FortiGuard
FortiGuard services comprise of signature packages and querying services that provide content, web and device security. It is delivered via various types of FortiGuard servers that are part of the FortiGuard Distribution Network (FDN).
FortiGuard service subscriptions can be purchased and registered to your FortiGate unit. The FortiGate must be connected to the Internet in order to automatically connect to the FDN to validate the license and download FDN updates or perform real-time queries.
To view FDN support contract information, go to System > FortiGuard. The Licensed widgets show the status of your FortiGate’s entitlements and breaks down the status of each service.
License Information widget
The service entitlements and the license statuses are listed on the System > FortiGuard > Subscriptions tab. Upon expanding each entitlement, the corresponding definitions associated with the service are listed.
The following table list the available FortiGuard services and entitlements with a brief description.
|
Entitlement |
FortiGuard service description |
||
|---|---|---|---|
Basic subscriptions |
|||
|
Support Comprehensive Support Elite Service Enhanced Support |
|
||
|
Firmware, VM, and base subscriptions Application Control Signatures Inline-CASB application definitions Device & OS identification definitions GeoIP definitions Trusted CA certificate definitions1 Internet service and botnet IP definitions Local protection signatures PSIRT check definitions Time zone definitions |
The FortiCare support entitlement includes firmware and general updates that come with various default signatures and definitions, including:
|
||
|
FortiConverter Hosted Service |
FortiConverter service |
||
FortiGuard Security Services |
|||
|
Intrusion Prevention System (IPS) IPS signatures IPS Engine Malicious URL definitions |
The IPS service includes engines, databases, and definitions used in the IPS and application control profiles.
See Intrusion prevention and Application control for details. |
||
|
Advanced Malware Protection AI-based heuristic antivirus engine Antivirus definitions Antivirus engine Mobile malware signatures Botnet domain definitions Virus outbreak prevention with file checksum query |
The Advanced Malware Protection service includes various engines, databases, and definitions used in the AV profile.
See Antivirus for details. |
||
|
File analysis with FortiGate Cloud Sandbox query AI-based Inline Malware Prevention Service |
Provides Inline protection against unknown/0-day threats - holding a file for up to 50 seconds for the verdict to be returned and based on it, files can either be blocked or released.
|
||
|
AntiSpam query |
Consults FortiGuard servers to help identify spammer IP address or emails, known phishing URLs, known spam URLs, known spam email checksums, and others.
|
||
|
URL, DNS & Video Filtering Malicious certificate definitions DNS Filtering Video Filtering |
The Web Security service includes:
|
||
|
Attack Surface Security IoT device identification definitions Outbreak check definitions Security rating and CIS compliance definitions |
The Attack Surface Security service includes:
|
||
|
Operational Technology (OT) Security Service OT threat definitions OT device identification definitions OT vulnerability correlation definitions & virtual patching signatures |
The OT Security service includes OT-related threat definitions used in IPS and application control profiles. It also includes OT Detection Definitions and Virtual Patching Signatures used in the virtual patching profile. See Virtual patching for details. |
||
|
Data Loss Prevention (DLP) Signatures DLP signatures |
The Data Loss Prevention service offers a database of predefined DLP patterns such as data types, dictionaries, and sensors that are used in the DLP profile. |
||
SD-WAN and SASE Services |
|||
|
SD-WAN Underlay Bandwidth and Quality Monitoring |
SD-WAN Underlay Bandwidth and Quality Monitoring service |
||
|
SD-WAN Overlay-as-a-Service |
Delivers efficient setup and management of new SD-WAN regions via the easy-to-use FortiCloud portal. |
||
|
SD-WAN Connector for FortiSASE Secure Private Access |
Organizations with new or existing FortiGate SD-WAN deployments can provide their FortiSASE remote users with access to private resources. |
||
|
SASE connector for FortiSASE Secure Edge Management |
Extend security capabilities to all endpoints, users, and devices across the network. |
||
NOC & SOC |
|||
|
FortiGate Cloud |
FortiGate Cloud management, analysis, and log retention services |
||
|
FortiGate Cloud Log Retention |
Store and access different logs, including traffic, system, web, applications, and security events securely in the cloud. |
||
|
FortiAnalyzer Cloud |
FortiAnalyzer Cloud service |
||
|
FortiManager Cloud |
FortiManager Cloud service |
||
|
FortiClient EMS Cloud |
FortiClient EMS Cloud service |
||
|
FortiSandbox Cloud |
FortiSandbox Cloud service |
||
|
FortiToken Cloud |
FortiIdentity Cloud service |
||
1 The Trusted CA certificate bundle follows Mozilla's published trusted CA list for updating its certificate bundle. To view the built-in and bundled CA certificates supported by your FortiGate, execute the command get vpn certificate ca | grep ==.
Licenses widget
On the Dashboard > Status page, the Licenses widget lists the status of major entitlements. Licensed entitlement icons are green, and unlicensed entitlement icons are orange.
The following topics contain more information: