Integrate with FortiGate 7.2.0 over REST-API
The following instructions are based on FortiGate 7.2.0 and FortiDeceptor 4.3.0. For information about the versions of FortiGate and FortiDeceptor you are using, select the version in the Fortinet Document Library.
1. Configure FortiGate
1.1 Configure a new profile with minimum permissions for REST API integration
- On FortiGate, go to System > Admin Profiles and click Create New.
- Configure the profile Access Permissions. The following are the minimum required permissions.
Access Control
Permissions
Security Fabric Read/Write FortiView Read User & Device Read/Write Firewall Read Log & Report Read Network Read System Read/Write Security Profile Read VPN Read WAN Opt & Cache Read WiFi & Switch Read
1.2 Create a new administrator
- On FortiGate, go to System > Administrators.
- Click Create New > Administrator.
- Enter a Username and Password for the administrator.
- From the Administrator profile dropdown, select the profile you created in step 1.1 Create the administrator profile in FortiGate.
- Click OK.
2. Configure FortiDeceptor to integrate with FortiGate
-
In FortiDeceptor, go to Fabric > Quarantine Integration and click Quarantine Integration With New Device.
- Configure the integration settings and click OK.
Enabled Enable the integration. Name Enter a name for the integration. Integrate Method Select FGT-REST-API. IP Enter the IP address of the FortiGate. Port Enter the Port for the FortiGate. Username Enter the username for the admin you just created. Password Enter the password for the admin you just created. Vdom
Enter the VDOM the FortiGate belongs to.
- Verify the integration Status is Ready.
3. Test the integration
- Send an attack against a decoy.
- On FortiDeceptor, check the quarantine status.
- On FortiGate, go to Dashboard > Users Device and expand the Quarantine widget to check quarantine status.
- (Optional) Check the quarantine status on FortiDeceptor after it has expired.
- On FortiDeceptor, go to Fabric > Quarantine Status to check the status.
- (Optional) Check the quarantine status on FortiGate after it has expired.
- On FortiGate, go to Dashboard > Users Device and expand the Quarantine widget to check quarantine status.