> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloudthinker.io/llms.txt
> Use this file to discover all available pages before exploring further.

# FortiGate

> Connect FortiGate to CloudThinker to check device health, license status, and interface traffic, and to change configuration with approval

Connect a FortiGate firewall to let CloudThinker agents check device health, licenses, interface traffic, and configuration, and make configuration changes you approve. FortiGate authenticates with a **REST API token**, and CloudThinker must be able to reach the FortiGate over HTTPS.

***

## Prerequisites

* A **FortiGate** reachable over **HTTPS**.
* An administrator with the **super\_admin** profile. Only this profile can create a REST API administrator.

***

## Setup

<Steps>
  <Step title="Create an administrator profile">
    Go to **System → Admin Profiles** and click **Create New**. Name it `cloudthinker` and set each permission to **Read**.

    Set **Read/Write** only on the areas you want agents to change.
  </Step>

  <Step title="Create a REST API administrator">
    Go to **System → Administrators** and click **Create New → REST API Admin**:

    * **Username**: `cloudthinker`
    * **Administrator Profile**: the profile you just created
    * **PKI Group**: leave empty
    * **Trusted Hosts**: optional. Add the addresses CloudThinker connects from; ask CloudThinker support for them.

    Click **OK** and copy the token. FortiGate shows it only once.
  </Step>

  <Step title="Add the connection in CloudThinker">
    Navigate to **Connections → FortiGate** and enter:

    * **FORTIGATE\_HOST**: your FortiGate address, such as `fw.example.com`
    * **FORTIGATE\_PORT**: `443` unless you changed the HTTPS port
    * **FORTIGATE\_API\_TOKEN**: the token you copied
    * **FORTIGATE\_VDOM**: `root`, or the virtual domain agents should use
    * **FORTIGATE\_VERIFY\_SSL**: **Verify SSL certificate** if the FortiGate has a trusted certificate, otherwise **Skip SSL verification**

    Click **Connect**. CloudThinker verifies the token and shows a **Connected** status.
  </Step>
</Steps>

***

## Connection details

| Field | Description | Example |
| - | - | - |
| **FORTIGATE\_HOST** | FortiGate address, without `https://` | `192.0.2.10` |
| **FORTIGATE\_PORT** | HTTPS port. Default `443` | `443` |
| **FORTIGATE\_API\_TOKEN** | REST API administrator token | — |
| **FORTIGATE\_VDOM** | Virtual domain agents use. Default `root` | `root` |
| **FORTIGATE\_VERIFY\_SSL** | **Skip SSL verification** (default) or **Verify SSL certificate** | **Verify SSL certificate** |

***

## Required permissions

The token has the permissions of its administrator profile.

| Goal | Profile access |
| - | - |
| Read health, licenses, traffic, and configuration | **Read** |
| Change configuration | **Read/Write** on the areas agents may change |

<Tip>
  Start with **Read**. Fortinet recommends giving a REST API administrator only the permissions it needs.
</Tip>

***

## Agent capabilities

| Capability | Description |
| - | - |
| **Device overview** | Hostname, model, serial number, firmware, and uptime |
| **License health** | License and subscription status and expiry |
| **Interface traffic** | Busiest interfaces by traffic and bandwidth |
| **Configuration review** | Firewall policies, routes, VPN settings, and other configuration |
| **Configuration changes** | Create, update, or delete one configuration object per [approval](/guide/approval) |

<Warning>
  Changing administrator or interface settings can lock you out of the FortiGate. Check the exact change before you approve it.
</Warning>

### Verify the connection

```text theme={null}
Summarize my FortiGate: model, firmware version, license status, and the five busiest interfaces
```

### Example prompts

```text theme={null}
Check which FortiGate licenses and subscriptions expire in the next 90 days
Show interface traffic on the FortiGate and flag any interface close to saturation
List the firewall address objects on the FortiGate and flag any that look unused
```

***

## Troubleshooting

<Accordion title="Failed to connect to FortiGate">
  Check the address and port, and that the FortiGate accepts HTTPS from CloudThinker. If the message ends with **returned error: 401**, the token was rejected: check the token, **Trusted Hosts**, and that **PKI Group** is empty.
</Accordion>

<Accordion title="SSL certificate problem">
  The FortiGate's certificate is not trusted. Install a trusted certificate on the FortiGate, or choose **Skip SSL verification**.
</Accordion>

<Accordion title="Invalid FortiGate connection configuration">
  **FORTIGATE\_HOST** or **FORTIGATE\_API\_TOKEN** is empty. Fill in both and connect again.
</Accordion>

<Accordion title="Connected, but objects are missing">
  Agents only see the virtual domain in **FORTIGATE\_VDOM**. Set it to the virtual domain that holds the objects.
</Accordion>

<Accordion title="A configuration change fails with HTTP 403">
  The administrator profile does not allow that change. Give the profile **Read/Write** on that area, or make the change in FortiGate yourself.
</Accordion>

***

## Security

* **Least privilege** — grant only the permissions the agents need for your use case; start read-only and widen later.
* **Read-only by default** — use read-only credentials unless you want agents to make changes through this connection.
* **Rotate credentials** — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
* **Revoke on offboarding** — remove the credential at the provider when you delete a connection or a teammate leaves.

- **Restrict trusted hosts** — limit the REST API administrator to the addresses CloudThinker connects from.
- **Verify the certificate** — use **Verify SSL certificate** when the FortiGate has a trusted certificate.

***

## Related

<CardGroup cols={2}>
  <Card title="Graylog Connection" icon="https://mintcdn.com/cloudthinker/PAPf7dQXz6G9xwkG/images/icons/graylog.svg?fit=max&auto=format&n=PAPf7dQXz6G9xwkG&q=85&s=11bac41a029ed27ed4c8a6a988847722" href="/guide/connections/graylog" width="256" height="256" data-path="images/icons/graylog.svg">
    Log search and alert investigation
  </Card>

  <Card title="Zabbix Connection" icon="https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/zabbix.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=1667a3279951cdeb93f5c73860eb6261" href="/guide/connections/zabbix" width="24" height="24" data-path="images/icons/zabbix.svg">
    Infrastructure monitoring and alerting
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.