Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Integrating OT Visibility Partners with FortiManager

Fortinet
07/25/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


But how do we scale this up from a single firewall in a single OT environment? I'm Matt Bolick, Technical Marketing Engineer with Fortinet. Let's take a look at how we scale our environment with the Fortinet Security Fabric and give us even more capabilities through fabric integrations. The Security Fabric is what allows Fortinet products, as well as third-party products, to seamlessly share security information, configuration, logging, alerts, and more. The integrated approach is really the only way to build intelligent and secure networks in the 21st century. It's easy enough to manage a single FortiGate, but when we need to configure and manage larger or multi-site environments, we get FortiManager involved. FortiManager can be deployed as a cloud service or, more typically in OT environments, as a physical or virtual appliance. There are plenty of videos covering the great things FortiManager can do, so I'll focus on one area of interest to many OT users – asset identification. Much like we have the Asset Identity Center on a single FortiGate, FortiManager also gives us an Asset Identity Center for an administrative domain where we can see all the devices we've discovered, along with any vulnerabilities. Here we have a very vulnerable, older piece of gear. Since these assets are visible on the FortiManager platform, it's easy to take action to quarantine or remove these vulnerable assets from the network, or even share device information discovered in one location with fabric members in another. Now, you'll remember that I mentioned the power of the Fortinet Security Fabric is in bringing together both Fortinet and third-party products. Nowhere is that more evident than in the integration with the leading OT and IoT device visibility partners, such as Dragos, Nozomi, Armus, and Clarity. Let's look at one of these fabric integrations with Clarity Xdome. Integration with other partners is going to be very similar, and this isn't saying that one is better than another. The key thing here is that the Security Fabric is designed to be open for easy integrations with the other vendors you have in your environment, no matter which logo they carry. Clarity offers several ways of sending visibility information to the Security Fabric. They can share information with FortiNAC, directly with a FortiGate, or they can integrate with FortiManager, which is what we'll do here. Xdome provides an easy wizard to guide you through the process, where you configure your FortiManager details and determine which tags from Xdome we want to export to the Security Fabric. If we look at the security zones in Xdome, Clarity is recommending several zones used in typical OT environments, based on discovered devices. We can accept or modify these zones to include certain device types. Let's accept their recommendation for creating a process zone. We can also add zones to our organization starting from scratch, using a wide range of discovered parameters to filter devices into this zone. Let's send some of these zones to the Security Fabric through FortiManager. We already have a controller zone, where we're grouping PLCs and their controllers, so let's export that. Next, we have an operation zone, which we'll also export to FortiManager. Let's look at our FortiManager integration, so we can manually send those zones over to the FortiManager. This integration will normally run on a schedule that we define, but we want to kickstart it here. It looks like we've synchronized over 1,000 devices in the operation zone, and 451 in the controller zone. Now let's take a look at the other side of this integration, already configured. In FortiManager, we add third-party integrations as external connectors. We have one external connector for Clarity Xdome configured using the JSON API connector. We're receiving two tags from Xdome, controllers and operation. That checks out. Xdome will be sending us asset information for each of these tags, so that FortiManager and the rest of the Security Fabric can take action on devices in those zones. One way we can make use of that information is by creating a dynamic address. Since we're dealing with address tags, this will be an SSO-style tag that we'll associate with the controller group from Xdome. This address tag will now be pushed down to all devices under this FortiManager administrative domain, so we can include it in our firewall policies. We'll do the same for our operations group, configure a new SSO tag that will be learned from the Xdome integration and passed down to other managed devices within the Fabric. Let's make use of those tags by creating a new firewall policy. This is just like creating any policy in FortiManager, except we can now select the controller group as our source and the operation group as the destination, applying whatever additional security inspection we need between those zones. This policy can now be applied across our OT environment, making use of the deep, customized device detection and grouping from Clarity. The APIs used for integrating with the Fortinet Security Fabric are available to many partners, such as Clarity, Nozomi, Dragos, and Armus, through the Fabric Ready program. The challenge of bringing robust security to any modern OT environment requires products from multiple vendors to cooperate and share information. Engineers responsible for building reliable and secure control systems will choose products from multiple vendors that meet their needs in each area. They need to be confident that those products will work together, sharing information to build a more robust and secure environment. You can find out more about the Fortinet Security Fabric or our more than 20 years of history building products for operational technology at fortinet.com slash OT. Thanks for watching.

TL;DR

  • FortiManager extends single-firewall OT security capabilities to multi-site environments through the Fortinet Security Fabric, enabling centralized asset visibility and vulnerability management.
  • Third-party OT visibility platforms like Claroty, Nozomi, Dragos, and Armis integrate with FortiManager through external connectors using standardized APIs from the Fabric Ready program.
  • Device zones and tags exported from OT visibility tools become dynamic address objects in FortiManager, which are automatically pushed to all managed FortiGates for policy enforcement.
  • The integration enables zone-based firewall policies that leverage specialized OT device detection without requiring manual device list maintenance across distributed environments.

Scaling OT Security with FortiManager and the Security Fabric

This technical demonstration walks through how Fortinet's Security Fabric enables integration between FortiManager and third-party OT visibility platforms like Claroty Xdome, Nozomi, Dragos, and Armis. The video shows how asset information discovered by specialized OT security tools can be synchronized with FortiManager, which then distributes that intelligence across the entire Security Fabric. The practical example demonstrates configuring Claroty Xdome to export device zones—such as controllers and operations—to FortiManager via JSON API connector, then using those imported tags to create dynamic address objects for firewall policies.

Creating Zone-Based Policies from Partner Data

The demonstration highlights how OT engineers can leverage deep device detection from partners like Claroty to build security policies that would be difficult to create manually. By synchronizing over 1,400 devices across controller and operation zones, administrators can create SSO-style dynamic address tags that automatically populate across all managed FortiGates in the administrative domain. This approach allows security teams to apply granular inspection policies between OT zones—such as between PLCs and their controllers—without manually maintaining device lists. The Fabric Ready program provides standardized APIs that enable similar integrations across multiple OT visibility vendors.

Chapters

0:00 - Introduction to OT Security Scaling
0:27 - Security Fabric Overview
1:07 - Asset Identity Center in FortiManager
1:46 - OT Visibility Partner Integrations
2:14 - Claroty Xdome Configuration
3:42 - FortiManager External Connectors
4:09 - Creating Dynamic Address Tags
4:43 - Building Zone-Based Firewall Policies

Key Quotes

0:37 "The integrated approach is really the only way to build intelligent and secure networks in the 21st century."
2:04 "The key thing here is that the Security Fabric is designed to be open for easy integrations with the other vendors you have in your environment, no matter which logo they carry."
5:24 "The challenge of bringing robust security to any modern OT environment requires products from multiple vendors to cooperate and share information."

FAQ

Which OT visibility vendors integrate with FortiManager through the Security Fabric?

Fortinet's Fabric Ready program supports integrations with leading OT and IoT visibility partners including Dragos, Nozomi, Armis, and Claroty. These vendors can share device information with FortiManager, FortiNAC, or directly with FortiGate firewalls using standardized APIs.

How do device tags from OT visibility tools become usable in firewall policies?

Tags exported from partners like Claroty Xdome are received by FortiManager through external connectors. Administrators create SSO-style dynamic address objects associated with those tags, which are then pushed to all managed FortiGates in the administrative domain and can be used as source or destination in firewall policies.


Categories:
  • » Webinar Library » Fortinet
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Network Security
  • Technical Deep Dive
  • Demo
  • FortiManager
  • OT Security
  • Security Fabric
  • Claroty Xdome Integration
  • Asset Visibility
  • Dynamic Address Objects
  • Fabric Ready Program
  • Industrial Control Systems
  • Zone-Based Policies
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Integrating OT Visibility Partners with FortiManager

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    03

                    Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                    08/03/202611:00 AM ET
                    • Aug
                      06

                      Safeguarding Sensitive Data in the Era of AI Adoption

                      08/06/202604:00 AM ET
                      • Aug
                        06

                        Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                        08/06/202602:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/03/2026
                          11:00 AM
                          08/03/2026
                          Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Safeguarding Sensitive Data in the Era of AI Adoption
                          https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-ai-adoption/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version