Firewall & Network Edge Defense
RoutePulse integrates deeply with FortiGate firewalls via SSH to provide VPN tunnel monitoring, policy zone visibility, and trusted peer management from a single pane of glass. An animated Canvas visualization renders all 27 VPN endpoints alongside SD-WAN tunnel status and real-time traffic rates, giving operators an immediate visual assessment of edge connectivity health. Automatic VPN trusted peers synchronization runs an SSH scanner daily at 04:00 with configurable auto-sync every 15 minutes, ensuring the peer list stays current as tunnels are added or removed. The 27 trusted VPN peers are protected from false DDoS detection, preventing RoutePulse from blackholing legitimate high-volume VPN traffic that might otherwise trigger volumetric anomaly thresholds.
Three SD-WAN sites — Bridge, Kappa, and Wallis — are displayed with redundant tunnel visualization, and SD-WAN tunnel detection leverages FortiGate comment patterns with address object resolution for accurate mapping. Six KPI cards summarize active tunnels, up/down status, total throughput, and SD-WAN health at a glance. Policy zone and VIP (Virtual IP) visibility surfaces firewall rule context directly in the dashboard, while Phase2 selector display shows source and destination subnet pairs per tunnel for detailed IPsec inspection. VPN traffic monitoring queries ClickHouse at a 30-second polling interval for near-real-time throughput data. Telegram notifications fire on tunnel state changes including up, down, new, and removed events. A “Trust All” bulk action allows rapid import of discovered VPN peers during initial setup or infrastructure expansion. FortiGate SSH configuration scanning also enables firewall rule auditing to verify policy compliance alongside operational monitoring.
Key Capabilities
- Deep FortiGate integration via SSH for VPN tunnel monitoring, policy zone visibility, and trusted peer management
- Animated Canvas visualization rendering 27 VPN endpoints with SD-WAN tunnel status and real-time traffic rates
- Automatic VPN trusted peers sync via SSH scanner daily at 04:00 plus configurable 15-minute auto-sync intervals
- 27 trusted VPN peers protected from false DDoS detection to prevent blackholing legitimate high-volume tunnel traffic
- 3 SD-WAN sites (Bridge, Kappa, Wallis) with redundant tunnel visualization and comment-pattern-based detection
- 6 KPI cards summarizing active tunnels, up/down status, total throughput, and SD-WAN health
- Policy zone and VIP (Virtual IP) visibility surfacing firewall rule context in the dashboard
- Phase2 selector display showing source/destination subnet pairs per tunnel for IPsec inspection
- VPN traffic monitoring from ClickHouse at 30-second polling intervals for near-real-time throughput data
- Telegram notifications on tunnel state changes: up, down, new, and removed events
- “Trust All” bulk action for rapid import of discovered VPN peers during setup or expansion
- FortiGate SSH configuration scanning for firewall rule auditing and policy compliance verification
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →