Fortinet black logo

Administration Guide

Configuring FortiNDR

Configuring FortiNDR

FortiNDR (formerly FortiAI) can be added to the Security Fabric so that it appears in the topology views and the dashboard widgets.

To add FortiNDR to the Security Fabric in the GUI:
  1. In FortiOS, ensure that FortiGate is prepared to add FortiNDR to the Security Fabric. See Preparing FortiGate for supported Security Fabric devices.

  2. (Optional) In FortiOS, configure pre-authorization of FortiNDR to enable the device to join the Security Fabric as soon as it connects. See Configuring pre-authorization of supported Security Fabric devices.

  3. In FortiNDR, go to System > FortiGuard and verify that the pre-trained models (engines) are up to date. Refer to the FortiGuard website for the latest FortiNDR ANN versions.

  4. In FortiNDR GUI, configure and authorize the FortiGate:

    FortiNDR instructions are included for convenience. For the latest FortiNDR instructions, see the FortiNDR Administration Guide.

    1. Go to Security Fabric > Fabric Connectors and click the gear icon in the top right corner of the Security Fabric card.

    2. Click the toggle to Enable Security Fabric.

    3. Enter the IP addresses for the root FortiGate and the FortiNDR.

    4. Click OK. The FortiNDR is now authorized.

  5. In FortiOS, authorize the FortiNDR. See Authorizing supported connectors.

    If FortiNDR is pre-authorized, you can skip this step.

  6. On FortiOS, go to Security Fabric > Physical Topology or Security Fabric > Logical Topology to view more information.

Configuring FortiNDR

FortiNDR (formerly FortiAI) can be added to the Security Fabric so that it appears in the topology views and the dashboard widgets.

To add FortiNDR to the Security Fabric in the GUI:
  1. In FortiOS, ensure that FortiGate is prepared to add FortiNDR to the Security Fabric. See Preparing FortiGate for supported Security Fabric devices.

  2. (Optional) In FortiOS, configure pre-authorization of FortiNDR to enable the device to join the Security Fabric as soon as it connects. See Configuring pre-authorization of supported Security Fabric devices.

  3. In FortiNDR, go to System > FortiGuard and verify that the pre-trained models (engines) are up to date. Refer to the FortiGuard website for the latest FortiNDR ANN versions.

  4. In FortiNDR GUI, configure and authorize the FortiGate:

    FortiNDR instructions are included for convenience. For the latest FortiNDR instructions, see the FortiNDR Administration Guide.

    1. Go to Security Fabric > Fabric Connectors and click the gear icon in the top right corner of the Security Fabric card.

    2. Click the toggle to Enable Security Fabric.

    3. Enter the IP addresses for the root FortiGate and the FortiNDR.

    4. Click OK. The FortiNDR is now authorized.

  5. In FortiOS, authorize the FortiNDR. See Authorizing supported connectors.

    If FortiNDR is pre-authorized, you can skip this step.

  6. On FortiOS, go to Security Fabric > Physical Topology or Security Fabric > Logical Topology to view more information.