Fortinet white logo
Fortinet white logo

Perform additional configuration settings for FortiSOAR

Perform additional configuration settings for FortiSOAR

After running the FortiSOAR Configuration Wizard, you can further configure the system for optimized and secured production deployment based on your specific requirements. This includes tasks such as replacing the default self-signed certificates, setting up network proxy, and backing up encryption keys.

Replace the self-signed certificates

FortiSOAR comes with default self-signed certificates for the webserver, which are valid for two years from the inception of your FortiSOAR instance. For steps on regenerating these certificates, see the Regenerating Self-Signed certificates topic in the Debugging, Troubleshooting, and Optimizing FortiSOAR chapter in the "Administration Guide." For a production deployment, it is important to replace these with valid signed certificates of your organization.

Set up network proxy

If your server’s access to the internet and other intranet zones is routed using a proxy, ensure that the proxy details are configured for the solution packs and connectors to establish the necessary outbound connections, and to service all requests from FortiSOAR. Additionally, make sure that the product software URL https://repo.fortisoar.fortinet.com is added to the allowlist in your organization’s firewall.

Additional settings

You can also perform additional, recommended settings such as changing the hostname, backing up the data encryption keys, and changing the FortiSOAR default database passwords, to meet your specific requirements.

Perform additional configuration settings for FortiSOAR

Perform additional configuration settings for FortiSOAR

After running the FortiSOAR Configuration Wizard, you can further configure the system for optimized and secured production deployment based on your specific requirements. This includes tasks such as replacing the default self-signed certificates, setting up network proxy, and backing up encryption keys.

Replace the self-signed certificates

FortiSOAR comes with default self-signed certificates for the webserver, which are valid for two years from the inception of your FortiSOAR instance. For steps on regenerating these certificates, see the Regenerating Self-Signed certificates topic in the Debugging, Troubleshooting, and Optimizing FortiSOAR chapter in the "Administration Guide." For a production deployment, it is important to replace these with valid signed certificates of your organization.

Set up network proxy

If your server’s access to the internet and other intranet zones is routed using a proxy, ensure that the proxy details are configured for the solution packs and connectors to establish the necessary outbound connections, and to service all requests from FortiSOAR. Additionally, make sure that the product software URL https://repo.fortisoar.fortinet.com is added to the allowlist in your organization’s firewall.

Additional settings

You can also perform additional, recommended settings such as changing the hostname, backing up the data encryption keys, and changing the FortiSOAR default database passwords, to meet your specific requirements.