Edge appliance manager
Topology
The following topology shows a network with an on-premise FortiDeceptor connected to a FortiDeceptor Edge appliance by a Layer 2 tunnel. The Layer 2 tunnel is a private tunnel protocol similar to SSL/TLS. The FortiDeceptor Layer 2 tunnel is embedded with its own authentication and encryption methods as well as heartbeat checks on top of SSL/TLS.
To configure the Edge appliance manager:
- On the management device, do one of the following:
- Go to Dashboard > Status. In the System Information widget, locate Edge Appliance Manager and click Change.
- Go to Central Management > Appliances and click Edge Appliance Manager.
The Add Edge Appliance Manager dialog opens.
- Configure the Edge appliance and click Save.
Interface Select a port from the list. Port Enter the port. The default is 9443. Auth Key Copy the existing key or click Generate new key. - On the client device, go to Dashboard > Status.
- In the System Information widget, locate Appliance Manager and click Change.
- On the client device, configure the Appliance Manager settings, and click Save.
Type Select Manager On Premise or DaaS Cloud. IP/Domain Enter the Manager IP or domain. Port
Enter the port. The default is 9443.
Auth Key Enter the Auth Key.
Limitations of connecting to EDGE clients
Please consider the following limitations when connecting EDGE clients to an on-promise FortiDeceptor with Central Management.
-
EDGE clients are supported in FDC-1000G, FDC-1000F, VM manager and FortiDeceptor DaaS
- The EDGE layer-2 tunnel terminates directly on the FortiDeceptor Central Management unit. This means the decoys for the EDGE client need to be hosted on the Central Management unit itself.
- Every EDGE client requires an exclusive decoy for its VLAN segment.
-
FortiDeceptor Manager can host up to 20 decoys. For example, up to 20 Edge clients can be connected, with each EDGE client having one decoy.