Resource Library
Solution BriefsVisibilitySegmentationFebruary 14, 2024

Fortinet and ORDR Solution Brief

SOLUTION BRIEF · FORTINET AND ORDR

Fortinet and ORDR Connected Device Visibility & Security Solution

Automated Visibility and Protection for ALL Connected Devices - from traditional servers, workstations and PCs to IoT, IoMT and OT devices

Executive Summary

Fortinet and ORDR have partnered to deliver an industry-leading IoT and unmanaged device security solution by integrating FortiGate next-generation firewall (NGFW), FortiManager automation-driven network management, and ORDR Systems Control Engine (SCE). The solution provides organizations with complete visibility of their network-connected devices, baselining of safe device behavior and the ability to protect critical IoT, OT and unmanaged devices with automated segmentation at the firewall. When combined with Fortinet FortiNAC, you have a comprehensive solution to secure both network access and local area network communications as well as all communications between security zones using FortiGate next-generation firewalls.

Challenge

The number of IoT and unmanaged devices connected to corporate networks, from conference TVs to business-critical infrastructure, has grown exponentially. Unfortunately, this brings with it a significant increase in attack surface since these devices often run legacy software without security agents. Without the means to be patched or to protect themselves against attack, IoT and unmanaged devices are extremely vulnerable and therefore lucrative targets. Organizations need to secure access to and from these devices to protect against direct attacks, lateral malware movement, and business interruption. This requires granular details of all devices, their risks, and their ongoing behavior, and then translating this knowledge into proper and automated security workflows. ORDR and Fortinet have teamed to deliver a solution that provides organizations with this ability to discover, assess, and use rich device context to power proactive device policies across the Fortinet fabric. FortiNAC administrators can use ORDR asset details and classifications to easily build dynamic business-driven rules, while firewall administrators can further reduce manual efforts and errors by pushing automated protection policies directly to FortiGate firewalls. ORDR's deep API integration scales from mid-sized businesses with individual FortiGates to complex enterprises leveraging extensive FortiManager and FortiGate deployments.

Joint Solution Benefits

The solution combines the ORDR Systems Control Engine with Fortinet FortiManager, FortiGate, and FortiNAC to deliver:

  • Discover and inventory every connected network asset, including the massive volume of IoT and unmanaged devices
  • Establish comprehensive security controls that restrict IoT devices to known-good network behaviors
  • Manage firewall and NAC policies using business-relevant context such as device type, manufacturer, location, and function rather than IP addresses
  • Automate updates of firewall groups and address info to ensure consistent policy enforcement regardless of device location, VLAN, or IP assignment, thus drastically reducing operational costs and downtime
  • Protect critical devices with automated, zone-based segmentation and microsegmentation within zones

Joint Solution

ORDR and Fortinet have partnered to deliver an industry-leading security solution to address the challenge of widespread IoT and unmanaged device sprawl. The API integration of the ORDR Systems Control Engine (SCE) with FortiManager, FortiGate, and FortiNAC, enabled through Fortinet's Open Fabric Ecosystem, delivers the ability for customers to reduce the time and effort to create and maintain a proper asset inventory, determine asset communication patterns, and create effective, business-relevant firewall and NAC segmentation policies that automatically update as devices are added, moved, and changed.

IoT and unmanaged devices pose a unique and growing security challenge to organizations. By nature, a large majority of IoT devices run neither anti-malware nor patch management software and are thus an inherent risk to an organization. The only way to handle these devices is to proactively segment them from your critical assets.

Within minutes of a device appearing on an organization's network, ORDR automatically discovers, identifies, classifies, risk assesses, and groups it with peers. ORDR transmits this device context to FortiNAC to dramatically speed and simplify NAC policy creation. And, with just a few clicks, administrators can create business-relevant segmentation policies in FortiGate firewalls that ensure devices of a specific type and role only connect over approved communication channels with necessary destinations—all unique and custom to your organization.

Solution Architecture: Device Discovery to Policy Enforcement

ORDR's SCE Sensor passively monitors SPAN/TAP/NetFlow/IPFIX data from the core switch to classify devices such as medical devices, facilities systems, retail systems, and physical security cameras. ORDR SCE then sends device data and classification to FortiNAC, which enforces logical segmentation policy and quarantine/remediation actions down through the access switches and wireless LAN controller (WLC) to the end devices.

