Your firewall logs every connection at the edge. The intruder moving between your servers never passes it — WatchGuard NDR turns the NetFlow and sFlow your firewalls, routers and switches already export into alerts for lateral movement and call-home traffic, then lets you block the IP, the device or the user from one WatchGuard Cloud incident.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers WatchGuard NDR — with Total NDR and NDR for Firebox, the two other ways it is licensed. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It watches who talks to whom inside the network, using the flow records that switches and firewalls already keep.
What consolidation actually replaces, dimension by dimension.
| Dimension | Firewall logs alone | WatchGuard NDR |
|---|---|---|
| Seeing lateral movement | Only when it crosses the firewall | From switch and router flow records |
| Naming the user | DHCP leases checked by hand | DHCP and AD logs tie IPs to people |
| Cloud subnets | A separate console per cloud | Azure, AWS VPC and IONOS flows in one view |
| Acting on a finding | Log in to each device in turn | Block, contain or disable from one incident |
| Hardware to add | Nothing, and nothing seen inside | One collector per site, no taps |
| What it is NOT | — | Packet capture, decryption or an India-hosted service |
The cheapest test is the 30-day trial: one collector at your busiest site, NetFlow from its core switch, and a month of Smart Alerts to judge.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Fireboxes report natively; other firewalls, routers and switches export NetFlow or sFlow, and DHCP servers and Active Directory record which device held each IP address.
A WatchGuard Agent on Ubuntu or Windows listens on port 2055 for NetFlow and 6343 for sFlow, then relays the records to WatchGuard Cloud through an IPSec tunnel.
In WatchGuard Cloud, multi-layer neural networks and flow-based machine learning learn each device’s normal pattern, then raise Smart Alerts for scanning, beaconing or odd transfers.
Alerts arrive as ThreatSync incidents, where an operator blocks an IP or domain at the Firebox, blocks a device through Endpoint Security 360, or disables the account.
Flow records from gear you own — relayed by a small collector, analysed in WatchGuard Cloud, answered at the Firebox.
WatchGuard NDR finds intruders inside the network from flow records, without packet capture or taps.
WatchGuard documents integrations for SonicWall, FortiGate and Meraki gear; any device that exports NetFlow or sFlow can feed it.
Azure VNet flow logs (June 2025), IONOS (November 2025) and AWS VPC flow logs (December 2025) bring cloud subnets into view.
A Windows Log Agent on DHCP servers and domain controllers links each flow to a device and a user, so an alert names a person.
Flows between servers, endpoints and workloads expose an intruder moving inside the network, traffic a perimeter firewall never sees.
Outbound connections repeated at steady intervals stand out in flow timing, even when every payload is encrypted and unread.
Since February 2026 third-party VPN logs drive four policies: failed logins, unusual hours, unusual locations and new VPN users.
With a Firebox in the account, an incident action blocks the offending IP address or domain from the WatchGuard Cloud console.
Where Endpoint Security 360 or AuthPoint is licensed, the same incident can block the device or disable the user’s account.
CEF syslog to a SIEM arrived in March 2026, and a REST Management API for assets and Smart Alerts followed in April 2026.
Why MSPs add NDR beside the firewall, NDR and SASE for hybrid networks, and a 2024 preview of the CyGlass technology it grew from. All from WatchGuard’s official channel; none is a product demo.
Why partners add network detection beside the firewall, and how WatchGuard frames NDR as a managed service.
NDR alongside SASE for networks that span offices, remote users and cloud subnets.
An early look at the CyGlass technology (CyGlass, now WatchGuard NDR), recorded before the current name.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Packet-based NDR needs SPAN ports, taps and line-rate sensors. WatchGuard NDR asks the firewalls, routers and switches you own to export NetFlow or sFlow to a modest collector, usually one per site, and analyses it in WatchGuard Cloud: a configuration change, not a hardware rollout.
WatchGuard NDR and Total NDR count users, on a fixed term or a monthly subscription a service provider spreads across client accounts. Total NDR adds SaaS DR and Compliance Reporting, with NIS2 and DORA reports. NDR for Firebox is per Firebox model, with no device cap.
Detections become ThreatSync incidents whose actions reach three layers WatchGuard sells: an IP or domain blocked at a Firebox, a device blocked by Endpoint Security 360, a user disabled in AD or AuthPoint. Total MDR can watch those signals for teams with no night shift.
Flow records carry no payloads, so there is no decryption, file carving or packet replay. There is no price list, no NDR analyst placement and no India region. NDR for Firebox omits collectors and cloud flows, and data is deleted seven days after a licence lapses.
List firewalls, routers and switches at each site, confirm each can send NetFlow or sFlow, and note DHCP servers and domain controllers.
Choose NDR for Firebox, WatchGuard NDR or Total NDR by whether you need collectors, cloud flow logs and compliance reports.
Install the WatchGuard Agent on an Ubuntu 22.04 server at the main site, open ports 2055 and 6343, and add log agents on DHCP.
Leave the models to learn normal traffic, then tune policy thresholds and notification rules before anyone judges alert volume.
Enable Firebox, Endpoint Security 360 or AuthPoint actions in ThreatSync, forward alerts to the SIEM over CEF, then add sites.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We pointed three plant switches at one Ubuntu collector and had lateral-movement alerts from the shop-floor VLAN within a week.”
“As an MSP we bill it monthly per user from the same WatchGuard Cloud account that already runs our clients’ Fireboxes.”
