I understand the point of a NGFW is to consolidat a stack of security appliances into one. But isn't the fiewall itself subject to DDoS attacks - esp since it doesn't act in stealth mode? Wouldn't it be best practice to have either a cloud based DDoS service or a dedicated and stealthed DDoS security appliance like FortiDDoS infront of the gateway firewall?
FortiGate/FortiOS is not immunized against DDoS (Distributed DoS). It can however block DoS attacks.
DDoS are by definition not detectable by a simple equipment like FGT, FWB or any other server.
As per my knowledge DDoS need some cooperation between ISPs. So I think the correct way to prevent DDoS attacks is to purchase the service from your ISP (if it is not already included in your package).
User | Count |
---|---|
2538 | |
1351 | |
795 | |
642 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.