FortiSandbox Advanced Malware Protection in Dubai, UAE
FortiSandbox Advanced Malware Protection, commonly shortened to AMP, is a FortiGuard subscription option that brings cloud-based sandbox analysis into compatible FortiGate deployments. It is aimed at buyers who want stronger malware detection, threat visibility and enriched security logs without running a dedicated FortiSandbox appliance. The important buying decision is not simply whether sandboxing is required, but which FortiGate model is being licensed, how long the subscription should run, what security services are already present, and whether the organisation needs detection-led analysis or a separate inline prevention service.

Before you request a quote
Share the exact FortiGate model, serial or renewal context where appropriate, required term, quantity and current security bundle. Those details help determine the correct AMP service SKU and avoid quoting a license intended for another appliance model.
FortiGuard SaaS subscription
Sandbox detection and visibility
Compatible FortiGate deployments
Model and subscription term
AMP is not the inline-blocking tier
A direct answer for buyers
FortiSandbox Advanced Malware Protection is a FortiGate-oriented FortiGuard subscription that combines cloud sandbox analysis with a broader malware-protection service set. It is mainly used to improve detection of suspicious and unknown files, add threat visibility and enrich logs without requiring a customer-operated sandbox appliance. Organisations already standardising on FortiGate should consider it when they want a straightforward SaaS route to sandboxing. Before proceeding, confirm the exact FortiGate model, term, current bundle or standalone services, whether this is a new purchase or renewal, and whether the requirement is visibility-led detection or true inline blocking. Those factors directly affect the correct SKU and whether AMP is the right tier.
What this subscription does
Fortinet currently presents Advanced Malware Protection as a FortiGuard security subscription that combines Antivirus with FortiSandbox Cloud and other malware-focused services. Within the current FortiSandbox SaaS ordering framework, AMP is positioned as the detection tier: suspicious content can be submitted for sandbox analysis, the security team receives additional visibility, and related events can contribute richer context to logs and investigations. The aim is to give a FortiGate environment an additional layer for content that may not be resolved by conventional known-threat detection alone.
The cloud delivery model matters. A business can add sandbox analysis without buying and operating a dedicated FortiSandbox hardware appliance. That can simplify procurement and infrastructure overhead for organisations that prefer a service subscription, but it does not remove the need to plan licensing correctly. The AMP SKU is tied to the FortiGate platform being covered and is normally selected for a defined subscription period.
Who should consider it
AMP can suit businesses that already operate FortiGate and want cloud-hosted malware analysis added to the security stack without maintaining sandbox infrastructure. It may be relevant to branch networks, headquarters, distributed enterprises and security teams that need better insight into suspicious files moving through inspected traffic. It can also make sense when procurement wants a subscription service aligned with an existing firewall lifecycle rather than a separate appliance project.
It is less suitable when the requirement is specifically for dedicated on-premises sandbox control, private infrastructure deployment, very high-volume SOC analysis or a policy that demands customer-controlled sandbox resources. Fortinet offers other FortiSandbox deployment forms for those cases, including dedicated hosted, virtual and hardware options. It is also important not to select AMP when the stated business need is active inline malware blocking as the primary outcome; Fortinet’s current ordering guide separates that requirement into the Inline Malware Prevention Service tier.
Business problems AMP can help address
Unknown-file uncertainty
A file can look unfamiliar even when conventional controls do not immediately classify it as malicious. Cloud sandbox analysis gives the security workflow another way to examine suspicious content and return a verdict with more context. Buyers should still define which traffic and file types are in scope and confirm the FortiGate policies that will submit content for sandbox analysis.
Limited investigation context
A basic security event may tell an administrator that a file was suspicious without giving enough information for fast follow-up. AMP’s sandbox detection and log enrichment can add useful evidence for triage. The operational value depends on how logs are reviewed, retained and correlated with the rest of the organisation’s monitoring stack.
Avoiding new sandbox hardware
Some organisations want advanced file analysis but do not want another appliance to size, rack, patch and maintain. The SaaS model avoids dedicated sandbox hardware on the customer side. That convenience should be balanced against data-handling, region and governance requirements that may favour other FortiSandbox deployment options.
Subscription alignment
Security services are easier to manage when procurement understands which firewall is covered, when the entitlement begins and ends, and whether the same capability already exists inside a bundle. Reviewing the current FortiGate services before purchase helps prevent duplicated subscriptions or a renewal being ordered against the wrong platform.
Core capabilities in the AMP buying context
FortiSandbox Cloud analysis
The subscription includes FortiSandbox Cloud as part of the malware-protection service set. Suspicious content can be analysed in the cloud instead of requiring a dedicated customer-operated sandbox appliance. The exact behaviour depends on FortiGate configuration and applicable entitlement.
Antivirus service
Antivirus is part of the AMP package, providing known-threat detection alongside the sandbox component. The combination is important because sandboxing is an additional analysis layer rather than a replacement for all established malware controls.
Virus outbreak protection
The Fortinet service description includes Virus Outbreak Protection, intended to help cover emerging threats during the period when conventional signatures may still be catching up. Buyers should confirm current service naming and bundle content for the quoted FortiGate and subscription term.
Content disarm and reconstruction
Content Disarm and Reconstruction is also listed in the AMP service set. Its role is different from sandbox detonation: rather than waiting for behavioural analysis, it removes active content from supported documents to create a safer reconstructed file. Feature behaviour and supported content should be checked against the current FortiOS release.
Botnet IP and domain security
Botnet-related IP and domain protection is included in Fortinet’s current AMP service description. This complements file-focused controls by helping identify communications associated with known malicious infrastructure, subject to policy and service configuration.
Mobile malware coverage
Mobile Security is part of the AMP package description. Buyers should treat this as a security-service component within the FortiGate subscription rather than assuming it replaces endpoint management or mobile-device management requirements.
Is AMP the right fit?
| Requirement | Suitable when | Confirm before ordering |
|---|---|---|
| Cloud sandbox detection | You want suspicious-file analysis without a dedicated sandbox appliance. | FortiGate model, supported FortiOS configuration and entitlement. |
| Threat visibility and log enrichment | Operations teams need more context around suspicious content. | Logging destination, retention and analyst workflow. |
| No new sandbox hardware | A service-based model is preferred for operational simplicity. | Data handling, region, governance and internet connectivity requirements. |
| Inline blocking as the main goal | AMP alone should not be assumed to meet this requirement. | Evaluate FortiGuard Inline Malware Prevention Service and current bundle options. |
| Dedicated on-prem sandbox | Choose a different FortiSandbox deployment model if local control is required. | Appliance sizing, VM capacity, licensing, data residency and integration scope. |
Buyer information table
| Brand | Fortinet |
|---|---|
| Product / Service | FortiGuard Advanced Malware Protection with FortiSandbox Cloud |
| Product type | Security subscription / SaaS malware protection |
| Main purpose | Sandbox detection, threat visibility, log enrichment and complementary malware-protection services. |
| Primary deployment context | FortiGate-based SaaS deployment. |
| Dedicated hardware required | No dedicated FortiSandbox hardware is required for the SaaS AMP route. |
| Subscription dependency | Exact FortiGate model and term must be confirmed. |
| Inline malware blocking | Not the defining AMP tier capability in Fortinet’s current ordering model; evaluate IL MPS when active inline blocking is required. |
| Included service set | Fortinet currently lists Antivirus, Botnet IP/Domain Security, Mobile Security, FortiSandbox Cloud, Virus Outbreak Protection and Content Disarm & Reconstruction. |
| Ordering format | Available as a FortiGate a-la-carte subscription and within applicable FortiGate bundles; exact SKU is model dependent. |
| UAE availability | Contact FourTeck for current model, term, quotation and availability guidance. |
Licensing and compatibility notice
AMP should be ordered against the exact FortiGate platform that will consume the service. Fortinet uses model-specific service SKUs, and subscription duration is another part of the ordering decision. A part number that is correct for one FortiGate model should not be assumed to work for another. Before requesting a quotation, identify the firewall model, whether the request is for an initial subscription or renewal, the required term, and whether another bundle already contains overlapping services.
Configuration also affects how much value the organisation receives from the subscription. Sandbox inspection, antivirus profiles, logging and any related Security Fabric workflows should be reviewed in the context of the deployed FortiOS version. Cloud-service region, internet access, data handling and internal governance may also matter. When the business needs dedicated sandbox capacity, private cloud placement or on-premises control, the broader FortiSandbox portfolio should be evaluated rather than forcing a SaaS AMP subscription into a deployment model it was not intended to replace.
A practical purchase and deployment journey
Identify the protected FortiGate
Record the exact appliance or virtual FortiGate model and current FortiOS release. If this is a renewal, include the existing entitlement context and expiry date where available. This is the foundation for selecting the correct service SKU.
Define the security outcome
Decide whether the requirement is stronger malware detection and visibility, active inline blocking, or a dedicated sandbox platform. AMP is most directly aligned with the first outcome. The distinction prevents a purchase that does not match the operational goal.
Review existing subscriptions
Check current FortiGuard bundles and standalone services. If similar capabilities are already active, procurement may need a renewal or bundle change rather than an additional overlapping subscription.
Select the term and quantity
Confirm how many FortiGate units require coverage and the requested subscription period. Multi-site estates should be mapped carefully so that each licensed device is matched to the appropriate service item.
Prepare the quotation
Include product licensing, renewal information and any requested configuration assistance in the quote scope. Pricing can vary by FortiGate model, term, quantity and current vendor policy, so generic online prices should not be treated as a final UAE selling price.
Activate and validate
After entitlement activation, review FortiGate configuration, sandbox submission behaviour and logging. Validate that the service is functioning as intended and that security operations staff know where to review relevant events.
Cloud sandbox analysis without a dedicated appliance
The most practical reason many FortiGate customers consider AMP is the service model. Traditional sandbox deployments can involve hardware or virtual infrastructure, capacity planning, operating-system images for dynamic analysis, lifecycle management and integration work. The SaaS option removes the need for the customer to operate a dedicated FortiSandbox platform simply to obtain cloud sandbox analysis.
That does not mean the solution is infrastructure independent. The FortiGate still has to be licensed correctly and configured to use the relevant security service. Internet connectivity and service reachability matter, and organisations with strict data-residency rules should confirm whether the cloud model aligns with their policy before purchase. The 2026 FortiSandbox ordering guidance explicitly separates SaaS, hosted dedicated, virtual and hardware approaches because operational control and deployment requirements differ.
For an SMB or mid-market buyer, the SaaS model can reduce project complexity because the security function is acquired as a subscription linked to the firewall. For larger organisations, it can also be useful for distributed FortiGate estates where a service-based approach is preferable to installing local sandbox infrastructure at every location. A security architect should still assess traffic patterns, the purpose of sandbox inspection and whether central SOC workflows require a more dedicated FortiSandbox architecture.
Layered malware protection rather than a single detector
AMP is useful to understand as a service set, not simply as a cloud sandbox button. Fortinet’s current service description combines Antivirus, Botnet IP/Domain Security, Mobile Security, FortiSandbox Cloud, Virus Outbreak Protection and Content Disarm & Reconstruction. These controls address different parts of the malware problem. Antivirus is designed for recognised malicious content; sandboxing adds analysis for suspicious or unknown files; outbreak protection addresses emerging threat windows; CDR takes a sanitisation approach to supported documents; and botnet intelligence can help identify known malicious communication infrastructure.
For buyers, this means the value is broader than one detection method, but it also means existing subscriptions should be audited before purchase. A FortiGate bundle may already include some or all relevant capabilities. Buying a separate service without checking the current entitlement can create unnecessary overlap. Conversely, assuming that a general FortiGate support contract automatically includes AMP can leave a gap between expectation and actual licensed capability.
FourTeck can help map the current security-service position against the target outcome. The useful procurement question is not “Do we have FortiGuard?” but “Which FortiGuard services are active on this exact FortiGate, when do they expire, and which additional capability are we trying to add?” That produces a cleaner bill of materials and a clearer renewal plan.
Security operations value comes from visibility and workflow
A sandbox verdict is most useful when somebody can act on it. Fortinet’s current positioning for the AMP SaaS tier emphasises sandbox detection, visibility and log enrichment. In practical terms, that means the organisation should decide who reviews suspicious-file events, where those logs are retained, and how the team escalates a detection. A small IT team may review events directly in FortiGate interfaces, while a larger SOC may correlate activity through broader logging, analytics or Security Fabric tools.
This operational question affects the buying decision because better detection alone does not automatically create a mature response process. Teams should document notification paths, investigation ownership, false-positive review and any containment actions that follow a malicious verdict. If the organisation expects automatic blocking before execution as the primary control, it should validate whether the FortiGuard Inline Malware Prevention Service or another architecture better matches that policy requirement.
