Fortinet FortiDDoS is a dedicated distributed denial-of-service protection platform designed to detect and mitigate volumetric, protocol-based, and application-oriented DDoS attacks before they disrupt critical servers and network services. Rather than depending primarily on downloaded attack signatures, FortiDDoS learns normal traffic behavior and monitors deviations across a large number of network parameters. Fortinet positions the platform for protection against known and previously unseen attacks from Layer 3 through Layer 7.
A Fortinet FortiDDoS license therefore needs to be selected around actual network capacity rather than simply the number of protected servers. Internet bandwidth, packet rate, DNS/NTP traffic, protected subnets, interface speeds, Service Protection Profiles, deployment topology, and required resilience all affect the correct model.
Quick Benefits
- Autonomous machine-learning-based DDoS detection
- Protection against Layer 3 through Layer 7 attacks
- Sub-second mitigation capability on current platforms
- Inspection based on traffic behavior rather than mandatory attack signatures
- Protection against SYN, UDP, ICMP, DNS, NTP, HTTP, TLS, DTLS, and QUIC attack patterns
- Physical and virtual deployment options
- Dedicated DNS and NTP reflection mitigation
- Support for inline, asymmetric, tap, bypass, and HA designs
- Service Protection Profiles for separating protected network segments
Review Fortinet FortiDDoS Price List and request a quote tailored to your licensing needs.

Fortinet FortiDDoS At a Glance
What it is: Dedicated DDoS detection and mitigation platform
Parent category: Fortinet License
Primary deployment: Inline between the Internet and protected infrastructure
Protection scope: Layer 3 through Layer 7 DDoS attacks
Detection approach: Behavioral baselining and machine learning
Current physical options: 200F, 1500F/1500F-LR, 2000F and 3000G
Virtual editions: FortiDDoS-VM04, VM08 and VM16
Current VM capacity: Approximately 3 Gbps, 5 Gbps and 10 Gbps inspected throughput respectively
License Overview
FortiDDoS licensing differs noticeably between physical and virtual deployments. As part of the broader Fortinet License portfolio, hardware and virtual FortiDDoS deployments are selected according to protection capacity, deployment model, and required security services. Current Fortinet ordering information lists the FDD-200F, FDD-1500F, FDD-1500F-LR, FDD-2000F and FDD-3000G platforms. Optional FortiGuard IP Reputation and Domain Reputation subscriptions can be added where those intelligence services are required, while 24×7 support is offered in multiple term lengths.
The virtual editions use perpetual VM licenses. Current SKUs include FDD-VM04, FDD-VM08 and FDD-VM16. Reputation services and support are ordered separately. Fortinet explicitly notes that the reputation subscriptions are optional and are not required for enterprise DDoS mitigation, which is important when comparing a base FortiDDoS deployment with a fully subscribed configuration.
Sizing should not stop at Gbps. A DDoS attack can exhaust packet-processing capacity well before it consumes the full bandwidth of an uplink, particularly when attackers use extremely small UDP or SYN packets. Packet rate, therefore, matters almost as much as inspected throughput.
Product Overview
Behavioral DDoS Detection
FortiDDoS continuously observes normal network behavior and creates adaptive traffic baselines. Instead of waiting for a recognizable attack signature, the platform evaluates traffic characteristics and reacts when those characteristics move outside expected behavior. This approach is useful against changing or previously unseen DDoS techniques. Fortinet states that FortiDDoS inspects hundreds of thousands of parameters and uses machine learning to distinguish abnormal behavior from legitimate traffic.The system can evaluate different protected services separately. A public DNS cluster, for example, should not have the same baseline as an outbound corporate firewall or an HTTPS application farm.
Service Protection Profiles
FortiDDoS uses Service Protection Profiles (SPPs) to group protected networks and apply traffic-learning and mitigation behavior according to their role. A network team might create separate SPPs for authoritative DNS servers, public web services, outbound firewall infrastructure, and the broader corporate address space. Fortinet recommends defining these protected segments before establishing traffic thresholds because each service can have very different normal packet patterns. Current Fortinet ordering data lists four SPPs for VM04, eight for VM08 and the 200F, and up to sixteen for VM16 and the larger appliance families.
DNS and Reflection Attack Protection
DNS is a particularly important FortiDDoS use case. DNS reflection and amplification attacks can consume substantial bandwidth while overwhelming authoritative DNS infrastructure. Fortinet states that FortiDDoS examines DNS traffic in both directions and validates numerous characteristics of DNS queries and responses. The current physical platforms also scale significantly in DNS/NTP mitigation performance, with the higher-end appliances built for environments receiving millions of responses per second during attacks.
How Fortinet FortiDDoS Works
A normal enterprise design places FortiDDoS inline between upstream Internet connectivity and the internal network. Because the appliance sees traffic before it reaches the protected servers, it can evaluate each flow against learned behavior and the thresholds associated with its Service Protection Profile.
During initial deployment, FortiDDoS should first learn the network rather than immediately block traffic. The platform records normal behavior, generates traffic statistics, and establishes suitable thresholds. Fortinet’s current guidance recommends allowing the system to learn traffic patterns for at least a week when establishing System Recommendation thresholds.
Once the baseline is understood, individual SPPs can operate in Prevention Mode. When a threshold is exceeded, FortiDDoS can validate source behavior, inspect packet characteristics, rate-limit specific parameters or sources, and apply protocol-specific mitigation rather than simply blocking everything associated with a destination.

Core Technical Flow
Internet / Upstream Router
→ FortiDDoS Traffic Inspection
→ Behavioral Baseline and Adaptive Thresholds
→ Service Protection Profile Evaluation
→ Protocol and Source Validation
→ Rate Limiting / Attack Mitigation
→ Firewall and Protected Network
→ Applications, DNS and Infrastructure Services
Options and Licensing Models
The current FortiDDoS portfolio covers very different network sizes. Fortinet’s public product page lists the 200F at up to 8 Gbps / 9 Mpps, the 1500F at approximately 30 Gbps / 28 Mpps, and the 2000F at approximately 76 Gbps / 60 Mpps under its published model specifications. Current ordering documentation also introduces the higher-capacity 3000G, listed at 85 Gbps enterprise inspected throughput and 104 Mpps for small UDP traffic. Actual performance varies by traffic conditions and configuration.
Virtual deployments provide smaller capacity steps. VM04, VM08 and VM16 are listed at approximately 3, 5 and 10 Gbps of inspected throughput. Fortinet notes that achieving the stated VM performance requires appropriate DPDK-capable CPUs, SR-IOV networking and suitable PCIe resources. Without that architecture, VM performance can drop substantially. This makes VM selection a hardware-design decision as much as a license decision.
Features and Benefits
FortiDDoS is particularly valuable when the primary requirement is protecting network availability rather than providing another general-purpose firewall. It specializes in recognizing abnormal packet behavior at scale, including attack patterns that can overwhelm stateful firewalls before those devices have a chance to apply higher-layer security policy.
Another advantage is that the mitigation engine does not require a subscription signature to recognize every attack. Baselines continuously reflect legitimate network behavior, allowing unusual changes to be detected without waiting for a new attack pattern to be distributed.
The platform also provides operational visibility. Administrators can inspect attack logs, traffic graphs, top attacks and mitigation events to understand what was targeted and how the system responded. This can be useful for capacity planning because repeated attacks may reveal whether the organization’s Internet circuits or upstream providers are becoming the limiting factor rather than FortiDDoS itself.
Compatibility and Requirements
FortiDDoS sizing should begin with the network edge. Record the normal and peak Internet bandwidth, interface speeds, average and maximum packet rates, routing topology, and whether traffic paths are symmetric. Fortinet can support asymmetric traffic, but that deployment requires specific configuration because the system may see only one direction of some TCP or UDP flows.
The number and type of protected services also matter. DNS infrastructure may require substantially different thresholds from HTTPS applications, VPN gateways or outbound firewall traffic. Determine how many separate SPPs are needed and how many protected subnets each profile must cover.
For virtual FortiDDoS, verify the hypervisor, CPU architecture, NIC support, SR-IOV capability and PCIe allocation. Fortinet also notes that VMs do not provide the same built-in traffic-bypass capabilities as physical appliances, so external bypass may be required for many production VM designs. Finally, check HA requirements and the upstream circuit capacity. An on-premises DDoS appliance cannot recover bandwidth that has already been saturated before traffic reaches the site.
Activation and Deployment
A FortiDDoS hardware appliance arrives with its operating software installed. The system should be registered with Fortinet so administrators can access support resources and firmware updates. Fortinet recommends checking the current firmware before completing production configuration.
Virtual appliances use a license file. Fortinet documents that a FortiDDoS-VM can initially operate with a trial license and then be converted to the purchased license by uploading the provided license file through the management interface. License installation does not require a traffic interruption or appliance reboot.
After licensing, deployment should move through a learning stage. Protected subnets and SPPs are defined, FortiDDoS observes normal traffic, and Detection Mode is used to validate thresholds before Prevention Mode begins actively mitigating attacks. This staged approach reduces the risk of treating legitimate traffic spikes as malicious events.
Pricing and Quote Process
The price of a Fortinet FortiDDoS license depends first on the required performance platform. An 8 Gbps enterprise edge has a very different cost and hardware requirement from a data center that must inspect tens of gigabits and millions of packets per second. For an accurate quote, the most useful inputs are the Internet/uplink capacity, normal and peak traffic, maximum packet rate, required port speeds, number of protected subnets, SPP requirements, DNS/NTP exposure, deployment topology, and HA design. For virtual deployment, include the available CPU, NIC and hypervisor architecture as well.
The order can then be built around the appropriate hardware model or VM tier, optional IP/Domain Reputation services, and support term. Buying only from headline Gbps capacity should be avoided; a model that appears large enough in bandwidth terms may still be undersized for a high-Mpps small-packet flood.
Fortinet pricing depends on your product edition, FortiGate model, security services, license term, deployment model, and support requirements.
