Fortinet white logo
Fortinet white logo

Administration Guide

FortiGuard

FortiGuard

FortiGuard services comprise of signature packages and querying services that provide content, web and device security. It is delivered via various types of FortiGuard servers that are part of the FortiGuard Distribution Network (FDN).

FortiGuard service subscriptions can be purchased and registered to your FortiGate unit. The FortiGate must be connected to the Internet in order to automatically connect to the FDN to validate the license and download FDN updates or perform real-time queries.

To view FDN support contract information, go to System > FortiGuard. The Licensed widgets show the status of your FortiGate’s entitlements and breaks down the status of each service.

License Information widget

The service entitlements and the license statuses are listed on the System > FortiGuard > Subscriptions tab. Upon expanding each entitlement, the corresponding definitions associated with the service are listed.

The following table list the available FortiGuard services and entitlements with a brief description.

Entitlement

FortiGuard service description

Basic subscriptions

Support

Comprehensive Support

Elite Service

Enhanced Support

Firmware, VM, and base subscriptions

Application Control Signatures

Inline-CASB application definitions

Device & OS identification definitions

GeoIP definitions

Trusted CA certificate definitions1

Internet service and botnet IP definitions

Local protection signatures

PSIRT check definitions

Time zone definitions

The FortiCare support entitlement includes firmware and general updates that come with various default signatures and definitions, including:

  • Application control signatures used in application control profiles

  • Device & OS identification used for device detection and asset management

  • Virtual patch signatures used in local-in policies

  • Inline CASB application definitions used in inline CASB profiles

  • ISDB destinations that can be applied in various policies and rules

  • PSIRT vulnerability definitions used in security ratings

FortiConverter Hosted Service

FortiConverter service

FortiGuard Security Services

Intrusion Prevention System (IPS)

IPS signatures

IPS Engine

Malicious URL definitions

The IPS service includes engines, databases, and definitions used in the IPS and application control profiles.

Note

In order to download updated IPS definitions, at least 1 policy with a security profile that has IPS scanning must be enabled.

See Intrusion prevention and Application control for details.

Advanced Malware Protection

AI-based heuristic antivirus engine

Antivirus definitions

Antivirus engine

Mobile malware signatures

Botnet domain definitions

Virus outbreak prevention with file checksum query

The Advanced Malware Protection service includes various engines, databases, and definitions used in the AV profile.

Note

In order to download updated AV definitions, at least 1 policy with a security profile that has Antivirus scanning must be enabled.

See Antivirus for details.

File analysis with FortiGate Cloud Sandbox query

AI-based Inline Malware Prevention Service

Provides Inline protection against unknown/0-day threats - holding a file for up to 50 seconds for the verdict to be returned and based on it, files can either be blocked or released.

  • AV profile

  • Send Files to FortiSandbox for Inspection

  • Scan strategy to Inline

AntiSpam query

Consults FortiGuard servers to help identify spammer IP address or emails, known phishing URLs, known spam URLs, known spam email checksums, and others.

  • Email filter profile

  • FortiGuard Spam Filtering

URL, DNS & Video Filtering

Malicious certificate definitions

DNS Filtering

Video Filtering

The Web Security service includes:

  • FortiGuard categories used in web filter profiles

  • Malicious certificates used in SSL/SSH inspection profiles

  • FortiGuard categories used in DNS filter profiles

  • FortiGuard categories used in video filter profiles

Attack Surface Security

IoT device identification definitions

Outbreak check definitions

Security rating and CIS compliance definitions

The Attack Surface Security service includes:

  • Running all the built-in free and paid security rating rules

  • Displaying CIS compliance information within security ratings

  • IoT Detection and IoT Query

Operational Technology (OT) Security Service

OT threat definitions

OT device identification definitions

OT vulnerability correlation definitions & virtual patching signatures

The OT Security service includes OT-related threat definitions used in IPS and application control profiles. It also includes OT Detection Definitions and Virtual Patching Signatures used in the virtual patching profile.

See Virtual patching for details.

Data Loss Prevention (DLP) Signatures

DLP signatures

The Data Loss Prevention service offers a database of predefined DLP patterns such as data types, dictionaries, and sensors that are used in the DLP profile.

SD-WAN and SASE Services

SD-WAN Underlay Bandwidth and Quality Monitoring

SD-WAN Underlay Bandwidth and Quality Monitoring service

SD-WAN Overlay-as-a-Service

Delivers efficient setup and management of new SD-WAN regions via the easy-to-use FortiCloud portal.

SD-WAN Connector for FortiSASE Secure Private Access

Organizations with new or existing FortiGate SD-WAN deployments can provide their FortiSASE remote users with access to private resources.

SASE connector for FortiSASE Secure Edge Management

Extend security capabilities to all endpoints, users, and devices across the network.

NOC & SOC

FortiGate Cloud

FortiGate Cloud management, analysis, and log retention services

FortiGate Cloud Log Retention

Store and access different logs, including traffic, system, web, applications, and security events securely in the cloud.

FortiAnalyzer Cloud

FortiAnalyzer Cloud service

FortiManager Cloud

FortiManager Cloud service

FortiClient EMS Cloud

FortiClient EMS Cloud service

FortiSandbox Cloud

FortiSandbox Cloud service

FortiToken Cloud

FortiIdentity Cloud service

1 The Trusted CA certificate bundle follows Mozilla's published trusted CA list for updating its certificate bundle. To view the built-in and bundled CA certificates supported by your FortiGate, execute the command get vpn certificate ca | grep ==.

Licenses widget

On the Dashboard > Status page, the Licenses widget lists the status of major entitlements. Licensed entitlement icons are green, and unlicensed entitlement icons are orange.