FortiSandbox technology can integrate across the wider Fortinet ecosystem, but a specific AMP deployment should only be designed around the products actually present. Do not assume FortiMail, FortiClient, FortiSIEM, FortiSOAR or FortiWeb integration just because those products are part of the broader Fortinet platform. The project should list the existing systems, desired workflow and supported integration points before configuration work begins. This makes implementation more predictable and helps procurement distinguish a software entitlement from optional professional services.
Where the service may fit in real environments
Branch and headquarters firewalls
Organisations that already secure internet traffic through FortiGate may use AMP to add cloud sandbox analysis to the firewall security stack. The relevant question is whether the traffic profiles and policies are configured to submit suspicious content and whether the business is comfortable with the cloud service model.
SMB security consolidation
Smaller teams often prefer subscription services that avoid another specialised appliance. AMP can be attractive when the business wants malware-protection services aligned with an existing FortiGate. The correct device model and subscription term remain essential for accurate ordering.
Distributed enterprises
A multi-site business can use a consistent licensing approach across compatible FortiGate deployments, but procurement must still map the correct service SKU to each model. Estates containing several FortiGate families should not be quoted as if one service part number covers all devices.
Security teams improving suspicious-file triage
Where administrators need more context around files that evade simple known-threat classification, sandbox analysis can help. The operational benefit is greatest when logging, investigation ownership and escalation processes are already defined.
Cloud-first infrastructure policy
Businesses reducing specialised on-premises security appliances may prefer the SaaS route. However, cloud-first does not automatically mean cloud-appropriate for every workload. Data residency, regulated content and internal risk policy should still be reviewed.
Renewal and lifecycle planning
AMP can appear in renewal discussions when a customer wants to continue or adjust existing FortiGuard services. The renewal request should identify current expiry, existing bundle and any planned firewall replacement so the organisation does not renew a service for hardware that is about to be changed.
Integration and operational considerations
Start with the FortiGate configuration rather than the subscription name. Antivirus profiles, sandbox inspection settings, web filtering interactions where relevant, logging and Security Fabric connections can influence how suspicious content is submitted and how verdicts are consumed. The exact settings available depend on the deployed FortiOS version and should be checked against current documentation before a production change.
Security teams should also consider what happens when the cloud service cannot be reached and how policy should behave during an outage or connectivity issue. This is an operational design choice, not merely a licensing question. Change windows, rollback planning and monitoring should be included if AMP is being introduced into a business-critical FortiGate.
For organisations with multiple firewalls, standardise policy where practical but keep device-specific exceptions documented. A central operating model is useful, yet branch connectivity, bandwidth, local applications and regulatory requirements may create justified differences.
Questions to resolve before ordering
An accurate quote depends on a small set of precise facts. Which FortiGate model requires coverage? Is this a new subscription, co-term request or renewal? Which services are already included in the current bundle? What term is required? How many firewalls need licensing? Is the primary outcome sandbox detection and visibility, or must malicious content be blocked inline before execution?
The buyer should also identify any cloud-use restrictions, data-residency concerns and the desired logging workflow. If the organisation uses other Fortinet products, list them so integration can be evaluated rather than assumed. If configuration help is required, include that scope separately from the license so the quotation clearly distinguishes subscription entitlement from engineering work.
Finally, note any upcoming hardware refresh. Buying a long subscription term for a device that will soon be replaced can complicate lifecycle planning. FourTeck can review the intended term against the firewall estate and help prepare a cleaner requirement for quotation.
Procurement checklist
How FourTeck can assist
FourTeck can help convert a general request for “FortiSandbox protection” into a specific bill of materials. That may include confirming whether AMP is the intended service tier, matching the license to the FortiGate model, checking the requested subscription period, identifying potential overlap with an existing FortiGuard bundle and clarifying whether configuration support should be included.
For buyers comparing options, FourTeck can also explain when it is worth evaluating the broader FortiSandbox portfolio instead of the FortiGate SaaS route. If the organisation needs dedicated hosted capacity, customer-controlled virtual deployment, on-premises hardware or a different prevention outcome, the recommendation should reflect that requirement rather than forcing every malware-analysis project into the same subscription.
You can review more technology options on the FourTeck product catalogue or discuss engineering scope through FourTeck technology services.
UAE availability and support guidance
Contact FourTeck to confirm current UAE availability, the correct FortiGuard service SKU and the quotation term for your FortiGate model. Subscription pricing can differ by firewall platform and contract length, and vendor policy may change over time. For that reason, a web price for one model should not be treated as the selling price for another model.
Delivery coordination for subscription entitlements is different from shipping a hardware appliance, but procurement still needs accurate customer, product and renewal details. If configuration assistance is required, include it in the quotation request so engineering scope can be discussed separately from the license itself. Current availability, entitlement start date and support arrangements should be confirmed before purchase.
For a current UAE quotation, use the FourTeck contact page.
Dubai, Abu Dhabi, Sharjah and Ajman coverage
FourTeck can coordinate FortiSandbox Advanced Malware Protection requirements for businesses in Dubai, Abu Dhabi, Sharjah and Ajman through one combined requirement-review process. For a subscription project, the most useful information is the FortiGate model, the number of devices, current service status, required term and whether the customer needs only licensing or also configuration assistance. Multi-site organisations should provide a simple device list so that different FortiGate models are not accidentally grouped under one service SKU. Delivery or activation timing, vendor lead time where applicable, and implementation scope should be confirmed after the exact requirement is understood. Businesses planning a wider Fortinet refresh can also review Fortinet firewall options through FourTeck as part of lifecycle planning.
GCC Availability
For GCC organisations, FourTeck can assist with requirement review, FortiGate model confirmation, AMP subscription selection, quotation coordination and planning for associated configuration work. A regional request should identify the destination country, licensed firewall model, quantity, subscription term and expected activation or renewal timeline. Businesses operating across the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman may have different procurement processes, service-region considerations and project schedules, so one country’s quote should not automatically be reused for another. Product availability, licensing structure, delivery schedules, service visits, project scope and vendor lead times can vary by country, model, quantity and requirement. Buyers should also identify whether the project includes a new FortiGate deployment, an existing-device renewal or a broader security-service change. FourTeck can then help prepare a clearer bill of materials and discuss regional coordination without assuming local stock, fixed activation timing or country-specific certification.
Africa Availability
Organisations planning Fortinet security subscriptions for African operations can use FourTeck to review the exact FortiGate platform, required AMP term, current entitlement position, configuration needs and renewal timing before a quotation is prepared. This is particularly useful for groups managing sites across more than one market, because license requirements and project logistics should be mapped to the actual device estate rather than estimated from a generic product description. Availability and fulfilment may depend on the destination country, FortiGate model, quantity, subscription region, vendor lead time and local project conditions. Buyers in East Africa or other African regions should share the destination country, model list, required term, preferred schedule and any implementation or support expectations. FourTeck can assist with procurement planning and suitable guidance through its regional technology presence, including FourTeck Africa and FourTeck Kenya, while final availability and service scope remain subject to confirmation.
Related options to discuss with FourTeck
FortiGuard Inline Malware Prevention
Consider this when the stated requirement is active inline malware blocking rather than AMP’s detection-led SaaS tier. Confirm current FortiGate compatibility and bundle availability before selection.
FortiSandbox PaaS
A dedicated Fortinet-hosted sandbox option may suit organisations that want more control and dedicated resources than a shared SaaS approach without operating hardware themselves.
FortiSandbox Virtual Appliance
A virtual deployment can be evaluated where the organisation wants to place sandbox resources in supported public or private infrastructure and manage the environment more directly.
FortiSandbox Hardware
Dedicated appliances are relevant when compliance, data residency, performance predictability or high-volume SOC requirements make on-premises control important.
FortiGate security bundles
Before buying AMP a la carte, compare current bundle entitlements. A broader FortiGate service bundle may already include overlapping functionality or better match the organisation’s complete security requirement.
Configuration support
Licensing does not automatically include design or change work. If sandbox inspection, policy updates, logging integration or operational validation are required, request those activities as a separate professional-services scope.
Why businesses contact FourTeck for this requirement
FortiGuard subscriptions can look simple until the buyer reaches the part-number stage. The service name may be familiar, but the correct SKU still depends on the FortiGate platform and contract term. FourTeck can help reduce that ambiguity by reviewing the exact device model, current entitlement, renewal status and target security outcome before a quote is prepared.
This is also useful when the initial request mixes several Fortinet concepts, such as FortiSandbox, cloud sandboxing, Advanced Malware Protection and inline malware prevention. Those terms are related but not interchangeable. A requirement review can separate detection, prevention, deployment model and operational scope so the organisation buys the service that actually matches its policy objective.
For larger estates, FourTeck can assist with bill-of-material organisation, model-by-model license mapping, renewal planning and coordination of optional configuration work. If the project extends beyond malware protection, buyers can learn more about FourTeck and discuss the wider infrastructure context rather than treating the subscription as an isolated line item.
What buyers are trying to understand before choosing AMP
People researching Advanced Malware Protection often begin with a simple question such as “Does FortiSandbox come with FortiGate?” The more accurate answer is that FortiSandbox exists as a broader product portfolio with SaaS, hosted, virtual and hardware deployment options, while the Advanced Malware Protection subscription is a FortiGate-oriented service offering that includes FortiSandbox Cloud together with other malware-protection services. That distinction matters because a customer asking for “FortiSandbox” may actually need a dedicated sandbox platform, whereas a customer asking for “FortiGate malware protection” may be looking for AMP or another FortiGuard service tier.
Search results frequently surface part numbers for popular FortiGate models such as the 60F. Those listings are examples, not a universal AMP license. Fortinet’s own ordering material notes that comparable service SKUs are available across FortiGate models. The correct license therefore starts with the exact firewall model, not with copying a part number from an online listing.
Current Fortinet ordering guidance separates AMP, which is positioned around sandbox detection, visibility and log enrichment, from the Inline Malware Prevention Service, which is positioned for active blocking. Buyers should describe the desired outcome in operational terms so the license choice follows the requirement rather than the other way around.
Another common research pattern is pricing. Online stores may show one-year AMP prices for a specific FortiGate model, sometimes in different currencies and sometimes from older price lists. These references can help a buyer understand that AMP is typically licensed as a recurring service, but they are not reliable substitutes for a current UAE quote. The price depends on the FortiGate model, subscription duration, quantity, bundle structure and current vendor policy. A 60F license price cannot be extrapolated directly to larger appliances, and a marketplace price may exclude tax, support conditions or regional commercial terms.
Renewal questions are equally important. Buyers often ask whether they can simply renew the same part number. That is only safe when the firewall model, subscription structure and desired term remain unchanged and the current vendor ordering catalogue still uses the same service mapping. If the organisation has upgraded the firewall, moved from an a-la-carte subscription to a bundle, changed contract dates or consolidated sites, renewal planning should be reviewed before a purchase order is raised. A clean renewal request includes the FortiGate model, existing entitlement, expiry date and preferred renewal term.
Compatibility research should go beyond the appliance name. The FortiGate software version influences the configuration interface and available feature behaviour, so administrators should verify current FortiOS guidance before applying sandbox settings. Organisations should also decide how events will be monitored. Sandbox detection is more valuable when suspicious files, verdicts and related logs feed a defined review process. For a small IT team, that could mean routine review in FortiGate monitoring. For a mature SOC, it could mean correlation with broader security operations tools already deployed in the environment.
Cloud governance is another recurring concern. SaaS avoids a dedicated sandbox appliance, but it also means suspicious content is analysed through a cloud service. Businesses with regulated data, strict residency policy or sensitive file-handling requirements should assess whether that operating model is acceptable. Fortinet offers dedicated and on-premises FortiSandbox options precisely because not every organisation has the same control requirement. The right selection therefore depends on both security capability and governance constraints.
Buyers also ask what information a supplier needs to quote correctly. For AMP, the useful set is compact: exact FortiGate model, quantity, country of use, requested subscription term, current bundle or standalone services, renewal status and whether configuration assistance is needed. If the requirement mentions inline blocking, dedicated sandbox capacity, FortiMail integration, endpoint workflows or a central SOC, include that context too. It may indicate that the broader FortiSandbox portfolio or an alternative FortiGuard tier should be evaluated instead of treating AMP as the automatic answer.
The best purchasing approach is therefore to translate search terms into a deployment statement. Instead of asking only for “FortiSandbox AMP price,” state, for example, that a compatible FortiGate needs a one-year cloud sandbox detection subscription, that the organisation wants visibility rather than inline blocking, and that the current service bundle must be checked for overlap. That level of detail gives procurement, engineering and the supplier a common basis for an accurate quotation.
Questions worth answering before the purchase order
Do we need AMP or a dedicated FortiSandbox deployment?
Choose the direction based on operating model. AMP is the FortiGate SaaS route for cloud sandbox detection and related malware services. A dedicated FortiSandbox PaaS, VM or hardware deployment is more relevant when the organisation needs dedicated resources, customer-controlled placement, on-premises data handling or larger SOC-scale architecture. The decision should be made before discussing appliance sizing or subscriptions.
Is AMP enough when policy says unknown files must be blocked inline?
Do not assume so. Fortinet’s current ordering model distinguishes AMP’s detection tier from Inline Malware Prevention Service. If the security policy specifically requires active inline blocking, that requirement should be quoted and validated against the relevant FortiGuard tier and FortiGate model. This is one of the most important distinctions to resolve before purchasing.
Can one AMP SKU cover different FortiGate models?
Service SKUs are model dependent. A part number shown for a FortiGate 60F, for example, should not be copied into a quote for another model. Multi-site organisations should provide a model inventory so each device can be matched to the correct license and term. This reduces ordering errors and makes later renewals easier to manage.
What should we check before renewing?
Confirm the firewall is still in service, verify the existing entitlement and expiry date, identify any bundle changes, and check whether a hardware refresh is planned. If the firewall will soon be replaced, renewal term selection should be coordinated with that lifecycle plan. A renewal should not be treated as a purely administrative repeat order when the infrastructure has changed.
Does buying the subscription include configuration work?
A license entitlement and professional configuration are separate commercial items unless the quotation explicitly combines them. If you need sandbox inspection enabled, policies reviewed, logs validated or change support scheduled, ask for that engineering scope when requesting the quote. This keeps responsibilities, timing and acceptance criteria clear.
How should we prepare for a multi-site quotation?
Create a simple spreadsheet or device list containing site name, FortiGate model, quantity, current service status, expiry date and desired term. Flag any site requiring special cloud, data-residency or change-window treatment. FourTeck can use that information to organise the bill of materials and separate licensing from optional configuration or migration support.
Frequently asked questions
What is FortiSandbox Advanced Malware Protection?
It is a FortiGuard Advanced Malware Protection subscription for FortiGate that includes FortiSandbox Cloud together with other malware-focused services. In Fortinet’s current FortiSandbox SaaS ordering framework, AMP is positioned for sandbox detection, threat visibility and log enrichment.
Does AMP require a FortiSandbox hardware appliance?
No dedicated FortiSandbox hardware appliance is required for the SaaS AMP route. Customers that need dedicated hosted resources, virtual deployment or on-premises control should evaluate other FortiSandbox deployment models.
What services are included in Advanced Malware Protection?
Fortinet currently lists Antivirus, Botnet IP/Domain Security, Mobile Security, FortiSandbox Cloud, Virus Outbreak Protection and Content Disarm & Reconstruction as part of the AMP service offering. Bundle contents should still be confirmed for the quoted FortiGate and term.
Is inline malware blocking included with AMP?
Fortinet’s current ordering guide distinguishes AMP as a detection-focused tier and positions Inline Malware Prevention Service for active inline blocking. If blocking before execution is a requirement, ask FourTeck to review the appropriate FortiGuard option.
How do I know which AMP SKU to order?
The service SKU depends on the exact FortiGate model and subscription term. Provide the appliance model, whether the request is new or renewal, required duration and current FortiGuard bundle so the correct item can be identified.
Can AMP be purchased as a standalone subscription?
Fortinet states that Advanced Malware Protection is available as a FortiGate a-la-carte subscription and in applicable FortiGate bundles. Buyers should compare both routes so they do not duplicate services already included elsewhere.
What should be checked before an AMP renewal?
Confirm the FortiGate is still active, review the existing entitlement and expiry date, identify any bundle changes and consider upcoming hardware replacement. The renewal term should align with the firewall lifecycle.
Can FourTeck help with configuration as well as licensing?
Yes, configuration requirements can be discussed as part of the quotation. Licensing and engineering scope should be listed separately so the buyer can see what entitlement is being purchased and what change or validation work is requested.
How do I request a UAE quote for AMP?
Send FourTeck the exact FortiGate model, quantity, required subscription term, current service status and whether the requirement is new, renewal or part of a wider Fortinet project. Current pricing and availability can then be confirmed for the UAE requirement.
Turn the product name into the correct license request
Send FourTeck the FortiGate model, requested term, number of devices, existing FortiGuard service position and the operational outcome you want. We can help distinguish AMP cloud sandbox detection from inline malware prevention or dedicated FortiSandbox deployment, then prepare the requirement for a current Dubai and UAE quotation.