Task 1 - Preparation of FortiAnalyzer and FortiWeb
Prepare FortiAnalyzer and FortiWeb for the Lab
This Chapter includes necessary steps to setup Log shipping and Event Monitoring with FortiAnalyzer of FortiWeb. Please make sure you have completed this section before moving on!
FortiWeb Preparations
- Login to FortiWeb with the give credentials
- On the left sided menu, goto
Log&Report
-Log Policy
-FortiAnalyzer Policy
- Select
Create New
at the top left to open the Configuration Wizard
- Provide a meaningful name for the Policy and the click
OK
to save
- After the Policy has been saved, click on
Create New
to a add a new entry to the policy - Enter the IP Address of Fortianalyzer into the corresponding field, then click on
OK
to add the entry
- Check that the new entry was added successfully, click
OK
again to make sure that everything is saved.
- On the left sided menu, goto
Log&Report
-Log Config
-Global Log Settings
- Enable FortiAnalyzer and select the previous configured FortiAnalyzer Policy
Click on
Apply
at the bottom of the Page to save the configuration.To enable the global logging, open the built-in CLI by clicking on the
>_
Symbol the to top right
- Execute the following commands
config log traffic-log
set status enable
end
- Logging of FortiWeb to FortiAnalyzer is now enabled. Please proceed with the configuration of FortiAnalyzer
FortiAnalyzer Preparations
- Login to FortiAnalyzer with the given Credentials
- Goto
Device Manager
and click onAdd Device
to add FortiWeb
Provide the follwoing Information, then click on
Next
to proceed with the configuration.- Name:
FortiWeb
- Serial Number: (This can be found at the Dashboard of FortiWeb)
- Wait until the Device got added successfully. Then click on
Finish
to close the wizard.
- To finalize the FortiWeb configuration, select the entry from the Device table and click on
Edit
- Update
Admin User
andPassword
with the given credentials, then click onOK
to save.
- To be able to feed Security Events within FortiSOAR, Events need to get generated within the Event Monitor. For this to work, a so called Handler needs to be in Place. The Handler for FortiWeb is disabled by default and needs to be enabled. For this, goto
Incidents & Events
-Handlers
- Select the
Basic Handlers
Tab, then use the Search field at the top right to search forFWB
- Right click on the search result, click on
Enable
to activate the handler.
- Check that the Status changes from
disabled
toenabled
(green checkmark)
- As soon as FortiWeb detects an attack, a new Event entry will get added. See the following Example:
Please make sure, that a
Web Protection Profile
is used within the configured FortiWeb Policy. The default policies provided by FortiWeb are more than enough with regards to this lab.- Name:
Congratulations, you are done with the preparations. Please continue to the next Section of the Lab.