QuestionQ18

SOAR Incident Handling and Threat Hunting

Refer to the exhibits.

Question Image

Question Image

You have configured the FortiGate connector on FortiSOAR. You want to permit FortiSOAR (10.200.200.160) to perform actions on FortiGate (172.16.200.1), but the connection attempt fails. Assume the FortiGate connector is configured correctly on the FortiSOAR side.

Which two configurations are required on FortiGate?

Choose two
  • A HTTPS must be enabled on the FortiGate interface that FortiSOAR will communicate with.
  • B FortiSOAR IP address must be added under Trusted Hosts.
  • C The administrator profile must have System read and write permissions.
  • D The FortiGate interface role must be set to Custom API Endpoint.
Explanation

FortiGate REST API access requires HTTPS to be enabled on the target interface; the FortiSOAR connector uses HTTPS, normally on port 443. A REST API administrator with Trusted Hosts configured accepts access only from the listed source addresses or subnets, so 10.200.200.160 must be added. The administrator profile needs only the least privileges required by the intended actions, not necessarily System read/write permissions.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!