Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tiago_rcxit
New Contributor

FortiSIEM Multi-Tenant – Consume Watchlist from Remote Site via Collector (FortiGate Threat Feed Int

Hello Fortinet team,

I’m working on an integration between FortiSIEM 7.4 (multi-tenant environment) and FortiGate Threat Feeds, and I’d like to request guidance on the best way to achieve the following setup.


Goal

Allow a FortiGate located at a remote site (which has no direct connectivity to the FortiSIEM Supervisor) to consume a watchlist feed (External Fabric Threats) through its local FortiSIEM Collector, using the Collector as a proxy or relay.

The FortiGate should authenticate using HTTP Basic Authentication, as documented (format: super/username), with the standard endpoint:

 

#https://<Supervisor_IP>:<port>/phoenix/rest/watchlist/ip?name=External%20Fabric%20Threats

 

Current Setup:

FortiSIEM 7.4, multi-tenant mode.

FortiGate firewalls at remote sites.

Collectors installed in each remote site (Collectors have connectivity to the Supervisor).

Supervisor is not directly reachable from the FortiGates for security reasons.

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors