Skip to main content
ssriswadpong
Staff & Editor
Staff & Editor
August 31, 2021

Technical Tip: How to send a notification from FortiGate Cloud when FortiGate or FortiProxy is disconnected or management tunnel is down

  • August 31, 2021
  • 0 replies
  • 5575 views

Description

 

This article describes how to configure FortiGate Cloud to send alerts whenever a FortiGate or FortiProxy unit is disconnected from the management tunnel for an extended period of time.

 

Scope

 

FortiGate Cloud, FortiGate, FortiProxy.

Solution

 

  1. Log in to FortiGate Cloud: FortiGate Cloud.
  2. On the left-hand navigation menu, go to Analytics -> Incidents & Events -> Automation -> Select the Actions tab -> Select Create New.
                                                                                            

1.png

 

  1. Create a New Event Handler Action, specifying a Name and the action to take (Email and/or Webhook). In this example, Email will be used, so specify a recipient email address (To) and a Subject line for the email, then select OK to create the action.
  2. Still in Analytics -> Incidents & Events -> Automation, change to the Stitches tab and select Create new.
  3. Select the Add trigger button, then search for and select the Device Tunnel To Server Down option. Select the Add action button and specify the Email action created earlier.
  4. Select a FortiGate from the available list that this Automation Stitch should apply to. Only devices with active FortiGate Cloud subscriptions may be associated with these Automation Stitches. Select OK to complete the Automation Stitch creation.

 

FortiGate Cloud - Stitch Creation.png

 

By default, FortiGate Cloud waits for 30 minutes after the FortiGate/FortiProxy management tunnel goes offline before the 'Device Tunnel To Server Down' trigger is executed.

This is meant to avoid excessive notifications caused by flaps in network connectivity, and so brief outages (such as reboots of the FortiGate) may not trigger this Automation Stitch.


In FortiGate Cloud v25.4.a and above, it is possible to configure this value as follows.

 

To adjust the time before triggering 'Device Tunnel to Server Down':

Go to Analytics -> Incidents & Events -> Event Handler:

190919_01.png

 

  1. Select 'Device Tunnel to Server Down' -> Select 'Edit'.


190919_02_mod.png

 

  1. Select the Event Handler Rule -> Select Edit.


event_handler_mod.png

  1. Enter a value between 10 and 144 minutes and select 'OK'.


190919_04_mod.png

  1. In the 'Edit Event Handler' pane, select 'OK'.


190919_05_mod.png

 

  1. The timer has now been adjusted for all automation stitches that reference the trigger.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.