01. Intro To Multi-Tenancy Flashcards
Organizations in FortiSIEM enterprise mode
Only one org exists (Super)
Organizations in FortiSIEM provider mode
multi-tenancy through multiple organizations, alongside the super
FortiSIEM built-in orgs
Super local
Super global
These orgs are not shown under the Organizations tab.
super local organization
known simply as super, can be thought of as the FortiSIEM back end, or a local tenant.
Service providers can discover and monitor their own devices under this organization just like the enterprise edition.
Default ownership of any assets
everything belongs to the super organization, unless other customers are added
Super global org
a virtual organization that can view all organizations under management, including the super organization.
Users in super global org
Are global admins and can see other orgs and their data
Scopes definition
Scopes on FortiSIEM are administrative views where logs sent by a collector from a customer location can be viewed locally.
How called scope for an individual customer.
Local.
Switching org view
Service provider administrator users can change scopes for administration purposes. This allows the administrator to change the organization view.
log in to the supervisor node
To login as a super global user, in the CUST/ORG ID field, type super
Organization: super user: admin scope:Global
log in to the individual organization
By typing the organization name in the CUST/ORG ID field.
Organization: Banking User: bankadmin Scope: Local
Deployment mode: FortiSIEM without a collector
best suited for a hosting type environment.
The key is that each customer is on a unique IP address scheme, with no overlap allowed.
Each customer device is local to the FortiSIEM cluster, and you can distinguish events and incidents by filtering with the reporting IP address of devices that belong to individual customers.
Deployment type: FortiSIEM with collector
Most common deployment type
Allows for overlapping IP address ranges
Customer can have one or more collectors defined.
Collectors can be placed anywhere on the LAN, WAN, DMZ, or remote sites across the internet or in the cloud
Additional benefit of FortiSIEM with collector deployment
remote administration of customer devices, is possible if collectors are used.