Hello Fortinet team,
I’m working on an integration between FortiSIEM 7.4 (multi-tenant environment) and FortiGate Threat Feeds, and I’d like to request guidance on the best way to achieve the following setup.
Allow a FortiGate located at a remote site (which has no direct connectivity to the FortiSIEM Supervisor) to consume a watchlist feed (External Fabric Threats) through its local FortiSIEM Collector, using the Collector as a proxy or relay.
The FortiGate should authenticate using HTTP Basic Authentication, as documented (format: super/username), with the standard endpoint:
#https://<Supervisor_IP>:<port>/phoenix/rest/watchlist/ip?name=External%20Fabric%20Threats
Current Setup:
FortiSIEM 7.4, multi-tenant mode.
FortiGate firewalls at remote sites.
Collectors installed in each remote site (Collectors have connectivity to the Supervisor).
Supervisor is not directly reachable from the FortiGates for security reasons.
User | Count |
---|---|
2626 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.