Configure Target

Update the Fortigate Target

  1. Navigate to Netshot > Targets img.png img.png
  2. Click on FG1 img.png img.png
  3. Click Edit Record at the bottom right img.png img.png
  4. Update the following fields
    • Name: Branch1
    • IP: 10.100.88.8
    • Device Password: $3curityFabric img_1.png img_1.png
  5. Click Save at the bottom left

Trigger Netshot from the device

Click the tab Netshot Data, then click the button Run Netshot img_2.png img_2.png

You will notice that the Netshot Status indicator shows Running img_2.png img_2.png

You will also notice which data queries are complete or waiting img_2.png img_2.png

Once netshot completes, you should see a total score that the device earned from the various audits performed. The audit scores come from the profiles that were assigned to the device. img_2.png img_2.png

Investigate the Results

  1. Click on the row under netshot data called get system status
  2. Click on the Source Data tab, and expand the Normalized Data img_3.png img_3.png Source data is the raw data from the query, and normalized data is what the raw data was transformed into. In this case, the data wasn’t modified or cleaned in any way
  3. Scroll down and to the Output Data Reports and click License is Valid img_4.png img_4.png

Notice the settings here. This report is saying that the text field from the normalized data must contain a regex of License Status(\s+)?: Valid . If that Regex Pattern Exists, then the report gives out 25 points img_5.png img_5.png

Understand Domains

Domains allow you to create a grouping of devices that needed audited.

  1. Navigate to Netshot > Domains
  2. Open the Netshot Workshop domain
  3. Select the Targets Tab

Notice that the domain consists of 2 Fortigates and 1 Fortimanager img_5.png img_5.png

Understand Reports

  1. Navigate to the Reports Module img_6.png img_6.png
  2. Click View on the Netshot Report Domain img_6.png img_6.png
  3. Select the Netshot Workshop Domain for the Report Input img_6.png img_6.png
  4. Click OK

Check out the report, There were some exceptions found from the FMG because it did not meet the specified 7.6 version img_6.png img_6.png