Talk to us
by WatchGuardTechBag Intel Page

WatchGuard NDR

Your firewall logs every connection at the edge. The intruder moving between your servers never passes it — WatchGuard NDR turns the NetFlow and sFlow your firewalls, routers and switches already export into alerts for lateral movement and call-home traffic, then lets you block the IP, the device or the user from one WatchGuard Cloud incident.

NDR from NetFlow and sFlowBlock at Firebox, endpoint or IdPQuoted per user, no public price

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
WatchGuard prints no NDR price; partners quote per user, or per Firebox for NDR for Firebox
Quote
Data depth
NetFlow, sFlow and cloud flow logs; no packet capture and no payload decryption
Flow records
Analysts
WatchGuard cites no NDR Magic Quadrant placement; its 2025 Gartner mention is for firewalls
No NDR MQ
India
Flow metadata is analysed in a WatchGuard Cloud region outside India
Overseas region

Quick answer

WatchGuard NDR is a cloud service that reads NetFlow and sFlow from Fireboxes, third-party firewalls, routers and switches, plus Azure, AWS VPC and IONOS flow logs, and uses machine learning to flag lateral movement, beaconing and command-and-control. It is licensed per user and quoted by partners. It studies flow records, not packets, and WatchGuard Cloud has no India region. Read more ↓ Show less ↑
Part 01 · Orient

The WatchGuard platform family

This page covers WatchGuard NDR — with Total NDR and NDR for Firebox, the two other ways it is licensed. The rest:

Quick facts

30-second orientation
Product
Cloud-native network detection and response that works on flow records rather than packets
Maker
WatchGuard Technologies, Seattle; owned by Vector Capital; CEO Joe Smolarski since November 2025
Heritage
Ex-CyGlass technology; generally available as ThreatSync+ NDR from 27 June 2024
Licences
WatchGuard NDR and Total NDR per user; NDR for Firebox per Firebox model, devices unlimited
Price
No list price is published; every licence is quoted by a WatchGuard partner
Sources
NetFlow, sFlow, DHCP and Active Directory logs, VPN logs, Azure, AWS VPC and IONOS flow logs
Collector
Ubuntu 22.04 or 24.04 Server with 2 cores, 8 GB RAM and 128 GB disk; usually one per site
Response
Block an IP at a Firebox, block a device via Endpoint Security 360, disable a user in AD or AuthPoint
India
No India region: WatchGuard Cloud runs in the Americas, EMEA and APAC (Japan)
In India via
TechBag — collector design, partner quote in INR with GST, first alert review
Part 02 · Learn

Understand flow-based network detection before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is flow-based NDR?

It watches who talks to whom inside the network, using the flow records that switches and firewalls already keep.

Firewall logs alone vs WatchGuard NDR — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionFirewall logs aloneWatchGuard NDR
Seeing lateral movementOnly when it crosses the firewallFrom switch and router flow records
Naming the userDHCP leases checked by handDHCP and AD logs tie IPs to people
Cloud subnetsA separate console per cloudAzure, AWS VPC and IONOS flows in one view
Acting on a findingLog in to each device in turnBlock, contain or disable from one incident
Hardware to addNothing, and nothing seen insideOne collector per site, no taps
What it is NOT—Packet capture, decryption or an India-hosted service

The cheapest test is the 30-day trial: one collector at your busiest site, NetFlow from its core switch, and a month of Smart Alerts to judge.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the flow data starts

Sources

Fireboxes and third-party gear

Fireboxes report natively; other firewalls, routers and switches export NetFlow or sFlow, and DHCP servers and Active Directory record which device held each IP address.

02
How flows reach the cloud

Collector

NDR Collection Agent

A WatchGuard Agent on Ubuntu or Windows listens on port 2055 for NetFlow and 6343 for sFlow, then relays the records to WatchGuard Cloud through an IPSec tunnel.

03
Where detection happens

Analytics

Neural networks on flow data

In WatchGuard Cloud, multi-layer neural networks and flow-based machine learning learn each device’s normal pattern, then raise Smart Alerts for scanning, beaconing or odd transfers.

04
What happens after an alert

Response

ThreatSync XDR actions

Alerts arrive as ThreatSync incidents, where an operator blocks an IP or domain at the Firebox, blocks a device through Endpoint Security 360, or disables the account.

Flow records from gear you own — relayed by a small collector, analysed in WatchGuard Cloud, answered at the Firebox.

Part 03 · Evaluate

Nine capabilities. Collect, detect, respond.

