DOCUMENT LIBRARY
DOCUMENT LIBRARY
Products
Best Practices
Hardware Guides
Products A-Z
Summary
By Solution
By 4D Pillars
By Cloud
Secure Networking
Unified SASE
Security Operations
Secure SD-WAN
Secure Access Service Edge (SASE)
ZTNA
LAN Edge
Identity and Access Management
Next Generation Firewall
Public Cloud
Private Cloud
FortiCloud
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
More >>
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiTrust Identity
FortiPAM
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
/
FortiNDR Cloud
FortiDeceptor
FortiRecon
More >>
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
/
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
/
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
/
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
/
FortiNDR Cloud
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Application Delivery
FortiADC
/
FortiGSLB
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/ FortiOS
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Application Gateway
FortiGate/ FortiOS
FortiProxy
FortiADC
/
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
/
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
/
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Wireless
FortiAP / FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiEdge Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiToken Cloud
FortiTrust Identity
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Managed Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Platform as a service (PAAS)
FortiSASE
FortiAnalyzer Cloud
FortiManager Cloud
FortiClient Cloud
FortiSandbox Cloud
FortiMail Cloud
FortiSOAR Cloud
Other SAAS Services
Overlay-as-a-Service
FortiRecon
FortiConverter
ForiIPAM
FortiFlex
FortiCare Elite
4D Resources
Solution Hubs
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
FortiAIOps
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiGate
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
AV Engine
AWS Firewall Rules
AscenLink
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAppSec Cloud
FortiAuthProxy
FortiAuthenticator
FortiAuthenticator Cloud
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCASB
FortiCNP
FortiCWP
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiData
FortiData Private Cloud
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiInsight
FortiInsight Cloud
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRPS
FortiRecon
FortiRecorder
FortiSASE
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSRA Private Cloud
FortiSRA Public Cloud
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSwitch
FortiSwitch Manager
FortiSwitchNMS
FortiTap
FortiTelemetry
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWLM
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
Online Help
What's New
Cloud/Container Protection Switch
FortiCNP Access Management
Cloud Protection Permission Group
Container Protection Permission Group
Global Settings Permission Group
Create Resource Group for Cloud Protection
Create Resource Group for Container Protection
Create User Profile Using Resource Group and Permission Group
Assign Profile to FortiCNP User
Switch Between Multiple Profiles
Global Settings
API Access
IP Address Groups
Cloud Protection
Cloud Protection License and Subscription
AWS Marketplace Subscription
Subscribe Monthly Consumption License through AWS Marketplace
Subscribe Annual Contract License through AWS Marketplace
FortiCloud License Subscription
Cloud Protection Service Usage
Data Protection Service Usage
Unsubscribe or Cancel AWS Marketplace Subscription
About FortiCloud Account Master User
Cloud Account Onboarding Process
Amazon Web Services Account OnBoarding
AWS Permission and Resource Requirements
Automatically Add AWS Account
Add AWS Account Automatically
Update AWS Account Automatically
Manually Add AWS Account
Add AWS Account Manually
Update AWS Account Manually
Update AWS Role External ID
Add Multiple AWS Accounts
Activate Security Token Service (STS)
Setup permissions for Stack Sets Operations
Add Multiple AWS accounts via CloudFormation
Create AWS StackSet for Security Hub Integration
Add AWS Organization
Add AWS Organization
Update AWS Organization
Add AWS Organization Sub Account Status
Fixes for AWS Organization Checklist
Add AWS Organization: Fix No Permission Status
AWS Security Hub and Amazon EventBridge
AWS Security Hub and EventBridge Configuration
AWS Traffic Configuration
Google Cloud Platform Account Onboading
Add Google Cloud Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Add Google Cloud Account
Update Google Cloud Account
Configure Google Workspace Account
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Update Google Cloud Account
Google Cloud Traffic Log Configuration
Microsoft Azure Account Onboarding
Add Microsoft Azure Account
Add Azure Account: CANNOT ADD Subscription Status
Update Microsoft Azure Account
Microsoft Azure Traffic Log Configuration
Cloud Service Integration Pricing
AWS Security Service Charge
Azure Security Center Charge
Google Security Command Center Charge
FortiCNP Insights and Findings
Resource Risk Insights
Resource Risk Insight State
Associated Resources View
Resource Vulnerability View (AWS Only)
Resource Traffic View
Resource Changes View
Findings and Policy Relationship
Example on Using Filter in Findings
Configure Finding States
User Activity Details
Cloud Storage Files Details
Generate FortiCNP Reports
Generate Compliance Report
Compliance Standards
Compliance Standard Configuration Example
Generate C-Level Report
Generate Findings Report
Generate User Activity Report
FortiCNP Policies and Configuration
Risk Management Policy
Create Customized Risk Management Policy
Risk Management Example - CloudTrail should be enabled across all regions
Risk Score Modifier
Create Key-Value Pairs on Cloud Infrastructure Workload
Add Key-Value Pairs to Risk Calculation
Threat Detection Policy
Allowlist Configuration
Threat Protection Example - Suspicious Time
Threat Protection Example - Suspicious Movement
Data Scan Policy
Create Customized Data Pattern
Create Customized Data Scan Policy
Anti-Virus Scan Policy
Data Scan Example - DLP US CA Driver License
Data Scan Example - DLP Visa Credit Card Policy
Integrations Policy
Enable Microsoft Azure Integration
Predefined Policy Configuration
Collections Configuration
User Collection
IP Collection
File Collection
Predefined Compliance Collection
Custom Compliance Collection
Cloud Protection User Admin
Cloud Account Management
Cloud Account Status
Update Cloud Account
Delete Cloud Account
Turn off Cloud Protection
Turn on Cloud Protection
Configure Security Hub Integration (AWS account only)
Cloud Storage Management
Activate Data Protection on Bucket/Container
Disable Data Protection on Storage Bucket/Container
Create Notification Target
Add Amazon SQS Notification Target
Add Amazon SNS Notification Target
Add Jira Notification Target
Jira Software Configuration
Add ServiceNow Notification Target
Create Automatic Notification
Create Resource Risk Insight Automatic Notification
Create Finding Automatic Notification
Create Report Automatic Notification
Create System Information Automatic Notification
FortiCNP APIs
Generate Credentials
Get Credentials Token
Get Refresh Token
Get Resource Map
Get Account Severity Level
Get Alert by Filter
Get Alert Policy List
Get Country List
Get Document Activity
Get Document Detail
Get Document Violation
Get Event
Get Finding List
Get Number of Malware Documents
Get Number of DLP Documents
Get Policy Risk
Get Policy Violation
Get Resource Highlight
Get Resource Config
Get Resource Detail
Get Resource List
Get Resource Risk Level
Get Severity
Get Severity Alert
Get Status Detail
Get Status List
Get Storage Risk
Get Virtual Machine Overview
FortiCNP NAT IP Address
Container Protection
License Overview
Kubernetes Agent
Deploy Kubernetes Agent Command
Upgrade Kubernetes Agent
Uninstall the Current Kubernetes Agent
Kubernetes Agent Log Collection
Support for Traffic Collection with Cilium CNI
Add Credential Store
Add AWS Account - Manual
Add AWS Account - Automatic
Add AWS IAM Role via CloudFormation
AWS Administrator Role Creation
Reference - Role Policy in CloudFormation
Add Azure Account
Add Role to Azure Subscription
Add User Access Administrator Role to Multiple Azure Subscriptions (optional)
Add Azure Account Credential
Add Docker Hub Account
Add Google Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Enable required APIs
Add Google Account
Add Harbor Account
Add OpenShift Account
Openshift Account Configuration
Add OpenShift Account
Add Kubernetes Cluster
AWS Add Kubernetes Cluster - EKS - Auto Deployment
Add IAM Role to Kubernetes Configmap
Make Kubernetes API server accessible by Container Protection
Add Kubernetes Cluster - EKS - Auto Deployment
AWS Add Kubernetes Cluster - EKS - Manual Deployment
AWS Add Kubernetes Cluster - Self Managed - Auto Deployment
AWS Create and Attach Role to EC2 Instance
AWS Kubernetes Service Account Creation
AWS Kubernetes Obtain Access Token
AWS Add Self Managed Kubernetes Cluster - Auto Deployment
AWS Add Kubernetes Cluster - Self Managed - Manual Deployment
Azure Add Kubernetes Cluster - AKS
Azure Add Kubernetes Cluster - Self Managed
Google Cloud Add Kubernetes Cluster - GKE - Auto Deployment
Google Cloud Add Kubernetes Cluster - GKE - Manual Deployment
Google Cloud Add Kubernetes Cluster - Self Managed
Private Cloud Add Kubernetes Cluster - Self Managed
Deploy Kubernetes Agent Controller
Deploy Kubernetes Agent on AWS EKS
Deploy Kubernetes Agent on Azure AKS
Deploy Kubernetes Agent on Google Cloud GKE
Kubernetes Agent and Node Status
Add Registry
