Skip to main content
sreddi
Staff
Staff
May 29, 2020

Technical Tip: How to activate FortiSandbox Cloud

  • May 29, 2020
  • 0 replies
  • 19187 views

Description


The article describes how to connect a FortiGate to the FortiSandbox Cloud. After the FortiGate is connected to FortiSandbox Cloud, it is possible to configure an anti-virus profile for sending suspicious files for inspection.

 

Scope

 

FortiGate.

Solution


Before connecting a FortiGate to FortiSandbox Cloud, an active FortiCloud account is needed. After creating a FortiCloud account, enable sandbox inspection.

 

Make sure the 'FortiGate Cloud Sandbox' feature is enabled on the FortiGate unit under the GUI -> Feature Visibility -> 'FortiGate Cloud Sandbox'.

 

image (8).png


From the GUI, go to Security Fabric -> Settings, enable 'Sandbox Inspection', and set it to FortiSandbox Cloud.

 
In v7.0 and 7.2, to configure FortiSandbox/FortiSandbox Cloud, navigate to Security Fabric -> Fabric Connectors -> Sandbox Settings.
 

sandbox.png

 

In 7.4, go to Security Fabric -> Fabric Connectors, right-click over the Sandbox box and select Edit.

 

KB Sandbox.png

 

Select Enabled and select the desired type. For this purpose, FortiGate Cloud will be configured. Then, select the region that FortiGate is registered to and select OK.

 

KB Sandbox2.png

 

 After a few seconds, the Sandbox connector comes UP.

 

KB Sandbox3.png

 

Note:
To enable FortiSandbox Cloud, it requires a valid entitlement under the same account where the FortiGate is registered. To see the results from FortiSandbox Cloud in the FortiGate logs. Go to Log & Report -> Log Settings and enable 'Send Logs to FortiCloud'.
 
 
Set GUI Preferences to display logs from FortiCloud.
 

 

The table below can be referenced to verify the paid or the free subscription:

 

2022-01-17 11_51_30-FortiGate Cloud.png

 

Important note: In some cases, the FortiGate Cloud Sandbox status shows 'Unreachable or not authorized':

 

To ensure proper connectivity to FortiGate Cloud Sandbox, an Antivirus profile needs to be configured having the option 'Send files to FortiSandbox for inspection' configured - then, this AV profile needs to be applied on a policy. Only this way the FortiGate Cloud Sandbox connection can be initiated.

 

Related articles:

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!