Fortinet black logo

External Systems Configuration Guide

Nozomi SCADAguardian

Nozomi SCADAguardian

Support Added: FortiSIEM 5.2.5

Last Modification: FortiSIEM 6.5.0

Vendor Version Tested: Not Provided

Vendor: Nozomi Networks

Product: Nozomi Networks SCADAguardian

Product Information: https://www.nozominetworks.com/products/guardian/

What is Discovered and Monitored

Protocol Information discovered Metrics collected Used for
Syslog Device type Node detection, protocol information, network changes Security and Compliance

Event Types

In ADMIN > Device Support > Event Types, search for "Nozomi" to see the event types associated with this device.

Rules

There are no specific rules for Nozomi, however rules that match the Event Type Groups associated with Nozomi Events may trigger.

Reports

There are no specific Reports for Nozomi, however reports that match the Event Type Groups associated with Nozomi Events may return results.

Configuring Syslog on Nozomi

  1. Log in to the Guardian console.
  2. Navigate to Administration->Data Integration.
  3. Press +Add on the right side of the screen.
  4. Select the Common Event Format (CEF) from the drop down.
  5. You should see the data entry screen.

  6. Enter the appropriate host information. For example udp://<FortiSIEM IP>:514.
  7. Select Enable sending Alerts and/or Enable sending Audit Logs and/or Enable sending Health Logs.
  8. Press New Endpoint.

Configuring FortiSIEM for Nozomi

Complete these steps in the FortiSIEM UI:

  1. Go to the ADMIN > Setup > Credentials tab.
  2. In Step 1: Enter Credentials, click New to create a new credential.
    1. Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
    2. Enter these settings in the Access Method Definition dialog box and click Save:

      Settings Description
      Name Enter a name for the credential
      Device Type Nozomi Networks SCADAGuardian
      Access Protocol Nozomi REST API
      User NameEnter the username used to access your Nozomi server.
      PasswordEnter the password associated with your username.
      Description Description of the device.
  3. In Step 2: Enter IP Range to Credential Associations, click New to create a mapping.
    1. Enter a host name, an IP, or an IP range in the IP/Host Name field.
    2. Select the name of your Nozomi credential from the Credentials drop-down list.
    3. Click Save.
  4. Click the Test drop-down list and select Test Connectivity to test the connection to the Nozomi server.
  5. Navigate to ADMIN > Setup > Discovery.
  6. Click New to create a Nozomi scan discovery definition.
  7. In the Discovery Definition dialog box, take the following steps:
    1. In the Name field, enter a name for the Discovery Definition.
    2. From the Discovery Type drop-down list, select Nozomi Scan.
    3. In the Credential drop-down list, your Nozomi Access Method Definition should be automatically selected.
    4. Fill in the other fields as necessary.
    5. When done, click Save.

Nozomi SCADAguardian

Support Added: FortiSIEM 5.2.5

Last Modification: FortiSIEM 6.5.0

Vendor Version Tested: Not Provided

Vendor: Nozomi Networks

Product: Nozomi Networks SCADAguardian

Product Information: https://www.nozominetworks.com/products/guardian/

What is Discovered and Monitored

Protocol Information discovered Metrics collected Used for
Syslog Device type Node detection, protocol information, network changes Security and Compliance

Event Types

In ADMIN > Device Support > Event Types, search for "Nozomi" to see the event types associated with this device.

Rules

There are no specific rules for Nozomi, however rules that match the Event Type Groups associated with Nozomi Events may trigger.

Reports

There are no specific Reports for Nozomi, however reports that match the Event Type Groups associated with Nozomi Events may return results.

Configuring Syslog on Nozomi

  1. Log in to the Guardian console.
  2. Navigate to Administration->Data Integration.
  3. Press +Add on the right side of the screen.
  4. Select the Common Event Format (CEF) from the drop down.
  5. You should see the data entry screen.

  6. Enter the appropriate host information. For example udp://<FortiSIEM IP>:514.
  7. Select Enable sending Alerts and/or Enable sending Audit Logs and/or Enable sending Health Logs.
  8. Press New Endpoint.

Configuring FortiSIEM for Nozomi

Complete these steps in the FortiSIEM UI:

  1. Go to the ADMIN > Setup > Credentials tab.
  2. In Step 1: Enter Credentials, click New to create a new credential.
    1. Follow the instructions in "Setting Credentials" in the User's Guide to create a new credential.
    2. Enter these settings in the Access Method Definition dialog box and click Save:

      Settings Description
      Name Enter a name for the credential
      Device Type Nozomi Networks SCADAGuardian
      Access Protocol Nozomi REST API
      User NameEnter the username used to access your Nozomi server.
      PasswordEnter the password associated with your username.
      Description Description of the device.
  3. In Step 2: Enter IP Range to Credential Associations, click New to create a mapping.
    1. Enter a host name, an IP, or an IP range in the IP/Host Name field.
    2. Select the name of your Nozomi credential from the Credentials drop-down list.
    3. Click Save.
  4. Click the Test drop-down list and select Test Connectivity to test the connection to the Nozomi server.
  5. Navigate to ADMIN > Setup > Discovery.
  6. Click New to create a Nozomi scan discovery definition.
  7. In the Discovery Definition dialog box, take the following steps:
    1. In the Name field, enter a name for the Discovery Definition.
    2. From the Discovery Type drop-down list, select Nozomi Scan.
    3. In the Credential drop-down list, your Nozomi Access Method Definition should be automatically selected.
    4. Fill in the other fields as necessary.
    5. When done, click Save.