FortiGate Connector

This section details how to configure the FortiGate Connector.

Required By

Prerequisites

On the FortiGate side, you need to create a REST API administrator for Horizon, with an administrator profile allowed to read and write the certificate configuration. Make sure the Horizon IP address is part of the trusted hosts of this administrator.

After performing these steps, you will get the following information, required later:

  • the REST API key generated for this administrator

  • optionally, a client certificate if the FortiGate requires mutual TLS authentication

How to configure FortiGate Connector

1. Log in to Horizon Administration Interface.

2. Access FortiGate Connectors from the drawer or card: Third Parties  FortiGate  Connectors.

3. Click on Add Connector.

4. Fill the mandatory fields.

General

  • Name* (string input):
    Enter a meaningful connector name. It must be unique for each connector. Horizon uses the name to identify the connector.

  • Hostname* (string input):
    Enter the FortiGate hostname or URL.

  • Credentials* (select):
    Select API Token credentials containing the FortiGate REST API key.

  • Certificate credentials (select):
    Select Certificate credentials to authenticate with mutual TLS, in addition to the API key.

  • VDOM (string input):
    Virtual domain to deploy certificates to. When empty, certificates are deployed in the global scope.

  • Prefix* (string input):
    Prefix of the certificate names on the FortiGate, used to identify the certificates managed by Horizon.

  • Proxy (select):
    The HTTP/HTTPS proxy to use.

  • Timeout* (finite duration):
    Maximum time Horizon waits for a response from the FortiGate.

  • TLS Insecure (boolean):
    If enabled, TLS validation will ignore expired, invalid or untrusted certificates.

This is not recommended for production usage

Actors and renewal management

These configuration elements mainly define the number of authorized interactions with the remote service on a defined period. For example, one needs to ensure that the remote service will not be contacted more than 5 times per 3 seconds. Throttle parallelism defines the number of times and Throttle duration the period of time. Therefore, on the above example, throttle parallelism would be set to 5 and throttle duration would be set to 3 seconds.

  • Throttle duration* (finite duration):
    Must be a valid finite duration.

  • Throttle parallelism* (int):
    Number of deployments processed in parallel.

5. Click on the save button.

You can update Edit Connector or delete Delete Connector the FortiGate Connector.

You will not be able to delete a FortiGate Connector if it is referenced in any other configuration element.