FortiGate Connector
1. Connector Types & Use Cases
-
Public Network (Accessible over the internet):
Configure using the FortiGate Event Downloader & Response Connector directly. -
Private Network (No internet access):
Use App Connector to bridge the firewall with the XDR platform.
👉 App Connector Setup Guide
2. FortiGate Security Configuration
a. Blocklist Configuration
- Go to Policy & Objects > Firewall Policy.
-
Create a deny rule:
- Destination:
HH-XDR-Blocklist-address
- Action: Deny
- Destination:
-
Create another deny rule:
- Source:
HH-XDR-Blocklist-address
- Action: Deny (for inbound traffic)
- Source:
b. Web Filter Profile
- Navigate to Security Profiles > Web Filter.
- Create or edit a profile.
-
Under FortiGuard Category Based Filter:
- Ensure it’s enabled.
- For HH-XDR-Blocklist-category under Remote Categories, set Action = Block.
- Save the profile.
- Apply the profile in the Firewall Policy.
c. AntiVirus Profile
- Go to Security Profiles > AntiVirus.
- Create or edit a profile.
-
Under Virus Outbreak Prevention:
- Enable Use external malware blocklist.
- Set Action = Block.
- Select HH-XDR-Blocklist-malware (or All).
- Save the profile.
- Apply the profile in the Firewall Policy.
3. API Token Configuration
- Navigate to System > Administrators.
- Click Create New > REST API Admin.
-
Fill in:
- Username
- Comment (optional)
-
Click +Create under Administrator Profile:
-
Assign:
- Read access to Log & Report
- Read/Write access to System
-
- Disable PKI Group.
- Click OK to generate the API Key.
- Copy and save the API key (used as the Access Token in connector setup).
4. FortiGate Event Downloader Connector Configuration
Location: XDR Portal → Connectors → Ingestion
- Select FortiGate Event Downloader Connector.
- Click Configure.
-
Provide:
- Server URL
- Access Token (API key)
- Trust Any Certificate (
true/false
) - Has Public Access? (
yes/no
) - App Connector Identifier (if
public access = no
)
- Click Validate and Save.
5. FortiGate Response Connector Configuration
Location: XDR Portal → Connectors → Response
- Select FortiGate Response Connector.
- Click Configure.
-
Provide:
- Server URL
- Access Token
- Trust Any Certificate (
true/false
) - Has Public Access? (
yes/no
) - App Connector Identifier (if applicable)
- Click Validate and Save.
Let me know if you’d like a downloadable format (PDF, DOCX, Markdown) or if you want the App Connector setup instructions included inline.