FortiManager Connector
This section details how to configure the FortiManager Connector.
Prerequisites
On the FortiManager side, you need to create an administrator account for Horizon with JSON-RPC API access in read-write mode, allowed to manage certificates on the FortiManager and, when deploying to managed devices, on the targeted ADOM.
After performing these steps, you will get the following information, required later:
-
the administrator login/username
-
the administrator password
How to configure FortiManager Connector
1. Log in to Horizon Administration Interface.
2. Access FortiManager Connectors from the drawer or card: .
3. Click on .
4. Fill the mandatory fields.
General
-
Name* (string input):
Enter a meaningful connector name. It must be unique for each connector. Horizon uses the name to identify the connector. -
Hostname* (string input):
Enter the FortiManager hostname or URL. -
Credentials* (select):
SelectLogincredentials containing the username and password created for Horizon in the FortiManager. -
Prefix* (string input):
Prefix of the certificate names on the FortiManager, used to identify the certificates managed by Horizon. -
Proxy (select):
The HTTP/HTTPS proxy to use. -
Timeout* (finite duration):
Maximum time Horizon waits for a response from the FortiManager. -
TLS Insecure (boolean):
If enabled, TLS validation will ignore expired, invalid or untrusted certificates.
| This is not recommended for production usage |
Target
-
Target* (select):
Select where certificates are deployed:-
Unit: the certificate store of the FortiManager unit itself. -
Device: a FortiGate device managed by the FortiManager. The following fields are then required:-
ADOM* (string input):
Administrative domain the device belongs to. -
Device* (string input):
Name of the managed device. -
VDOM* (string input):
Virtual domain on the managed device. -
Synchronize devices (boolean):
If enabled, Horizon installs the configuration on the device after importing the certificate. Otherwise, the certificate is only imported in the FortiManager device database. Disabled by default.
-
-
Actors and renewal management
These configuration elements mainly define the number of authorized interactions with the remote service on a defined period. For example, one needs to ensure that the remote service will not be contacted more than 5 times per 3 seconds. Throttle parallelism defines the number of times and Throttle duration the period of time. Therefore, on the above example, throttle parallelism would be set to 5 and throttle duration would be set to 3 seconds.
-
Throttle duration* (finite duration):
Must be a valid finite duration. -
Throttle parallelism* (int):
Number of deployments processed in parallel.
Deployment jobs retry
Deployments to this third party are run as asynchronous jobs. When a job fails, Horizon retries it using an exponential backoff strategy.
-
Attempts* (int):
Maximum number of retry attempts before the job is considered failed. -
Minimum backoff* (finite duration):
Delay to wait before the first retry. -
Maximum backoff* (finite duration):
Maximum delay between two retries, capping the exponential backoff. -
Random factor* (decimal):
Random jitter added to each delay to avoid simultaneous retries (e.g.0.1adds up to 10%).
5. Click on the save button.
You can update or delete
the FortiManager Connector.
|
You will not be able to delete a FortiManager Connector if it is referenced in any other configuration element. |