Fortinet white logo
Fortinet white logo

EMS Administration Guide

Creating a Fabric connector

Creating a Fabric connector

EMS supports new Fortinet Security Fabric connectors that use token authentication, with the server creating the connection. Previously, Fabric connectors only used certificate authentication, with the client (FortiGate) creating the connection by sending a request to the server (EMS). EMS creates a client ID and secret, which the client uses to obtain a JSON web access token. The client uses the token as a bearer token for authentication to call EMS APIs. EMS newly supports Fabric connector for the following Fortinet products:

  • FortiADC
  • FortiAnalyzer
  • FortiEDR
  • FortiManager
  • FortiSIEM
  • FortiToken Cloud
  • FortiWeb
To create a connector:
  1. Go to Fabric & Connectors > Fabric Devices.
  2. Under OAuth 2.0 Fabric Connectors, click Add.
  3. Configure the connector:
    1. From the Connector Type dropdown list, select the desired Fortinet product to connect to.
    2. In the Serial Number field, enter the device serial number.
    3. In the VDOM (Optional) field, enter the virtual domain (VDOM) name if desired. Only enter a VDOM name if you want to create a connector for a single VDOM on a device. Click Next.

    4. From the Role dropdown list, select the desired admin role. The role defines which EMS APIs the connector is authorized to access. See Admin roles.
    5. In the Token Lifetime field, enter the desired token lifetime in seconds. After the token lifetime expires, the token is no longer authorized to provide EMS API access. The default value is 3600 seconds. Enter a value greater than 60 seconds.
    6. In the Alias (Optional) field, enter the desired alias.
    7. Click Finish.

    8. EMS displays a dialog that contains the client ID and secret. Copy the ID and secret to a clipboard. EMS will not display the secret again. You may need to provide them on the Fortinet device that you have created the connector for. Click Close.
    9. Click Yes in the confirmation dialog.

Creating a Fabric connector

Creating a Fabric connector

EMS supports new Fortinet Security Fabric connectors that use token authentication, with the server creating the connection. Previously, Fabric connectors only used certificate authentication, with the client (FortiGate) creating the connection by sending a request to the server (EMS). EMS creates a client ID and secret, which the client uses to obtain a JSON web access token. The client uses the token as a bearer token for authentication to call EMS APIs. EMS newly supports Fabric connector for the following Fortinet products:

  • FortiADC
  • FortiAnalyzer
  • FortiEDR
  • FortiManager
  • FortiSIEM
  • FortiToken Cloud
  • FortiWeb
To create a connector:
  1. Go to Fabric & Connectors > Fabric Devices.
  2. Under OAuth 2.0 Fabric Connectors, click Add.
  3. Configure the connector:
    1. From the Connector Type dropdown list, select the desired Fortinet product to connect to.
    2. In the Serial Number field, enter the device serial number.
    3. In the VDOM (Optional) field, enter the virtual domain (VDOM) name if desired. Only enter a VDOM name if you want to create a connector for a single VDOM on a device. Click Next.

    4. From the Role dropdown list, select the desired admin role. The role defines which EMS APIs the connector is authorized to access. See Admin roles.
    5. In the Token Lifetime field, enter the desired token lifetime in seconds. After the token lifetime expires, the token is no longer authorized to provide EMS API access. The default value is 3600 seconds. Enter a value greater than 60 seconds.
    6. In the Alias (Optional) field, enter the desired alias.
    7. Click Finish.

    8. EMS displays a dialog that contains the client ID and secret. Copy the ID and secret to a clipboard. EMS will not display the secret again. You may need to provide them on the Fortinet device that you have created the connector for. Click Close.
    9. Click Yes in the confirmation dialog.