<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Fortinet Security Integration in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29639#M370</link>
    <description>the communication is between Management Center (NetSight) and Fortigate.&lt;BR /&gt;
The communicaiton is &lt;U&gt;&lt;B&gt;NOT &lt;/B&gt;&lt;/U&gt;bewteen AccessControllEngine (NAC-GW) and Fortigate.&lt;BR /&gt;
&lt;BR /&gt;
Configure IP address of Management Center as your radius server on the Fortigate = that means the Fortigate will understand the shared secret and will accept radius accounting from the Management Center.&lt;BR /&gt;
&lt;BR /&gt;
Configure Extreme Connect  (OneFabric Connect) module to talk to your fortigate.&lt;BR /&gt;
&lt;BR /&gt;
---&lt;BR /&gt;
client connects to the network access switch/AP, AccessControllEngine (NAC-GW) wil process it. when the IP resolution is done, the Management Center (NetSight) sends radius accounting to the Fortigate with appropriate radius attributes. finaly the fortigate knows IP-profile-username&lt;BR /&gt;
&lt;BR /&gt;
good luck </description>
    <pubDate>Fri, 29 Jul 2016 14:54:00 GMT</pubDate>
    <dc:creator>Zdeněk_Pala</dc:creator>
    <dc:date>2016-07-29T14:54:00Z</dc:date>
    <item>
      <title>Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29629#M360</link>
      <description>I have found a Solution Brief about a security integration about Extreme Networks and Fortinet, &lt;BR /&gt;
&lt;A href="http://learn.extremenetworks.com/rs/extreme/images/Fortinet-SB.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;http://learn.extremenetworks.com/rs/extreme/images/Fortinet-SB.pdf&lt;/A&gt;&lt;BR /&gt;
We have a lot of customer with this two vendor and this type of integration can add value at our works, but I cannot find any doc that explain HOW TO deploy this type of scenario/integration ... &lt;BR /&gt;
Is only a marketing doc or there are behind this partnership a real integration?&lt;BR /&gt;
Someone have already made somthing similar?&lt;BR /&gt;
&lt;BR /&gt;
Roberto&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Jul 2016 20:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29629#M360</guid>
      <dc:creator>_up__bb_</dc:creator>
      <dc:date>2016-07-13T20:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29630#M361</link>
      <description>Hi.    Of course there is a lot of technology behind the integration on both ends = Forti and Extreme.    I do have several happy customers (small and big also).    I suggest you contact extreme Value Added Partner/resseller or Extreme representative.  To demonstrate/test/implement the solution.    The list of partners is available on our corporate website.    Unfortunately the implementation can be very complex and also very simple (based on the network equipment).    Good luck    Zdenek</description>
      <pubDate>Wed, 13 Jul 2016 21:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29630#M361</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-13T21:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29631#M362</link>
      <description>Are we talking about OneFabricConnect, OneConnnect, Connect.... at this point I'm not sure what the name of the product is.&lt;BR /&gt;
&lt;BR /&gt;
With Extreme Management Suite 7.0 it's included in the installation (NMS-ADV, no need to install it separate) but I can't find a 7.0 manual for it on the product download page - would you please be so kind and point me in the right direction.</description>
      <pubDate>Wed, 13 Jul 2016 21:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29631#M362</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-07-13T21:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29632#M363</link>
      <description>Me too &lt;BR /&gt;</description>
      <pubDate>Wed, 13 Jul 2016 21:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29632#M363</guid>
      <dc:creator>_up__bb_</dc:creator>
      <dc:date>2016-07-13T21:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29633#M364</link>
      <description>&lt;A href="https://extranet.extremenetworks.com/downloads/Pages/OneFabricConnect.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extranet.extremenetworks.com/downloads/Pages/OneFabricConnect.aspx&lt;/A&gt; -&amp;gt; Partner Resources -&amp;gt; there is documentation available.&lt;BR /&gt;
&lt;BR /&gt;
the integration with Fortigate is now being enhanced =&amp;gt; new version will be even better from scalability point of view.&lt;BR /&gt;
&lt;BR /&gt;
regards&lt;BR /&gt;
&lt;BR /&gt;
Zdenek</description>
      <pubDate>Wed, 13 Jul 2016 21:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29633#M364</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-13T21:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29634#M365</link>
      <description>&lt;A href="https://extranet.extremenetworks.com/downloads/Pages/OneFabricConnect.aspx" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extranet.extremenetworks.com/downloads/Pages/OneFabricConnect.aspx&lt;/A&gt; -&amp;gt; documentation &lt;BR /&gt;
&lt;BR /&gt;
the version 2.x is for NetSight 6.y&lt;BR /&gt;
The Extreme Management Center does have Connect version 3.0 included in the product = as stated by Ronald.</description>
      <pubDate>Wed, 13 Jul 2016 21:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29634#M365</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-13T21:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29635#M366</link>
      <description>Hi roberto the configuration guide for this feature is now part of the Extreme Control online help.&lt;BR /&gt;
&lt;BR /&gt;
If you need an standalone document, you can use the previous version published here:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://extranet.extremenetworks.com/downloads/Pages/dms.ashx?download=9eb4a775-2f5e-499f-8205-27366dde1449" target="_blank" rel="nofollow noreferrer noopener"&gt;https://extranet.extremenetworks.com/downloads/Pages/dms.ashx?download=9eb4a775-2f5e-499f-8205-27366...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
just note that since Extreme control 7.0 the installation comes pre-installed with Extreme control and you don't need to install it manually.&lt;BR /&gt;
&lt;BR /&gt;
For a dynamic response scenario, we are developing a generic DIPS plugin probably for the end of the year. &lt;BR /&gt;
&lt;BR /&gt;
To deploy a dynamic response scenario with fortinet you must configure the DIPS feature for paloalto and configure teh fortinet firewall to send syslog messages with the format defined in the PaloAlto plugin.&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Jul 2016 00:07:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29635#M366</guid>
      <dc:creator>Ferrer__Salvado</dc:creator>
      <dc:date>2016-07-14T00:07:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29636#M367</link>
      <description>Hi all,&lt;BR /&gt;
&lt;BR /&gt;
I'm Luca, I'm working with Roberto in Fortigate integration.&lt;BR /&gt;
&lt;BR /&gt;
I have read the Palo Alto document, but there is a big issue: Palo Alto devices integration is done using XML API (User API) but Fortigate integration should be done using RSSO (Radius SSO).&lt;BR /&gt;
&lt;BR /&gt;
We have to configure "remote" Radius user group.&lt;BR /&gt;
&lt;BR /&gt;
I'm reading the "old" One Fabric Connect install document, but it has some omission: the first one is how to tell NAC Radius server to consider Fortigate as a client. Now I will try to add it as a switch. &lt;BR /&gt;
&lt;BR /&gt;
Have you got some suggestion?&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Jul 2016 11:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29636#M367</guid>
      <dc:creator>Luca_Messori</dc:creator>
      <dc:date>2016-07-29T11:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29637#M368</link>
      <description>Hi.    Just follow the installation guide. The fortigate must be configured: management center (netsight) as radius server with correct  shared secret..    From the terminology point of view the fortigate is the radius accounting server and management center is a radius accounting client. But the place where you configure it on the fortigate gui is little bit confusing.    Z.</description>
      <pubDate>Fri, 29 Jul 2016 14:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29637#M368</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-29T14:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29638#M369</link>
      <description>Hi Zdenek,&lt;BR /&gt;
&lt;BR /&gt;
thank you for the reply.&lt;BR /&gt;
&lt;BR /&gt;
Really, I'm little confusing on Extreme side of the configuration steps.&lt;BR /&gt;
&lt;BR /&gt;
I think that (first of all) I have to add the FG to NAC switches: I think that this step will add the firewall to the list of Radius client. Good, but the Fortigate will not do Radius authetication sessions. Fortigate sould receive accounting information from the NAC, so I have to configure the NAC to send accounting info.&lt;BR /&gt;
&lt;BR /&gt;
Where and how can I configure the NAC to send Accounting info to the fortigate?&lt;BR /&gt;
&lt;BR /&gt;
Regards,&lt;BR /&gt;
&lt;BR /&gt;
Luca&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Jul 2016 14:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29638#M369</guid>
      <dc:creator>Luca_Messori</dc:creator>
      <dc:date>2016-07-29T14:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29639#M370</link>
      <description>the communication is between Management Center (NetSight) and Fortigate.&lt;BR /&gt;
The communicaiton is &lt;U&gt;&lt;B&gt;NOT &lt;/B&gt;&lt;/U&gt;bewteen AccessControllEngine (NAC-GW) and Fortigate.&lt;BR /&gt;
&lt;BR /&gt;
Configure IP address of Management Center as your radius server on the Fortigate = that means the Fortigate will understand the shared secret and will accept radius accounting from the Management Center.&lt;BR /&gt;
&lt;BR /&gt;
Configure Extreme Connect  (OneFabric Connect) module to talk to your fortigate.&lt;BR /&gt;
&lt;BR /&gt;
---&lt;BR /&gt;
client connects to the network access switch/AP, AccessControllEngine (NAC-GW) wil process it. when the IP resolution is done, the Management Center (NetSight) sends radius accounting to the Fortigate with appropriate radius attributes. finaly the fortigate knows IP-profile-username&lt;BR /&gt;
&lt;BR /&gt;
good luck </description>
      <pubDate>Fri, 29 Jul 2016 14:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29639#M370</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-29T14:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29640#M371</link>
      <description>It does not make sense to configure Fortigate as switch (radius client) in AccessControl (NAC) configuration. I do not expect you want Forgite send radius requests to AccessControlEngine (NAC-GW) to process.</description>
      <pubDate>Fri, 29 Jul 2016 14:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29640#M371</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2016-07-29T14:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29641#M372</link>
      <description>Hi Zdenek,&lt;BR /&gt;
&lt;BR /&gt;
thank you very much, I think that now I'm understanging.&lt;BR /&gt;
&lt;BR /&gt;
The bad news is that I cannot do it without OneFabric Connect that require Advanced license.&lt;BR /&gt;
&lt;BR /&gt;
Is this correct?&lt;BR /&gt;
&lt;BR /&gt;
Is it possible to inform the Fortigate about connected users without using OneFabric Connect?&lt;BR /&gt;
&lt;BR /&gt;
Thank you very much for the time spent,&lt;BR /&gt;
&lt;BR /&gt;
have a nice weekend,&lt;BR /&gt;
&lt;BR /&gt;
Luca&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Jul 2016 18:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29641#M372</guid>
      <dc:creator>Luca_Messori</dc:creator>
      <dc:date>2016-07-29T18:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29642#M373</link>
      <description>Hello, gentlemen!&lt;BR /&gt;
&lt;BR /&gt;
Could you please answer me: is the integration between NMS-ADV and Fortinet (FG-600D in my case) possible without NAC?&lt;BR /&gt;
&lt;BR /&gt;
I've found two articles:&lt;BR /&gt;
&lt;A href="https://www.fortinet.com/content/dam/fortinet/assets/alliances/Extreme-Network-Fortinet-SB.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.fortinet.com/content/dam/fortinet/assets/alliances/Extreme-Network-Fortinet-SB.pdf&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
and&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://drive.google.com/file/d/0B5bMj99cONofd19hanpLdUpFQ1U/view" target="_blank" rel="nofollow noreferrer noopener"&gt;https://drive.google.com/file/d/0B5bMj99cONofd19hanpLdUpFQ1U/view&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
But they are old and may be something changed?&lt;BR /&gt;
&lt;BR /&gt;
Thanks!&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sun, 21 May 2017 15:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29642#M373</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-21T15:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29643#M374</link>
      <description>Hi.     The integration gives of two benefits:    Inform the firewall about user-ip or location-&amp;amp;user-ip mapping. For this we need NAC (extreme control)    If the firewall/ips/anti-anything detects the security issue then it send syslog/trap to the NetSight (extreme management) and management does perform reaction. This can be done through ASM (Autometed Security Manager)  or through NAC.    ASM is available with NetSight version 7. Actualy there is no plan to support ASM in the NetSight / EMC version 8.    There are some limits what ASM can do and in what network.    Sales answer for your question is: you do not need NAC for the integration to work. But with NAC it is much more powerfull and much easier and flexible.    Regards    Zdenek</description>
      <pubDate>Sun, 21 May 2017 16:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29643#M374</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2017-05-21T16:29:00Z</dc:date>
    </item>
    <item>
      <title>RE: Fortinet Security Integration</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29644#M375</link>
      <description>Thanks, Zdenek!&lt;BR /&gt;
&lt;BR /&gt;
Could you please clarify something for me....&lt;BR /&gt;
&lt;BR /&gt;
What means: "ASM is available with NetSight version 7. Actualy there is no plan to support ASM in the NetSight / EMC version 8". &lt;BR /&gt;
&lt;BR /&gt;
Extreme Networks is going to stop supporting Security Integration with Fortinet?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sun, 21 May 2017 16:29:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/fortinet-security-integration/m-p/29644#M375</guid>
      <dc:creator>Ilya_Semenov</dc:creator>
      <dc:date>2017-05-21T16:29:00Z</dc:date>
    </item>
  </channel>
</rss>

