Managing encryption keys
Any PCAP captured and stored in FortiNDR Cloud will be encrypted by adding the associated keys to the account.
FortiNDR Cloud requires the encryption of all PCAP data captured and stored on the platform, backed by public key cryptography.
Encryption key requirement impact on existing sensors
If you do not have a PCAP-enabled sensor | The encryption key will be required to enable PCAP on sensors |
If you have a PCAP-enabled sensor |
|
When deleting the encryption key |
|
Enabling PCAP on a sensor requires encryption
When enabling PCAP on an individual sensor, the PCAP Enabled option is disabled unless you have encryption enabled and display a note advising that you must enable encryption before enabling PCAP.
Warning appears on Sensor Update dialog accessed from the list of sensors:
Warning appears on the detailed Sensor Settings page:
Deleting a PCAP encryption key
When deleting a PCAP key for an account, a warning will appear advising that PCAP will be disabled for sensors associated with that account.
Click Confirm to acknowledge the message and proceed.