Fortinet white logo
Fortinet white logo

CLI Reference

global

global

Use this command to configure global settings that affect miscellaneous FortiAnalyzer features.

Syntax

config system global

set admin-lockout-duration <integer>

set admin-lockout-threshold <integer>

set adom-mode {advanced | normal}

set adom-select {enable | disable}

set adom-status {enable | disable}

set backup-compression {high | low | none | normal}

set backup-to-subfolders {enable | disable}

set clt-cert-req {enable | disable}

set console-output {more | standard}

set country-flag {enable | disable}

set create-revision {enable | disable}

set daylightsavetime {enable | disable}

set default-disk-quota <integer>

set default-search-mode {advanced | filter-based}

set detect-unregistered-log-device {enable | disable}

set device-view-mode {regular | tree}

set enc-algorithm {high | medium | low}

set fgfm-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

set ha-member-auto-grouping {enable | disable}

set hitcount_concurrent <integer>

set hitcount_interval <integer>

set hostname <string>

set language {english | japanese | simch | trach}

set ldap-cache-timeout <integer>

set ldapconntimeout <integer>

set lock-preempt {enable | disable}

set log-checksum {md5 | md5-auth | none}

set log-mode {analyzer | collector}

set max-aggregation-tasks <integer>

set max-log-forward <integer>

set max-running-reports <integer>

set oftp-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

set policy-hit-count {enable | disable}

set policy-object-in-dual-pane {enable | disable}

set pre-login-banner {enable | disable}

set pre-login-banner-message <string>

set remoteauthtimeout <integer>

set search-all-adoms {enable | disable}

set ssl-low-encryption {enable | disable}

set ssl-protocol {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3}

set ssl-static-key-ciphers {enable | disable}

set task-list-size <integer>

set tftp

set timezone <integer>

set tunnel-mtu <integer>

set usg {enable | disable}

set webservice-proto {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3 | sslv2}

set workflow-max-sessions <integer>

end

Variable

Description

admin-lockout-duration <integer>

Set the lockout duration for FortiAnalyzer administration, in seconds (default = 60).

admin-lockout-threshold <integer>

Set the lockout threshold for FortiAnalyzer administration (1 - 10, default = 3).

adom-mode {advanced | normal}

Set the ADOM mode (default = normal).

adom-select {enable | disable}

Enable/disable a pop-up window that allows administrators to select an ADOM after logging in (default = enable).

adom-status {enable | disable}

Enable/disable administrative domains (default = disable).

backup-compression {high | low | none | normal}

Set the backup compression level: high (slowest), low (fastest), none, or normal (default).

backup-to-subfolders {enable | disable}

Enable/disable the creation of subfolders on server for backup storage (default = disable).

clt-cert-req {enable | disable}

Enable/disable requiring a client certificate for GUI login (default = disable).

When both clt-cert-req and admin-https-pki-required are enabled, only PKI administrators can connect to the GUI.

console-output {more | standard}

Select how the output is displayed on the console (default = standard).

Select more to pause the output at each full screen until keypress. Select standard for continuous output without pauses.

country-flag {enable | disable}

Enable/disable a country flag icon beside an IP address (default = enable).

create-revision {enable | disable}

Enable/disable create revision by default (default = disable).

daylightsavetime {enable | disable}

Enable/disable daylight saving time (default = enable).

If you enable daylight saving time, the FortiAnalyzer unit automatically adjusts the system time when daylight saving time begins or ends.

default-disk-quota <integer>

This variable does not function on FortiAnalyzer.

default-search-mode {advanced | filter-based}

Set the default search mode of log view (default = filter-based).

detect-unregistered-log-device {enable | disable}

Enable/disable unregistered log device detection (default = enable).

device-view-mode {regular | tree}

Set the devices/groups view mode (default = regular).

enc-algorithm {high | medium | low}

Set SSL communication encryption algorithms:

  • high: SSL communication using high encryption algorithms (default).
  • medium: SSL communication using high and medium encryption algorithms.
  • low: SSL communication using all available encryption algorithms.

fgfm-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

Set the lowest SSL protocols for fgfmsd (default = tlsv1.2).

ha-member-auto-grouping {enable | disable}

Enable/disable automatically grouping HA members when the group name is unique in your network (default = enable).

hitcount_concurrent <integer>

Set the number of FortiGates that FortiAnalyzer polls at one time (10 - 500, default = 100).

hitcount_interval <integer>

Set the interval for getting the hit count from connected FortiGate devices, in seconds (60 - 86400, default = 300).

hostname <string>

FortiAnalyzer host name.

language {english | japanese | simch | spanish | trach}

GUI language:

  • english: English (default)
  • japanese: Japanese
  • simch: Simplified Chinese
  • spanish: Spanish
  • trach: Traditional Chinese

ldap-cache-timeout <integer>

LDAP cache timeout, in seconds (default =86400).

ldapconntimeout <integer>

LDAP connection timeout, in milliseconds (default = 60000).

lock-preempt {enable | disable}

Enable/disable the ADOM lock override (default = disable).

log-checksum {md5 | md5-auth | none}

Record log file hash value, timestamp, and authentication code at transmission or rolling:

  • md5: Record log file’s MD5 hash value only.
  • md5-auth: Record log file’s MD5 hash value and authentication code.
  • none: Do not record the log file checksum (default).

log-mode {analyzer | collector}

Set the log system operation mode (default = analyzer).

max-aggregation-tasks <integer>

Set the maximum number of concurrent tasks of a log aggregation session (1 - 10, default = 0).

max-log-forward <integer>

Set the maximum log forwarding and aggregation number (5 - 20).

max-running-reports <integer>

Maximum running reports number (1 - 10, default = 1).

oftp-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

Set the lowest SSL protocols for oftpd (default = tlsv1.2).

policy-hit-count {enable | disable}

Enable/disable show policy hit count (default= disable).

The policy hit count is the number of sessions that match to a firewall policy on a FortiGate. When policy-hit-count is enabled, it collects all hits from all managed FortiGate devices. FortiAnalyzer sums up all hit counts for each policy package from the assigned FortiGate devices, and displays the hit count for each of the firewall rules.

policy-object-in-dual-pane {enable | disable}

Enable/disable show policies and objects in dual pane (default= disable).

pre-login-banner {enable | disable}

Enable/disable pre-login banner (default= disable).

pre-login-banner-message <string>

Set the pre-login banner message.

remoteauthtimeout <integer>

Remote authentication (RADIUS/LDAP) timeout, in seconds (default = 10).

search-all-adoms {enable | disable}

Enable/disable search all ADOMs for where-used queries (default= disable).

ssl-low-encryption {enable | disable}

Enable/disable SSL low-grade (40-bit) encryption (default= disable).

ssl-protocol {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3}

Set the SSL protocols (default = tlsv1.2).

ssl-static-key-ciphers {enable | disable}

Enable/disable SSL static key ciphers (default = enable).

task-list-size <integer>

Set the maximum number of completed tasks to keep (default = 2000).

tftp

timezone <integer>

The time zone for the FortiManager unit (default = Pacific Time). See Time zones.

tunnel-mtu <integer>

Set the maximum transportation unit (68 - 9000, default = 1500).

usg {enable | disable}

Enable/disable contacting only FortiGuard servers in the USA (default = enable).

webservice-proto {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3 | sslv2}

Web Service connection (default = tlsv1.2).

workflow-max-sessions <integer>

This variable does not function on FortiAnalyzer.

Example

The following command turns on daylight saving time, sets the FortiAnalyzer unit name to FMG3k, and chooses the Eastern time zone for US & Canada.

config system global

set daylightsavetime enable

set hostname FMG3k

set timezone 12

end

Time zones

Integer

Time zone

Integer

Time zone

00

(GMT-12:00) Eniwetak, Kwajalein

40

(GMT+3:00) Nairobi

01

(GMT-11:00) Midway Island, Samoa

41

(GMT+3:30) Tehran

02

(GMT-10:00) Hawaii

42

(GMT+4:00) Abu Dhabi, Muscat

03

(GMT-9:00) Alaska

43

(GMT+4:00) Baku

04

(GMT-8:00) Pacific Time (US & Canada)

44

(GMT+4:30) Kabul

05

(GMT-7:00) Arizona

45

(GMT+5:00) Ekaterinburg

06

(GMT-7:00) Mountain Time (US & Canada)

46

(GMT+5:00) Islamabad, Karachi,Tashkent

07

(GMT-6:00) Central America

47

(GMT+5:30) Calcutta, Chennai, Mumbai, New Delhi

08

(GMT-6:00) Central Time (US & Canada)

48

(GMT+5:45) Kathmandu

09

(GMT-6:00) Mexico City

49

(GMT+6:00) Almaty, Novosibirsk

10

(GMT-6:00) Saskatchewan

50

(GMT+6:00) Astana, Dhaka

11

(GMT-5:00) Bogota, Lima, Quito

51

(GMT+6:00) Sri Jayawardenapura

12

(GMT-5:00) Eastern Time (US & Canada)

52

(GMT+6:30) Rangoon

13

(GMT-5:00) Indiana (East)

53

(GMT+7:00) Bangkok, Hanoi, Jakarta

14

(GMT-4:00) Atlantic Time (Canada)

54

(GMT+7:00) Krasnoyarsk

15

(GMT-4:00) La Paz

55

(GMT+8:00) Beijing,ChongQing, HongKong,Urumqi

16

(GMT-4:00) Santiago

56

(GMT+8:00) Irkutsk, Ulaanbaatar

17

(GMT-3:30) Newfoundland

57

(GMT+8:00) Kuala Lumpur, Singapore

18

(GMT-3:00) Brasilia

58

(GMT+8:00) Perth

19

(GMT-3:00) Buenos Aires, Georgetown

59

(GMT+8:00) Taipei

20

(GMT-3:00) Nuuk (Greenland)

60

(GMT+9:00) Osaka, Sapporo, Tokyo, Seoul

21

(GMT-2:00) Mid-Atlantic

61

(GMT+9:00) Yakutsk

22

(GMT-1:00) Azores

62

(GMT+9:30) Adelaide

23

(GMT-1:00) Cape Verde Is

63

(GMT+9:30) Darwin

24

(GMT) Casablanca, Monrovia

64

(GMT+10:00) Brisbane

25

(GMT) Greenwich Mean Time:Dublin, Edinburgh, Lisbon, London

65

(GMT+10:00) Canberra, Melbourne, Sydney

26

(GMT+1:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna

66

(GMT+10:00) Guam, Port Moresby

27

(GMT+1:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague

67

(GMT+10:00) Hobart

28

(GMT+1:00) Brussels, Copenhagen, Madrid, Paris

68

(GMT+10:00) Vladivostok

29

(GMT+1:00) Sarajevo, Skopje, Sofija, Vilnius, Warsaw, Zagreb

69

(GMT+11:00) Magadan

30

(GMT+1:00) West Central Africa

70

(GMT+11:00) Solomon Is., New Caledonia

31

(GMT+2:00) Athens, Istanbul, Minsk

71

(GMT+12:00) Auckland, Wellington

32

(GMT+2:00) Bucharest

72

(GMT+12:00) Fiji, Kamchatka, Marshall Is

33

(GMT+2:00) Cairo

73

(GMT+13:00) Nuku'alofa

34

(GMT+2:00) Harare, Pretoria

74

(GMT-4:30) Caracas

35

(GMT+2:00) Helsinki, Riga,Tallinn

75

(GMT+1:00) Namibia

36

(GMT+2:00) Jerusalem

76

(GMT-5:00) Brazil-Acre)

37

(GMT+3:00) Baghdad

77

(GMT-4:00) Brazil-West

38

(GMT+3:00) Kuwait, Riyadh

78

(GMT-3:00) Brazil-East

39

(GMT+3:00) Moscow, St.Petersburg, Volgograd

79

(GMT-2:00) Brazil-DeNoronha

global

global

Use this command to configure global settings that affect miscellaneous FortiAnalyzer features.

