Fortinet white logo
Fortinet white logo

User Guide

Managing encryption keys

Managing encryption keys

Any PCAP captured and stored in FortiNDR Cloud will be encrypted by adding the associated keys to the account.

FortiNDR Cloud requires the encryption of all PCAP data captured and stored on the platform, backed by public key cryptography.

Encryption key requirement impact on existing sensors

If you do not have a PCAP-enabled sensor The encryption key will be required to enable PCAP on sensors.
If you have a PCAP-enabled sensor
  • There is no change in behavior for existing PCAP-enabled sensors.

  • After the encryption key is provided, the PCAP-enabled sensor will upload encrypted PCAP files.

  • For existing PCAP-enabled sensors that are capturing without a key, you should still be able to disable them without a key.

  • Encryption keys can be updated directly without needing to delete an existing key. Existing behaviors and PCAP-enabled sensors will not be impacted.

When deleting the encryption key
  • PCAP will be disabled on all the sensors for this account.

  • All PCAP upload requests for those sensors will be silently ignored.

  • When the encryption key is provided again after it's been deleted, you will need to enable PCAP on the sensor manually.

Encryption key settings

To access PCAP Encryption Keys settings:
  1. Go to Settings > Account Management.
  2. Select an account.
  3. On the left navigation, select Settings.

    pcap-encryption-key-access

    The Set PCAP encryption key button will only appear for the Admin role.

Encryption warnings

Encryption must be enabled to use PCAP. The PCAP Enabled option remains unavailable until encryption is enabled, and a message indicates that encryption must be configured before PCAP can be enabled.

A warning appears in the Sensor Update dialog when accessed from the sensor list:

pcap-enabling

A warning appears on the Sensor Settings page:

pcap-in-sensor

Deleting a PCAP encryption key

To delete a PCAP encryption key:
  1. Go to Settings > Account Management > Settings tab.
  2. In the PCAP Encryption Keys section, click the delete button (X) next to the encryption key. A warning appears indicating that PCAP will be disabled for all sensors associated with the account.
  3. When deleting a PCAP key for an account, a warning will appear advising that PCAP will be disabled for sensors associated with that account.

    pcapdelete

  4. Click Confirm to acknowledge the message and proceed.

Managing encryption keys

Managing encryption keys

Any PCAP captured and stored in FortiNDR Cloud will be encrypted by adding the associated keys to the account.

FortiNDR Cloud requires the encryption of all PCAP data captured and stored on the platform, backed by public key cryptography.

Encryption key requirement impact on existing sensors

If you do not have a PCAP-enabled sensor The encryption key will be required to enable PCAP on sensors.
If you have a PCAP-enabled sensor
  • There is no change in behavior for existing PCAP-enabled sensors.

  • After the encryption key is provided, the PCAP-enabled sensor will upload encrypted PCAP files.

  • For existing PCAP-enabled sensors that are capturing without a key, you should still be able to disable them without a key.

  • Encryption keys can be updated directly without needing to delete an existing key. Existing behaviors and PCAP-enabled sensors will not be impacted.

When deleting the encryption key
  • PCAP will be disabled on all the sensors for this account.

  • All PCAP upload requests for those sensors will be silently ignored.

  • When the encryption key is provided again after it's been deleted, you will need to enable PCAP on the sensor manually.

Encryption key settings

To access PCAP Encryption Keys settings:
  1. Go to Settings > Account Management.
  2. Select an account.
  3. On the left navigation, select Settings.

    pcap-encryption-key-access

    The Set PCAP encryption key button will only appear for the Admin role.

Encryption warnings

Encryption must be enabled to use PCAP. The PCAP Enabled option remains unavailable until encryption is enabled, and a message indicates that encryption must be configured before PCAP can be enabled.

A warning appears in the Sensor Update dialog when accessed from the sensor list:

pcap-enabling

A warning appears on the Sensor Settings page:

pcap-in-sensor

Deleting a PCAP encryption key

To delete a PCAP encryption key:
  1. Go to Settings > Account Management > Settings tab.
  2. In the PCAP Encryption Keys section, click the delete button (X) next to the encryption key. A warning appears indicating that PCAP will be disabled for all sensors associated with the account.
  3. When deleting a PCAP key for an account, a warning will appear advising that PCAP will be disabled for sensors associated with that account.

    pcapdelete

  4. Click Confirm to acknowledge the message and proceed.