Fortinet black logo

User Guide

Managing encryption keys

Managing encryption keys

Any PCAP captured and stored in FortiNDR Cloud will be encrypted by adding the associated keys to the account.

FortiNDR Cloud requires the encryption of all PCAP data captured and stored on the platform, backed by public key cryptography.

Encryption key requirement impact on existing sensors

If you do not have a PCAP-enabled sensor The encryption key will be required to enable PCAP on sensors
If you have a PCAP-enabled sensor
  • There is no change in behavior for existing PCAP-enabled sensors.

  • After the encryption key is provided, the PCAP-enabled sensor will upload encrypted PCAP files.

  • For existing PCAP-enabled sensors that are capturing without a key, you should still be able to disable them without a key.

  • Encryption keys can be updated directly without needing to delete an existing key. Existing behaviors and PCAP-enabled sensors will not be impacted.

When deleting the encryption key
  • PCAP will be disabled on all the sensors for this account.

  • All PCAP upload requests for those sensors will be silently ignored.

  • When the encryption key is provided again after it's been deleted, you will need to enable PCAP on the sensor manually.

Enabling PCAP on a sensor requires encryption

When enabling PCAP on an individual sensor, the PCAP Enabled option is disabled unless you have encryption enabled and display a note advising that you must enable encryption before enabling PCAP.

Warning appears on Sensor Update dialog accessed from the list of sensors:

pcap-enabling

Warning appears on the detailed Sensor Settings page:

pcap-in-sensor

Deleting a PCAP encryption key

When deleting a PCAP key for an account, a warning will appear advising that PCAP will be disabled for sensors associated with that account.

pcapdelete

Click Confirm to acknowledge the message and proceed.

Managing encryption keys

Any PCAP captured and stored in FortiNDR Cloud will be encrypted by adding the associated keys to the account.

FortiNDR Cloud requires the encryption of all PCAP data captured and stored on the platform, backed by public key cryptography.

Encryption key requirement impact on existing sensors

If you do not have a PCAP-enabled sensor The encryption key will be required to enable PCAP on sensors
If you have a PCAP-enabled sensor
  • There is no change in behavior for existing PCAP-enabled sensors.

  • After the encryption key is provided, the PCAP-enabled sensor will upload encrypted PCAP files.

  • For existing PCAP-enabled sensors that are capturing without a key, you should still be able to disable them without a key.

  • Encryption keys can be updated directly without needing to delete an existing key. Existing behaviors and PCAP-enabled sensors will not be impacted.

When deleting the encryption key
  • PCAP will be disabled on all the sensors for this account.

  • All PCAP upload requests for those sensors will be silently ignored.

  • When the encryption key is provided again after it's been deleted, you will need to enable PCAP on the sensor manually.

Enabling PCAP on a sensor requires encryption

When enabling PCAP on an individual sensor, the PCAP Enabled option is disabled unless you have encryption enabled and display a note advising that you must enable encryption before enabling PCAP.

Warning appears on Sensor Update dialog accessed from the list of sensors:

pcap-enabling

Warning appears on the detailed Sensor Settings page:

pcap-in-sensor

Deleting a PCAP encryption key

When deleting a PCAP key for an account, a warning will appear advising that PCAP will be disabled for sensors associated with that account.

pcapdelete

Click Confirm to acknowledge the message and proceed.