Document
Library
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiProxy
NOC & SOC Management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
/
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
/
FortiVoice Cloud
FortiRecorder
/
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
/
FortiWeb Cloud
FortiADC
/
FortiGSLB
FortiGuard ABP
SAAS Security
FortiMail
/
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
/
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
/
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Curated links by solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Define, Design, Deploy, Demo
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Hardware Guides
Filter Products
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
Filter Products
AscenLink
AV Engine
AWS Firewall Rules
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR/XDR
FortiExplorer
FortiExplorer Go
FortiExtender
FortiExtender Cloud
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Search documents and hardware ...
Online Help
What's New
Cloud/Container Protection Switch
FortiCNP Access Management
Cloud Protection Permission Group
Container Protection Permission Group
Global Settings Permission Group
Create Resource Group for Cloud Protection
Create Resource Group for Container Protection
Create User Profile Using Resource Group and Permission Group
Assign Profile to FortiCNP User
Switch Between Multiple Profiles
Global Settings
API Access
IP Address Groups
Cloud Protection
Cloud Protection License and Subscription
AWS Marketplace Subscription
Subscribe Monthly Consumption License through AWS Marketplace
Subscribe Annual Contract License through AWS Marketplace
FortiCloud License Subscription
Cloud Protection Service Usage
Data Protection Service Usage
Unsubscribe or Cancel AWS Marketplace Subscription
About FortiCloud Account Master User
Amazon Web Services Account OnBoarding
AWS Permission and Resource Requirements
Automatically Add AWS Account
Add AWS Account Automatically
Update AWS Account Automatically
Manually Add AWS Account
Add AWS Account Manually
Update AWS Account Manually
Update AWS Role External ID
Add Multiple AWS Accounts
Activate Security Token Service (STS)
Setup permissions for Stack Sets Operations
Add Multiple AWS accounts via CloudFormation
Create AWS StackSet for Security Hub Integration
Add AWS Organization
Add AWS Organization
Update AWS Organization
Add AWS Organization Sub Account Status
Fixes for AWS Organization Checklist
Add AWS Organization: Fix No Permission Status
AWS Security Hub and Amazon EventBridge
AWS Security Hub and EventBridge Configuration
AWS Traffic Configuration
Google Cloud Platform Account Onboading
Add Google Cloud Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Add Google Cloud Account
Update Google Cloud Account
Configure Google Workspace Account
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Update Google Cloud Account
Google Cloud Traffic Log Configuration
Microsoft Azure Account Onboarding
Add Microsoft Azure Account
Add Azure Account: CANNOT ADD Subscription Status
Update Microsoft Azure Account
Microsoft Azure Traffic Log Configuration
Cloud Service Integration Pricing
AWS Security Service Charge
Azure Security Center Charge
Google Security Command Center Charge
FortiCNP Insights and Findings
Resource Risk Insights
Resource Risk Insight State
Associated Resources View
Resource Vulnerability View (AWS Only)
Resource Traffic View
Resource Changes View
Findings and Policy Relationship
Example on Using Filter in Findings
Configure Finding States
User Activity Details
Cloud Storage Files Details
Generate FortiCNP Reports
Generate Compliance Report
Compliance Standards
Compliance Standard Configuration Example
Generate C-Level Report
Generate Findings Report
Generate User Activity Report
FortiCNP Policies and Configuration
Risk Management Policy
Create Customized Risk Management Policy
Risk Management Example - CloudTrail should be enabled across all regions
Risk Score Modifier
Create Key-Value Pairs on Cloud Infrastructure Workload
Add Key-Value Pairs to Risk Calculation
Threat Detection Policy
Allowlist Configuration
Threat Protection Example - Suspicious Time
Threat Protection Example - Suspicious Movement
Data Scan Policy
Create Customized Data Pattern
Create Customized Data Scan Policy
Anti-Virus Scan Policy
Data Scan Example - DLP US CA Driver License
Data Scan Example - DLP Visa Credit Card Policy
Integrations Policy
Enable Microsoft Azure Integration
Predefined Policy Configuration
Collections Configuration
