Fortinet white logo
Fortinet white logo

Administration Guide

Edge appliance manager

Edge appliance manager

Topology

The following topology shows a network with an on-premise FortiDeceptor connected to a FortiDeceptor Edge appliance by a Layer 2 tunnel. The Layer 2 tunnel is a private tunnel protocol similar to SSL/TLS. The FortiDeceptor Layer 2 tunnel is embedded with its own authentication and encryption methods as well as heartbeat checks on top of SSL/TLS.

To configure the Edge appliance manager:
  1. On the management device, do one of the following:
    • Go to Dashboard > Status. In the System Information widget, locate Edge Appliance Manager and click Change.
    • Go to Central Management > Appliances and click Edge Appliance Manager.

    The Add Edge Appliance Manager dialog opens.

  2. Configure the Edge appliance and click Save.

    InterfaceSelect a port from the list.
    PortEnter the port. The default is 9443.
    Auth KeyCopy the existing key or click Generate new key.
  3. On the client device, go to Dashboard > Status.
  4. In the System Information widget, locate Appliance Manager and click Change.
  5. On the client device, configure the Appliance Manager settings, and click Save.

    TypeSelect Manager On Premise or DaaS Cloud.
    IP/DomainEnter the Manager IP or domain.

    Port

    Enter the port. The default is 9443.

    Auth KeyEnter the Auth Key.

Limitations of connecting to EDGE clients

Please consider the following limitations when connecting EDGE clients to an on-promise FortiDeceptor with Central Management.

  • EDGE clients are supported in FDC-1000G, FDC-1000F, VM manager and FortiDeceptor DaaS

  • The EDGE layer-2 tunnel terminates directly on the FortiDeceptor Central Management unit. This means the decoys for the EDGE client need to be hosted on the Central Management unit itself.
  • Every EDGE client requires an exclusive decoy for its VLAN segment.
  • FortiDeceptor Manager can host up to 20 decoys. For example, up to 20 Edge clients can be connected, with each EDGE client having one decoy.

Edge appliance manager

Edge appliance manager

Topology

The following topology shows a network with an on-premise FortiDeceptor connected to a FortiDeceptor Edge appliance by a Layer 2 tunnel. The Layer 2 tunnel is a private tunnel protocol similar to SSL/TLS. The FortiDeceptor Layer 2 tunnel is embedded with its own authentication and encryption methods as well as heartbeat checks on top of SSL/TLS.

To configure the Edge appliance manager:
  1. On the management device, do one of the following:
    • Go to Dashboard > Status. In the System Information widget, locate Edge Appliance Manager and click Change.
    • Go to Central Management > Appliances and click Edge Appliance Manager.

    The Add Edge Appliance Manager dialog opens.

  2. Configure the Edge appliance and click Save.

    InterfaceSelect a port from the list.
    PortEnter the port. The default is 9443.
    Auth KeyCopy the existing key or click Generate new key.
  3. On the client device, go to Dashboard > Status.
  4. In the System Information widget, locate Appliance Manager and click Change.
  5. On the client device, configure the Appliance Manager settings, and click Save.

    TypeSelect Manager On Premise or DaaS Cloud.
    IP/DomainEnter the Manager IP or domain.

    Port

    Enter the port. The default is 9443.

    Auth KeyEnter the Auth Key.

Limitations of connecting to EDGE clients

Please consider the following limitations when connecting EDGE clients to an on-promise FortiDeceptor with Central Management.

  • EDGE clients are supported in FDC-1000G, FDC-1000F, VM manager and FortiDeceptor DaaS

  • The EDGE layer-2 tunnel terminates directly on the FortiDeceptor Central Management unit. This means the decoys for the EDGE client need to be hosted on the Central Management unit itself.
  • Every EDGE client requires an exclusive decoy for its VLAN segment.
  • FortiDeceptor Manager can host up to 20 decoys. For example, up to 20 Edge clients can be connected, with each EDGE client having one decoy.