Add AWS ECR Registry
Add AWS Registry Example
Add Azure Registry
Add Azure Registry Example
Add Docker Hub Registry
Docker Hub Collaborators Access Configuration
Docker Hub Organization Access Configuration
Add Docker Hub Registry
Add Docker Hub Registry Example
Docker Hub Add Registry Review
Add Google Cloud Registry
Add Google Cloud Registry Example
Add Harbor Cloud Registry
Add Harbor Cloud Registry Example
Add OpenShift Registry
Add OpenShift Registry Example
CI/CD Integration Policy Configuration
Add Policy to CI/CD Integration
Jenkins Configuration
Compliance Policy Configuration
Compliance Audit Setting
FortiView
Container Image
CI/CD Integration Protection
Compliance Assessment
Container Visibility
Cluster Layer
Namespace Layer
Deployment Layer
Pod Layer
Container Traffic
Container Image Scan
Resource Group
Create Resource Group by Rule Matching
Create Resource Group by Specification
Troubleshooting
Cloud Protection
Number of VM exceeds available Cloud Protection license seats
Stack Already Exists Error
AWS Account Checklist Troubleshooting
AWS Marketplace Subscription Troubleshooting
UUID Modified In AWS Account Onboarding
Azure Account Checklist Troubleshooting
Google Cloud Account Checklist Troubleshooting
Container Protection
Error: Update AWS IAM Role
Warning: Do not use the update function to change to a new cluster
Appendix
Appendix A - Cloud Protection Amazon Policy Usage
Appendix B - Container Protection Compliance Audit Configuration File Path
CIS Kubernetes Benchmark 1.5 Configuration File Paths
CIS Kubernetes Benchmark 1.6 Configuration File Paths
Google GKE Compliance Audit Configuration File Paths
Amazon EKS Compliance Audit Configuration File Paths
Appendix C - Regex Syntax Rule
Appendix D - Risk Score Algorithm
Appendix E - Azure API Usage on FortiCNP
Data Retention Policy
End User License Agreements
Home
FortiCNP 22.3.b
Online Help
22.3.b
22.4.a
22.3.b
22.3.a
Container Protection
Container Protection
Credential Store:
Error: Update AWS IAM Role
Kubernetes Cluster :
Warning: Do not use the update function to change to a new cluster
Previous
Next
Container Protection
Container Protection
Credential Store:
Error: Update AWS IAM Role
Kubernetes Cluster :
Warning: Do not use the update function to change to a new cluster
Previous
Next
Home
Products
Summary
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
NOC Management
FortiManager
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
NOC Management
FortiManager
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
More >>
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiTrust Identity
FortiPAM
Early Detection & Prevention
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiRecon
More >>
Security Operations Automation
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
By Solution
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
NOC Management
FortiManager
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiAppSec Cloud
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
By 4D Pillars
Secure SD-WAN
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP / FortiWiFi
FortiExtender
FortiExtender Cloud
Application Delivery
FortiADC
FortiGSLB
Secure Access Service Edge(SASE)
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/ FortiOS
FortiAP / FortiWiFi
FortiExtender
FortiExtender Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
ZTNA
Application Gateway
FortiGate/ FortiOS
FortiProxy
FortiADC
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
LAN Edge
Wireless
FortiAP / FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity and Access Management
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
Next Generation Firewall
FortiGate / FortiOS
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
By Cloud
Public Cloud
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
Private Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
FortiCloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiEdge Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiToken Cloud
FortiTrust Identity
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Best Practices
4D Resources
Define, Design, Deploy, Demo
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Solution Hubs
Curated Links by Solution
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
Hardware Guides
FortiAIOps
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiGate
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Products A-Z
AV Engine
AWS Firewall Rules
AscenLink
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAP / FortiWiFi
FortiAP-U Series
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAppSec Cloud
FortiAuthProxy
FortiAuthenticator
FortiAuthenticator Cloud
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCASB
FortiCNP
FortiCWP
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiData
FortiData Private Cloud
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDevice
FortiEDR/XDR
FortiEdge Cloud
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate CNF
FortiGate Cloud
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGuest
FortiHypervisor
FortiIPAM
FortiInsight
FortiInsight Cloud
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRPS
FortiRecon
FortiRecorder
FortiSASE
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSRA Private Cloud
FortiSRA Public Cloud
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSwitch
FortiSwitch Manager
FortiSwitchNMS
FortiTap
FortiTelemetry
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWLM
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
SOCaaS
Security Awareness and Training
Wireless Controller
Ordering Guides
Table of Contents
What's New
Cloud/Container Protection Switch
FortiCNP Access Management
Cloud Protection Permission Group
Container Protection Permission Group
Global Settings Permission Group
Create Resource Group for Cloud Protection
Create Resource Group for Container Protection
Create User Profile Using Resource Group and Permission Group
Assign Profile to FortiCNP User
Switch Between Multiple Profiles
Global Settings
API Access
IP Address Groups
Cloud Protection
Cloud Protection License and Subscription
AWS Marketplace Subscription
Subscribe Monthly Consumption License through AWS Marketplace
Subscribe Annual Contract License through AWS Marketplace
FortiCloud License Subscription
Cloud Protection Service Usage
Data Protection Service Usage
Unsubscribe or Cancel AWS Marketplace Subscription
About FortiCloud Account Master User
Cloud Account Onboarding Process
Amazon Web Services Account OnBoarding
AWS Permission and Resource Requirements
Automatically Add AWS Account
Add AWS Account Automatically
Update AWS Account Automatically
Manually Add AWS Account
Add AWS Account Manually
Update AWS Account Manually
Update AWS Role External ID
Add Multiple AWS Accounts
Activate Security Token Service (STS)
Setup permissions for Stack Sets Operations
Add Multiple AWS accounts via CloudFormation
Create AWS StackSet for Security Hub Integration
Add AWS Organization
Add AWS Organization
Update AWS Organization
Add AWS Organization Sub Account Status
Fixes for AWS Organization Checklist
Add AWS Organization: Fix No Permission Status
AWS Security Hub and Amazon EventBridge
AWS Security Hub and EventBridge Configuration
AWS Traffic Configuration
Google Cloud Platform Account Onboading
Add Google Cloud Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Add Google Cloud Account
Update Google Cloud Account
Configure Google Workspace Account
Configure Service Account
Grant Service Account API Access
Grant Service Account and Organization Roles
Enable Required APIs
Enable Activity And Alert Monitoring
Update Google Cloud Account
Google Cloud Traffic Log Configuration
Microsoft Azure Account Onboarding
Add Microsoft Azure Account
Add Azure Account: CANNOT ADD Subscription Status
Update Microsoft Azure Account
Microsoft Azure Traffic Log Configuration
Cloud Service Integration Pricing
AWS Security Service Charge
Azure Security Center Charge
Google Security Command Center Charge
FortiCNP Insights and Findings
Resource Risk Insights
Resource Risk Insight State
Associated Resources View
Resource Vulnerability View (AWS Only)
Resource Traffic View
Resource Changes View
Findings and Policy Relationship
Example on Using Filter in Findings
Configure Finding States
User Activity Details
Cloud Storage Files Details
Generate FortiCNP Reports
Generate Compliance Report
Compliance Standards
Compliance Standard Configuration Example
Generate C-Level Report
Generate Findings Report
Generate User Activity Report
FortiCNP Policies and Configuration
Risk Management Policy
Create Customized Risk Management Policy
Risk Management Example - CloudTrail should be enabled across all regions
Risk Score Modifier
Create Key-Value Pairs on Cloud Infrastructure Workload
Add Key-Value Pairs to Risk Calculation
Threat Detection Policy
Allowlist Configuration
Threat Protection Example - Suspicious Time
Threat Protection Example - Suspicious Movement
Data Scan Policy
Create Customized Data Pattern
Create Customized Data Scan Policy
Anti-Virus Scan Policy
Data Scan Example - DLP US CA Driver License
Data Scan Example - DLP Visa Credit Card Policy
Integrations Policy
Enable Microsoft Azure Integration
Predefined Policy Configuration
Collections Configuration
User Collection
IP Collection
File Collection
Predefined Compliance Collection
Custom Compliance Collection
Cloud Protection User Admin
Cloud Account Management
Cloud Account Status
Update Cloud Account
Delete Cloud Account
Turn off Cloud Protection
Turn on Cloud Protection
Configure Security Hub Integration (AWS account only)
Cloud Storage Management
