Deploying decoys
Verify there are multiple IPs on the Azure platform and then configure the decoy on FortiDeceptor.
To verify there are multiple IPs on the Azure platform:
- In Azure, select the configuration to deploy the decoys.
- Go to Settings > IP configurations. The IPs are displayed in the Private IP column.
To locate the on the Azure platform:
Go to Network Setting >Properties.
To configure the decoy on FortiDeceptor:
- In FortiDeceptor, go to Deception Deployment Wizard and create a new template.
- In the Configuration tab, next to Available Deception OSes, select the Azure cloud device.
- In the Set Network tab, click Add network for Deployment and configure the following settings:
Deploy Network Select one of the multiple interfaces. Mac Address The related MAC address is auto-populated when you select a port.
NOTE: The MAC addresses of the decoys must match those populated in Azure. To avoid connection issues, we recommend verifying the address is correct. To verify the MAC address in Azure, go to Network Settings > Properties.
IP Ranges Enter one IP address. - Click Done to deploy the decoy.
- (Optional) Deploy more decoys.
To deploy decoys for different interfaces, repeat Verify there are multiple IPs on the Azure platform.
To deploy more decoys for the same interface, repeat steps 1-4.
- Attack this decoy IP via the endpoint in the cloud and check the incidents as regular deployment.