Configure Fortinet FortiGate

Configure Guardian firewall integration with the Fortinet FortiGate firewall.

Before you begin

Make sure that:
  • You have administrator privileges
  • You have generated the REST application programming interface (API) access token from the firewall admin Web user interface (UI)
  • You have added the Guardian address subnet to trusted hosts
    Note:
    The access token needs to have permission to insert, read, and delete entities such as:
    • Addresses
    • Addrgroups
    • Routes
    • Sessions
    • Policies

About this task

Guardian integration supports FortiOS versions 6.2, 6.4, 7.0, 7.2, and 7.4.9. This integration uses the REST API.

Procedure

  1. In the top navigation bar, select Administration icon - which looks like a gear cog
    The administration page opens.
  2. In the Settings section, select Firewall integration.
    The Firewall integration page opens.
  3. In the top right section, select +
    A dialog shows.
  4. From the Choose firewall dropdown, select Fortinet FortiGate.
    A dialog shows.
  5. If it is not populated already, in the Host (CA-Emitted TLS Certificate) field, enter the host internet protocol (IP) address.
    Firewall configuration dialog for Fortinet FortiGate showing fields for host, vdoms, and access token, with multiple optional settings for session control, node and link blocking, ports check, and logging.

  6. Optional: In the vdom (optional) field, enter one or more Virtual DOM (vdom)s. Use a comma to separate multiple entries.
  7. In the Access token field, enter the access token.
  8. Optional: If necessary, in the Options section, select one or more of these options:
    1. Select Insert a new policy on top of all policies.
    2. For Firewall rules strategy, select a strategy.
      Figure 1. Firewall rules strategy toggle

      Edit Fortinet FortiGate dialog showing the Options panel with the Firewall rules strategy toggle with Block active alerts and Block unlearned options.

      • Block active alerts: Guardian creates link-blocking policies when specific alerts are triggered. Guardian generates rules based on real-time detection events, not on node learning state. For more details, see Alert-based firewall rule creation.
      • Block unlearned: Guardian creates block policies for unlearned nodes and links. This is the default behavior.

      If you selected Block active alerts, select one or more alert types that should trigger firewall rule creation:

      • SIGN:MITM
      • SIGN:SCADA-INJECTION
      • SIGN:PACKET-RULE
      • SIGN:OUTBOUND-CONNECTIONS
      • SIGN:MALWARE-DETECTED
      • SIGN:MULTIPLE-ACCESS-DENIED
      • SIGN:MULTIPLE-UNSUCCESSFUL-LOGINS
      • SIGN:NETWORK-SCAN

      If SIGN:PACKET-RULE is selected, enter a Severity threshold value and a Risk threshold value. Guardian creates a firewall rule for SIGN:PACKET-RULE alerts only when both the alert severity and the risk score meet or exceed the configured thresholds.

    3. Select Enable nodes blocking.
    4. Select Enable links blocking.
    5. Select Enable session kill. Then select the specific alert type(s).
    6. Select Keep on selecting sessions.
    7. Select Enable ports check.
    8. Select Enable transparent mode.
    9. Select Policies are sent as enabled.
  9. Select Save.

Results

The firewall integration has been configured.