Transcript
But how do we scale this up from a single firewall in a single OT environment? I'm Matt Bolick, Technical Marketing Engineer with Fortinet. Let's take a look at how we scale our environment with the Fortinet Security Fabric and give us even more capabilities through fabric integrations. The Security Fabric is what allows Fortinet products, as well as third-party products, to seamlessly share security information, configuration, logging, alerts, and more. The integrated approach is really the only way to build intelligent and secure networks in the 21st century. It's easy enough to manage a single FortiGate, but when we need to configure and manage larger or multi-site environments, we get FortiManager involved. FortiManager can be deployed as a cloud service or, more typically in OT environments, as a physical or virtual appliance. There are plenty of videos covering the great things FortiManager can do, so I'll focus on one area of interest to many OT users – asset identification. Much like we have the Asset Identity Center on a single FortiGate, FortiManager also gives us an Asset Identity Center for an administrative domain where we can see all the devices we've discovered, along with any vulnerabilities. Here we have a very vulnerable, older piece of gear. Since these assets are visible on the FortiManager platform, it's easy to take action to quarantine or remove these vulnerable assets from the network, or even share device information discovered in one location with fabric members in another. Now, you'll remember that I mentioned the power of the Fortinet Security Fabric is in bringing together both Fortinet and third-party products. Nowhere is that more evident than in the integration with the leading OT and IoT device visibility partners, such as Dragos, Nozomi, Armus, and Clarity. Let's look at one of these fabric integrations with Clarity Xdome. Integration with other partners is going to be very similar, and this isn't saying that one is better than another. The key thing here is that the Security Fabric is designed to be open for easy integrations with the other vendors you have in your environment, no matter which logo they carry. Clarity offers several ways of sending visibility information to the Security Fabric. They can share information with FortiNAC, directly with a FortiGate, or they can integrate with FortiManager, which is what we'll do here. Xdome provides an easy wizard to guide you through the process, where you configure your FortiManager details and determine which tags from Xdome we want to export to the Security Fabric. If we look at the security zones in Xdome, Clarity is recommending several zones used in typical OT environments, based on discovered devices. We can accept or modify these zones to include certain device types. Let's accept their recommendation for creating a process zone. We can also add zones to our organization starting from scratch, using a wide range of discovered parameters to filter devices into this zone. Let's send some of these zones to the Security Fabric through FortiManager. We already have a controller zone, where we're grouping PLCs and their controllers, so let's export that. Next, we have an operation zone, which we'll also export to FortiManager. Let's look at our FortiManager integration, so we can manually send those zones over to the FortiManager. This integration will normally run on a schedule that we define, but we want to kickstart it here. It looks like we've synchronized over 1,000 devices in the operation zone, and 451 in the controller zone. Now let's take a look at the other side of this integration, already configured. In FortiManager, we add third-party integrations as external connectors. We have one external connector for Clarity Xdome configured using the JSON API connector. We're receiving two tags from Xdome, controllers and operation. That checks out. Xdome will be sending us asset information for each of these tags, so that FortiManager and the rest of the Security Fabric can take action on devices in those zones. One way we can make use of that information is by creating a dynamic address. Since we're dealing with address tags, this will be an SSO-style tag that we'll associate with the controller group from Xdome. This address tag will now be pushed down to all devices under this FortiManager administrative domain, so we can include it in our firewall policies. We'll do the same for our operations group, configure a new SSO tag that will be learned from the Xdome integration and passed down to other managed devices within the Fabric. Let's make use of those tags by creating a new firewall policy. This is just like creating any policy in FortiManager, except we can now select the controller group as our source and the operation group as the destination, applying whatever additional security inspection we need between those zones. This policy can now be applied across our OT environment, making use of the deep, customized device detection and grouping from Clarity. The APIs used for integrating with the Fortinet Security Fabric are available to many partners, such as Clarity, Nozomi, Dragos, and Armus, through the Fabric Ready program. The challenge of bringing robust security to any modern OT environment requires products from multiple vendors to cooperate and share information. Engineers responsible for building reliable and secure control systems will choose products from multiple vendors that meet their needs in each area. They need to be confident that those products will work together, sharing information to build a more robust and secure environment. You can find out more about the Fortinet Security Fabric or our more than 20 years of history building products for operational technology at fortinet.com slash OT. Thanks for watching.