosted Windows Cloud VMs . Alternatively, the Custom VMs can be deployed within the cloud but will incur additional charges as per infrastructure instance price.
Highlights
AI-powered sandbox malware analysis - Two-stage AI-based Static and Dynamic analysis for fast and reliable detection of Zero-day Malware.
Broad Coverage of the Attack Surface with Security Fabric - Effective defense against advanced targeted attacks through a cohesive and extensible architecture working to protect network, application layers and endpoint devices from campus to cloud.
Automated Zero-day, Advanced Malware Detection and Mitigation - Native integration and open APIs automate the submission of objects from Fortinet and third-party vendor protection points, and the sharing of threat intelligence in real time for immediate threat response.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the EC2 instance you run FortiSandbox on. This is usage-based billing with no upfront commitment. All dimensions cover the same software; they differ only by instance size and family. The c-family instances are compute-optimized, while the m-family instances balance compute and memory. Within each family, sizes range from xlarge up to 24xlarge, plus metal and flex variants. Hourly cost rises as you pick more vCPU and memory. Choose an instance that matches your scanning volume and performance needs; larger sizes handle higher file throughput.
Top-of-mind questions for buyers
What does the hourly charge cover, and am I billed when the instance is stopped?
You pay per hour for each running EC2 instance hosting FortiSandbox. Charges accrue only while the instance runs. A stopped or powered-off instance stops the software charge. Underlying AWS storage may still incur separate fees while the instance is stopped.
How do I choose between the c-family and m-family instance sizes?
The c-family is compute-optimized for heavier scan processing. The m-family balances compute and memory. FortiSandbox runs suspicious files in virtual machine sandboxes, so match the instance to your scan volume. Larger sizes provide more vCPU and memory for higher file throughput.
Does the hourly software price include a Fortinet license, or do I supply my own?
This on-demand listing bundles the FortiSandbox software license into the hourly rate. The deployment process still requires uploading a firmware license and the rating and tracer engine to the instance. Contact Fortinet support for custom VM images used during scanning.
www.fortinet.com+2
Helpful?
Vendor refund policy
You may terminate the instance at anytime to stop incurring charges.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
After deploying the instance, click on Manage in AWS Console to see the running instance and public DNS address to continue the configuration of the FortiSandbox-VM. Connect to the secured Web UI via the public DNS address: https://<public DNS address>. For any CLI configuration/settings, SSH is required to log into the CLI. Default login credentials are with a username of admin and the AWS Instance ID value as the password. The FortiSandbox-VM AWS Install and Configure guide is located at https://docs.fortinet.com/document/fortisandbox-public-cloud/latest/fortisandbox-vm-on-aws/443751/overview
https://support.fortinet.com This product is intended for On-Demand subscription. Please contact Customer Support with the following information : 1. The serial number of your FortiSandbox-VM instance 2. The email ID of your Fortinet account. If you do not have an account yet, please sign up at https://support.fortinet.com/login/CreateAccount.aspx .
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Fortinet FortiGate allows mitigation of blind spots to improve policy compliance by implementing critical security controls within your AWS environment. FortiGate includes all of the security and networking services common to FortiGate physical appliances.
Fortinet professional design and implementation services for network, application, and cloud-native (CNAPP) security for AWS, hybrid, and multi-cloud environments.
FortiAuthenticator is a centralized user Identity Management solution to transparently identify network users and enforce identity-driven access policy in a Fortinet fabric. It supports FortiToken Two-factor authentication, Certificate and Wireless Guest management and Single Sign On capability.
The Fortinet FortiManager provides easy centralized configuration, policy-based provisioning, update management and end-to-end network monitoring for your Fortinet installed environment.
The FortiWeb web application firewall (WAF) defends web-based applications from known and zero-day threats. Its AI-based machine learning identifies threats with virtually no false positive detections.
FortiSandbox: Advanced Zero-Day Detection with Real-Time Automated Analysis
Reviewed on Mar 31, 2026
Review provided by G2
What do you like best about the product?
the most helpfull features and upsides of FortiSandbox are. 1 Advanced Threat Detection (Zero-Day Protection) 2 Real time Automated analysis 3 its Integration with security systems (Fortinet Security Fabrics) 4 Automate threat response
What do you dislike about the product?
the main points to raise in here are 1 its high cost 2 it is a bit complex for setup and management 3 it needs strong CPU/RAM. it requires significant system resources 4 it does have latency files must be analyzed before being allowed or blocked.
What problems is the product solving and how is that benefiting you?
FortiSandbox analyzes suspicious files in a safe environment to detect hidden threats and automatically block them. This helps protect the network, reduce security risks, and save time during investigations.
AhmedNatil
Advanced sandboxing has protected users from zero-day threats and has simplified secure file scanning
Reviewed on Feb 02, 2026
Review from a verified AWS customer
What is our primary use case?