Syntax

config system global

set admin-lockout-duration <integer>

set admin-lockout-threshold <integer>

set adom-mode {advanced | normal}

set adom-select {enable | disable}

set adom-status {enable | disable}

set backup-compression {high | low | none | normal}

set backup-to-subfolders {enable | disable}

set clt-cert-req {enable | disable}

set console-output {more | standard}

set country-flag {enable | disable}

set create-revision {enable | disable}

set daylightsavetime {enable | disable}

set default-disk-quota <integer>

set default-search-mode {advanced | filter-based}

set detect-unregistered-log-device {enable | disable}

set device-view-mode {regular | tree}

set enc-algorithm {high | medium | low}

set fgfm-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

set ha-member-auto-grouping {enable | disable}

set hitcount_concurrent <integer>

set hitcount_interval <integer>

set hostname <string>

set language {english | japanese | simch | trach}

set ldap-cache-timeout <integer>

set ldapconntimeout <integer>

set lock-preempt {enable | disable}

set log-checksum {md5 | md5-auth | none}

set log-mode {analyzer | collector}

set max-aggregation-tasks <integer>

set max-log-forward <integer>

set max-running-reports <integer>

set oftp-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

set policy-hit-count {enable | disable}

set policy-object-in-dual-pane {enable | disable}

set pre-login-banner {enable | disable}

set pre-login-banner-message <string>

set remoteauthtimeout <integer>

set search-all-adoms {enable | disable}

set ssl-low-encryption {enable | disable}

set ssl-protocol {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3}

set ssl-static-key-ciphers {enable | disable}

set task-list-size <integer>

set tftp

set timezone <integer>

set tunnel-mtu <integer>

set usg {enable | disable}

set webservice-proto {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3 | sslv2}

set workflow-max-sessions <integer>

end

Variable

Description

admin-lockout-duration <integer>

Set the lockout duration for FortiAnalyzer administration, in seconds (default = 60).

admin-lockout-threshold <integer>

Set the lockout threshold for FortiAnalyzer administration (1 - 10, default = 3).

adom-mode {advanced | normal}

Set the ADOM mode (default = normal).

adom-select {enable | disable}

Enable/disable a pop-up window that allows administrators to select an ADOM after logging in (default = enable).

adom-status {enable | disable}

Enable/disable administrative domains (default = disable).

backup-compression {high | low | none | normal}

Set the backup compression level: high (slowest), low (fastest), none, or normal (default).

backup-to-subfolders {enable | disable}

Enable/disable the creation of subfolders on server for backup storage (default = disable).

clt-cert-req {enable | disable}

Enable/disable requiring a client certificate for GUI login (default = disable).

When both clt-cert-req and admin-https-pki-required are enabled, only PKI administrators can connect to the GUI.

console-output {more | standard}

Select how the output is displayed on the console (default = standard).

Select more to pause the output at each full screen until keypress. Select standard for continuous output without pauses.

country-flag {enable | disable}

Enable/disable a country flag icon beside an IP address (default = enable).

create-revision {enable | disable}

Enable/disable create revision by default (default = disable).

daylightsavetime {enable | disable}

Enable/disable daylight saving time (default = enable).

If you enable daylight saving time, the FortiAnalyzer unit automatically adjusts the system time when daylight saving time begins or ends.

default-disk-quota <integer>

This variable does not function on FortiAnalyzer.

default-search-mode {advanced | filter-based}

Set the default search mode of log view (default = filter-based).

detect-unregistered-log-device {enable | disable}

Enable/disable unregistered log device detection (default = enable).

device-view-mode {regular | tree}

Set the devices/groups view mode (default = regular).

enc-algorithm {high | medium | low}

Set SSL communication encryption algorithms:

  • high: SSL communication using high encryption algorithms (default).
  • medium: SSL communication using high and medium encryption algorithms.
  • low: SSL communication using all available encryption algorithms.

fgfm-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

Set the lowest SSL protocols for fgfmsd (default = tlsv1.2).

ha-member-auto-grouping {enable | disable}

Enable/disable automatically grouping HA members when the group name is unique in your network (default = enable).

hitcount_concurrent <integer>

Set the number of FortiGates that FortiAnalyzer polls at one time (10 - 500, default = 100).

hitcount_interval <integer>

Set the interval for getting the hit count from connected FortiGate devices, in seconds (60 - 86400, default = 300).

hostname <string>

FortiAnalyzer host name.

language {english | japanese | simch | spanish | trach}

GUI language:

  • english: English (default)
  • japanese: Japanese
  • simch: Simplified Chinese
  • spanish: Spanish
  • trach: Traditional Chinese

ldap-cache-timeout <integer>

LDAP cache timeout, in seconds (default =86400).

ldapconntimeout <integer>

LDAP connection timeout, in milliseconds (default = 60000).

lock-preempt {enable | disable}

Enable/disable the ADOM lock override (default = disable).

log-checksum {md5 | md5-auth | none}

Record log file hash value, timestamp, and authentication code at transmission or rolling:

  • md5: Record log file’s MD5 hash value only.
  • md5-auth: Record log file’s MD5 hash value and authentication code.
  • none: Do not record the log file checksum (default).

log-mode {analyzer | collector}

Set the log system operation mode (default = analyzer).

max-aggregation-tasks <integer>

Set the maximum number of concurrent tasks of a log aggregation session (1 - 10, default = 0).

max-log-forward <integer>

Set the maximum log forwarding and aggregation number (5 - 20).

max-running-reports <integer>

Maximum running reports number (1 - 10, default = 1).

oftp-ssl-protocol {sslv3 | tlsv1.0 | tlsv1.1 | tlsv1.2}

Set the lowest SSL protocols for oftpd (default = tlsv1.2).

policy-hit-count {enable | disable}

Enable/disable show policy hit count (default= disable).

The policy hit count is the number of sessions that match to a firewall policy on a FortiGate. When policy-hit-count is enabled, it collects all hits from all managed FortiGate devices. FortiAnalyzer sums up all hit counts for each policy package from the assigned FortiGate devices, and displays the hit count for each of the firewall rules.

policy-object-in-dual-pane {enable | disable}

Enable/disable show policies and objects in dual pane (default= disable).

pre-login-banner {enable | disable}

Enable/disable pre-login banner (default= disable).

pre-login-banner-message <string>

Set the pre-login banner message.

remoteauthtimeout <integer>

Remote authentication (RADIUS/LDAP) timeout, in seconds (default = 10).

search-all-adoms {enable | disable}

Enable/disable search all ADOMs for where-used queries (default= disable).

ssl-low-encryption {enable | disable}

Enable/disable SSL low-grade (40-bit) encryption (default= disable).

ssl-protocol {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3}

Set the SSL protocols (default = tlsv1.2).

ssl-static-key-ciphers {enable | disable}

Enable/disable SSL static key ciphers (default = enable).

task-list-size <integer>

Set the maximum number of completed tasks to keep (default = 2000).

tftp

timezone <integer>

The time zone for the FortiManager unit (default = Pacific Time). See Time zones.

tunnel-mtu <integer>

Set the maximum transportation unit (68 - 9000, default = 1500).

usg {enable | disable}

Enable/disable contacting only FortiGuard servers in the USA (default = enable).

webservice-proto {tlsv1.2 | tlsv1.1 | tlsv1.0 | sslv3 | sslv2}

Web Service connection (default = tlsv1.2).

workflow-max-sessions <integer>

This variable does not function on FortiAnalyzer.