User Collection
IP Collection
File Collection
Predefined Compliance Collection
Custom Compliance Collection
Cloud Protection User Admin
Cloud Account Management
Cloud Account Status
Update Cloud Account
Delete Cloud Account
Turn off Cloud Protection
Turn on Cloud Protection
Cloud Storage Management
Activate Data Protection on Bucket/Container
Disable Data Protection on Storage Bucket/Container
Cloud Protection Notification Configuration
Add Email Notification Target
Add Amazon SQS Notification Target
Add Amazon SNS Notification Target
Add Jira Notification Target
Jira Software Configuration
Add ServiceNow Notification Target
FortiCNP APIs
Generate Credentials
Get Credentials Token
Get Refresh Token
Get Resource Map
Get Account Severity Level
Get Alert by Filter
Get Alert Policy List
Get Country List
Get Document Activity
Get Document Detail
Get Document Violation
Get Event
Get Finding List
Get Number of Malware Documents
Get Number of DLP Documents
Get Policy Risk
Get Policy Violation
Get Resource Highlight
Get Resource Config
Get Resource Detail
Get Resource List
Get Resource Risk Level
Get Severity
Get Severity Alert
Get Status Detail
Get Status List
Get Storage Risk
Get Virtual Machine Overview
Container Protection
License Overview
Kubernetes Agent
Deploy Kubernetes Agent Command
Upgrade Kubernetes Agent
Uninstall the Current Kubernetes Agent
Kubernetes Agent Log Collection
Support for Traffic Collection with Cilium CNI
Add Credential Store
Add AWS Account - Manual
Add AWS Account - Automatic
Add AWS IAM Role via CloudFormation
AWS Administrator Role Creation
Reference - Role Policy in CloudFormation
Add Azure Account
Add Role to Azure Subscription
Add User Access Administrator Role to Multiple Azure Subscriptions (optional)
Add Azure Account Credential
Add Docker Hub Account
Add Google Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Enable required APIs
Add Google Account
Add Harbor Account
Add OpenShift Account
Openshift Account Configuration
Add OpenShift Account
Add Kubernetes Cluster
AWS Add Kubernetes Cluster - EKS - Auto Deployment
Add IAM Role to Kubernetes Configmap
Make Kubernetes API server accessible by Container Protection
Add Kubernetes Cluster - EKS - Auto Deployment
AWS Add Kubernetes Cluster - EKS - Manual Deployment
AWS Add Kubernetes Cluster - Self Managed - Auto Deployment
AWS Create and Attach Role to EC2 Instance
AWS Kubernetes Service Account Creation
AWS Kubernetes Obtain Access Token
AWS Add Self Managed Kubernetes Cluster - Auto Deployment
AWS Add Kubernetes Cluster - Self Managed - Manual Deployment
Azure Add Kubernetes Cluster - AKS
Azure Add Kubernetes Cluster - Self Managed
Google Cloud Add Kubernetes Cluster - GKE - Auto Deployment
Google Cloud Add Kubernetes Cluster - GKE - Manual Deployment
Google Cloud Add Kubernetes Cluster - Self Managed
Private Cloud Add Kubernetes Cluster - Self Managed
Deploy Kubernetes Agent Controller
Deploy Kubernetes Agent on AWS EKS
Deploy Kubernetes Agent on Azure AKS
Deploy Kubernetes Agent on Google Cloud GKE
Kubernetes Agent and Node Status
Add Registry
Add AWS ECR Registry
Add AWS Registry Example
Add Azure Registry
Add Azure Registry Example
Add Docker Hub Registry
Docker Hub Collaborators Access Configuration
Docker Hub Organization Access Configuration
Add Docker Hub Registry
Add Docker Hub Registry Example
Docker Hub Add Registry Review
Add Google Cloud Registry
Add Google Cloud Registry Example
Add Harbor Cloud Registry
Add Harbor Cloud Registry Example
Add OpenShift Registry
Add OpenShift Registry Example
CI/CD Integration Policy Configuration
Add Policy to CI/CD Integration
Jenkins Configuration
Compliance Policy Configuration
Compliance Audit Setting
FortiView
Container Image
CI/CD Integration Protection
Compliance Assessment
Container Visibility
Cluster Layer
Namespace Layer
Deployment Layer
Pod Layer
Container Traffic
Container Image Scan
Resource Group
Create Resource Group by Rule Matching
Create Resource Group by Specification
Troubleshooting
Cloud Protection
Number of VM exceeds available Cloud Protection license seats
Stack Already Exists Error
AWS Account Checklist Troubleshooting
AWS Marketplace Subscription Troubleshooting
Azure Account Checklist Troubleshooting
Google Cloud Account Checklist Troubleshooting
Container Protection
Error: Update AWS IAM Role
Warning: Do not use the update function to change to a new cluster
Appendix
Appendix A - Cloud Protection Amazon Policy Usage
Appendix B - Container Protection Compliance Audit Configuration File Path
CIS Kubernetes Benchmark 1.5 Configuration File Paths
CIS Kubernetes Benchmark 1.6 Configuration File Paths
Google GKE Compliance Audit Configuration File Paths
Amazon EKS Compliance Audit Configuration File Paths
Appendix C - Regex Syntax Rule
Appendix D - Risk Score Algorithm
Data Retention Policy
End User License Agreements
Home
FortiCNP 22.3.a
Online Help
Troubleshooting
22.3.a
22.4.a
22.3.b
22.3.a
Copy Link
Copy Doc ID
cf00dcb1-0886-11ed-bb32-fa163e15d75b:380306
Troubleshooting
Previous
Next
Troubleshooting
Previous
Next
Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
FortiGuard ABP
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR/XDR
FortiExplorer
FortiExplorer Go
FortiExtender
FortiExtender Cloud
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Table of Contents
What's New
Cloud/Container Protection Switch
FortiCNP Access Management
Cloud Protection Permission Group
Container Protection Permission Group
Global Settings Permission Group
Create Resource Group for Cloud Protection
Create Resource Group for Container Protection
Create User Profile Using Resource Group and Permission Group
Assign Profile to FortiCNP User
Switch Between Multiple Profiles
Global Settings
API Access
IP Address Groups
Cloud Protection
Cloud Protection License and Subscription
AWS Marketplace Subscription
Subscribe Monthly Consumption License through AWS Marketplace
Subscribe Annual Contract License through AWS Marketplace
FortiCloud License Subscription
Cloud Protection Service Usage
Data Protection Service Usage
Unsubscribe or Cancel AWS Marketplace Subscription
About FortiCloud Account Master User
Amazon Web Services Account OnBoarding
AWS Permission and Resource Requirements
Automatically Add AWS Account
Add AWS Account Automatically
Update AWS Account Automatically
Manually Add AWS Account
Add AWS Account Manually
Update AWS Account Manually
Update AWS Role External ID
Add Multiple AWS Accounts
Activate Security Token Service (STS)
Setup permissions for Stack Sets Operations
Add Multiple AWS accounts via CloudFormation
Create AWS StackSet for Security Hub Integration
Add AWS Organization
Add AWS Organization
Update AWS Organization
Add AWS Organization Sub Account Status
Fixes for AWS Organization Checklist
Add AWS Organization: Fix No Permission Status
AWS Security Hub and Amazon EventBridge
AWS Security Hub and EventBridge Configuration
AWS Traffic Configuration
Google Cloud Platform Account Onboading
Add Google Cloud Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Add Google Cloud Account
Update Google Cloud Account
Configure Google Workspace Account
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Update Google Cloud Account
Google Cloud Traffic Log Configuration
Microsoft Azure Account Onboarding
Add Microsoft Azure Account
Add Azure Account: CANNOT ADD Subscription Status
Update Microsoft Azure Account
Microsoft Azure Traffic Log Configuration
Cloud Service Integration Pricing
AWS Security Service Charge
Azure Security Center Charge
Google Security Command Center Charge
FortiCNP Insights and Findings
Resource Risk Insights
Resource Risk Insight State
Associated Resources View
Resource Vulnerability View (AWS Only)
Resource Traffic View
Resource Changes View
Findings and Policy Relationship
Example on Using Filter in Findings
Configure Finding States
User Activity Details
Cloud Storage Files Details
Generate FortiCNP Reports
Generate Compliance Report
Compliance Standards
Compliance Standard Configuration Example
Generate C-Level Report
Generate Findings Report
Generate User Activity Report
FortiCNP Policies and Configuration
Risk Management Policy
Create Customized Risk Management Policy
Risk Management Example - CloudTrail should be enabled across all regions
Risk Score Modifier
Create Key-Value Pairs on Cloud Infrastructure Workload
Add Key-Value Pairs to Risk Calculation
Threat Detection Policy
Allowlist Configuration
Threat Protection Example - Suspicious Time
Threat Protection Example - Suspicious Movement
Data Scan Policy
Create Customized Data Pattern
Create Customized Data Scan Policy
Anti-Virus Scan Policy
Data Scan Example - DLP US CA Driver License
Data Scan Example - DLP Visa Credit Card Policy
Integrations Policy
Enable Microsoft Azure Integration
Predefined Policy Configuration
Collections Configuration
User Collection
IP Collection
File Collection
Predefined Compliance Collection
Custom Compliance Collection
Cloud Protection User Admin
Cloud Account Management
Cloud Account Status
Update Cloud Account
Delete Cloud Account
Turn off Cloud Protection
Turn on Cloud Protection
Cloud Storage Management
Activate Data Protection on Bucket/Container
Disable Data Protection on Storage Bucket/Container
Cloud Protection Notification Configuration
Add Email Notification Target
Add Amazon SQS Notification Target
Add Amazon SNS Notification Target
Add Jira Notification Target
Jira Software Configuration
Add ServiceNow Notification Target
FortiCNP APIs
Generate Credentials
Get Credentials Token
Get Refresh Token
Get Resource Map
Get Account Severity Level
Get Alert by Filter
Get Alert Policy List
Get Country List
Get Document Activity
Get Document Detail
Get Document Violation
Get Event
Get Finding List
Get Number of Malware Documents
Get Number of DLP Documents
Get Policy Risk
Get Policy Violation
Get Resource Highlight
Get Resource Config
Get Resource Detail
Get Resource List
Get Resource Risk Level
Get Severity
Get Severity Alert
Get Status Detail
Get Status List
Get Storage Risk
Get Virtual Machine Overview
Container Protection
License Overview
Kubernetes Agent
Deploy Kubernetes Agent Command
Upgrade Kubernetes Agent
Uninstall the Current Kubernetes Agent
Kubernetes Agent Log Collection
Support for Traffic Collection with Cilium CNI
Add Credential Store
Add AWS Account - Manual
Add AWS Account - Automatic
Add AWS IAM Role via CloudFormation
AWS Administrator Role Creation
Reference - Role Policy in CloudFormation
Add Azure Account
Add Role to Azure Subscription
Add User Access Administrator Role to Multiple Azure Subscriptions (optional)
Add Azure Account Credential
Add Docker Hub Account
Add Google Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Enable required APIs
Add Google Account
Add Harbor Account
Add OpenShift Account
Openshift Account Configuration
Add OpenShift Account
Add Kubernetes Cluster
AWS Add Kubernetes Cluster - EKS - Auto Deployment
Add IAM Role to Kubernetes Configmap
Make Kubernetes API server accessible by Container Protection
Add Kubernetes Cluster - EKS - Auto Deployment
AWS Add Kubernetes Cluster - EKS - Manual Deployment
AWS Add Kubernetes Cluster - Self Managed - Auto Deployment
AWS Create and Attach Role to EC2 Instance
AWS Kubernetes Service Account Creation
AWS Kubernetes Obtain Access Token
AWS Add Self Managed Kubernetes Cluster - Auto Deployment
AWS Add Kubernetes Cluster - Self Managed - Manual Deployment
Azure Add Kubernetes Cluster - AKS
Azure Add Kubernetes Cluster - Self Managed
Google Cloud Add Kubernetes Cluster - GKE - Auto Deployment
Google Cloud Add Kubernetes Cluster - GKE - Manual Deployment
Google Cloud Add Kubernetes Cluster - Self Managed
Private Cloud Add Kubernetes Cluster - Self Managed
Deploy Kubernetes Agent Controller
Deploy Kubernetes Agent on AWS EKS
Deploy Kubernetes Agent on Azure AKS
Deploy Kubernetes Agent on Google Cloud GKE
Kubernetes Agent and Node Status
Add Registry
Add AWS ECR Registry
Add AWS Registry Example
Add Azure Registry
Add Azure Registry Example
Add Docker Hub Registry
Docker Hub Collaborators Access Configuration
Docker Hub Organization Access Configuration
Add Docker Hub Registry
Add Docker Hub Registry Example
Docker Hub Add Registry Review
Add Google Cloud Registry
Add Google Cloud Registry Example
Add Harbor Cloud Registry
Add Harbor Cloud Registry Example
Add OpenShift Registry
Add OpenShift Registry Example
CI/CD Integration Policy Configuration
Add Policy to CI/CD Integration
Jenkins Configuration
Compliance Policy Configuration
Compliance Audit Setting
FortiView
Container Image
CI/CD Integration Protection
Compliance Assessment
Container Visibility
Cluster Layer
Namespace Layer
Deployment Layer
Pod Layer
Container Traffic
Container Image Scan
Resource Group
Create Resource Group by Rule Matching
Create Resource Group by Specification
Troubleshooting
Cloud Protection
Number of VM exceeds available Cloud Protection license seats
Stack Already Exists Error
AWS Account Checklist Troubleshooting
AWS Marketplace Subscription Troubleshooting
Azure Account Checklist Troubleshooting
Google Cloud Account Checklist Troubleshooting
Container Protection
Error: Update AWS IAM Role
Warning: Do not use the update function to change to a new cluster
Appendix
Appendix A - Cloud Protection Amazon Policy Usage
Appendix B - Container Protection Compliance Audit Configuration File Path
CIS Kubernetes Benchmark 1.5 Configuration File Paths
CIS Kubernetes Benchmark 1.6 Configuration File Paths
Google GKE Compliance Audit Configuration File Paths
Amazon EKS Compliance Audit Configuration File Paths
Appendix C - Regex Syntax Rule
Appendix D - Risk Score Algorithm
Data Retention Policy
End User License Agreements