Skip to content

Firewall monitoring and config change tracking

Denetta Firewall Monitoring is the module that re-scans FortiGates on a schedule, read-only, and tells you when an unannounced configuration change opens a new critical or high risk: it shows what changed, which new finding appeared and how the score moved, and never puts configuration values into any notification.

How often are devices scanned?

The schedule is per site: daily or weekly, in the site’s local time (03:00 every night by default). A scheduled scan takes the same read-only path as an on-demand pull and is bound to the signed consent scope. Scans run one after another; customers’ firewalls are never flooded with requests in the same minute.

What happens when the configuration changes?

A config change alert is raised when the configuration changes. It shows which section changed, which findings opened or closed in that scan, and the score difference. If the change produced a new critical or high finding, an email is sent.

Alerts and emails never carry configuration values, IP addresses, passwords or policy names; only the finding code, title, severity and the score. Reading the same device through a different path (e.g. API instead of a file) never produces a false change alert.

How is the full configuration backup archived? (early access)

Denetta does not take the backup by reading your device: your device sends the full, restorable backup it produces itself, through an automation set up once. The file is encrypted with AES-256-GCM; a new version is kept only when the content changes (at least weekly), and each version is retained for 1 year after it was last seen on the device. Denetta never restores a backup to your device.

This feature is in early access: until the device automation is validated in our lab on every FortiOS release, we set it up together with the customer.

What does it not include?

Firewall Monitoring does not watch traffic or attacks in real time and never blocks anything. On-demand pulls and file uploads are part of Firewall Audit.