Trend Vision One enables sharing of suspicious object data with FortiGate Next-Generation Firewall through a Service Gateway.
Configure sharing of suspicious object data with this integration through a Service Gateway.
At least one Service Gateway must be configured to enable integration.
For more information, see Service Gateway Management.
Object type: Select the file hash value format to use.
Risk level: Select the risk level of the suspicious object data to include in the shared data.
Frequency: Select the frequency at which suspicious object data is shared.
URL parameters: Select whether to remove query strings from URLs.
Click Connect.
The Service Gateway Connection panel appears.
Select a Service Gateway.
Configure the integration server settings.
(Optional) Click Test Connection to verify if the settings are valid.
Click Connect.
The connection configuration is added to the list.
Click the Generate
Now icon () to generate suspicious object
data sharing files immediately.
Hover over the Copy
URL icon () to copy the suspicious object
data sharing URLs to use on your integration.
The following steps were performed using version 7.0.0 of the FortiOS GUI.
If you are using a different version, refer to the documentation for your version.
FortiGuard Category: Create an object to retrieve suspicious object data for URLs.
IP Address: Create an object to retrieve suspicious object data for IP addresses.
Domain Name: Create an object to retrieve suspicious object data for domain names.
Malware Hash: Create an object to retrieve suspicious object data for file hashes.
Name: Type a name for this object.
URI of external resource: Paste the suspicious object data sharing URL that you obtained from the Trend Vision One console.
HTTP basic authentication: Disable this setting.
Refresh rate: Specify the rate at which this object checks for updates.
Trend Micro recommends matching the refresh rate to the suspicious object data sharing Frequency configured on Trend Vision One.
Comments: Type some comments to help you identify this object.
Status: Enable this setting.
Click OK.
Your FortiGate appliance is configured to retrieve suspicious object data from the Trend Vision One Service Gateway.
The configured Threat Feeds objects can be used as external resources in Policies and Security Profiles.
Click the Refresh icon to retrieve suspicious object data from the Trend Vision One Service Gateway immediately.
(Optional) Click View Entries to display the suspicious object data retrieved from the Trend Vision One Service Gateway.