Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Discovering OT Assets and Vulnerabilities with FortiGate

Fortinet
05/08/2026
29
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • FortiGate firewalls can discover OT devices using MAC addresses, network traffic analysis, and FortiGuard database lookups without requiring additional discovery tools.
  • Device detection is enabled at the interface level and works across VLANs representing different Purdue model levels in industrial environments.
  • Enabling application control profiles adds vulnerability intelligence, automatically identifying CVEs associated with discovered hardware and software combinations.
  • The asset identity center provides both list and Purdue model views, with automatic device categorization that can be manually adjusted to match actual deployments.

OT Asset Discovery Challenges and FortiGate's Approach

Industrial control system environments present unique visibility challenges as they evolve organically over years or decades, accumulating devices from multiple vendors and generations—some with unpatched vulnerabilities. This demonstration walks through FortiGate's device detection capabilities in a simulated OT environment spanning multiple levels of the Purdue model. The setup pairs a FortiGate firewall with a FortiSwitch managed via FortiLink, creating VLANs for process, control, monitoring, and operations networks. Device detection is enabled at the interface level, allowing the firewall to identify assets through MAC addresses, residual traffic like ARP and DHCP, and FortiGuard database lookups.

Building Device Profiles with Application Control

The demonstration shows how enabling application control profiles on firewall policies significantly enriches device intelligence. By applying OT-specific application signatures and SSL certificate inspection, the FortiGate identifies not just device types but also known vulnerabilities—including specific CVEs for command injection and buffer errors on discovered hardware. The asset identity center displays devices arranged in a Purdue model view, automatically categorizing them by type and network location while allowing manual reassignment. Fortinet positions this combined discovery and security capability as a differentiator, noting that while specialized discovery tools exist, FortiGate uniquely integrates asset identification with industrial firewall controls and virtual patching capabilities.

Chapters

0:00 - OT Visibility Challenges
0:55 - Lab Topology Overview
1:37 - Configuring Device Detection
2:14 - Initial Device Discovery
3:25 - Adding Application Control
4:10 - Vulnerability Identification
5:00 - Purdue Model Asset View

Key Quotes

0:17 "Gaining visibility into the devices in your environment is something that we can tackle with a FortiGate firewall."
1:06 "The switch is integrated and managed by the FortiGate using the FortiLink interface, letting the switch act as an extension of the firewall."
4:26 "Using application control, we now know about potential vulnerabilities. We can see that this hardware and software combination has a known command injection and a buffer error vulnerabilities."
5:24 "While there are many vendors that specialize in device discovery, FortiGates are unique in that they combine discovery with the leading industrial security appliance in the FortiGate firewall."

Categories:
  • » Webinar Library » Fortinet
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Network Security
  • Vulnerability Management
  • Demo
  • Technical Deep Dive
  • OT asset discovery
  • Industrial control system security
  • FortiGate firewall
  • Purdue model
  • Device detection
  • Vulnerability identification
  • Application control
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Discovering OT Assets and Vulnerabilities with FortiGate

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version