Fortinet Document Library

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

Administration Guide

Integration Devices

Use Fabric > Integration Devices to view and configure FortiGate and other device settings for integration with FortiDeceptor. Integration uses REST APIs, XML APIs, or webhooks. When decoys are accessed, FortiDeceptor makes quarantine calls and attackers are immediately quarantined on the device for further analysis.

The following information is displayed:

Action

Click Edit to edit the integration settings.

Click Delete to delete the device.

Enabled

Shows if the device is enabled or disabled.

Status

Device status.

Name

Alias of the integrated device.

Integrate Method

The integration method of this device.

Severity

Security level. The selected level and all levels above it are blocked. For example, if you select Medium, then medium, high, and critical levels are blocked. If you select Critical, then only the critical level is blocked.

Detail

Device integration details.

To integrate a device:
  1. Go to Fabric > Integration Devices.
  2. Click Integrate With New Device.
  3. Configure the device for integration. Then click Save.

    Enabled

    Enable or disable this device.

    Name

    Specify a name for this device.

    Block Severity

    Select the security level. The selected level and all levels above it are blocked. For example, if you select Medium, then medium, high, and critical levels are blocked. If you select Critical, then only the critical level is blocked.

    Integrate Method

    The integration method of this device.

    Different integration methods have different settings.

    IP or Device IP

    IP address of the integrated device.

    Port

    Port number of the integrated device API service. Default is 443.

    Username and Password

    Username and password of the integrated device.

    VDOM

    For FortiGate devices, the default access VDOM.

    Expiry

    Default blocking time in second. Default is 3600 seconds.

    Block Action

    For integration by webhook, specify the Expiry, URL, Authorization, HTTP Method, HTTP Header, and HTTP Data for the block action.

    HTTP Header and HTTP Data allow you to use field names and values. You can also add multiple HTTP header and data fields.

    Unblock Action

    For integration by webhook, specify the URL, Authorization, HTTP Method, HTTP Header, and HTTP Data for the unblock action.

Integration Devices

Use Fabric > Integration Devices to view and configure FortiGate and other device settings for integration with FortiDeceptor. Integration uses REST APIs, XML APIs, or webhooks. When decoys are accessed, FortiDeceptor makes quarantine calls and attackers are immediately quarantined on the device for further analysis.

The following information is displayed:

Action

Click Edit to edit the integration settings.

Click Delete to delete the device.

Enabled

Shows if the device is enabled or disabled.

Status

Device status.

Name

Alias of the integrated device.

Integrate Method

The integration method of this device.

Severity

Security level. The selected level and all levels above it are blocked. For example, if you select Medium, then medium, high, and critical levels are blocked. If you select Critical, then only the critical level is blocked.

Detail

Device integration details.

To integrate a device:
  1. Go to Fabric > Integration Devices.
  2. Click Integrate With New Device.
  3. Configure the device for integration. Then click Save.

    Enabled

    Enable or disable this device.

    Name

    Specify a name for this device.

    Block Severity

    Select the security level. The selected level and all levels above it are blocked. For example, if you select Medium, then medium, high, and critical levels are blocked. If you select Critical, then only the critical level is blocked.

    Integrate Method

    The integration method of this device.

    Different integration methods have different settings.

    IP or Device IP

    IP address of the integrated device.

    Port

    Port number of the integrated device API service. Default is 443.

    Username and Password

    Username and password of the integrated device.

    VDOM

    For FortiGate devices, the default access VDOM.

    Expiry

    Default blocking time in second. Default is 3600 seconds.

    Block Action

    For integration by webhook, specify the Expiry, URL, Authorization, HTTP Method, HTTP Header, and HTTP Data for the block action.

    HTTP Header and HTTP Data allow you to use field names and values. You can also add multiple HTTP header and data fields.

    Unblock Action

    For integration by webhook, specify the URL, Authorization, HTTP Method, HTTP Header, and HTTP Data for the unblock action.