WatchGuard NDR finds intruders inside the network from flow records, without packet capture or taps.

Collect
Multi-vendor

Reads other vendors’ flows

WatchGuard documents integrations for SonicWall, FortiGate and Meraki gear; any device that exports NetFlow or sFlow can feed it.

Collect
Cloud flows

Azure, AWS and IONOS networks

Azure VNet flow logs (June 2025), IONOS (November 2025) and AWS VPC flow logs (December 2025) bring cloud subnets into view.

Collect
Identity

A name behind every IP

A Windows Log Agent on DHCP servers and domain controllers links each flow to a device and a user, so an alert names a person.

Detect
Lateral movement

East-west spread flagged

Flows between servers, endpoints and workloads expose an intruder moving inside the network, traffic a perimeter firewall never sees.

Detect
Beaconing

Call-home timing spotted

Outbound connections repeated at steady intervals stand out in flow timing, even when every payload is encrypted and unread.

Detect
VPN anomalies

Odd remote-access logins

Since February 2026 third-party VPN logs drive four policies: failed logins, unusual hours, unusual locations and new VPN users.

Respond
Firebox block

Stop it at the firewall

With a Firebox in the account, an incident action blocks the offending IP address or domain from the WatchGuard Cloud console.

Respond
Device and user

Contain the laptop and the login

Where Endpoint Security 360 or AuthPoint is licensed, the same incident can block the device or disable the user’s account.

Respond
SIEM and API

Alerts out to other tools

CEF syslog to a SIEM arrived in March 2026, and a REST Management API for assets and Smart Alerts followed in April 2026.

See it, don’t just read it

Watch WatchGuard NDR in action

Why MSPs add NDR beside the firewall, NDR and SASE for hybrid networks, and a 2024 preview of the CyGlass technology it grew from. All from WatchGuard’s official channel; none is a product demo.

WatchGuard (official)·Video, April 2026

Beyond the Firewall: Growing Your MSP with NDR

Why partners add network detection beside the firewall, and how WatchGuard frames NDR as a managed service.

WatchGuard (official)·Video, September 2025

No More Weak Links: Unleashing NDR and SASE for Hybrid Networks

NDR alongside SASE for networks that span offices, remote users and cloud subnets.

WatchGuard (official)·Webinar, March 2024

Webinar - A Preview of CyGlass Detection and Response with WatchGuard

An early look at the CyGlass technology (CyGlass, now WatchGuard NDR), recorded before the current name.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why WatchGuard NDR

Your switches already record every flow. WatchGuard NDR turns those records into alerts.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Network detection without a packet project

Packet-based NDR needs SPAN ports, taps and line-rate sensors. WatchGuard NDR asks the firewalls, routers and switches you own to export NetFlow or sFlow to a modest collector, usually one per site, and analyses it in WatchGuard Cloud: a configuration change, not a hardware rollout.

02

Licensed the way MSPs sell

WatchGuard NDR and Total NDR count users, on a fixed term or a monthly subscription a service provider spreads across client accounts. Total NDR adds SaaS DR and Compliance Reporting, with NIS2 and DORA reports. NDR for Firebox is per Firebox model, with no device cap.

03

An alert that ends in an action

Detections become ThreatSync incidents whose actions reach three layers WatchGuard sells: an IP or domain blocked at a Firebox, a device blocked by Endpoint Security 360, a user disabled in AD or AuthPoint. Total MDR can watch those signals for teams with no night shift.

04

Where it stops

Flow records carry no payloads, so there is no decryption, file carving or packet replay. There is no price list, no NDR analyst placement and no India region. NDR for Firebox omits collectors and cloud flows, and data is deleted seven days after a licence lapses.

The idea
NDR from flow records, no taps
The response
Block at Firebox, endpoint or IdP
The price
Quoted per user; no public list
Proof, not promises

The numbers behind the platform

Port 2055
where the collection agent listens for NetFlow; sFlow arrives on port 6343
— Vendor
8 GB RAM
the minimum memory for a Linux collector, alongside 2 CPU cores and 128 GB of disk
— Vendor
500000 flows/min
the NetFlow rate above which WatchGuard says a collector needs more CPU, RAM and disk
— Vendor
3 cloud sources
Azure VNet, AWS VPC and IONOS flow logs, all added between June and December 2025
— Vendor
7 days
the grace period after a licence expires, before NDR configuration and data are deleted
— Vendor
2024
the year ThreatSync+ NDR, today’s WatchGuard NDR, reached general availability (27 June)
— Vendor

What your WatchGuard NDR rollout looks like

Week 1Model

Map what exports flows

List firewalls, routers and switches at each site, confirm each can send NetFlow or sFlow, and note DHCP servers and domain controllers.

Week 2Decide

Pick the licence

Choose NDR for Firebox, WatchGuard NDR or Total NDR by whether you need collectors, cloud flow logs and compliance reports.

Week 3Pilot

Stand up one collector

Install the WatchGuard Agent on an Ubuntu 22.04 server at the main site, open ports 2055 and 6343, and add log agents on DHCP.

Month 2Prove

Let the baseline settle

Leave the models to learn normal traffic, then tune policy thresholds and notification rules before anyone judges alert volume.

Month 3Commit

Wire up response

Enable Firebox, Endpoint Security 360 or AuthPoint actions in ThreatSync, forward alerts to the SIEM over CEF, then add sites.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
34+ reviews*
78% would recommend
Collector setup4.3
Multi-vendor flow support4.2
Response actions4.0
Detection quality3.9
Value for money3.8
5★
40%
4★
36%
3★
15%
2★
6%
1★
3%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“We pointed three plant switches at one Ubuntu collector and had lateral-movement alerts from the shop-floor VLAN within a week.”
IT Manager
Manufacturing
IT Services
“As an MSP we bill it monthly per user from the same WatchGuard Cloud account that already runs our clients’ Fireboxes.”
MSP Security Lead
IT Services
BFSI
“A beaconing alert named the laptop and the employee, because the DHCP log agent had mapped the address. That saved real digging.”
SOC Analyst
BFSI
Education
“The first fortnight was noisy until the baseline settled. Tuning the policy thresholds and notification rules fixed most of it.”
Network Engineer
Education
Logistics
“Our auditors asked where flow data is analysed. The answer was a WatchGuard Cloud region outside India, which needed a formal sign-off.”
Compliance Officer
Logistics
Healthcare
“It reads flows, not packets, so when we needed to see what a file transfer contained there was nothing to replay.”
Security Architect
Healthcare
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the network detection and response market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Network Detection Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
WatchGuard NDRThis page

Quoted per user through partners; no NDR MQ placement cited.

Grid 02 · The architecture

Data Depth × Built-in Response

The grid nobody publishes — how deep into the traffic a product looks, from flow records to decrypted packets, vs how much it can block or contain on its own.

Flow-based respondersDeep and decisiveFlow-only watchersDeep but detect-first
WatchGuard NDRThis page

Flow records only; blocks via Firebox, Endpoint Security 360 or AuthPoint.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

WatchGuard NDR vs the network detection field

Against Sophos NDR, LinkShadow Intelligent NDR, Darktrace Hybrid Network, Vectra AI Platform and ExtraHop RevealX — on data depth, deployment, price, sizing, response, managed options and India.

DimensionWatchGuard NDRSophos NDRLinkShadow Intelligent NDRDarktrace Hybrid NetworkVectra AI PlatformExtraHop RevealX
What it isCloud NDR on flow dataNDR for Sophos XDR/MDRPacket NDR, flagshipSelf-learning NDRNetwork, identity, cloudWire-data NDR
DeploymentSaaS + small collectorVM or certified boxSensors + MasterPhysical, virtual, cloudBrain + sensorsSaaS or self-managed
Data analysedFlows, not packetsPackets via SPANMirrored packetsRaw traffic, metadataSensor metadataFull-stream packets
Reach beyond the LANAzure, AWS, IONOS flowsAWS sensor, IoT on LANDSPM, ITDR separateCloud, OT, identityAD, Entra, M365, cloudsData centre to cloud
Pricing modelPer user; per FireboxUsers + serversPer sensor and MasterPublic AWS tiersStandard or CompleteQuote; external billing
Published entry priceNot publishedNot publishedNone at allTiered, else quoted$499 a month listedNot published
Included vs add-onFirebox tier is narrowerSensors are includedModules priced apartMDR priced apartComplete adds MDRCloud recordstore in 360
Sizing and limits500k flows/min per agent1 Gbps per VM sensorNo figure publishedScoped per deployment14–90 days of metadataSized to traffic
Detection depthBehaviour from flowsFive enginesDPI + behaviourEncrypted and decryptedAI attack signalTLS 1.3 decryption
Response and integrationsFirebox, endpoint, IdPBlock needs the firewallDetect onlyAutonomous responseVia the BrainVia SOAR and firewalls
Who watches alertsTotal MDR optionSophos MDR SOCYour SOC or partnerDarktrace MDRMDR in CompletePartner MNDR, US only
India data locationNo India regionMumbai Central existsOn-prem MasterYour appliancesBrain local, UI cloudSensors local
Lock-in and exitData gone after lapseTied to Sophos CentralMetadata on your siteDarktrace appliancesCloud UI holds workRecords in the cloud
Best fitFlow-rich SMB estatesSophos XDR/MDR usersOn-prem NDR in IndiaHands-off responseIdentity-heavy hybridForensics-led SOCs
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose WatchGuard NDR if…

  • ✓You want east-west detection from flow records your switches and firewalls already export, with no SPAN ports or line-rate sensors to buy
  • ✓You run Fireboxes, Endpoint Security 360 or AuthPoint and want each alert to end in an IP block, a device block or a disabled account
  • ✓You are an MSP that needs per-user NDR billed monthly across many client accounts from one WatchGuard Cloud login

Compare alternatives if…

  • ✓You need payload evidence or TLS decryption — ExtraHop RevealX and Sophos NDR inspect packets, WatchGuard NDR does not
  • ✓Your board wants a Gartner NDR Leader — Darktrace, Vectra AI and ExtraHop each announce that 2026 placement
  • ✓Traffic metadata must stay in your own Indian data centre — LinkShadow’s on-premises Master is built for that

Do not expect…

  • ✓Packet capture, file reconstruction or TLS decryption from a flow-based service
  • ✓An Indian WatchGuard Cloud region, or an NDR price list
  • ✓Collection agents or cloud flow logs on the NDR for Firebox licence

WatchGuard NDR is one of 17 firewall & network security products TechBag carries. The Firewall & Network Security guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does chasing internal traffic by hand cost you?

Drag the sliders (users the licence would cover; analyst-hour cost). Estimates model the analyst time spent pulling firewall and switch logs, matching IP addresses to people and chasing unexplained internal traffic, at an assumed 1.5 hours per user a year, with 70% of it saved by flow analytics that name the device and user. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual investigation labour cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. WatchGuard publishes no price for any NDR licence, and its SKU list sits behind the partner portal. WatchGuard NDR and Total NDR are licensed per user, as a fixed term or as a monthly subscription for service providers; NDR for Firebox is licensed per Firebox model, with no device cap but no collectors or cloud flow logs. A one-time 30-day trial is available. In India it is sold through partners, with RoundRobin Tech Services in Mumbai as distributor, and no rupee price is published. TechBag counts your users and flow sources first, then gets the quote in INR with GST.

WatchGuard NDR

Best for multi-vendor networks and cloud subnets

  • Licensed per user, term or monthly
  • Collectors, log agents and cloud flow logs
  • Quoted by a WatchGuard partner

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Total NDR

Best when you also need SaaS and audit reports

  • WatchGuard NDR plus WatchGuard SaaS DR
  • Compliance Reporting, NIS2 and DORA reports
  • Licensed per user; no public price

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Flow sources

Can every firewall, router and switch that matters export NetFlow or sFlow, or will some segments stay dark?

2
Licence type

Do you need collectors or cloud flow logs? NDR for Firebox excludes both and cannot be combined with WatchGuard NDR.

3
Collector sizing

Does any site pass 500,000 flows a minute? Above that WatchGuard asks for more CPU, RAM and disk on the collector.

4
User mapping

Will a Windows Log Agent run on your DHCP servers (Windows Server 2019 or 2022) so alerts name the device and user?

5
Response path

Which actions may fire — Firebox block, Endpoint Security 360 device block, AD or AuthPoint disable — and who approves?

6
Alert owner

Who reads a 2 a.m. Smart Alert: your own team, a partner SOC, or WatchGuard Total MDR?

7
Data location

Will your auditors accept flow metadata analysed in an overseas WatchGuard Cloud region under the DPDP Act and sector rules?

8
Renewal

Is alert history exported before term end? NDR configuration and data are deleted seven days after a licence lapses.

FAQ

Questions buyers ask

A network detection and response service that runs in WatchGuard Cloud. It analyses NetFlow and sFlow from Fireboxes, other vendors’ firewalls, routers and switches, plus DHCP, Active Directory, VPN and cloud flow logs, and flags lateral movement, beaconing, scanning and odd transfers.

Ready to evaluate WatchGuard NDR?

List the sites, switches and firewalls that can export flows first, or let a TechBag advisor size the collectors, choose the licence and get the partner quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.