Skip to main content
Connect a FortiGate firewall to let CloudThinker agents check device health, licenses, interface traffic, and configuration, and make configuration changes you approve. FortiGate authenticates with a REST API token, and CloudThinker must be able to reach the FortiGate over HTTPS.

Prerequisites

  • A FortiGate reachable over HTTPS.
  • An administrator with the super_admin profile. Only this profile can create a REST API administrator.

Setup

1

Create an administrator profile

Go to System → Admin Profiles and click Create New. Name it cloudthinker and set each permission to Read.Set Read/Write only on the areas you want agents to change.
2

Create a REST API administrator

Go to System → Administrators and click Create New → REST API Admin:
  • Username: cloudthinker
  • Administrator Profile: the profile you just created
  • PKI Group: leave empty
  • Trusted Hosts: optional. Add the addresses CloudThinker connects from; ask CloudThinker support for them.
Click OK and copy the token. FortiGate shows it only once.
3

Add the connection in CloudThinker

Navigate to Connections → FortiGate and enter:
  • FORTIGATE_HOST: your FortiGate address, such as fw.example.com
  • FORTIGATE_PORT: 443 unless you changed the HTTPS port
  • FORTIGATE_API_TOKEN: the token you copied
  • FORTIGATE_VDOM: root, or the virtual domain agents should use
  • FORTIGATE_VERIFY_SSL: Verify SSL certificate if the FortiGate has a trusted certificate, otherwise Skip SSL verification
Click Connect. CloudThinker verifies the token and shows a Connected status.

Connection details


Required permissions

The token has the permissions of its administrator profile.
Start with Read. Fortinet recommends giving a REST API administrator only the permissions it needs.

Agent capabilities

Changing administrator or interface settings can lock you out of the FortiGate. Check the exact change before you approve it.

Verify the connection

Example prompts


Troubleshooting

Check the address and port, and that the FortiGate accepts HTTPS from CloudThinker. If the message ends with returned error: 401, the token was rejected: check the token, Trusted Hosts, and that PKI Group is empty.
The FortiGate’s certificate is not trusted. Install a trusted certificate on the FortiGate, or choose Skip SSL verification.
FORTIGATE_HOST or FORTIGATE_API_TOKEN is empty. Fill in both and connect again.
Agents only see the virtual domain in FORTIGATE_VDOM. Set it to the virtual domain that holds the objects.
The administrator profile does not allow that change. Give the profile Read/Write on that area, or make the change in FortiGate yourself.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Restrict trusted hosts — limit the REST API administrator to the addresses CloudThinker connects from.
  • Verify the certificate — use Verify SSL certificate when the FortiGate has a trusted certificate.

Graylog Connection

Log search and alert investigation

Zabbix Connection

Infrastructure monitoring and alerting