Activate Data Protection on Bucket/Container
Disable Data Protection on Storage Bucket/Container
Create Notification Target
Add Amazon SQS Notification Target
Add Amazon SNS Notification Target
Add Jira Notification Target
Jira Software Configuration
Add ServiceNow Notification Target
Create Automatic Notification
Create Resource Risk Insight Automatic Notification
Create Finding Automatic Notification
Create Report Automatic Notification
Create System Information Automatic Notification
FortiCNP APIs
Generate Credentials
Get Credentials Token
Get Refresh Token
Get Resource Map
Get Account Severity Level
Get Alert by Filter
Get Alert Policy List
Get Country List
Get Document Activity
Get Document Detail
Get Document Violation
Get Event
Get Finding List
Get Number of Malware Documents
Get Number of DLP Documents
Get Policy Risk
Get Policy Violation
Get Resource Highlight
Get Resource Config
Get Resource Detail
Get Resource List
Get Resource Risk Level
Get Severity
Get Severity Alert
Get Status Detail
Get Status List
Get Storage Risk
Get Virtual Machine Overview
FortiCNP NAT IP Address
Container Protection
License Overview
Kubernetes Agent
Deploy Kubernetes Agent Command
Upgrade Kubernetes Agent
Uninstall the Current Kubernetes Agent
Kubernetes Agent Log Collection
Support for Traffic Collection with Cilium CNI
Add Credential Store
Add AWS Account - Manual
Add AWS Account - Automatic
Add AWS IAM Role via CloudFormation
AWS Administrator Role Creation
Reference - Role Policy in CloudFormation
Add Azure Account
Add Role to Azure Subscription
Add User Access Administrator Role to Multiple Azure Subscriptions (optional)
Add Azure Account Credential
Add Docker Hub Account
Add Google Account
Configure Google Workspace Account
Configure OAuth Consent Screen
Configure Service Account
Enable required APIs
Add Google Account
Add Harbor Account
Add OpenShift Account
Openshift Account Configuration
Add OpenShift Account
Add Kubernetes Cluster
AWS Add Kubernetes Cluster - EKS - Auto Deployment
Add IAM Role to Kubernetes Configmap
Make Kubernetes API server accessible by Container Protection
Add Kubernetes Cluster - EKS - Auto Deployment
AWS Add Kubernetes Cluster - EKS - Manual Deployment
AWS Add Kubernetes Cluster - Self Managed - Auto Deployment
AWS Create and Attach Role to EC2 Instance
AWS Kubernetes Service Account Creation
AWS Kubernetes Obtain Access Token
AWS Add Self Managed Kubernetes Cluster - Auto Deployment
AWS Add Kubernetes Cluster - Self Managed - Manual Deployment
Azure Add Kubernetes Cluster - AKS
Azure Add Kubernetes Cluster - Self Managed
Google Cloud Add Kubernetes Cluster - GKE - Auto Deployment
Google Cloud Add Kubernetes Cluster - GKE - Manual Deployment
Google Cloud Add Kubernetes Cluster - Self Managed
Private Cloud Add Kubernetes Cluster - Self Managed
Deploy Kubernetes Agent Controller
Deploy Kubernetes Agent on AWS EKS
Deploy Kubernetes Agent on Azure AKS
Deploy Kubernetes Agent on Google Cloud GKE
Kubernetes Agent and Node Status
Add Registry
Add AWS ECR Registry
Add AWS Registry Example
Add Azure Registry
Add Azure Registry Example
Add Docker Hub Registry
Docker Hub Collaborators Access Configuration
Docker Hub Organization Access Configuration
Add Docker Hub Registry
Add Docker Hub Registry Example
Docker Hub Add Registry Review
Add Google Cloud Registry
Add Google Cloud Registry Example
Add Harbor Cloud Registry
Add Harbor Cloud Registry Example
Add OpenShift Registry
Add OpenShift Registry Example
CI/CD Integration Policy Configuration
Add Policy to CI/CD Integration
Jenkins Configuration
Compliance Policy Configuration
Compliance Audit Setting
FortiView
Container Image
CI/CD Integration Protection
Compliance Assessment
Container Visibility
Cluster Layer
Namespace Layer
Deployment Layer
Pod Layer
Container Traffic
Container Image Scan
Resource Group
Create Resource Group by Rule Matching
Create Resource Group by Specification
Troubleshooting
Cloud Protection
Number of VM exceeds available Cloud Protection license seats
Stack Already Exists Error
AWS Account Checklist Troubleshooting
AWS Marketplace Subscription Troubleshooting
UUID Modified In AWS Account Onboarding
Azure Account Checklist Troubleshooting
Google Cloud Account Checklist Troubleshooting
Container Protection
Error: Update AWS IAM Role
Warning: Do not use the update function to change to a new cluster
Appendix
Appendix A - Cloud Protection Amazon Policy Usage
Appendix B - Container Protection Compliance Audit Configuration File Path
CIS Kubernetes Benchmark 1.5 Configuration File Paths
CIS Kubernetes Benchmark 1.6 Configuration File Paths
Google GKE Compliance Audit Configuration File Paths
Amazon EKS Compliance Audit Configuration File Paths
Appendix C - Regex Syntax Rule
Appendix D - Risk Score Algorithm
Appendix E - Azure API Usage on FortiCNP
Data Retention Policy
End User License Agreements