Flow

Description

SCE → FortiNAC

Device data and classification for dynamic NAC policy creation

FortiNAC → Access Switch/WLC

Enforce logical segmentation policy

FortiNAC → Core Switch

Quarantine / remediate offending devices

End Devices

Medical devices, facilities systems, retail (POS) systems, physical security cameras

Joint Solution Integration

The Fortinet FortiGate, FortiManager, and FortiNAC integration with ORDR SCE allows customers to reduce the amount of time spent on establishing a proper asset inventory, establishing where those assets are communicating, and creating firewall and NAC segmentation policies. Further, the integration allows for automated segmentation and microsegmentation.

When a device changes physical location and its IP address changes, or similar devices are discovered, ORDR will automatically update the device membership in Fortinet solutions to reduce manual processes (for example, requiring devices of a specific type be assigned to a specific VLAN or subnet) and maintenance tasks (for example, costly and time-consuming change control windows to implement firewall policy changes based on IP address changes). Additionally, because ORDR transmits granular device details to FortiGate, FortiManager, and FortiNAC, administrators can further tune policies and make informed decisions about their network without deciphering IP and MAC addresses.

The FortiGate next-generation firewalls enhance ORDR's visibility into north-south and east-west communications by sending flow data to a centralized ORDR sensor. This extends the visibility in remote and lateral communications to improve visibility, enhance anomaly detection, and increase the efficacy of FortiGate zone-based segmentation and FortiNAC access control policies. FortiGate NGFWs can also reduce incident response efforts by informing ORDR when malicious traffic is dropped at the firewall. This closed-loop integration allows clearing of associated ORDR security incidents related to potentially malicious device communications to known-bad websites and destinations.

Network Segmentation Policies by Device Type

The ORDR SCE Sensor sends device classification data to FortiManager, which distributes device-specific policies to the Internet firewall, campus logical segment firewall, and data center firewall protecting each zone of the campus network:

MRI — Medical Devices

MRI Policy

BAC — Facilities Systems

BACNET Policy

PCI — Retail Systems

PCI Policy

CAM — Physical Security

Camera Policy

Joint Use Cases

Protect Critical IoT Running Unsupported OS at the Secure Access Service Edge

Critical IoT devices are commonly deployed with deprecated operating systems. While typical user workstations are managed by desktop management services, organizations are often blind to unmanaged IoT devices running vulnerable software. ORDR informs FortiGate firewalls of all devices running unsupported operating systems such as Windows XP/7 and seamlessly provides the visibility necessary to apply protection policies that segment these devices from external and internal threats.

Business-Relevant Microsegmentation in the Campus and Data Center

Unsanctioned IoT devices that lack authentication can easily connect to the network and become both targets and launch points for malware and compromise. ORDR augments FortiNAC with additional intelligence, needed to ensure only authorized devices can access the network, and further automates the application of consistent segmentation policies to FortiNAC and FortiGate firewalls to restrict both lateral movement as well as access to critical resources in the data center.

About ORDR

ORDR makes it easy to secure every connected device, from traditional IT devices to newer and more vulnerable IoT, IoMT, and OT. ORDR Systems Control Engine uses deep packet inspection and advanced machine learning to discover every device, profile its risk and behavior, map all communications and protect it with automated policies. Organizations worldwide trust ORDR to provide real-time asset inventory, address risk and compliance and accelerate IT initiatives. ORDR is backed by top investors including Battery Ventures, Wing, and TenEleven Ventures. For more information, visit www.ordr.net and follow ORDR on Twitter and LinkedIn.

Frequently asked questions
How can we discover and classify unmanaged IoT and OT devices across our network?
ORDR's automated discovery engine identifies all connected IoT, OT, and unmanaged devices in real-time without requiring manual asset tracking. The platform classifies each device by type, risk level, and behavioral patterns, integrating seamlessly with Fortinet FortiGate NGFW and FortiNAC to provide comprehensive visibility across your enterprise network.
Can we enforce network segmentation without knowing all our connected devices?
No—that's why ORDR's integration with Fortinet is critical. ORDR automatically discovers invisible assets and classifies them by risk, enabling FortiGate and FortiNAC to enforce segmentation policies based on actual device profiles. This eliminates security gaps by ensuring access controls are applied to previously unknown connected assets.
What's the business impact of combining Fortinet FortiGate with ORDR's discovery platform?
The combination delivers real-time visibility, automated device classification, and policy-driven segmentation without manual overhead. Security teams can identify risk, enforce access controls immediately, and reduce the attack surface of unmanaged devices—closing visibility gaps that typically take months to address manually.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →