--- title: "Fortinet Fortigate NGFW With Wasabi" slug: "how-do-i-use-fortinets-fortigate-ngfw-with-wasabi" updated: 2026-08-04T21:59:55Z published: 2026-08-04T21:59:55Z canonical: "docs.wasabi.com/how-do-i-use-fortinets-fortigate-ngfw-with-wasabi" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.wasabi.com/llms.txt > Use this file to discover all available pages before exploring further. # Fortinet's Fortigate NGFW With Wasabi [FortiGate NGFWs](https://www.fortinet.com/products/next-generation-firewall) deliver industry-leading enterprise security for any edge at any scale with full visibility and threat protection. FortiGate NGFWs now partner with Wasabi to extend visibility & monitoring. Follow the instructions below to integrate NGFWs with Wasabi. ## Requirements - FortiOS v6.4.8 Build 1914 or higher recommended - Current FortiGuard subscription that provides current application signatures - Active Wasabi’s Hot Cloud Storage subscription ## Reference Architecture ![mceclip0.png](https://cdn.document360.io/bef0a1ea-7768-4d5a-b520-c4fe2f7fafad/Images/Documentation/bzpw5wil30u5pk8psw9gmceclip0.png) A FortiGate firewall must be in the data path between the Wasabi client and the Wasabi storage regions. A firewall policy rule should exist with the following: 1. Permits the desired traffic from the client host to Wasabi 2. Enables the Application Control feature 3. Enable “deep-inspection” for the SSL Inspection feature - Note: If deep inspection is disabled, FortiGate firewall will identify traffic being sent to/received from Wasabi. When enabled, Fortigate firewall will be able to detect what type of interactions are being exchanged with Wasabi storage ( upload vs download vs deletion) 4. Enable the Log Allowed Traffic with All Sessions option. ![mceclip1.png](https://cdn.document360.io/bef0a1ea-7768-4d5a-b520-c4fe2f7fafad/Images/Documentation/sxutsepwn0cccymhq0xesgmceclip1.png) To use logging via syslog, go to Log Settings, **Remote Logging and Archiving**. - Enable the syslog option and enter the destination syslog IP. ![mceclip2.png](https://cdn.document360.io/bef0a1ea-7768-4d5a-b520-c4fe2f7fafad/Images/Documentation/uz7piihkk9vf9ldcjxwmceclip2.png) Additionally, FortiAnalyzer can serve as a logging destination, with logs accessible via its API or forwarded to a packet capture infrastructure.