Firewall & Network Edge Defense — FortiGate VPN, Policy & CR Score, in One Pane
A FortiGate cluster with 11 interfaces (outside / inside / DMZ × 4 / IPSec / HA-Sync / mgmt) has 11 different normal behaviours. Aggregate z-score collapses them into one mean and produces noise on every legitimate shift. RoutePulse integrates with FortiGate via SSH + API to surface per-interface visibility, 27 VPN endpoint health, SD-WAN link state, FortiGuard Cyber Risk score, and policy/VIP context — then routes everything into the **Compositional Anomaly Detector (CAD)** which decomposes traffic by peer class and detects via KL-divergence per (host, peer-class, hour-bucket) bucket. **90% noise reduction on multi-modal hosts** since v4.32.55.
An animated Canvas visualisation renders all 27 VPN endpoints with real-time traffic rates and SD-WAN tunnel state across the three sites (Bridge / Kappa / Wallis). Automatic VPN trusted-peer sync runs an SSH scanner daily at 04:00 with configurable 15-min auto-sync, and the 27 trusted peers are explicitly protected from false DDoS detection — they will not be blackholed by volumetric anomaly thresholds even at heavy load. Every FortiGate-sourced event in the Security Events timeline expands into a rich attack-context panel showing FortiGuard CR score (0–100), policy name, source/destination IP+port, protocol, attack signature, and aggregation counters (“47 sibling drops in the last 60min from this source”). Composite actor attribution (v4.32.104–105) tags every IP with `(yours)` or `(external)` so the operator never has to guess who is attacking whom.
VPN tunnel monitoring — 27 endpoints, redundant SD-WAN
Canvas-rendered topology with traffic-rate-proportional flow lines for every IPSec tunnel. Phase2 selector display shows source/destination subnet pairs per tunnel for detailed IPSec inspection. Six KPI cards summarise active tunnels, up/down counts, total throughput, and SD-WAN link health. VPN traffic monitoring queries ClickHouse at 30s polling for near-real-time throughput. Telegram notifications fire on state changes (up / down / new / removed). “Trust All” bulk action allows rapid import during setup or infrastructure expansion.
Policy & VIP visibility — firewall rule context inline
Policy zone and Virtual IP (VIP) context surfaces directly on every event row. SSH configuration scanning enables firewall rule auditing for policy compliance verification alongside operational monitoring. SD-WAN tunnel detection leverages FortiGate comment patterns with address-object resolution for accurate mapping.
FortiGuard CR score & attack-context panel
Every FortiGate event in the Security Events timeline expands into a structured panel: FortiGuard Cyber Risk score (0–100), policy name that matched, source IP + port, destination IP + port + protocol, attack signature, and 60min aggregation counters. The composite actor attribution (`Attacker (external) → Your host: X → Y :443 TCP`) is rendered consistently across the UI, Telegram, Email and Webhook delivery.
CAD — per-interface profiles, not per-host
The same FortiGate has 16 PROFILE_* role definitions across its zones: PROFILE_OUTSIDE_WAN, PROFILE_INSIDE_LAN, PROFILE_HA_HEARTBEAT, PROFILE_DMZ_WEB, PROFILE_DMZ_DB, PROFILE_IPSEC_TUNNEL, PROFILE_MGMT, etc. Outside spike on `internal_lan` peer-class = exfiltration; inside spike on `transit_isp` = compromised host; HA-Sync spike on anything = fabric abuse. Triple-gate severity (semantic + volume-floor + direction guard) cut FortiGate-sourced critical noise by 90%.
Key Capabilities
- Deep FortiGate integration via SSH + API for VPN tunnel monitoring, policy/VIP visibility, and trusted-peer management
- Animated Canvas topology rendering 27 VPN endpoints with real-time traffic-proportional flow lines
- Automatic VPN trusted-peer sync via SSH scanner daily 04:00 + configurable 15-min auto-sync
- 27 trusted VPN peers explicitly excluded from volumetric DDoS detection (no false blackholing of legit high-volume tunnels)
- 3 SD-WAN sites (Bridge / Kappa / Wallis) with redundant tunnel visualisation, comment-pattern-based detection + address-object resolution
- FortiGuard Cyber Risk score (0–100) inline on every FortiGate event row + attack-context panel (policy, IP/port/proto, signature, 60min aggregation counters)
- Composite actor attribution `From (external) → To (yours)` consistent across UI, Telegram, Email, Webhook (v4.32.104–105)
- Phase2 selector display showing source/destination subnet pairs per tunnel for IPSec inspection
- 6 KPI cards: active tunnels, up/down counts, total throughput, SD-WAN health at a glance
- VPN traffic polling at 30s intervals from ClickHouse for near-real-time throughput data
- Telegram notifications on tunnel state changes (up / down / new / removed) + “Trust All” bulk-import action
- CAD compositional detector: per-interface baselines via 16 PROFILE_* role constants — 90% noise reduction on multi-modal firewalls (v4.32.55–56)
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →