FortiDDoS FDD-VM DDoS Protection Software in Africa
Protect business services from disruptive volumetric, protocol and application-layer denial-of-service activity with an inline virtual protection platform designed for supported on-premises infrastructure. FortiDDoS FDD-VM gives organisations a structured path to dedicated DDoS defence without requiring a separate physical FortiDDoS appliance, provided the server, network interfaces and traffic path are engineered correctly for the chosen capacity.
✓ Inline on-premises deployment
✓ Configuration review
✓ Quote and licensing guidance
Request Quote
Check Africa Availability
Quick Product Information
Fortinet
FortiDDoS FDD-VM
Virtual inline DDoS protection system
VM04, VM08 and VM16 perpetual licenses
Supported on-premises VMware or KVM environments
Protect public services, applications and infrastructure from DDoS disruption
Configuration dependent, up to 3, 5 or 10 Gbps inspected throughput by model
Contact FourTeck for current license and support options
Not designed for direct deployment in AWS, Azure or Google Cloud
Product Overview
Distributed denial-of-service incidents can affect much more than a public website. An attack may overload an internet-facing service, exhaust connection tables, disrupt authoritative DNS, consume application resources, create excessive packet-processing load or prevent legitimate users from reaching services that the organisation depends on. For businesses with customer portals, payment systems, learning platforms, government services, remote access gateways, hosted applications or other public infrastructure, even a short interruption can create operational, financial and reputational consequences.
FortiDDoS FDD-VM is built as a dedicated virtual network function for inline DDoS detection and mitigation. Rather than treating every traffic spike as malicious, the platform learns normal traffic behaviour and monitors a large set of traffic characteristics so that abnormal patterns can be identified and controlled. It is intended to sit in the traffic path on supported on-premises infrastructure, examining inbound and outbound packets while protecting defined services and subnets. The virtual format can be attractive when an organisation already operates suitable high-performance servers and prefers a software license rather than a dedicated appliance chassis.
The FDD-VM family is not one fixed-size license. It includes VM04, VM08 and VM16 choices. These options differ in supported vCPU count, inspected throughput, packet mitigation rate, memory requirement and the number of service protection profiles available. This makes the buying decision more detailed than selecting a model name from a list. The project team must understand the normal and peak traffic profile, the smallest-packet rate that may reach the protected environment, the number of distinct services requiring separate policies, and the amount of capacity that should remain available for growth.
FourTeck supports buyers by translating these technical questions into a practical procurement scope. The review can cover the required license, server readiness, NIC capabilities, hypervisor version, physical link attachment, external bypass design, high-availability expectations, support duration and optional reputation subscriptions. This approach helps avoid a situation where the software license is purchased before the underlying infrastructure has been confirmed. The result is a better-aligned deployment plan for organisations that need dependable service availability and clear ownership of DDoS protection.
Key Business Benefits
A DDoS protection purchase should be assessed by the operational value it creates, not only by a throughput number. The following benefits explain how the virtual platform can support continuity, security operations and future planning when it is correctly sized and deployed.
◆ Dedicated DDoS Control
A purpose-built mitigation layer gives the security team controls designed specifically for denial-of-service behaviour. This reduces reliance on general firewall rules alone and provides a clearer operational view of attack events, thresholds, protected services and mitigation activity.
◆ Service Continuity
Inline inspection can help preserve access for legitimate users while unwanted traffic is identified and controlled within the deployed capacity. This is important for organisations where online systems support revenue, customer service, communication or essential public functions.
◆ Behaviour-Based Protection
Adaptive traffic baselines help the platform distinguish unusual activity from normal business variation. This is valuable when attack methods change, use multiple vectors or attempt to resemble legitimate connections rather than matching a simple static pattern.
◆ Flexible Virtual Sizing
Three license tiers allow the organisation to select capacity that more closely matches current traffic and expansion plans. The virtual approach can also fit businesses that have standardised on supported server and virtualisation infrastructure.
◆ Policy Separation
Service protection profiles allow different networks or applications to be treated according to their own traffic patterns and risk. This supports clearer administration when web, DNS, communication and other services do not share the same normal behaviour.
