Fortinet black logo

System integration and support

System integration and support

The following integration is tested and supported in FortiNDR 7.4.3.

FOS/FortiGate
  • FortiNDR Fabric Device widgets including Detection Statistics and System Information supported in FOS 7.0.5 and 7.2.4

  • File submission: FOS 6.4.0 and higher

    (FOS 6.2 and 5.6 file submission with OFTP, via the FortiSandbox field, is tested and compatible)

  • FortiGate inline blocking (with AV profile) is supported in FOS 7.0.1 and higher (via HTTP2).
  • FortiGate quarantine via webhook 6.4.0 and higher.

FortiProxy

  • HTTP2 file submission from FortiProxy 7.0.0 and higher
  • FortiProxy inline blocking (with AV profile) is supported in FPX 7.0.0 and higher.
FortiAnalyzer
  • FortiAnalyzer integration is supported in FortiAnalyzer 7.0.1 and higher.
FortiSIEM
  • Integration is supported in version 6.3.0 and higher.

FortiSandbox
  • FortiSandbox integration (API submission from FortiSandbox to FortiNDR) is supported from FortiSandbox version 4.0.1 and higher.

FortiMail
  • Version 7.2.0

FortiAuthenticator

  • FortiAuthenticator v6.4.5 and higher is supported for 2FA token login with the GUI. Push tokens are not supported at this time.
ICAP
  • FortiGate 6.4.0 and higher.
  • FortiWeb 6.3.11 and higher.
  • Squid and other compatible ICAP clients.
  • FortiProxy 7.0.0.
  • FortiNAC quarantine support (v9.2.2+)
  • FortiAuthenticator v6.4.5 and higher is supported for 2FA token login with the GUI. Push tokens are not supported at this time.

  • FortiSwitch quarantine via FortiLink (FortiSwitch v7.0.0+ and FortiGate v7.0.5+)
    Note

    FortiNDR 7.0.1 and later supports sending both malware and NDR logs to FortiAnalyzer and FortiSIEM or other syslog devices.

    FortiAnalyzer 7.2.0 supports receiving logs from FortiNDR (log view only).

    FortiAnalyzer 7.2.1 supports reporting based on logs.

System integration and support

The following integration is tested and supported in FortiNDR 7.4.3.

FOS/FortiGate
  • FortiNDR Fabric Device widgets including Detection Statistics and System Information supported in FOS 7.0.5 and 7.2.4

  • File submission: FOS 6.4.0 and higher

    (FOS 6.2 and 5.6 file submission with OFTP, via the FortiSandbox field, is tested and compatible)

  • FortiGate inline blocking (with AV profile) is supported in FOS 7.0.1 and higher (via HTTP2).
  • FortiGate quarantine via webhook 6.4.0 and higher.

FortiProxy

  • HTTP2 file submission from FortiProxy 7.0.0 and higher
  • FortiProxy inline blocking (with AV profile) is supported in FPX 7.0.0 and higher.
FortiAnalyzer
  • FortiAnalyzer integration is supported in FortiAnalyzer 7.0.1 and higher.
FortiSIEM
  • Integration is supported in version 6.3.0 and higher.

FortiSandbox
  • FortiSandbox integration (API submission from FortiSandbox to FortiNDR) is supported from FortiSandbox version 4.0.1 and higher.

FortiMail
  • Version 7.2.0

FortiAuthenticator

  • FortiAuthenticator v6.4.5 and higher is supported for 2FA token login with the GUI. Push tokens are not supported at this time.
ICAP
  • FortiGate 6.4.0 and higher.
  • FortiWeb 6.3.11 and higher.
  • Squid and other compatible ICAP clients.
  • FortiProxy 7.0.0.
  • FortiNAC quarantine support (v9.2.2+)
  • FortiAuthenticator v6.4.5 and higher is supported for 2FA token login with the GUI. Push tokens are not supported at this time.

  • FortiSwitch quarantine via FortiLink (FortiSwitch v7.0.0+ and FortiGate v7.0.5+)
    Note

    FortiNDR 7.0.1 and later supports sending both malware and NDR logs to FortiAnalyzer and FortiSIEM or other syslog devices.

    FortiAnalyzer 7.2.0 supports receiving logs from FortiNDR (log view only).

    FortiAnalyzer 7.2.1 supports reporting based on logs.