Integration with PAN devices
To integrate FortiDeceptor with PAN devices:
- Configure PAN.
- Configure the PAN device on FortiDeceptor.
- Check the PAN status on FortiDeceptor.
- Verify the policy has been added on PAN.
- Attack a decoy and check the quarantine status in FortiDeceptor.
1. Configure PAN
Create an administrator on the PAN device. For information, see the PAN-OS Administrator’s Guide.
2. Configure the PAN device on FortiDeceptor
- In FortiDeceptor, go to Fabric > Quarantine Integration and click + Quarantine Integration with new device.
- Configure the integration settings and click Save.
Enabled
Enable
Name
Enter a name for the integration.
Integration Method Select PAN-XMLAPI. Device IP Enter the IP for the PAN device. Port
Enter the port number for the PAN device.
Username Enter the username for the PAN device. Password Enter the password the PAN device. Vsys
The virtual system (Vsys) which is configured on the PAN device.
Policy Index
Select Top or Bottom.
Expiry
Default blocking time in seconds. Default is 3600 seconds.
3. Check the PAN status on FortiDeceptor
In FortiDeceptor, click Quarantine Integration and verify the PAN device status is Ready.
4. Verify the policy has been added on PAN
For more information about PAN polices, see the PAN-OS Administrator’s Guide.
5. Attack a decoy and check the quarantine status in FortiDeceptor
To check quarantine status in FortiDeceptor:
- Go to Fabric > Quarantine Status.
- Search for the PAN device in the Integrated Device column.