◆ Operational Visibility
Monitoring, event information and traffic statistics can help security teams understand what occurred, which service was targeted and how the system responded. Better visibility supports incident review, tuning and communication with management or service providers.
◆ Optional Ecosystem Services
Core enterprise mitigation can be deployed without requiring optional reputation subscriptions, while IP and domain reputation services may be added where the organisation’s policy and risk model justify them. Support terms can also be selected separately.
Product Highlights
Designed to inspect traffic rather than depend on sampled flow data alone.
Addresses volumetric, protocol and selected application-layer DDoS behaviour.
Learns normal service patterns and responds when traffic deviates from expected behaviour.
VM04, VM08 and VM16 provide distinct throughput, vCPU and profile levels.
FortiDDoS is designed to monitor a very large number of traffic parameters and use learned behaviour to detect abnormal changes. This is relevant for attacks that do not rely on one simple signature, including multi-vector events that change methods during the incident. The system can apply service-aware mitigation to protect defined network resources while maintaining visibility into what is being blocked.
The virtual editions retain the main FortiDDoS operating model but depend heavily on the underlying host. Performance claims require suitable DPDK-capable CPUs, SR-IOV network interfaces and correct PCIe allocation. Virtual models do not provide built-in traffic bypass control, and their flood mitigation and graphing granularity is not identical to hardware appliances. These are important buying facts, not minor technical details. A well-planned VM can be a strong fit, while a poorly matched host or traffic design can reduce performance and complicate troubleshooting.
Technical Specifications
| Specification | VM04 | VM08 | VM16 |
|---|---|---|---|
| SKU | FDD-VM04 | FDD-VM08 | FDD-VM16 |
| License type | Perpetual virtual machine license; support and optional reputation services ordered separately | ||
| Supported vCPU | Up to 4 | Up to 8 | Up to 16 |
| Inspected throughput | Up to 3 Gbps | Up to 5 Gbps | Up to 10 Gbps |
| Mitigation rate | 3 Gbps / 4 Mpps | 5 Gbps / 6 Mpps | 10 Gbps / 10 Mpps |
| SYN validation | 2.6 Mpps | 5 Mpps | 5 Mpps |
| Service Protection Profiles | 4 | 8 | 16 |
| Protected subnets | Up to 512 per Service Protection Profile | ||
| Network interfaces | Up to 8 data interfaces, arranged as 4 bridged port pairs in promiscuous mode; speed depends on host hardware | ||
| Management interfaces | 2 | ||
| Memory requirement | 16 GB | 16 GB | 32 GB |
| Storage requirement | At least 200 GB | ||
| Hypervisor support | VMware ESX/ESXi 6.x or 7.x with hardware-assisted virtualisation enabled; KVM from libvirt 6.0.0 | ||
| Performance prerequisites | DPDK-capable CPUs, SR-IOV NICs and suitable PCIe x8 bus allocation are required for stated performance | ||
| Traffic bypass | Controlled by underlying NICs; external bypass is required for most production deployments | ||
| Cloud environment note | Not suitable for direct deployment in public cloud service environments such as AWS, Azure or Google Cloud | ||
How to interpret these specifications
Throughput is only one part of sizing. A network carrying many small packets can place more processing pressure on a mitigation platform than a network with the same bandwidth made up of larger packets. Buyers should therefore review both Gbps and Mpps expectations. The number of protection profiles also matters because separate services may require their own learned baseline and policy.
Published performance is based on appropriate hardware and an optimised design. Using ordinary virtual NICs, shared PCIe resources or unsupported host configurations can reduce results substantially. Final architecture should be validated against the current Fortinet documentation and the real server bill of materials before purchase.
Configuration and Buyer Guidance
Selecting the right virtual DDoS license begins with the protected environment, not with the model list. A useful sizing exercise documents the internet circuit capacity, normal traffic, peak traffic, packet rate, protected IP ranges, public services, expected growth and the type of attacks already observed. The team should also identify whether upstream congestion is a concern. An on-premises platform can protect within the available link capacity, but a very large attack that saturates the internet circuit may require coordination with an upstream or cloud scrubbing provider.
