Fortinet white logo
Fortinet white logo

Administration Guide

FortiGuard

FortiGuard

FortiGuard services comprise of signature packages and querying services that provide content, web and device security. It is delivered via various types of FortiGuard servers that are part of the FortiGuard Distribution Network (FDN).

FortiGuard service subscriptions can be purchased and registered to your FortiGate unit. The FortiGate must be connected to the Internet in order to automatically connect to the FDN to validate the license and download FDN updates or perform real-time queries.

To view FDN support contract information, go to System > FortiGuard. The License Information table shows the status of your FortiGate’s entitlements and breaks down the status of each service.

License Information widget

The service entitlements and the license statuses are listed on the System > FortiGuard page. Upon expanding each entitlement, the corresponding definitions associated with the service are listed.

The following table list the available FortiGuard services and entitlements with a brief description.

Entitlement

FortiGuard service description

FortiCare Support

FortiCloud Account

Enhanced Support

The FortiCare support entitlement includes a FortiCloud account and access to enhanced support.

Virtual Machine

Allocated CPUs

Allocated RAM

The Virtual Machine entitlement includes allocated vCPUs and RAM.

Firmware & General Updates

Application Control Signatures

Device & OS Identification

Internet Service Database Definitions

The Firmware & General Updates entitlement includes firmware and general updates that come with various default signatures and definitions:

  • Application control signatures used in application control profiles
  • Device & OS identification used for device detection and asset management
  • Virtual patch signatures used in local-in policies

Intrusion Prevention

IPS Definitions

IPS Engine

Malicious URLs

Botnet IPs

Botnet Domains

The IPS service includes engines, databases, and definitions used in the IPS and application control profiles.

Note

In order to download updated IPS definitions, at least 1 policy with a security profile that has IPS scanning must be enabled.

See Intrusion prevention and Application control for details.

AntiVirus

AI Malware Detection Model

AV Definitions

AV Engine

Mobile Malware

The AntiVirus entitlement includes various engines, databases, and definitions used in the AV profile.

Note

In order to download updated AV definitions, at least 1 policy with a security profile that has Antivirus scanning must be enabled.

See Antivirusfor details.

Web Filtering

Outbreak Prevention

SD-WAN Network Monitor

Security Rating

The Web Filtering entitlement includes:

  • Outbreak prevention includes various engines, databases, and definitions used in the Web Filter profile.
  • SD-WAN Underlay Bandwidth and Quality Monitoring service

  • Displaying CIS compliance information within security ratings

Industrial DB

Industrial Attack Definitions

The Industrial DB entitlement includes definitions used in the AV profile.

IoT Detection Service

IoT Detection Definitions

The Industrial DB entitlement includes definitions used in the IoT Detection and IoT query.

FortiGate Cloud

FortiGate Cloud management, analysis, and log retention services

Licenses widget

On the Dashboard > Status page, the Licenses widget lists the status of major entitlements.

The following topics contain more information:

FortiGuard

FortiGuard

FortiGuard services comprise of signature packages and querying services that provide content, web and device security. It is delivered via various types of FortiGuard servers that are part of the FortiGuard Distribution Network (FDN).

FortiGuard service subscriptions can be purchased and registered to your FortiGate unit. The FortiGate must be connected to the Internet in order to automatically connect to the FDN to validate the license and download FDN updates or perform real-time queries.

To view FDN support contract information, go to System > FortiGuard. The License Information table shows the status of your FortiGate’s entitlements and breaks down the status of each service.

License Information widget

The service entitlements and the license statuses are listed on the System > FortiGuard page. Upon expanding each entitlement, the corresponding definitions associated with the service are listed.

The following table list the available FortiGuard services and entitlements with a brief description.

Entitlement

FortiGuard service description

FortiCare Support

FortiCloud Account

Enhanced Support

The FortiCare support entitlement includes a FortiCloud account and access to enhanced support.

Virtual Machine

Allocated CPUs

Allocated RAM

The Virtual Machine entitlement includes allocated vCPUs and RAM.

Firmware & General Updates

Application Control Signatures

Device & OS Identification

Internet Service Database Definitions

The Firmware & General Updates entitlement includes firmware and general updates that come with various default signatures and definitions:

  • Application control signatures used in application control profiles
  • Device & OS identification used for device detection and asset management
  • Virtual patch signatures used in local-in policies

Intrusion Prevention

IPS Definitions

IPS Engine

Malicious URLs

Botnet IPs

Botnet Domains

The IPS service includes engines, databases, and definitions used in the IPS and application control profiles.

Note

In order to download updated IPS definitions, at least 1 policy with a security profile that has IPS scanning must be enabled.

See Intrusion prevention and Application control for details.

AntiVirus

AI Malware Detection Model

AV Definitions

AV Engine

Mobile Malware

The AntiVirus entitlement includes various engines, databases, and definitions used in the AV profile.

Note

In order to download updated AV definitions, at least 1 policy with a security profile that has Antivirus scanning must be enabled.

See Antivirusfor details.

Web Filtering

Outbreak Prevention

SD-WAN Network Monitor

Security Rating

The Web Filtering entitlement includes:

  • Outbreak prevention includes various engines, databases, and definitions used in the Web Filter profile.
  • SD-WAN Underlay Bandwidth and Quality Monitoring service

  • Displaying CIS compliance information within security ratings

Industrial DB

Industrial Attack Definitions

The Industrial DB entitlement includes definitions used in the AV profile.

IoT Detection Service

IoT Detection Definitions

The Industrial DB entitlement includes definitions used in the IoT Detection and IoT query.

FortiGate Cloud

FortiGate Cloud management, analysis, and log retention services

Licenses widget

On the Dashboard > Status page, the Licenses widget lists the status of major entitlements.

The following topics contain more information: