Fortinet white logo
Fortinet white logo

Administration Guide

Allowing FortiDLP Agent communication through the FortiGate

Allowing FortiDLP Agent communication through the FortiGate

Every FortiDLP Agent requires a direct connection to the FortiDLP Cloud to report real-time data and receive configuration updates. This is outlined in Allowing communication between the FortiDLP Agent and FortiDLP Cloud.

As such, FortiDLP Agents operating behind the FortiGate firewall must be able to reach the FortiDLP Cloud servers. The servers must be trusted by the FortiGate and a corresponding firewall policy must allow traffic to these servers.

To view the FortiDLP Cloud server addresses on the FortiGate:
  1. Go to Policy & Objects > Internet Service Database.

  2. Search for FortiDLP.

  3. Double-click the Fortinet-FortiDLP.Cloud entry to view it.

  4. In the right hand panel, click View/Edit Entries to see the addresses.

To allow traffic to FortiDLP Cloud servers:
  1. Go to Policy & Objects > Firewall Policy.

  2. Click Create new.

  3. Select the Incoming Interface and the Outgoing Interface.

  4. Select the Source address.

  5. For the Destination address

    1. Click in the field and, in the slide-out pane, select the Internet Service tab.

    2. Search for FortiDLP.

    3. Select the Fortinet-FortiDLP.Cloud entry.

    4. Click Close.

  6. Leave remaining settings as their default values and click OK.

Allowing FortiDLP Agent communication through the FortiGate

Allowing FortiDLP Agent communication through the FortiGate

Every FortiDLP Agent requires a direct connection to the FortiDLP Cloud to report real-time data and receive configuration updates. This is outlined in Allowing communication between the FortiDLP Agent and FortiDLP Cloud.

As such, FortiDLP Agents operating behind the FortiGate firewall must be able to reach the FortiDLP Cloud servers. The servers must be trusted by the FortiGate and a corresponding firewall policy must allow traffic to these servers.

To view the FortiDLP Cloud server addresses on the FortiGate:
  1. Go to Policy & Objects > Internet Service Database.

  2. Search for FortiDLP.

  3. Double-click the Fortinet-FortiDLP.Cloud entry to view it.

  4. In the right hand panel, click View/Edit Entries to see the addresses.

To allow traffic to FortiDLP Cloud servers:
  1. Go to Policy & Objects > Firewall Policy.

  2. Click Create new.

  3. Select the Incoming Interface and the Outgoing Interface.

  4. Select the Source address.

  5. For the Destination address

    1. Click in the field and, in the slide-out pane, select the Internet Service tab.

    2. Search for FortiDLP.

    3. Select the Fortinet-FortiDLP.Cloud entry.

    4. Click Close.

  6. Leave remaining settings as their default values and click OK.