Fortinet FortiDDoS 1000B
DDoS Attack Mitigation Appliances
Sorry, this product is no longer available. Please Contact Us for a replacement.
Click here to jump to more pricing!
Overview:
The Ever-changing DDoS Attack
Distributed Denial of Service (DDoS) attacks continue to remain the top threat to IT security and have evolved in almost every way to do what they do best: shut down your vital online services. Never has a problem been so dynamic and broad-based without being tied to one particular technology. There is almost an unlimited array of tools that Hacktivists and Cyberterrorists can use to prevent access to your network. Sophisticated DDoS attacks target Layer 7 application services where they are much smaller in size making it nearly impossible for traditional ISP-based mitigation methods to detect them.
To combat these attacks, you need a solution that is equally dynamic and broadbased. Fortinet’s FortiDDoS Attack Mitigation appliances use behavior-based attack detection methods and 100% ASIC-based processors to deliver the most advanced and fastest DDoS attack mitigation on the market today.
A Different and Better Approach to DDoS Attack Mitigation
Only Fortinet uses a 100% ASIC approach to its DDoS products without the overhead and risks of a CPU or CPU/ASIC hybrid system. The FortiASIC-TP2 transaction processors provide both detection and mitigation of DDoS attacks. The FortiASIC-TP2 processor handles all Layer 3, 4 and 7 traffic types, speeding detection and mitigation performance resulting in the lowest latency in the industry.
FortiDDoS uses a 100% heuristic/behavior-based method to identify threats compared to competitors that rely primarily on signature-based matching. Instead of using pre-defined signatures to identify attack patterns, FortiDDoS builds a baseline of normal activity and then monitors traffic against it. Should an attack begin, FortiDDoS sees this as an anomaly and then immediately takes action to mitigate it. You’re protected from known attacks and from the unknown “zero-day” attacks as FortiDDoS doesn’t need to wait for a signature file to be updated.
FortiDDoS also handles attack mitigation differently than other solutions. In other DDoS attack mitigation appliances, once an attack starts, it’s 100% blocked until the threat is over. If an event is mistakenly matched to a signature creating a “false positive”, then all traffic comes to a halt requiring intervention. FortiDDoS uses a more surgical approach by monitoring normal traffic and then using a reputation penalty scoring system, rates IP addresses that are “good” and others that are causing the problem.
FortiDDoS blocks the offending IP addresses then repeatedly reevaluates the attack at user defined periods (every 15 seconds by default). If the offending IP addresses continue to be a persistent threat for each of these reevaluation periods, their reputation penalty score will increase and will eventually be blacklisted once they hit a user-defined threshold.
Advanced DDoS Protection for Enterprise Datacenters
- 100% hardware-based Layer 3, 4 and 7 DDoS protection provides fast identification and mitigation of attacks.
- Behavior-based DDoS protection reacts to any threat without the need for signature files.
- Up to 24 Gbps full-duplex throughput with bidirectional attack mitigation.
- Combines IP reputation scoring, Geo-location ACLs, and slow attack mitigation for complete Layer 3, 4, and 7 DDoS attack protection in a single appliance.
- Industry leading ultra-low latency of less than 50 microseconds.
- Continuous threat evaluation minimizes risk of “false positive” detections.
- Advanced connectivity with up to 16x 10G SFP+ Fiber interfaces with built-in bypass capabilities.
- Easy to deploy and manage with intuitive GUI and comprehensive reporting and analysis tools.
Easy to Set up and Manage
The FortiDDoS Automated Learning tools require less than an hour to build a complete baseline of your application traffic patterns. Once complete, set your thresholds or simply use the default settings. FortiDDoS then automatically begins defending you from any DDoS attack without having to spend hours configuring option after option or worrying about signature updates.
Comprehensive reporting and dashboards give you the tools you need to review attacks and threats to your services. You can run reports as you need them or schedule them to be delivered to you on a regular basis. Dashboards allow you to view and understand attack trends in an easy-to-use single screen layout. Whether it’s general status reporting or indepth granular attack analysis, FortiDDoS provides detailed information on service level attacks and mitigation responses for specific events or over periods of time.
Flexible Defensive Mechanisms
FortiDDoS protects against every DDoS attack including Bulk Volumetric, Layer 7 Application, and SSL/HTTPS attacks. From the oldest trick in the book to the latest in advanced service-level attacks, FortiDDoS has you covered.
Bulk Volumetric Attacks were the first DDoS attack types and continue to pose significant threats today. Usually ISPs prevent most simple attacks of this type, however increasingly they are used to mask more complex application-level attack methods. The easiest way to deal with these types of threats is to simply block all traffic until the attack stops. The FortiDDoS IP Reputation scoring system continues to let “good” traffic in while mitigating IP addresses that are causing the problem. This process not only provides the protection you need, but also minimizes the effects of a “false positive” match from halting good client traffic.
Layer 7 Targeted Attacks are the fastest growing source of DDoS attacks. They attempt to exploit vulnerabilities within a service to exhaust its resources rendering it unavailable. Usually these types of attacks are embedded in Bulk Volumetric Attacks, however they can occur separately. As these types of attacks require considerably less bandwidth to deny service, they are more difficult to detect and regularly pass from ISPs directly to your network. All Layer 7 targeted attacks, large or small, will trigger changes at the service level that will be identified by the FortiDDoS behavioral analysis engine and mitigated.
SSL-Based Attacks use SSL-based encryption methods to hide the content of the attack packets. Additionally, the encryption methods employed will often mean that there are far less resources available that need to be exhausted. Most signature-based solutions require decryption of the traffic to perform matching against known attack profiles. With a behavioral system such as FortiDDoS, these attacks are detected without decryption as they will cause a change in behavior. This change can then be compared with normal behavior and an understanding of the resources available. When the relevant resources become threatened does the FortiDDoS put mitigation in place and respond to the attack.
Key Features and Benefits | |
---|---|
100% Behavioral-based Detection | FortiDDoS doesn’t rely on signature files that need to be updated with the latest threats so you’re protected from both known and unknown “zero-day” attacks. |
100% Hardware-based DDoS Protection | The FortiASIC-TP2 transaction processor provides bi-directional detection and mitigation of Layer 2, 3 and 7 DDoS attacks for industry-leading performance. |
Continuous Attack Evaluation | Minimizes the risk of “false positive” detection by reevaluating the attack to ensure that “good” traffic isn’t disrupted. |
Congestion Resistant | With up to 24 Gbps of throughput, FortiDDoS won’t easily be overwhelmed by high-volume DDoS attacks. |
Automated Learning Process | With minimal configuration, FortiDDoS will automatically build normal traffic and resources behavior profiles saving you time and IT management resources. |
Multiple Attack Protection | By understanding behaviors FortiDDoS can detect any DDoS attack from basic Bulk Volumetric to sophisticated Layer 7 SSL-based attacks without the need to decrypt traffic. |
Comprehensive Reporting Capabilities | Real-time and historic reports provide granular visibility for network and protocol layers. |
Pricing Notes:
- Hardware plus FortiCare Premium and FortiADC Network Security Bundle
Hardware Unit, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, FortiCare Premium Ticket Handling, Antivirus, IP Reputation and GeoIP and Intrusion Prevention Service - Hardware plus FortiCare Premium and FortiADC Application Security Bundle
Hardware Unit, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, FortiCare Premium Ticket Handling, Antivirus, IP Reputation and GeoIP, Intrusion Prevention Service, WAF Security, Credential Stuffing Defense, Sandbox Cloud and Data Loss Prevention Service - Hardware plus FortiCare Premium and FortiADC AI Security Bundle
Hardware Unit, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, FortiCare Premium Ticket Handling, Antivirus, IP Reputation and GeoIP, Intrusion Prevention Service, WAF Security, Credential Stuffing Defense, Sandbox Cloud, Data Loss Prevention, Threat Analytics and Advanced Bot Protection Service - Network Security - IP Reputation and Geo-IP, AV, IPS, and FortiCare Premium
Advanced Hardware Replacement (NBD), Firmware and General Upgrades, FortiCare Premium Ticket Handling, Antivirus, IP Reputation and GeoIP and Intrusion Prevention Service - Application Security - Network Security Bundle Plus WAF Security Service, FortiADC Cloud Sandbox, Credential Stuffing Defense, FortiGuard Data Loss Prevention Service, and FortiCare Premium
Advanced Hardware Replacement (NBD), Firmware and General Upgrades, FortiCare Premium Ticket Handling, Antivirus, IP Reputation and GeoIP, Intrusion Prevention Service, WAF Security, Credential Stuffing Defense, Sandbox Cloud and Data Loss Prevention Service - AI Security - Application Security Bundle Plus Threat Analytics, FortiGuard Advanced Bot Protection, and FortiCare Premium
Advanced Hardware Replacement (NBD), Firmware and General Upgrades, FortiCare Premium Ticket Handling, Antivirus, IP Reputation and GeoIP, Intrusion Prevention Service, WAF Security, Credential Stuffing Defense, Sandbox Cloud, Data Loss Prevention, Threat Analytics and Advanced Bot Protection Service - FortiCare Premium Support
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades - FortiDDoS FortiCare Premium Support
FortiCare Premium Ticket Handling, Advanced Hardware Replacement (NBD), Firmware and General Upgrades. This service level includes a FortiDDoS responsiveness SLA of 30 minutes for Priority 1 incidents. - Prices are for one year of Premium RMA support. Usual discounts can be applied.
- Annual contracts only. No multi-year SKUs are available for these services.
- Contact Fortinet Renewals team for upgrade quotations for existing FortiCare contracts.
- Pricing and product availability subject to change without notice.
List Price:
Our Price: $943.77
List Price:
Our Price: $3,777.64