Clients primarily ask us to integrate Fortinet FortiSandbox either with FortiMail or with firewalls to scan downloadable files and ensure that client access browsing is secure with no harmful files downloaded to the client side.
For users on the client side, Fortinet FortiSandbox can protect them from ignorance regarding attacks, cybersecurity, or viruses. If a user downloads a malicious document, Fortinet FortiSandbox scans, runs, and checks if it has malware, and if it does have malware, it can protect or delete it. If it's clean, the user can download it. From the client side, it provides insight and protection for the organization if they are targeted by zero-day attacks or malware.
What is most valuable?
The smooth integrations between Fortinet FortiSandbox and other Fortinet solutions such as FortiWeb and FortiFirewall and with other Fortinet environments are what I really appreciate.
We have minimum false positives during threat detection. Our clients have not given negative feedback from detection. As you know, it still needs some tuning after implementation. However, we never receive negative feedback for many false positives during implementation.
What needs improvement?
I think Fortinet FortiSandbox could introduce more automation tools and AI tools.
For how long have I used the solution?
I have been using this solution for almost five or six years.
What do I think about the stability of the solution?
The current function is acceptable. I have worked with other sandboxing solutions that introduce more complexity on their devices. Fortinet FortiSandbox works fine, is easy to manage, and functions well.
What do I think about the scalability of the solution?
It is very easy to scale.
How are customer service and support?
I would rate it an eight out of ten. This depends on who is managing the cases. Sometimes the technical engineer is very good and helpful, and sometimes we go through many processes until it gets escalated to a higher level or to another advanced technical engineer.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have tried Trend Micro, but I think Fortinet FortiSandbox is more simple and seamless than Trend Micro.
How was the initial setup?
The setup is very simple.
What about the implementation team?
An implementation team was involved in the setup.
What was our ROI?
I think a rating of nine out of ten would be appropriate.
What's my experience with pricing, setup cost, and licensing?
The cost is in the mid-range. It is not low and it is not high.
What other advice do I have?
We are still working with Fortinet FortiSandbox and other vendors. We are a business partner for Fortinet and other vendors as well. We have configured one of our clients for Fortinet FortiSandbox. I give this product a review rating of ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Computer Software
A good security investment that gives real value and steady protection
Reviewed on Sep 17, 2025
Review provided by G2
What do you like best about the product?
The best part is it takes a big load off our security team. By catching threats early, it saves us both time and cleanup costs
What do you dislike about the product?
It’s given us good results, but it isn’t budget-friendly. For those not using other Fortinet tools, the price may be tough
What problems is the product solving and how is that benefiting you?
Before, a single infection meant hours of cleanup. Now the sandbox blocks them upfront, saving IT work and keeping things running
Urvish M.
After a smooth deployment, it has consistently safeguarded our network from advanced threats
Reviewed on Sep 17, 2025
Review provided by G2
What do you like best about the product?
I really like the endpoint integration. FortiClient silently sends unknown files to FortiSandbox in the background, and we don’t have to babysit it. Once we tuned the policies, it’s been running reliably without slowing down users, which is a big plus for productivity.
What do you dislike about the product?
It can be resource-hungry. We had to allocate more hardware than initially expected to keep the performance smooth, especially with FortiClient endpoints constantly sending samples. Once scaled properly it’s fine, but the upfront sizing needs careful planning.
What problems is the product solving and how is that benefiting you?
Before deploying it, we were constantly dealing with suspicious attachments slipping through email and reaching endpoints. Now FortiClient forwards anything unknown to FortiSandbox, and verdicts come back quickly. It’s cut down on user-reported incidents and allowed us to keep our environment clean without adding more endpoint load.
Brijesh R.
A reliable and proactive solution that has strengthened our overall security posture.
Reviewed on Sep 17, 2025
Review provided by G2
What do you like best about the product?
The strongest part for me is how well it works with FortiClient on our endpoints. Whenever a suspicious file shows up, it’s automatically sent to FortiSandbox, and the verdict comes back quickly. If it’s malicious, FortiClient immediately blocks it and updates its signatures, it’s closed several gaps we used to worry about.
What do you dislike about the product?
The main drawback I’ve noticed is the occasional delay during peak load. When multiple suspicious files come in at once, analysis can take a bit longer, which slightly slows down our incident triage. It’s not frequent, but it’s something we’ve had to plan around.
What problems is the product solving and how is that benefiting you?
It’s helped us close the gap against zero-day and evasive malware that our traditional signature-based tools were missing. By sending suspicious files from FortiClient to FortiSandbox for behavioral analysis, we’re catching threats before they ever execute. This has greatly reduced infection incidents and strengthened our security posture.