Prerequisites
- A FortiGate reachable over HTTPS.
- An administrator with the super_admin profile. Only this profile can create a REST API administrator.
Setup
1
Create an administrator profile
Go to System → Admin Profiles and click Create New. Name it
cloudthinker and set each permission to Read.Set Read/Write only on the areas you want agents to change.2
Create a REST API administrator
Go to System → Administrators and click Create New → REST API Admin:
- Username:
cloudthinker - Administrator Profile: the profile you just created
- PKI Group: leave empty
- Trusted Hosts: optional. Add the addresses CloudThinker connects from; ask CloudThinker support for them.
3
Add the connection in CloudThinker
Navigate to Connections → FortiGate and enter:
- FORTIGATE_HOST: your FortiGate address, such as
fw.example.com - FORTIGATE_PORT:
443unless you changed the HTTPS port - FORTIGATE_API_TOKEN: the token you copied
- FORTIGATE_VDOM:
root, or the virtual domain agents should use - FORTIGATE_VERIFY_SSL: Verify SSL certificate if the FortiGate has a trusted certificate, otherwise Skip SSL verification
Connection details
Required permissions
The token has the permissions of its administrator profile.Agent capabilities
Verify the connection
Example prompts
Troubleshooting
Failed to connect to FortiGate
Failed to connect to FortiGate
Check the address and port, and that the FortiGate accepts HTTPS from CloudThinker. If the message ends with returned error: 401, the token was rejected: check the token, Trusted Hosts, and that PKI Group is empty.
SSL certificate problem
SSL certificate problem
The FortiGate’s certificate is not trusted. Install a trusted certificate on the FortiGate, or choose Skip SSL verification.
Invalid FortiGate connection configuration
Invalid FortiGate connection configuration
FORTIGATE_HOST or FORTIGATE_API_TOKEN is empty. Fill in both and connect again.
Connected, but objects are missing
Connected, but objects are missing
Agents only see the virtual domain in FORTIGATE_VDOM. Set it to the virtual domain that holds the objects.
A configuration change fails with HTTP 403
A configuration change fails with HTTP 403
The administrator profile does not allow that change. Give the profile Read/Write on that area, or make the change in FortiGate yourself.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Restrict trusted hosts — limit the REST API administrator to the addresses CloudThinker connects from.
- Verify the certificate — use Verify SSL certificate when the FortiGate has a trusted certificate.
Related
Graylog Connection
Log search and alert investigation
Zabbix Connection
Infrastructure monitoring and alerting