Fortinet FortiManager (Beta)

👍

Quick Details

Recommended Agent: On-Demand
Supported Agents: On-Demand and Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Fortinet Fortigate Child Inspectors
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 8 hours)
Data Summary: FortiManager Inspector Summary

Overview


Inspector Setup Preparation

⚠️

Prerequisites & Access Requirements

Inspector Setup:

Create the Liongard Service API Account

The Liongard FortiManager Inspector requires a dedicated REST API Administrator account with a read-only administrator profile.

Complete the following steps to create the required account and generate an API key.


Step 1: Create a Read-Only Administrator Profile

  1. In FortiManager, navigate to System Settings → Admin Profiles.

  2. Click Create New.

  3. Enter a name for the profile, such as Read Only.

  4. Select every permission in the Read-Only column.

  5. Click OK.



Step 2: Create a REST API Administrator

  1. Navigate to System Settings → Administrators.

  2. Click Create New → REST API Admin.

  3. Configure the account using the following settings:

SettingValue
User Nameliongard_svc
Administrator ProfileSelect the Read Only profile created in Step 1
JSON API AccessRead and Write
Trusted Hosts (IPv4 Host 1)Enter the IP address of the server where the Liongard Agent is installed
  1. Click OK.
    ⚠️

    Important:

    After you save the account, FortiManager displays the API key only once. Copy the key immediately and store it securely. You will need this API key when configuring the Liongard FortiManager Inspector.


Step 2: Configure the Fortinet FortiManager Inspector in Liongard

  1. Log in to the Liongard platform.
  2. In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the Fortinet FortiManager Inspector > Select Add System.

Since the Fortinet FortiManager Inspectors are multi-tenant systems where a single portal can be used to manage many Environments, you will set up a single "Parent" Inspector that will then auto-discover "Child" Inspectors for each Environment.

Fill in the following information:

  • Type of Inspector: Parent
  • Environment: Select your MSP's Environment
  • Friendly Name: Suggested Naming: [Customer Name] FortiManager Parent
  • Agent: Select the On-Premises Agent installed for this Environment
  • Inspector Version: Latest
  • Deployment Type: Select On-Premises for a directly reachable FortiManager appliance, or FortiManager Cloud for a Fortinet-hosted instance
  • Host/FQDN: The IP address or FQDN of your FortiManager device. Do not include the protocol (ex: https://)
  • HTTPS Port: Enter the port used to reach your device (ex: 443)
  • Cloud Account ID: Enter your account ID — required only if Deployment Type is FortiManager Cloud
  • Cloud Region: Enter your region — required only if Deployment Type is FortiManager Cloud
  • API Key (Bearer): The API Key generated for the service account created above
  • Username and Password: Optional if you are not using an API Key.
  • Scheduling: The Inspector will default to running once a day at the time it is set up. Here you can adjust the schedule
  • Select Save. The Inspector will now be triggered to run within the minute.

Step 3: Child Inspector Setup

After the first run of the Parent Inspector, your client Fortinet FortiGate organizations will be auto-discovered in the Discovered Systems tab on the Inspectors > Appropriate Fortinet FortiManager Inspector page.

  • Activate or Archive your Discovered Systems by ensuring that they're mapped to the correct Environment > Check the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints
  • Click Save.

Did this page help you?