FortiManager
Integration & Setup Manual
FortiManager Integration Guide
Overview
Cup’n’String Guard integrates with Fortinet FortiManager to push AI tool network policies to managed FortiGate devices via ADOM policy packages. Guard uses the FortiManager JSON-RPC API with workspace lock semantics — it acquires the ADOM lock, stages only its tagged policy block, installs to target devices, and releases the lock, never conflicting with existing policy.
Support level
Guard Firewall Orchestration — workspace lock + staged-commit + device install with async job polling and synthetic rollback.
Recommended Guard mode
Observe first to audit rule drift against current FortiGate policy, then Enforce once the baseline is validated.
Known limitations
- Policy installs are ADOM-wide per install job — Guard cannot isolate its install to only its own rules.
- Per-process enforcement is not available at the FortiManager layer.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix