Trend Vision One enables sharing of suspicious object data with FortiGate Next-Generation Firewall through a Service Gateway.
Configure sharing of suspicious object data with this integration
through a Service Gateway.
NoteAt least one Service Gateway installed with the Suspicious Object Exchange
Service must be configured to enable integration.
For more information, see Service Gateway Management.
|
Procedure
- Configure settings on Trend Vision One.
- Go to .
- In the Integration column, click FortiGate Next-Generation Firewall.
- Use the toggle to enable or disable the integration.
- Review the Legal Statement and click Accept or Close to continue.
- Under Data Transfer, configure data sharing criteria and integration settings.
-
Object type: Select the file hash value format to use.
-
Risk level: Select the risk level of the suspicious object data to include in the shared data.
-
Frequency: Select the frequency at which suspicious object data is shared.
-
URL parameters: Select whether to remove query strings from URLs.
-
- Under Service Gateway
Connection, configure the connection between the Service
Gateway and the integration.
-
Click Connect.The Service Gateway Connection panel appears.
-
Select a Service Gateway installed with the Suspicious Object Exchange Service.
-
Configure the integration server settings.
-
(Optional) Click Test Connection to verify if the settings are valid.
-
Click Connect.The connection configuration is added to the list.
-
Click the Generate Now icon () to generate suspicious object data sharing files immediately.
-
Hover over the Copy URL icon () to copy the suspicious object data sharing URLs to use on your integration.
-
- Repeat the previous step to add multiple connection configurations for this integration.
- Click Save.
- Configure settings on your integration.
Note
The following steps were performed using version 7.0.0 of the FortiOS GUI.If you are using a different version, refer to the documentation for your version.- On the FortiOS GUI, go to .
- Click Create New and create
an object for each of the following types of Threat
Feeds.
-
FortiGuard Category: Create an object to retrieve suspicious object data for URLs.
-
IP Address: Create an object to retrieve suspicious object data for IP addresses.
-
Domain Name: Create an object to retrieve suspicious object data for domain names.
-
Malware Hash: Create an object to retrieve suspicious object data for file hashes.
-
- Configure the object.
-
Name: Type a name for this object.
-
URI of external resource: Paste the suspicious object data sharing URL that you obtained from the Trend Vision One console.
-
HTTP basic authentication: Disable this setting.
-
Refresh rate: Specify the rate at which this object checks for updates.
Tip
Trend Micro recommends matching the refresh rate to the suspicious object data sharing Frequency configured on Trend Vision One. -
Comments: Type some comments to help you identify this object.
-
Status: Enable this setting.
-
Click OK.
-
Your FortiGate appliance is configured to retrieve suspicious object data from the Trend Vision One Service Gateway.
-
The configured Threat Feeds objects can be used as external resources in Policies and Security Profiles.
-
- Repeat the previous two steps until you have created objects for each of the specified types of Threat Feeds.
- Go to , double-click on each object you created, and do the
following:
-
Click the Refresh icon to retrieve suspicious object data from the Trend Vision One Service Gateway immediately.
-
(Optional) Click View Entries to display the suspicious object data retrieved from the Trend Vision One Service Gateway.
-