Table of Contents

Advertisement

Quick Links

Administration Guide
FortiRecorder 7.0 .0

Advertisement

Table of Contents
loading

Summary of Contents for Fortinet FortiRecorder 7.0.0

  • Page 1 Administration Guide FortiRecorder 7.0 .0...
  • Page 2 FORTINET DOCUMENT LIBRARY https://docs.fortinet.com FORTINET VIDEO LIBRARY https://video.fortinet.com FORTINET BLOG https://blog.fortinet.com CUSTOMER SERVICE & SUPPORT https://support.fortinet.com FORTINET TRAINING & CERTIFICATION PROGRAM https://www.fortinet.com/training-certification FORTINET TRAINING INSTITUTE https://training.fortinet.com FORTIGUARD LABS https://www.fortiguard.com END USER LICENSE AGREEMENT https://www.fortinet.com/doc/legal/EULA.pdf FEEDBACK techdoc@fortinet.com Email: October 24, 2023...
  • Page 3: Table Of Contents

    Plugging in the cameras Discovering cameras in remote networks Configuring cameras Configuring video profiles Configuring camera profiles Configuring cameras More system settings Grouping cameras Configuring user and administrator accounts Configuring administrator profiles Configuring device access control FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 4 Network security Configuring intrusion detection Schedules Configuring a schedule Configuring the sunrise and sunset time Analytics Using motion detection analytics Using computer vision analytics Face recognition Identifying faces Reviewing new faces Reviewing known faces FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 5 Restoring a previous configuration Troubleshooting Login issues When an administrator account cannot log in from a specific IP Remote authentication query failures Resetting passwords Not able to push setting and log shows an error on password FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 6 Unauthorized DHCP clients or DHCP pool exhaustion Examining IP sessions Resolving IP address conflicts Examining live video streams Packet tracing Resetting the configuration Restoring firmware ("clean install") Appendices Appendix A: Port numbers Outgoing traffic Incoming traffic Appendix B: Maximum values FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 7: Change Log

    Change log The following is a list of documentation changes. For a list of software changes, see the Release Notes Date Change Description 2023-02-27 Initial release of FortiRecorder 7.0.0 Administration Guide. 2023-03-29 Updates. 2023-03-31 Bug fixes. 2023-04-13 Added security fabric info.
  • Page 8: Key Concepts

    It can also be connected to access control systems (ACS) to correlate events such as when doors are opened. Third-party camera support FortiRecorder supports Fortinet FortiCam cameras and third-party ONVIF-compliant cameras. Some features on third- party cameras might not be fully supported, however. In that case, you can configure those features through the built-in GUI on the camera.
  • Page 9: Licenses

    While referenced by another part of the configuration, an item cannot be deleted. If you need to trace references to it, then: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 10 This optimizes RAM usage, improving performance. The Help button is context-aware. When you click it, it jumps to the part of the documentation that matches your current location in the GUI. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 11: Quick Setup

    Due to this isolation, this network topology can also be used if you want to test a third-party camera or other device with FortiRecorder in a lab. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 12 4. Change the password. For details, see Setting the "admin" account password on page 5. Configure the built-in DHCP server: a. On the FortiRecorder GUI, go to System > Network > DHCP . b. Click the New button. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 13 Go to Camera > Configuration > Camera . b. Click the Discover button. After several seconds, a list of cameras appears. Newly discovered cameras are highlighted in yellow, and their Status column displays Not Configured . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 14: Connecting Cameras To A Dhcp Server And Fortirecorder

    The cameras get network settings from your DHCP server, but FortiRecorder does not. Like any server, FortiRecorder uses a static IP address so that its GUI or CLI can always be reached at the same location. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 15 IP address from the DHCP server. 3. On your DHCP server, create a reservation for each camera so that it always gets the same IP address. Fortinet strongly recommends to either: configure your cameras with a static IP address (see Address), or...
  • Page 16 Repeat this step for all cameras. 13. To verify that FortiRecorder is able to receive video from the camera, go to Monitor > Video > Video . You should be able to see the camera's live video feed. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 17: Setup

    More system settings on page Deployment topology Cameras and other devices such as ACS can be deployed in networks that are: Hybrid with FortiCamera Cloud on page 18 Local to FortiRecorder on page 19 FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 18: Hybrid With Forticamera Cloud

    FortiRecorder. You can use FortiCamera Cloud to configure most camera settings, and to monitor video from cameras, while FortiRecorder provides video storage and is used to configure remaining camera settings, if any. For details, see Managed by cloud. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 19: Local To Fortirecorder

    Often the switch is connected to a router, and devices connect through it to the Internet. However, this is not required unless you use camera or FortiRecorder features that require an Internet connection. See also Appendix A: Port numbers on page 170. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 20: Remote From Fortirecorder

    Connecting to the FortiRecorder GUI To configure the FortiRecorder appliance, you must connect to its management GUI or CLI console. initial installation During , you can connect to the GUI using its factory default settings. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 21: Connecting To The Fortirecorder Cli

    FortiRecorder Release Notes anymore. For details and a list of supported web browsers, see the To allow areas in the GUI to properly display, Fortinet recommends that you set your monitor to a screen resolution of at least 1280 x 1024 pixels.
  • Page 22 Setup Command syntax for FortiRecorder is similar to other Fortinet products. CLI connection via SSH By default, SSH and HTTPS administrative access are enabled so that you can connect to the CLI during initial setup. After initial setup, if you will connect using Telnet client, then enable Telnet on the network interface.
  • Page 23: Setting The "Admin" Account Password

    If multiple people will use FortiRecorder, configure separate accounts for each person later, once setup is complete. Configuring user and administrator accounts on page To change the "admin" administrator password 1. Log in to the admin administrator account. 2. Go to System > Administrator > Administrator. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 24: Configuring Network Settings

    A dedicated network connection only for cameras has many advantages: better security by preventing unauthorized access to cameras and video surveillance consistent quality of service for live video streams simpler bandwidth management To configure a network interface's IP address FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 25 Enable to send multicast camera discovery traffic from this network interface.You can also discover cameras on other subnets. See Discovering cameras in remote networks on page Access Enable the types of administrative access that you want to permit to this interface. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 26 SNMP manager. To configure the listening port number and configure queries and traps, see Configuring SNMP traps and queries on page Access: TELNET Enable to allow Telnet connections to the CLI through this network interface. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 27 A virtual LAN (VLAN) subinterface, also called a VLAN, is a virtual interface on a physical interface. The subinterface allows routing of VLAN tagged packets using that physical interface, but it is separate from any other traffic on the physical interface. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 28: Configuring Routing

    If one or more routers is between FortiRecorder and the Internet, your cameras, etc., then you must specify which is the default route ("gateway" router) that network traffic from FortiRecorder uses to reach other parts of your network. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 29 FortiRecorder that should be reachable from that location. If the connectivity test fails, you can use the CLI commands to determine if a complete route exists from the FortiRecorder to the host: execute ping <destination_ipv4> and to determine the point of connectivity failure: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 30: Configuring Dns Settings

    6. If the DNS query for the domain name succeeds, you should see results that indicate that the host name resolved into an IP address, and the route from FortiRecorder to that IP address: traceroute to www.fortinet.com (192.0.43.10), 30 hops max, 60 byte packets 172.20.130.2 (172.20.130.2) 0.426 ms...
  • Page 31: Making Reservations On Your Dhcp Server

    Setup Cannot handle "host" cmdline arg `www.fortinet.com' on position 1 (argc 3) Verify your DNS server IP address, routing, and that your firewalls or routers do not block or proxy UDP port 53. Making reservations on your DHCP server If your cameras get their network settings from a third-party DHCP server, then reserve the range of IP addresses that the cameras will use so that other devices cannot take them.
  • Page 32 IP address from the DHCP server or renew its existing lease. Otherwise, the DHCP server may attempt to assign it to the next DHCP client that requests an IP. The default is 604800 seconds (7 days). FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 33: Configuring Nat/Port Forwarding On Your Firewall/Router

    FortiRecorder with the camera. See Resolving IP address conflicts on page 159. 5. Click Create . Monitor > DHCP > DHCP . As cameras join the network, they appear on Configuring NAT/port forwarding on your firewall/router If your deployment: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 34 IPv6. NAT and port forwarding are usually required for remote networks that use IPv4, but If you only use IPv6, you may be able to skip this step. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 35: Configuring The Public Port Numbers And Domain Name

    Enter the minimum number of characters that a password must contain. The default value is 8. If any password does not meet the requirements, FortiRecorder requires that user to change the password during the next login. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 36 Local : Type the listening port number on FortiRecorder. Devices on the internal/private network connect directly to this port number. Public : If you configured port forwarding on a firewall/router (see Configuring NAT/port forwarding on your firewall/router on page 33), then FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 37: Configuring The System Time

    The FortiRecorder appliance is shipped with the latest operating system (firmware); however, if a new version has been released since your appliance was received, install the latest firmware before continuing the installation of your FortiRecorder. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 38: Installing Firmware

    Camera firmware can be updated later, after you have connected your cameras to the appliance. Fortinet periodically releases FortiRecorder firmware updates to include enhancements and address issues. After you Fortinet Support register your FortiRecorder appliance, FortiRecorder firmware is available for download from New firmware can introduce new features which you must configure for the first time.
  • Page 39 Setting the "admin" account password on page 23 To install firmware using the CLI 1. Download the firmware file from the Fortinet Technical Support web site: https://support.fortinet.com/ 2. Copy the new firmware image file to the root directory of the TFTP server.
  • Page 40: Installing Alternative Firmware

    GUI or CLI. To install alternate firmware via the CLI 1. Download the firmware file from the Fortinet Technical Support web site: https://support.fortinet.com/ 2. Copy the new firmware image file to the root directory of the TFTP server.
  • Page 41 12. Type the IP address of the TFTP server and press Enter. The following message appears: Enter local address [192.168.1.188]: 13. Type a temporary IP address that can be used by the FortiRecorder appliance to connect to the TFTP server. The following message appears: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 42: Booting From The Alternate Partition

    [Q]: Quit menu and continue to boot with default firmware. [H]: Display this list of options. Enter G,F,B,Q,or H: Please connect TFTP server to Ethernet port "1". 6. Press B to reboot and use the backup firmware. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 43: Upgrading Or Downgrading Camera Firmware

    Once the FortiRecorder is connected to your cameras, you can upgrade and downgrade the camera firmware through the FortiRecorder GUI. Fortinet does not recommend downgrading firmware. Downgrading firmware could result in a loss of configuration information. If possible, back up the configuration before you downgrade.
  • Page 44: Discovering Cameras In Remote Networks

    ), then you can skip this step during initial setup. Otherwise you can configure profiles with your custom settings. Video profiles are used in camera profiles. For details, see Configuring camera profiles on page FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 45 To configure a video profile 1. Go to Camera > Configuration > Video Profile . 2. Click New . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 46 Max bitrate Enter the maximum bitrate that the camera can stream. Lower bitrates use less bandwidth by sacrificing image quality. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 47: Configuring Camera Profiles

    Continuous : Records video for the entire duration of the schedule, regardless of movement or any other triggers. Motion detection : Records a video clip up to about 40 seconds long each time the camera's sensor detects movement. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 48 When the too, the video will finally be deleted from Compression Options Select whether or not FortiRecorder compresses continuous recordings. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 49: Configuring Cameras

    New (to configure a camera that is not yet discovered yet) click 3. Configure the following settings: Setting Name Description Enable Select this toggle to enable the FortiRecorder unit to communicate with this camera. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 50 If you are adding a new camera Model must configure these and other settings manually. For Fortinet FortiCam cameras, you must specify the models; for third-party cameras, you must specify the camera's login credentials (user name and password) so that FortiRecorder can connect to it.
  • Page 51 Wifi section and configure the following settings: Setting Name Description Enable Enable Wi-Fi on the camera. When enabled, these indicators appear: Status Signal strength SSID Enter the SSID of the Wi-Fi access point (AP) that the camera will connect to. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 52 DHCP server on page 31 Configuring the built-in DHCP server on page Static — Manually configure the camera with a static private network IP address that you specify in Address. It will no longer use DHCP. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 53 Setup Setting Name Description Fortinet strongly recommends to either: configure your cameras with a static IP address, or configure your DHCP server with lease reservations (see also Making reservations on your DHCP server on page 31). Without reservations, the IP address provided by the DHCP server might appear to work initially, but later, when the DHCP lease expires, the DHCP server might change the IP...
  • Page 54 Mode At night or in the dark, some camera models can use infrared light to record a black-and-white image. This mode also removes a daylight filter for more sensitivity. Select either: off — Disable. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 55 Fisheye — Use the raw, circle-shaped image. This option is suitable if de- warping is done on FortiCentral instead of FortiRecorder. Panorama — De-warp the image into a rectangle-shaped, 360- or 180- degree panorama. Mount Select the mount type of the camera, either: Ceiling Table Wall FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 56 Select whether to automatically optimize the exposure for the camera location. Options vary by camera model, but can be: Indoor Outdoor Manual Manual , select the amount of exposure gain: Max gain Exposure mode FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 57 Media profile Select which ONVIF media profile on the camera to use. Options vary by camera model. This option is only available on third-party ONVIF compatible cameras. Audio Expand the Audio section. Configure the following settings: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 58 The advantage to motion detection is that the camera only records when motion is detected. Other cameras stream continuously to FortiRecorder, and only notify it about the motion detection event. Then FortiRecorder FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 59 QuickStart Guide). You can enable or disable the LEDs by selecting Status LEDs . or deselecting Move home For the PTZ cameras, you can specify when the camera should stop PTZ and reset aim to the home position. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 60 1 : Ground To configure DIDO on FortiCam MB13 cameras 1. Go to Camera > Configuration > Camera , select the MB13 camera from the camera list and select Edit . 2. Expand the Detection section. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 61 DI trigger was HIGH and the door was left open for a long time, then the camera would trigger repeatedly. 4. Go to Camera > Configuration >Camera Profile . When you create a camera profile that uses a recording schedule, enable Digital input . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 62: More System Settings

    User accounts on FortiRecorder have privileges that are determined by their assigned profile. To configure an administrator or user account 1. Go to System > Administrator > Administrator . 2. Click New . 3. Expand the Preference section. Configure the following settings: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 63 Select a profile that matches the permissions that you want the user to have. New button to create a new profile, or select an existing profile Either click the from the dropdown menu. For more information, see Configuring administrator profiles on page FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 64 The administrator may switch the theme at any time after he or she logs in by Next Theme in the top right corner. clicking Notification Select one of the notification methods: Email Mobile app FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 65: Configuring Administrator Profiles

    System access Controls system login and network settings of FortiRecorder: Dashboard > Status GUI console System > Network System > Administrator System > Authentication System > Certificate System status Controls other system settings, such as Time Remote storage Log settings FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 66 Read: Provides viewable configuration settings. Write: Enables modifying configurations. 5. Click Create . 6. To use the profile, select it when configuring a user account. For details, see Configuring user and administrator accounts on page FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 67: Configuring Device Access Control

    If your users must log in to a RADIUS server, then configure a RADIUS profile that defines how FortiRecorder sends authentication queries to the RADIUS server. To configure a RADIUS query 1. Go to System > Authentication > RADIUS . 2. Click New . 3. Configure the following settings: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 68 If your users must log in to a LDAP server, then configure a LDAP profile that defines how FortiRecorder sends authentication queries to the LDAP server. To configure an LDAP query 1. Go to System > Authentication > LDAP . 2. Click New . 3. Configure the following settings: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 69 The query string filters the result set, and should be based upon any attributes that are common to all user objects but also exclude non-user objects. For example, if user objects in your directory have two distinguishing characteristics, their objectClass and mail attributes, the query filter might FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 70 SMS profile attribute : This attribute specifies which SMS profile the user will use. The SMS profile attribute must match the name of the profile configured in FortiRecorder. SMS number attribute : This attribute specifies the user SMS number for FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 71 Single sign-on (SSO) can save time for users by reducing the number of times that they must log in when using many network services. Once they log in, they can access all other authorized services that use SSO until their session expires. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 72 ACS URL The URL where FortiRecorder will receive authentication responses from the IdP (the assertion consumer service (ACS)), such as: https://FortiRecorder.example.com/sso/SAML2/POST Metadata The URL where the IdP can download SP metadata XML from FortiRecorder, such as: https://FortiRecorder.example.com/sso/Metadata FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 73: Connecting To The Security Fabric

    FortiRecorder can connect to an upstream FortiGate root and become an integrated cluster member of the Security Fabric. This allows FortiRecorder to display network and security information from across your other deployed Fortinet devices. The Security Fabric protocol with FortiOS 7.0+ also provides communications for other features, such as SSO integration with FortiAuthenticator REST API connections with other Fortinet devices and...
  • Page 74 When replacing a disk in the RAID array, the new disk must have the same or greater storage capacity than the existing disks in the array. If the new disk has a larger capacity than the other disks in the array, only the amount equal to the FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 75 <level_int> The FortiRecorder sets the RAID level and then reboots. Configuring external storage To extend your local storage, you can use an external USB storage device if your FortiRecorder model has USB ports. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 76 Hostname/IP Address Type either the IP address or fully-qualified domain name (such as nas.example.com) of the iSCSI or NFS server. iSCSI Server or NFS  is the selected protocol. This option only appears if FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 77: Configuring Email Settings For Notifications

    If you want FortiRecorder to send email for notifications, and you want to use your own email server to send them, then configure the settings that FortiRecorder will use to connect to your email server. In factory default settings, the mail relay server is: notification.fortinet.net To configure notification email settings FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 78 Enable if you want to use a mail server instead of the default provided by Fortinet ( notification.fortinet.net ). If you do not have your own Use custom mail server email server, this may be the name of your ISP's SMTP relay, or a 3rd-party email server such as Yahoo! or Gmail.
  • Page 79: Configuring Sms Text Message Settings For Notifications

    Configuring SMS text message settings for notifications For FortiRecorder to send SMS messages, you must specify the SMS service providers. To configure FortiRecorder to send SMS messages 1. Go to System > Configuration >SMS . 2. Configure the following settings: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 80 {{:message}} password password Caution:  Select the encrypt checkbox to obscure the password when viewing the configuration. If you do not, verify that no cameras or persons can see your screen, which would compromise security. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 81: Configuring Snmp Traps And Queries

    On the SNMP manager, you must also verify that the SNMP manager is a member of the community to which the FortiRecorder appliance belongs, and compile the necessary Fortinet-proprietary management information blocks (MIBs) and Fortinet-supported standard MIBs. For information on MIBs, see MIB support on page...
  • Page 82 SNMP manager may not accept the trap if its community name does not match. Caution : Fortinet strongly recommends that you do not add FortiRecorder to the community named public. This popular default name is well-known, and attackers that gain access to your network will often try this name first.
  • Page 83 To specify access for an SNMP user 1. Go to System > Configuration > SNMP. 2. If you have not already configured the agent, do so before continuing. See Configuring SNMP traps and queries on page FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 84 Description Fortinet Core MIB This Fortinet-proprietary MIB enables your SNMP manager to query for system information and to receive traps that are common to multiple Fortinet devices. FortiRecorder MIB This Fortinet-proprietary MIB enables your SNMP manager to query for FortiRecorder-specific information and to receive FortiRecorder-specific traps.
  • Page 85: Configuring Notification Triggers

    Configuring alert email on page 135. To configure camera notifications 1. Go to Camera > Notification > Camera Notification . 2. Click New . 3. Configure the following settings: Setting Name Description Name Enter a name for the notification entry. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 86 For information on how to view notifications in the GUI, see Monitoring motion detection notifications on page 107l. To verify email connectivity, from FortiRecorder, trigger an alert event that matches the type and severity levels that you have chosen. Then, check your email. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 87: Customizing Notification Templates

    If you require the same text in multiple templates or messages, create a variable in each. 3. Click Edit Variable . 4. Click New . You can modify the variables that you create, but you cannot edit or delete the predefined variables. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 88 6. Click OK . Predefined variables Like the variables that you create, each predefined variable usually can only be used within the scope of a specific type of system message or email template, as shown below. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 89 A hyperlink alternative to the QR code image in the mobile account registration email. The sender email address ( From: ) of the email. When using the %%SENDER%% default mail server settings, the value is: FortiRecorder <noreply@fortirecorder.com> FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 90: Customizing The Theme

    Enter the name of the product. Custom top logo Click Change to upload an icon used as the favicon for the FortiRecorder GUI. The image's dimensions must be 460 pixels wide by 36 pixels tall. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 91: Working With Certificates

    Configuring user and administrator accounts on page 62 3. Click Apply . Working with certificates When a FortiRecorder appliance initiates or receives an TLS connection, it will use certificates. Certificates can be used in secure connections with encryption and authentication. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 92 (P12), or certificate signing request (CSR) file format. PKCS #12 is recommended if you require a certificate backup that includes the private key. Certificate backups can also be made by downloading a configuration file backup, which includes all certificates and keys. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 93 Select the type of identifier to use in the certificate to identify the FortiRecorder appliance: Host IP — Select if the FortiRecorder appliance has a static IP address and enter the public IP address of the FortiRecorder appliance in the IP FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 94 Organization unit of your department. + icon, and enter each OU To enter more than one OU name, click the separately in each field. Optional Information: Optional. Type the legal name of your organization. Organization FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 95 Which method is best for you often depends on whether you have a convenient method for deploying CA certificates to clients, such as you may be able to for clients in an internal Microsoft Active Directory domain, and whether you often refresh the server certificate. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 96 This option is available only if Type is Certificate or PKCS12 Certificate. 4. Click OK . 5. To use a certificate, click its row to select it, then select Set status to put it in force. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 97 Time required to upload the file varies by the size of the file and the speed of your network connection. 7. To test your configuration, initiate a secure connection to an LDAPS server (see Configuring LDAP authentication on page 68 Configuring user and administrator accounts on page 62 FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 98 6. Click OK . The certificate is uploaded to the appliance. Time required varies by the size of the file and the speed of the network connection, but is typically only a few seconds. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 99: Using The Dashboard

    Dashboard > Console . If you need to pop the CLI Console out to a To access the CLI without exiting the GUI, go to Open in New Window . window that you can resize and reposition, then click FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 100: Using Fortiview

    Select either a line chart, which displays bandwidth information as a series of data points called "markers" connected by a line, or bar chart, which presents bandwidth data with rectangular bars with varying heights. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 101: Viewing Top Camera Usage

    FortiRecorder when receiving packets from the cameras. The collector drops graph shows any lost frames in the FortiRecorder by the daemon responsible for writing to disk. To edit the Advanced settings 1. Go to FortiView > Camera Statistics > Advanced . 2. Select the settings gear icon and configure the following: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 102: Viewing Network Connections And Sessions

    If you see network connections that you do not expect, verify the IP address of DHCP cameras and that the has not changed. If network connections seem to be missing, see Connectivity issues on page 151. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 103: Monitoring

    2. Below the video players, in the top right corner of the timeline, click Events Filter and select the type of events and/or annotations to include, such as motion detection ( Detection Recordings ) and face recognition ( Face Detection ). FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 104: Viewing Live Video

    3. If a live video stream is too dark, too bright, too blurry or too gray, then: a. Click the title bar of a view pane to select that camera. Show Camera Control button becomes available. b. Click Show Camera Control . c. Adjust: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 105: Viewing Previously Recorded Video

    Snapshots can also be viewed. 1. Go to Monitor > Video > Video . Use the timeline to jump to a previous date or time. 3. Click to select the time range or event that you want to view. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 106: Monitoring Events

    2. Click Select Cameras and select which cameras' events to include. 3. In Start date and End date , select the time range of events. 4. Click Events Filter and select the type of events and/or annotations to include. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 107: Monitoring Motion Detection Notifications

    Excessive logging frequency can cause undue wear on the hard disk and may cause premature failure. To download a log file 1. Go to one of the log types, such as Monitor > Log > Event . 2. Right click a log. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 108 You can show, hide, and re-order the display of logs. To display or hide columns in logs 1. Go to one of the log types, such as Monitor > Log > Event . 2. Select the Configure View drop-down menu. 3. Click Show/Hide Columns . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 109 Searching logs When viewing logs, you can locate a specific log message by searching for it. 1. Go to one of the log types, such as Monitor > Log > Event . 2. Click Search . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 110: Viewing Logs

    1. Go to Monitor > Log > Event . Columns and appearance varies slightly by the log type. 2. From the Level and Type dropdown lists, select the level of severity and type of log you are searching for. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 111 When in raw format, this is the log's log_id field. Detection The particular kind of detection the camera registered, such as motion. Type/Subtype Message The log message that describes the specific occurrence of a recordable event. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 112: Monitoring Face Recognition

    FortiRecorder records all of the failed login attempts and the IP addresses that are currently blocked from accessing the GUI and CLI. You can review and unblock IP addresses if an administrator or user has accidentally entered an incorrect password too many times. To unblock an IP address FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 113 Monitoring 1. Go to Monitor > Security > Blocked IP . 2. Select the IP address. 3. Click Add to Exempt List . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 114: Network Security

    3. Enter the IP address and netmask. 4. Click Create . To remove IP addresses from the auto exempt list 1. Go to Security > Intrusion Detection > Auto Exempt IP . 2. Select the IP address. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 115 Network security 3. Click Delete . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 116: Schedules

    Instead of using the time on the clock, you can schedule according to the cycles of day and night that vary from summer to winter. For details, see Configuring the sunrise and sunset time on page 117. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 117: Configuring The Sunrise And Sunset Time

    When using a combination of sunrise or sunset and the specific time, if the time crosses the boundary of sunrise or sunset, the schedule has no effect. For example, if the sunrise is at 8:00 AM and you set the schedule from sunrise to 7:00 AM, then the schedule has no effect. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 118: Analytics

    FortiRecorder. Every FortiCentral that runs face detection can contribute to your face recognition database. This distributed processing scales well as your organization grows. FortiRecorder can then use computer vision to analyze digital images to identify important people via face recognition. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 119 Event: Accept events of this type, process them for notification, and display them on timelines and logs. Event clip: Accept events of this type, process them for notification, display them on timelines and logs, and generate a video clip at the moment of detection. 6. Click Apply . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 120: Face Recognition

    Face recognition AI only analyzes video from the selected cameras. Analysis results in face clusters, which you must review and confirm in order to ensure accurate face recognition. Continue with Identifying faces on page 121. To enable face recognition in the CLI Enter these commands: config system global FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 121: Identifying Faces

    Click New User and enter their person's name, role, and department and then click Save . For details, see Configuring a department and role on page 122. 6. Click Link all to user . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 122: Reviewing Known Faces

    4. Enter the Department Name and Description . 5. Click Save . UserDB  section by selecting the You can also create a new department and role from the Edit button. user's row and then selecting the FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 123: Configuring A Floor Plan

    Next . 6. Select the polygon icon to draw on an area in the floor plan. Once the area is drawn, enter a name for the area and click Save . 7. Click Finish . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 124: Locating Cameras And Setting Processing Schedules

    5. From Schedule , select the schedule that governs the face recognition AI module. Face recognition AI will not function outside of the schedule. 6. Click Save . Notifications via face recognition Face recognition policies log and/or alert you to occurrences that fit your criteria. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 125: Searching The Face Recognition Database

    You can browse and search information in the face recognition database. To view face recognition information about a person 1. Go to Face Recognition > User Asset > UserDB . 2. Select the user. A profile appears displaying the following information: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 126: Using The Face Recognition Timeline

    24 hour period. Select an appearance to view more details and view video footage of the appearance. Filter the timeline display by selecting the range of time and the AI-enabled camera from the dropdown menus. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 127: Integrating With An Acs

    Source Map . For example, if you have camera A and camera B installed and pointed at the front entrance of the building, you can associate them with the front door. 1. Go to ACS > Configuration > Source Map . 2. Select a source such as a door. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 128: Monitoring Acs Events

    Time stamp when the event was triggered. Name Location of the triggered event. Card Info Card holder's name. Event Name of the event, as listed under ACS > Configuration. Cameras Cameras recording the events. Description Description of the events. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 129: Configuring Video Services

    Once you have entered the code into your web page, configure the FortiRecorder unit to allow your web page to access the camera group via HTTPS. If you want to share the video stream via RTSP, the user can use a RTSP client to access the video at: rtsp://<user_name>:<password_str>@<fortirecorder_ipv4>:<port_int>/camera=<id> For example: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 130: Downloading Video Clips Via Api

    4. In Interval , enter the number of seconds between each snapshot. 5. Enter the FTP settings. 6. In the Select Camera section, click New and select the cameras whose snapshots you want to share. 7. Enable or disable image processing. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 131: Streaming Recorded Video Clips To Youtube

    5. Select the camera from the drop-down menu and then specify which video stream to display, either viewing or recording. 6. Click OK . Using Chromecast with FortiRecorder You can use Google Chromecast with FortiRecorder to remotely monitor video streams from a camera on a mobile device, a computer, or a TV. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 132 6. Select the cameras that you want to stream. 7. Click Create . To stream photos to a Chromecast device 1. Go to Service > Chromecast > Image . 2. Click Add . 3. Select the file and then click Open . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 133: Analyzing Logs And Alerts

    23:00 (11:00 PM) on the 10th day. Log level Select the severity level that a log message must equal or exceed in order to be recorded to this storage location. For details, see Log severity levels on page 108 FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 134 FortiAnalyzer, and allocate enough disk space. Otherwise, depending on its configuration for unknown devices, FortiAnalyzer may ignore the logs. When the allocated disk space is full, it may drop subsequent logs. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 135: Configuring Alert Email

    See Configuring cameras on page 49 Camera communication error Enable to notify when there has been a network error during communications between the FortiRecorder and camera. See also Connectivity issues on page 151. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 136 Enable notify when various alerts have been triggered. Video disk events Enable to notify when the disk partition that stores video data is full. See also Data storage issues on page 150. 7. Click Apply . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 137: Best Practices

    Internet are connected to port3, then you would disable ("bring down") port4. This would prevent an attacker with physical access from connecting a cable to port4 and thereby gaining access if the configuration inadvertently allows it. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 138: Administrator Access

    By default, an administrator login times out if it is idle for more than 5 minutes. You can change this to a longer period in the idle timeout settings, but Fortinet does not recommend it. Left unattended, a GUI or CLI session could allow anyone with physical access to your computer to change FortiRecorder settings.
  • Page 139: Computer Cpu Usage

    If you do not need a log or alert, disable it to reduce the use of system resources. Reduce repetitive log messages. Use the alert email settings, to define the interval that emails are sent if the same condition persists following the initial occurrence. See Configuring alert email on page 135. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 140: Network Bandwidth Usage

    To improve compression, exclude areas of irrelevant motion such as fans or blinking lights from the camera's field of view. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 141: Sizing Guidelines

    Maximum number of simultaneous live video streams by users constant or variable Video resolution, frame rate, bitrate mode ( ) and its parameters (bitrate or image quality) See also Optimizing performance on page 138, or contact your Fortinet reseller. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 142: Number Of Supported Cameras

    Bitrate table (H.264 estimate) in Mbps with high quality image (x0.7 = standard quality): Bitrate/screen resolution Frame rate 0.16 0.24 (352 x 240 pixels) 0.75 (0.4 Mbps; 720 x 576 pixels) 720p (1 Mbps) SXGA 1.25 FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 143: Bandwidth Per Fortirecorder

    Video retention depends on the available storage capacity and the total amount of video bandwidth from the cameras. To calculate storage capacity, you can estimate that a 1 TB hard drive stores 1 camera configured to consume 1 Mbps for approximately 100 days. Video retention period in days for hard drive capacities: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 144: Software Updates And Backups

    = 5 Mbps In practice, Fortinet suggests to use the numbers provided in the bandwidth calculator as a starting point and then adjust them after installation to achieve the balance between quality and bandwidth. Software updates and backups Update to the newest firmware as soon as possible to receive new security features and stability enhancements.
  • Page 145 6. If you want to store backups on a remote server, then enable it and expand that section. Configure the following settings: Setting Name Description Protocol Currently only SFTP is supported. Server name/IP Enter the domain name or IP address of the server. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 146: Restoring A Previous Configuration

    Otherwise, to access the GUI again, in your web browser, modify the URL to match the new IP address of the network interface. For details, see Connecting to the FortiRecorder GUI on page FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 147: Troubleshooting

    To reset an account's password 1. Log in as the admin administrator account. 2. Go to System > User > User . 3. Select the row to select the account whose password you want to change. 4. Click Edit . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 148: Not Able To Push Setting And Log Shows An Error On Password

    You can minimize this by: Changing the camera's Resolution setting to the lowest acceptable resolution Changing the camera's Resolution setting to the lowest acceptable resolution Improving the bandwidth and latency of your network FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 149: Video Not Being Sent To Fortirecorder

    CPU usage, and memory usage. The report continues to refresh and display in the CLI until you press Q (quit). If you find a PID with abnormally high resource usage, you can terminate it: diagnose system kill 9 <pid_int> FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 150: Downloading A Trace Log

    Fortinet Technical Support Downloading a trace log If Fortinet Technical Support requests a trace log for system analysis purposes, you can download one using the GUI. Trace logs are compressed into an archive ( .gz file extension), and contain information that supplements debug-level log files.
  • Page 151: Deleting All Video Clips

    If no traffic arrives on a network interface even though the configuration appears to be correct, or if network performance is less than you expect, then it might be a problem with the physical hardware. Verify the following in order: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 152: Bringing Up Network Interfaces

    Functioning ARP is especially important in high availability (HA) topologies. If changes in which MAC address resolves to which IP address are not correctly propagated through your network, failovers may not work. To display the ARP table in the CLI, enter: diagnose network arp list FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 153: Examining Routing

    ICMP type 0 ( ECHO_REPSPONSE or "pong") might be effectively disabled. By default, traceroute uses UDP with destination ports numbered from 33434 to 33534. The traceroute utility FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 154 ECMP, split horizon, or network loops dynamic routing such as OSPF all equipment between the ICMP source and destination to minimize hops If the routing test fails, and ping shows total packet loss: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 155 The index number of the route in the list of static routes in the GUI is not necessarily the same as its position in the cached routing table ( diagnose netlink rtcache list ). FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 156: Discovery Fails

    To verify that your appliance and cameras are sending and receiving lease requests, you can perform a packet trace (see Packet tracing on page 159) and/or use the event log to look for: DHCPDISCOVER (destination IP address is broadcast, not specifically to FortiRecorder) DHCPOFFER DHCPREQUEST DHCPACK FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 157: Unauthorized Dhcp Clients Or Dhcp Pool Exhaustion

    IP address conflicts short DHCP server Lease time (Seconds) on page 32 socket exhaustion You can view a snapshot of FortiRecorder's session table according to the IP layer. Go to FortiView > Sessions > Sessions . FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 158 Their sessions will almost immediately expire and be removed from the session list, and therefore it may be very difficult to get a session list snapshot during the short time that the datagram is being transmitted. TCP has FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 159: Resolving Ip Address Conflicts

    Video performance on page 140. Packet tracing When troubleshooting networks, verifying hardware connections and routing with execute ping and execute traceroute CLI commands are often enough to diagnose the problem. For more rare problems, you can use traffic FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 160 More complex IP address, port number, and protocol filters can be configured via CLI Packet tracing via GUI 1. Go to System > Network > Traffic Capture . 2. Click New . 3. Configure the following settings: FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 161 Notepad++ plain text editor such as Strawberry Perl Perl interpreter such as Using the FortiOS built-in packet sniffer) fgt2eth.pl script (download at the bottom of Wireshark network protocol analyzer software such as FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 162 6. In Log file name , click the Browse button, then choose where to save the packet capture file, such as C:\Users\MyAccount\Downloads\packet_capture.txt . (You do not need to save it with the .log file extension.) FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 163 PuTTY packet_capture.pcap is the name of the converted output file 13. On your computer, open the PCAP file in compatible software such as Wireshark Compare the captured traffic with the expected behavior. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 164 000010 ac 14 83 2b eb f7 00 16 39 9f 83 88 23 6f 45 8f ...+..9...#oE. 000020 50 10 17 ff ed 72 00 00 00 00 00 00 00 00 P..r..FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 165 000010 ac 14 83 2b eb f7 00 16 39 9f 8d 98 23 6f 5c 9f ...+..9...#o\. 000020 50 10 18 00 cc 51 00 00 00 00 00 00 00 00 P..Q..FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 166: Resetting The Configuration

    Back up your configuration and export any important video recordings before beginning this procedure, if possible. It erases the configuration and data on the local storage FortiRecorder. You cannot undo the operation, except by restoring the configuration. Data cannot be restored. See Backups on page 144. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 167: Restoring Firmware ("Clean Install")

    However, be aware that from a remote location, you may not be able to power cycle the appliance if abnormalities occur. To restore the firmware FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 168 FortiRecorder appliance whose network interface configuration was reset, Connecting to the FortiRecorder GUI on page 20 1. Download the firmware file from the Fortinet Technical Support web site: https://support.fortinet.com/ 2. Connect your management computer to the FortiRecorder console port using a RJ-45-to-DB-9 serial cable or a null- modem cable.
  • Page 169 If you are downgrading the firmware to a previous version, and the settings are not fully backwards compatible, the FortiRecorder appliance may either remove incompatible settings, or use the feature's default values for that version of the firmware. You may need to reconfigure some settings. FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 170: Appendices

    HTTP Sending network settings and recording signals to cameras. See Configuring cameras on page NTP clock time synchronization. By default, FortiRecorder synchronizes its time with NTP servers at Fortinet. See Configuring the system time on page HTTPS Sending network settings and other configurations to cameras Face recognition AI license validation by Fortinet.
  • Page 171: Incoming Traffic

    3011 Currently, this port number is not configurable. 8550 Tunnel with FortiCentral to use the cameras, store face recognition data, and more. See also Access: FRC-Central on page 27 and the FortiCentral User Guide FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 172: Appendix B: Maximum Values

    Remote log servers 3 (400F: 5) Local certificates CA certificates Remote certificates SNMP users SNMP user hosts Camera groups DHCP server leases Camera notifications Video profiles Camera profiles Schedules Motion detection windows Privacy mask windows FortiRecorder 7.0.0 Administration Guide Fortinet Inc.
  • Page 173 Counsel, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests.

Table of Contents