Integration Devices
FortiDeceptor on FortiGate Security Fabric topology map
Security Fabric integration allows FortiDeceptor and deception decoys to be visible through the Fabric network topology map.
Use Fabric > Integration Devices to configure the integration between FortiDeceptor and FortiGate for Security Fabric.
To configure the integration between FortiDeceptor and FortiGate for Security Fabric:
- In FortiDeceptor, go to Use Fabric > Integration Devices.
- In the Fabric Upstream section, select Enabled.
- Enter the FortiGate IP address in Upstream IP Address and the FortiGate connector port in Port.
- In FortiGate, log in as an admin and go to Security Fabric > Fabric Connectors.
- Add the FortiDeceptor connector for this integration.
- In FortiGate, go to Security Fabric > Physical Topology to verify that the FortiDeceptor is on the topology map.
- In FortiGate, go top Dashboard > Status to view FortiDeceptor information and deception decoys configuration status.
FortiDeceptor integration for threat response mitigation
Use Fabric > Integration Devices to view and configure FortiGate and other device settings for integration with FortiDeceptor. Integration uses REST APIs, XML APIs, or webhooks. When decoys are accessed, FortiDeceptor makes quarantine calls and attackers are immediately quarantined on the device for further analysis.
The following information is displayed:
To integrate a device:
- Go to Fabric > Integration Devices.
- Click Quarantine Integration With New Device.
- Configure the device for integration. Then click Save.
Enabled
Enable or disable this device.
Name
Specify a name for this device.
Block Severity
The selected level and all levels above it are blocked. For example, if you select Medium, then when any attack reaches medium, high, or critical levels, the attacker IP address is blocked. If you select Critical, then only the critical level is blocked.
Appliance
Option for Central Management manager device to integrate the incidents from the specified appliances only.
Integrate Method
The integration method of this device:
- FGT-REST_API
- FGT-WEBHOOK
- PAN-XMLAPI
- GEN-WEBHOOK (FortiNAC can be integrated via GEN-WEBHOOK)
Different integration methods have different settings.
IP or Device IP
IP address of the integrated device.
Port
Port number of the integrated device API service. Default is 443.
Username and password of the integrated device.
VDOM
For FortiGate devices, the default access VDOM.
Expiry
Default blocking time in second. Default is 3600 seconds.