> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# FortiGate Integration Guide

## Overview

This guide describes how to integrate **OneFirewall Alliance (OFA) Threat Feeds** into a **FortiGate Security Fabric** using External Dynamic Lists (EDLs). The integration enables automatic enforcement of security rules based on live threat intelligence from OneFirewall, covering both **inbound** and **outbound** traffic.

## Prerequisites

| Feature                               | Minimum FortiOS Version |
| ------------------------------------- | ----------------------- |
| External Connectors (Threat Feeds)    | **6.0+**                |
| Support for Custom HTTP Headers       | **6.2.3+**              |
| Feed Auto-Refresh & Policy Binding    | **6.4+**                |
| Full GUI Integration & Advanced Logic | **7.0+**                |

* Custom Bearer token authentication used by OneFirewall's API requires **FortiOS 6.2.3 or higher**.
* Devices running FortiOS prior to 6.2.3 can only ingest unauthenticated feeds, which is incompatible with OneFirewall's authenticated feed.
* FortiOS 6.4 or 7.x is recommended: secure external connectors with headers, feed auto-refreshing, integration with inbound/outbound policies, and GUI-based management and logging.

## Step 1: Generate API Token

1. Log into your OneFirewall Alliance profile.
2. Navigate to the **API Access** section.
3. Generate a **JWT token**.
4. Save this token securely — it will be used for authenticating feed requests.

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-1.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=be685734218f716431dbe532b4663e97" alt="" width="2920" height="928" data-path="images/fortigate-1.webp" />

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-2.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=a3d2dea08e78a061078e32523ba21a1b" alt="" width="1460" height="680" data-path="images/fortigate-2.webp" />

## Step 2: Configure FortiGate External Connector

1. Access your FortiGate device.
2. Go to `Security Fabric` > `External Connectors`.
3. Click **Create New** > Select **IP Address Threat Feed**.
4. Configure the feed.
5. Set update interval as needed (e.g., every 15 minutes).
6. Save the connector.

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-3.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=c236e6a0ea5ff3dd8d0c2b37a3d43db6" alt="" width="538" height="554" data-path="images/fortigate-3.webp" />

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-4.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=87c1128a7bb789af643e9f8b7ac3ea98" alt="" width="1460" height="502" data-path="images/fortigate-4.webp" />

## Step 3: Create Security Policies

Apply the OFA threat intelligence through security policies.

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-5.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=c2adc8a882bc74231f1d933e08f93e40" alt="" width="1653" height="652" data-path="images/fortigate-5.webp" />

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-6.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=e45d95bba6f82e68e07869f22d2b68a6" alt="" width="1460" height="176" data-path="images/fortigate-6.webp" />

This example maps the **any** keyword to specific network interfaces:

<img src="https://mintcdn.com/onefirewall/WDi-dI7jVFz2iVVH/images/fortigate-7.webp?fit=max&auto=format&n=WDi-dI7jVFz2iVVH&q=85&s=6ba147bb1cd7c4125f56bce87b510857" alt="" width="1114" height="944" data-path="images/fortigate-7.webp" />