“A beaconing alert named the laptop and the employee, because the DHCP log agent had mapped the address. That saved real digging.”
“The first fortnight was noisy until the baseline settled. Tuning the policy thresholds and notification rules fixed most of it.”
“Our auditors asked where flow data is analysed. The answer was a WatchGuard Cloud region outside India, which needed a formal sign-off.”
“It reads flows, not packets, so when we needed to see what a file transfer contained there was nothing to replay.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the network detection and response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted per user through partners; no NDR MQ placement cited.
The grid nobody publishes — how deep into the traffic a product looks, from flow records to decrypted packets, vs how much it can block or contain on its own.
Flow records only; blocks via Firebox, Endpoint Security 360 or AuthPoint.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Sophos NDR, LinkShadow Intelligent NDR, Darktrace Hybrid Network, Vectra AI Platform and ExtraHop RevealX — on data depth, deployment, price, sizing, response, managed options and India.
| Dimension | WatchGuard NDR | Sophos NDR | LinkShadow Intelligent NDR | Darktrace Hybrid Network | Vectra AI Platform | ExtraHop RevealX |
|---|---|---|---|---|---|---|
| What it is | Cloud NDR on flow data | NDR for Sophos XDR/MDR | Packet NDR, flagship | Self-learning NDR | Network, identity, cloud | Wire-data NDR |
| Deployment | SaaS + small collector | VM or certified box | Sensors + Master | Physical, virtual, cloud | Brain + sensors | SaaS or self-managed |
| Data analysed | Flows, not packets | Packets via SPAN | Mirrored packets | Raw traffic, metadata | Sensor metadata | Full-stream packets |
| Reach beyond the LAN | Azure, AWS, IONOS flows | AWS sensor, IoT on LAN | DSPM, ITDR separate | Cloud, OT, identity | AD, Entra, M365, clouds | Data centre to cloud |
| Pricing model | Per user; per Firebox | Users + servers | Per sensor and Master | Public AWS tiers | Standard or Complete | Quote; external billing |
| Published entry price | Not published | Not published | None at all | Tiered, else quoted | $499 a month listed | Not published |
| Included vs add-on | Firebox tier is narrower | Sensors are included | Modules priced apart | MDR priced apart | Complete adds MDR | Cloud recordstore in 360 |
| Sizing and limits | 500k flows/min per agent | 1 Gbps per VM sensor | No figure published | Scoped per deployment | 14–90 days of metadata | Sized to traffic |
| Detection depth | Behaviour from flows | Five engines | DPI + behaviour | Encrypted and decrypted | AI attack signal | TLS 1.3 decryption |
| Response and integrations | Firebox, endpoint, IdP | Block needs the firewall | Detect only | Autonomous response | Via the Brain | Via SOAR and firewalls |
| Who watches alerts | Total MDR option | Sophos MDR SOC | Your SOC or partner | Darktrace MDR | MDR in Complete | Partner MNDR, US only |
| India data location | No India region | Mumbai Central exists | On-prem Master | Your appliances | Brain local, UI cloud | Sensors local |
| Lock-in and exit | Data gone after lapse | Tied to Sophos Central | Metadata on your site | Darktrace appliances | Cloud UI holds work | Records in the cloud |
| Best fit | Flow-rich SMB estates | Sophos XDR/MDR users | On-prem NDR in India | Hands-off response | Identity-heavy hybrid | Forensics-led SOCs |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
WatchGuard NDR is one of 17 firewall & network security products TechBag carries. The Firewall & Network Security guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (users the licence would cover; analyst-hour cost). Estimates model the analyst time spent pulling firewall and switch logs, matching IP addresses to people and chasing unexplained internal traffic, at an assumed 1.5 hours per user a year, with 70% of it saved by flow analytics that name the device and user. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. WatchGuard publishes no price for any NDR licence, and its SKU list sits behind the partner portal. WatchGuard NDR and Total NDR are licensed per user, as a fixed term or as a monthly subscription for service providers; NDR for Firebox is licensed per Firebox model, with no device cap but no collectors or cloud flow logs. A one-time 30-day trial is available. In India it is sold through partners, with RoundRobin Tech Services in Mumbai as distributor, and no rupee price is published. TechBag counts your users and flow sources first, then gets the quote in INR with GST.
Best for multi-vendor networks and cloud subnets
Best for a broader rollout
Best when you also need SaaS and audit reports
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Can every firewall, router and switch that matters export NetFlow or sFlow, or will some segments stay dark?
Do you need collectors or cloud flow logs? NDR for Firebox excludes both and cannot be combined with WatchGuard NDR.
Does any site pass 500,000 flows a minute? Above that WatchGuard asks for more CPU, RAM and disk on the collector.
Will a Windows Log Agent run on your DHCP servers (Windows Server 2019 or 2022) so alerts name the device and user?
Which actions may fire — Firebox block, Endpoint Security 360 device block, AD or AuthPoint disable — and who approves?
Who reads a 2 a.m. Smart Alert: your own team, a partner SOC, or WatchGuard Total MDR?
Will your auditors accept flow metadata analysed in an overseas WatchGuard Cloud region under the DPDP Act and sector rules?
Is alert history exported before term end? NDR configuration and data are deleted seven days after a licence lapses.
List the sites, switches and firewalls that can export flows first, or let a TechBag advisor size the collectors, choose the licence and get the partner quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.