The following topics contain more information:

FortiGuard

FortiGuard

FortiGuard services comprise of signature packages and querying services that provide content, web and device security. It is delivered via various types of FortiGuard servers that are part of the FortiGuard Distribution Network (FDN).

FortiGuard service subscriptions can be purchased and registered to your FortiGate unit. The FortiGate must be connected to the Internet in order to automatically connect to the FDN to validate the license and download FDN updates or perform real-time queries.

To view FDN support contract information, go to System > FortiGuard. The Licensed widgets show the status of your FortiGate’s entitlements and breaks down the status of each service.

License Information widget

The service entitlements and the license statuses are listed on the System > FortiGuard > Subscriptions tab. Upon expanding each entitlement, the corresponding definitions associated with the service are listed.

The following table list the available FortiGuard services and entitlements with a brief description.

Entitlement

FortiGuard service description

Basic subscriptions

Support

Comprehensive Support

Elite Service

Enhanced Support

Firmware, VM, and base subscriptions

Application Control Signatures

Inline-CASB application definitions

Device & OS identification definitions

GeoIP definitions

Trusted CA certificate definitions1

Internet service and botnet IP definitions

Local protection signatures

PSIRT check definitions

Time zone definitions

The FortiCare support entitlement includes firmware and general updates that come with various default signatures and definitions, including:

  • Application control signatures used in application control profiles

  • Device & OS identification used for device detection and asset management

  • Virtual patch signatures used in local-in policies

  • Inline CASB application definitions used in inline CASB profiles

  • ISDB destinations that can be applied in various policies and rules

  • PSIRT vulnerability definitions used in security ratings

FortiConverter Hosted Service

FortiConverter service

FortiGuard Security Services

Intrusion Prevention System (IPS)

IPS signatures

IPS Engine

Malicious URL definitions

The IPS service includes engines, databases, and definitions used in the IPS and application control profiles.

Note

In order to download updated IPS definitions, at least 1 policy with a security profile that has IPS scanning must be enabled.

See Intrusion prevention and Application control for details.

Advanced Malware Protection

AI-based heuristic antivirus engine

Antivirus definitions

Antivirus engine

Mobile malware signatures

Botnet domain definitions

Virus outbreak prevention with file checksum query

The Advanced Malware Protection service includes various engines, databases, and definitions used in the AV profile.

Note

In order to download updated AV definitions, at least 1 policy with a security profile that has Antivirus scanning must be enabled.

See Antivirus for details.

File analysis with FortiGate Cloud Sandbox query

AI-based Inline Malware Prevention Service

Provides Inline protection against unknown/0-day threats - holding a file for up to 50 seconds for the verdict to be returned and based on it, files can either be blocked or released.

  • AV profile

  • Send Files to FortiSandbox for Inspection

  • Scan strategy to Inline

AntiSpam query

Consults FortiGuard servers to help identify spammer IP address or emails, known phishing URLs, known spam URLs, known spam email checksums, and others.

  • Email filter profile

  • FortiGuard Spam Filtering

URL, DNS & Video Filtering

Malicious certificate definitions

DNS Filtering

Video Filtering

The Web Security service includes:

  • FortiGuard categories used in web filter profiles

  • Malicious certificates used in SSL/SSH inspection profiles

  • FortiGuard categories used in DNS filter profiles

  • FortiGuard categories used in video filter profiles

Attack Surface Security

IoT device identification definitions

Outbreak check definitions

Security rating and CIS compliance definitions

The Attack Surface Security service includes:

  • Running all the built-in free and paid security rating rules

  • Displaying CIS compliance information within security ratings

  • IoT Detection and IoT Query

Operational Technology (OT) Security Service

OT threat definitions

OT device identification definitions

OT vulnerability correlation definitions & virtual patching signatures

The OT Security service includes OT-related threat definitions used in IPS and application control profiles. It also includes OT Detection Definitions and Virtual Patching Signatures used in the virtual patching profile.

See Virtual patching for details.

Data Loss Prevention (DLP) Signatures

DLP signatures

The Data Loss Prevention service offers a database of predefined DLP patterns such as data types, dictionaries, and sensors that are used in the DLP profile.

SD-WAN and SASE Services

SD-WAN Underlay Bandwidth and Quality Monitoring

SD-WAN Underlay Bandwidth and Quality Monitoring service

SD-WAN Overlay-as-a-Service

Delivers efficient setup and management of new SD-WAN regions via the easy-to-use FortiCloud portal.

SD-WAN Connector for FortiSASE Secure Private Access

Organizations with new or existing FortiGate SD-WAN deployments can provide their FortiSASE remote users with access to private resources.

SASE connector for FortiSASE Secure Edge Management

Extend security capabilities to all endpoints, users, and devices across the network.

NOC & SOC

FortiGate Cloud

FortiGate Cloud management, analysis, and log retention services

FortiGate Cloud Log Retention

Store and access different logs, including traffic, system, web, applications, and security events securely in the cloud.

FortiAnalyzer Cloud

FortiAnalyzer Cloud service

FortiManager Cloud

FortiManager Cloud service

FortiClient EMS Cloud

FortiClient EMS Cloud service

FortiSandbox Cloud

FortiSandbox Cloud service

FortiToken Cloud

FortiIdentity Cloud service

1 The Trusted CA certificate bundle follows Mozilla's published trusted CA list for updating its certificate bundle. To view the built-in and bundled CA certificates supported by your FortiGate, execute the command get vpn certificate ca | grep ==.

Licenses widget

On the Dashboard > Status page, the Licenses widget lists the status of major entitlements. Licensed entitlement icons are green, and unlicensed entitlement icons are orange.

The following topics contain more information: