FortiProxy
FortiProxy provides enterprise-class protection against internet-borne threats and Advanced Web Content Caching
aahmadbasri
Staff
Staff
Article Id 283994
Description This article describes how to integrate FortiProxy with FortiManager.
Scope FortiProxy v7.2.x.
Solution
  1. Check FortiProxy and FortiManager compatibility: Compatibility with FortiProxy.
  2. Configuration on FortiProxy. Go to Security Fabric -> Fabric Connectors -> FortiManager and select 'Edit'.

KB5_1.png

 

In the CLI, this can be done with the following command: 

 

config system central-management
    set type fortimanager
    set fmg <FMG IP>
end

 

  1. Select 'Apply', and the following will be shown. Select then 'OK'. 

 

KB5_2.png

 

  1. Log in to FortiManager to authorize the device. An alert will be shown. 

 

KB5_4.png

 

  1. 'Double-click' on the alert, select the device, and select Authorize. Select the correct ADOM. When ADOM is 'enabled', the ADOM type must be either FortiProxy or Fabric. 

 

KB5_5.png

KB5_6.png
  1. Once the status is successful, the device is now managed by FortiManager and can be viewed in FortiManager. 

 

KB5_7.png

KB5_8.png

 

Troubleshooting:

When integrating FortiManager with FortiProxy, ensure there is no blocking port '541'. Check the telnet status from FortiProxy:

 

Screenshot 2023-12-28 145826.png

 

Check the tunnel FDSM status from FortiProxy:

 

Screenshot 2023-12-28 150019.png

 

If the FDSM status tunnel is down, check the traffic between these two devices via sniffer. Ensure there is traffic between these two devices. Check the connectivity between FortiManager and FortiProxy via sniffer:

 

Screenshot 2023-12-28 145721.png

 

Ensure the FortiManager and FortiProxy are compatible with each other.

 

Starting from v7.2.10, v7.4.7, and v7.6.3, the connection between FortiProxy-VM and FortiManager is restricted for security.

By default, FortiManager will not allow VM platform connection in FGFM. When upgrading from an earlier version of FortiManager, VM devices already managed by FortiManager will continue to be supported without interruption.

The administrator must make changes in FortiManager before adding additional VM devices. For more information, refer to this document: Adding VM devices to FortiManager 

 

Related document:

Compatibility with FortiProxy