Example

The following command turns on daylight saving time, sets the FortiAnalyzer unit name to FMG3k, and chooses the Eastern time zone for US & Canada.

config system global

set daylightsavetime enable

set hostname FMG3k

set timezone 12

end

Time zones

Integer

Time zone

Integer

Time zone

00

(GMT-12:00) Eniwetak, Kwajalein

40

(GMT+3:00) Nairobi

01

(GMT-11:00) Midway Island, Samoa

41

(GMT+3:30) Tehran

02

(GMT-10:00) Hawaii

42

(GMT+4:00) Abu Dhabi, Muscat

03

(GMT-9:00) Alaska

43

(GMT+4:00) Baku

04

(GMT-8:00) Pacific Time (US & Canada)

44

(GMT+4:30) Kabul

05

(GMT-7:00) Arizona

45

(GMT+5:00) Ekaterinburg

06

(GMT-7:00) Mountain Time (US & Canada)

46

(GMT+5:00) Islamabad, Karachi,Tashkent

07

(GMT-6:00) Central America

47

(GMT+5:30) Calcutta, Chennai, Mumbai, New Delhi

08

(GMT-6:00) Central Time (US & Canada)

48

(GMT+5:45) Kathmandu

09

(GMT-6:00) Mexico City

49

(GMT+6:00) Almaty, Novosibirsk

10

(GMT-6:00) Saskatchewan

50

(GMT+6:00) Astana, Dhaka

11

(GMT-5:00) Bogota, Lima, Quito

51

(GMT+6:00) Sri Jayawardenapura

12

(GMT-5:00) Eastern Time (US & Canada)

52

(GMT+6:30) Rangoon

13

(GMT-5:00) Indiana (East)

53

(GMT+7:00) Bangkok, Hanoi, Jakarta

14

(GMT-4:00) Atlantic Time (Canada)

54

(GMT+7:00) Krasnoyarsk

15

(GMT-4:00) La Paz

55

(GMT+8:00) Beijing,ChongQing, HongKong,Urumqi

16

(GMT-4:00) Santiago

56

(GMT+8:00) Irkutsk, Ulaanbaatar

17

(GMT-3:30) Newfoundland

57

(GMT+8:00) Kuala Lumpur, Singapore

18

(GMT-3:00) Brasilia

58

(GMT+8:00) Perth

19

(GMT-3:00) Buenos Aires, Georgetown

59

(GMT+8:00) Taipei

20

(GMT-3:00) Nuuk (Greenland)

60

(GMT+9:00) Osaka, Sapporo, Tokyo, Seoul

21

(GMT-2:00) Mid-Atlantic

61

(GMT+9:00) Yakutsk

22

(GMT-1:00) Azores

62

(GMT+9:30) Adelaide

23

(GMT-1:00) Cape Verde Is

63

(GMT+9:30) Darwin

24

(GMT) Casablanca, Monrovia

64

(GMT+10:00) Brisbane

25

(GMT) Greenwich Mean Time:Dublin, Edinburgh, Lisbon, London

65

(GMT+10:00) Canberra, Melbourne, Sydney

26

(GMT+1:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna

66

(GMT+10:00) Guam, Port Moresby

27

(GMT+1:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague

67

(GMT+10:00) Hobart

28

(GMT+1:00) Brussels, Copenhagen, Madrid, Paris

68

(GMT+10:00) Vladivostok

29

(GMT+1:00) Sarajevo, Skopje, Sofija, Vilnius, Warsaw, Zagreb

69

(GMT+11:00) Magadan

30

(GMT+1:00) West Central Africa

70

(GMT+11:00) Solomon Is., New Caledonia

31

(GMT+2:00) Athens, Istanbul, Minsk

71

(GMT+12:00) Auckland, Wellington

32

(GMT+2:00) Bucharest

72

(GMT+12:00) Fiji, Kamchatka, Marshall Is

33

(GMT+2:00) Cairo

73

(GMT+13:00) Nuku'alofa

34

(GMT+2:00) Harare, Pretoria

74

(GMT-4:30) Caracas

35

(GMT+2:00) Helsinki, Riga,Tallinn

75

(GMT+1:00) Namibia

36

(GMT+2:00) Jerusalem

76

(GMT-5:00) Brazil-Acre)

37

(GMT+3:00) Baghdad

77

(GMT-4:00) Brazil-West

38

(GMT+3:00) Kuwait, Riyadh

78

(GMT-3:00) Brazil-East

39

(GMT+3:00) Moscow, St.Petersburg, Volgograd

79

(GMT-2:00) Brazil-DeNoronha