What problem does it solve?
Network engineers often cannot tell what a FortiGate firewall is actually doing right now versus what FortiManager intended it to do, and IPsec tunnel status is frequently misreported because phase 1 and phase 2 get collapsed into a single ambiguous state.
Core Features & Use Cases
- Observed device state: Read system status, interfaces, routing tables, and running firewall policies directly from the FortiGate via the FortiOS REST API, always scoped to the answering member and VDOM.
- Split-phase IPsec reporting: Report phase 1 and phase 2 tunnel status separately, including per-selector detail, so a phase-1-up/phase-2-down selector mismatch is never hidden.
- Manager-vs-device drift detection: Compare the device's running policy against the FortiManager package to surface out-of-band changes made directly on the box.
- Use Case: Ask whether a site-to-site VPN tunnel is up and learn that IKE phase 1 is established but one of five phase 2 selectors is down due to a proxy-ID mismatch, then check the routing table for a path to the remote gateway.
Quick Start
Ask the agent to check whether the IPsec tunnel on your FortiGate is up and to report phase 1 and phase 2 status separately.