What are the normal Gbps, peak Gbps, packets per second and protocol mix?
How many websites, DNS zones, APIs, portals, gateways or other public services need distinct policies?
Does the server provide supported CPUs, memory, storage, SR-IOV NICs and dedicated PCIe resources?
Is high availability required, and how will traffic continue if the host, VM or interface fails?
Who will monitor events, tune baselines, review reports and coordinate incident response?
Which FortiCare term and optional reputation services align with the organisation’s policy?
The hypervisor version must be checked before procurement. The current product data lists VMware ESX or ESXi 6.x and 7.x with hardware-assisted virtualisation enabled, plus KVM from libvirt 6.0.0. Buyers running a different release should confirm compatibility rather than assume that a later or customised environment is automatically supported. The network architecture must also allow the virtual appliance to connect to physical traffic links because the data ports do not operate like ordinary addressed cloud interfaces.
FourTeck can help build a quote checklist covering license tier, support duration, optional services, host details, NIC model, cabling, external bypass, high availability and implementation assistance. This improves cost visibility and makes it easier for technical and procurement teams to compare a virtual deployment with a physical FortiDDoS appliance.
Ideal Business Use Cases
The virtual platform is most useful when dedicated DDoS protection is required and the organisation can provide a properly engineered on-premises host and inline traffic path. The following examples show where the solution may fit, subject to detailed sizing and architecture review.
Customer-Facing Digital Services
Organisations operating portals, mobile back ends, public APIs, online ordering, account services or other customer systems can use dedicated mitigation to reduce the risk that malicious traffic makes those services unavailable.
Authoritative DNS Protection
DNS infrastructure is a common target and can also be abused for reflection. A service-aware protection policy can help defend DNS availability while giving the team visibility into query patterns, anomalies and attack events.
Education and Research Networks
Universities and large learning environments often support public websites, admissions platforms, research systems and remote access. Separate protection profiles can help administrators manage diverse service behaviour.
Government and Public Services
Citizen portals, information services and public applications may require stronger availability controls because disruption affects many users and can create operational pressure during important events.
Financial and Transaction Platforms
Banks, payment operators and financial technology providers may use dedicated mitigation as one layer in a broader resilience architecture for public endpoints, transaction services and customer access systems.
Hosting and Data-Centre Services
Hosting providers and enterprise data centres can protect multiple defined services when the number of profiles, protected subnets and throughput are matched to the customer environment and traffic path.
A virtual license is not automatically the right choice for every site. Businesses without a suitable bare-metal host, dedicated high-performance NICs or a clear bypass design may find a hardware appliance easier to deploy and support. Likewise, organisations facing attacks larger than their upstream links should consider a hybrid model that combines local inspection with upstream scrubbing or provider coordination. FourTeck can help compare these approaches before a final order is placed.
FortiDDoS FDD-VM Adaptive Traffic Baselines
DDoS activity is not always a simple flood from one source. Attackers can change protocols, alternate between high-volume and low-volume methods, or send traffic that appears superficially legitimate. A static rule may be too broad and block genuine users, while a flow-sampling tool may not see enough detail to respond quickly. FortiDDoS addresses this challenge by learning the normal behaviour of protected services and monitoring traffic against that baseline.
For a buyer, the practical benefit is policy relevance. A DNS server, an application portal and a remote access gateway may all have very different patterns. One may receive short bursts of queries, another may maintain long sessions, and another may show strong time-of-day variation. Service Protection Profiles allow the platform to keep these patterns separate rather than treating the whole data centre as one uniform service. The VM04, VM08 and VM16 tiers provide progressively more profiles, so the number of distinct services should be considered during sizing.
Baselining still requires operational discipline. The system should be introduced in an appropriate learning or detection stage, traffic should be observed over a representative period, and the security team should review thresholds before prevention settings are relied on in production. Planned events, seasonal traffic and application changes may alter normal behaviour. A strong implementation therefore combines the platform’s automation with documented change management, event review and periodic tuning.
FortiDDoS FDD-VM Packet Inspection and Mitigation
The product is designed to inspect inbound and outbound packets across a wide range of traffic characteristics. This matters because DDoS events can target network bandwidth, protocol state, server resources or application behaviour. The mitigation platform can evaluate anomalies involving TCP, UDP, ICMP, DNS, NTP and selected application-layer attributes, applying controls that are more specific than a blanket block on an entire protocol.
Small-packet performance deserves special attention. A link may appear to have sufficient bandwidth capacity while the packet rate overwhelms routers, firewalls or security software. Fortinet therefore publishes both Gbps and Mpps figures for the VM models. VM04 is rated at up to 3 Gbps and 4 Mpps mitigation, VM08 at up to 5 Gbps and 6 Mpps, and VM16 at up to 10 Gbps and 10 Mpps under the stated conditions. These figures should be treated as sizing references rather than guaranteed outcomes in every host environment.
The business value is faster, more focused response within the available system and link capacity. Instead of waiting for a person to identify every attack pattern and write a manual rule, the platform can recognise abnormal traffic and enforce protection policies. Security teams still need monitoring and escalation procedures, especially when upstream bandwidth is at risk. Local mitigation is strongest when it is part of a documented availability plan that includes ISP contacts, hybrid scrubbing options, application owners and incident communication.
FortiDDoS FDD-VM Host Performance and Deployment Control
The underlying server is part of the security solution. Stated VM performance depends on DPDK-capable processing, SR-IOV network interfaces and appropriate PCIe x8 resources. If those requirements are not met, performance can fall substantially, and the VM may be limited to Gigabit Ethernet links regardless of the number of licensed vCPUs. Network cards should not share critical PCIe resources with unrelated applications, which is why a bare-metal server is generally recommended.
Traffic bypass also requires planning. Hardware FortiDDoS appliances can include integrated bypass capabilities on selected interfaces, while virtual editions rely on the underlying NIC design and do not control bypass directly. Most production VM deployments therefore need an external bypass solution or another carefully designed continuity method. High availability may also require two appropriately sized hosts, redundant links, compatible switching and a clear failure test procedure.
The data interfaces do not operate as ordinary addressed cloud network adapters. FortiDDoS VMs have no IP addresses on the data ports and must be attached to physical links, so they are not suitable for direct use in public cloud service environments such as AWS, Azure or Google Cloud. This distinction helps buyers avoid purchasing a license for an architecture that cannot route traffic to the mitigation VM. FourTeck can review the proposed topology, hypervisor, NICs, server specification and bypass approach before the commercial quote is finalised.
What Buyers Should Check Before Purchase
A good quotation should show more than the license SKU. It should reflect the required capacity, support term, optional services, host readiness, traffic path and implementation responsibilities. Buyers can use the checklist below to reduce the risk of selecting the wrong VM tier or discovering missing infrastructure after the order.
Configuration Fit
Confirm normal and peak throughput, packet rate, number of protection profiles, protected subnets and expected growth. Choose VM04, VM08 or VM16 from those requirements rather than from vCPU count alone.
Compatibility Check
Verify the hypervisor release, hardware-assisted virtualisation, CPU model, SR-IOV support, NIC driver, PCIe allocation and physical link design. Ask for current compatibility confirmation where the environment differs from published guidance.
Bypass and Resilience
Decide how traffic will continue if the VM, host or NIC fails. Include external bypass, redundant switching, high availability, power protection and failure testing in the project scope where service uptime is critical.
License and Renewal Scope
The base VM license is perpetual, but FortiCare support and optional IP or domain reputation services have separate terms. Compare one-, three- and five-year support choices and document future renewal ownership.
Upstream Attack Planning
Estimate the largest likely attack and compare it with the incoming circuit. If an attack can saturate the upstream link, ask the ISP or a scrubbing provider about diversion and hybrid mitigation options.
Implementation Needs
Clarify who will deploy the image, create interfaces, place the system inline, define protection profiles, train baselines, test prevention, document operations and hand over monitoring responsibilities.
Quote Preparation
Share the proposed model, traffic diagrams, circuit speeds, packet-rate estimates, protected services, server specification, preferred support term, delivery location and required implementation timeline with FourTeck.
Alternative Model Review
Ask whether a physical FortiDDoS appliance would provide simpler bypass, higher capacity or easier support. A virtual edition is valuable when the host and network design genuinely support it.
Long-term cost should include more than the perpetual license. Budget for server hardware, NICs, external bypass, redundancy, implementation, support renewal, optional reputation services, monitoring time and future capacity expansion. A lower initial license tier may become expensive if it must be replaced soon, while an oversized design may consume budget without improving risk control. FourTeck can help buyers compare the commercial and technical consequences of each option before a formal purchase request is approved.
Africa Availability and Service Support
FourTeck supports product inquiries across Africa with assistance for model selection, license review, configuration planning, quote preparation and delivery coordination. Availability can vary according to the selected VM tier, support duration, optional reputation services, supplier status and project quantity. For that reason, the page does not present an unverified stock claim or a fixed selling price.
A useful inquiry should include the current and expected internet capacity, packet rate estimates, number of protected services, server platform, preferred hypervisor, NIC details, high-availability requirement and support term. FourTeck can use this information to help identify whether VM04, VM08 or VM16 is the more suitable starting point and whether a physical appliance or hybrid mitigation design should also be considered.
Support guidance can include the difference between the perpetual software license and the separately ordered FortiCare or reputation service terms. Delivery coordination for a software product may involve license fulfilment, documentation and project scheduling rather than shipment of a physical chassis. Warranty and support handling depend on the final commercial package and vendor terms stated in the approved quote.
Africa Country and Regional Coverage
Businesses across Africa, including Kenya, Uganda, Nigeria, Ghana, Tanzania, Rwanda, Ethiopia, South Africa, Zambia, Botswana, Senegal and nearby regional markets, can contact FourTeck for product availability, configuration guidance and quotation assistance. The team can help buyers review license tiers, related hardware requirements, support options and project supply needs based on the business environment.
Regional fulfilment and support arrangements depend on the destination, order value, selected license, service term and vendor process. Buyers should provide the legal organisation name, billing location, deployment site, preferred currency and required timeline so the commercial team can prepare a more complete response. FourTeck also supports multi-site and project inquiries where consistent licensing and documentation are needed across several business locations.
GCC, Middle East and Africa Availability
FourTeck Africa can support product inquiries for businesses across Africa while also guiding regional technology requirements through selected FourTeck platforms for GCC and Middle East markets. Organisations with branches or project sites in the UAE, Saudi Arabia, Qatar, Oman and Bahrain can request coordinated assistance for licensing, deployment planning and commercial documentation.
Availability, delivery method, tax treatment, support handling and configuration assistance may vary by country and purchasing entity. A regional group should identify which office will hold the license, where the virtual appliance will be deployed, which support team will administer it and whether the same architecture will be used at every site. This prevents a quotation from being based on location alone while overlooking different circuit capacities or infrastructure designs.
For wider regional requirements, buyers may review FourTeck Africa, FourTeck Kenya, FourTeck Uganda and FourTeck UAE. Each inquiry should be confirmed through the relevant sales team because commercial terms and service coverage are configuration and location dependent.
Other Options Buyers May Consider
The correct alternative depends on traffic scale, physical deployment preferences, bypass requirements and the wider security architecture. These related Fortinet solutions may be discussed during sizing rather than treated as direct replacements in every case.
FortiDDoS 200F
A physical appliance option for organisations that prefer dedicated hardware, integrated appliance operations and defined interface choices.
FortiDDoS 1500F
Suitable for higher-capacity data-centre requirements where 10 Gigabit connectivity and stronger packet inspection performance are needed.
FortiGate Security
A next-generation firewall platform for access control, segmentation, VPN and broader network threat protection alongside dedicated DDoS controls.
FortiAnalyzer
A central analytics and reporting platform that may support wider Fortinet security operations, event review and compliance reporting requirements.
FortiManager
A management platform for organisations operating a larger Fortinet estate and seeking more structured policy and device administration.
FourTeck Security Services
Planning support for firewalls, secure access, infrastructure protection, implementation and business security requirements.
A related product should be evaluated against the same traffic, resilience and support criteria. A firewall is not automatically a substitute for dedicated DDoS mitigation, and a physical appliance is not automatically preferable to a VM. FourTeck can help compare the architecture and commercial scope so that each component has a clear role.
Why Buyers Choose FourTeck
Enterprise cybersecurity purchases involve technology, licensing, infrastructure and commercial coordination. FourTeck helps buyers bring these areas together so that a quote is based on the actual deployment requirement rather than only a model code.
Assistance with current license options, support terms and related components.
Review of throughput, packet rate, profile count, host requirements and resilience needs.
A structured response for procurement teams, projects, replacements and multi-site requirements.
Attention to hypervisor support, SR-IOV, PCIe design, external bypass and physical traffic links.
Support for destination, billing, delivery and project documentation across supported markets.
Comparison with physical FortiDDoS appliances, firewalls, analytics and management platforms.
FourTeck works with small and mid-sized organisations, enterprise buyers, public institutions, resellers and project teams that need practical product guidance. The objective is to reduce preventable selection mistakes, clarify the support and license scope, and help the customer prepare the information required for a useful quotation. Final product terms, availability and warranty handling remain subject to the approved supplier quote and applicable vendor conditions.
Frequently Asked Questions
What is FortiDDoS FDD-VM used for?
It is a virtual inline DDoS protection system used to detect and mitigate abnormal traffic targeting networks, applications and public services. It can protect defined subnets and services against volumetric, protocol and selected application-layer attacks within the capacity of the chosen VM model and the available internet link.
Which FDD-VM license should a business choose?
The choice between VM04, VM08 and VM16 should be based on inspected throughput, packet rate, number of Service Protection Profiles, protected subnets and future growth. The host platform must also support the required vCPU, memory, storage and network performance. FourTeck can help organise these details before quotation.
Can the VM be deployed directly in a public cloud?
No. The current product documentation states that FortiDDoS VMs are not suitable for direct deployment in public cloud service environments such as AWS, Azure or Google Cloud. The data ports do not have IP addresses and must be attached to physical links, which requires an on-premises architecture.
Does the software need special server hardware?
Yes. Published performance depends on DPDK-capable CPUs, SR-IOV network interfaces and suitable PCIe x8 bus allocation. Shared or ordinary virtual networking can reduce throughput significantly. A bare-metal host is recommended, and the NIC, driver, processor, memory and hypervisor should be checked before purchase.
Is an external bypass device required?
Virtual editions do not control traffic bypass directly. The capability depends on the underlying NICs, and Fortinet notes that external bypass is required for most deployments. Buyers should include bypass and high-availability planning in the design so that a host or VM failure does not create unnecessary service interruption.
Are support and reputation services included?
The FDD-VM base product is offered as a perpetual VM license. FortiCare support and optional IP or domain reputation services are ordered separately with their own terms. The required one-, three- or five-year package should be stated in the quotation so future renewal responsibilities are clear.
Can local DDoS protection stop every large attack?
Local mitigation protects within the capacity of the platform and the incoming network links. If an attack saturates the upstream internet circuit, legitimate traffic may be dropped before it reaches the on-premises system. Organisations with this risk should discuss ISP coordination, traffic diversion or hybrid cloud scrubbing.
Can FourTeck help with deployment planning?
FourTeck can assist with pre-sales sizing, license selection, host and NIC review, bypass requirements, support options, commercial quotation and delivery coordination. The final deployment scope can also identify who will configure interfaces, create protection profiles, train baselines, test mitigation and document the operational handover.
How do I request an accurate quote?
Provide the deployment country, expected traffic in Gbps and Mpps, number of protected services, current network diagram, host specification, NIC model, hypervisor version, high-availability requirement, preferred support term and required timeline. This information helps FourTeck prepare a more relevant model and commercial recommendation.
Need Help Choosing the Right DDoS Protection Option?
Share your traffic capacity, packet-rate expectations, protected services, server platform, preferred support term and project location. FourTeck can help review the suitable FDD-VM tier, related infrastructure, alternative physical appliances and current commercial availability.




Reviews
There are no reviews yet.