---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Fortinet Firewall SNMP-based

# Next-Generation Fortinet Network Firewall SNMP-based discovery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Next-Generation Fortinet Network Firewall SNMP-based discovery

The Next Generation Fortinet Network Firewall SNMP-based discovery pattern in ServiceNow enables automated identification and data collection of Fortinet firewall devices using SNMP calls.
This capability is part of the Discovery and Service Mapping Patterns application and supports horizontal discovery of Fortinet firewall devices and clusters, populating the Configuration Management Database (CMDB) with detailed device information.
Note that SNMP-based discovery does not detect FortiGate Virtual Domains (VDOMs); for those, the REST-based discovery method is required.
Show full answer Show less  

## Key Features

* **SNMP-based Discovery Pattern:** Uses a series of SNMP queries to find Fortinet firewalls within your network.
* **CMDB Integration:** Introduces specific CI classes for Fortinet Firewall Clusters and Devices that extend existing firewall CI classes to accurately model discovered assets.
* **Comprehensive Data Collection:** Captures key attributes such as hostname, IP address, manufacturer, model, firmware, operational status, and hardware OS details.
* **Related CI Classes:** Collects information on associated IP addresses, network adapters, and DNS names linked to Fortinet firewall devices.
* **CI Relationships and References:** Establishes relationships between firewall clusters, devices, IP addresses, network adapters, and router interfaces to provide a complete network topology view.
* **Prerequisites:** Requires up-to-date Discovery and Service Mapping Patterns application, SNMP access enabled on Fortinet devices, configured SNMP credentials in ServiceNow, and addition of Fortinet SNMP system OID records to the instance.

## Key Outcomes

* Automated discovery and accurate modeling of Fortinet firewall infrastructure within the CMDB.
* Enhanced visibility into firewall clusters and individual devices, including detailed operational and hardware information.
* Improved network topology understanding through established relationships between firewalls, clusters, IP addresses, and network adapters.
* Support for proactive network management and service mapping by integrating Fortinet firewall data into ServiceNow's ITOM Visibility capabilities.  
The Discovery and Service Mapping Patterns application uses the Next Generation Fortinet Network Firewall pattern to find Fortinet firewalls through a series of SNMP calls. Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.
The Next Generation Fortinet Network Firewall pattern uses a set of SNMP calls to find the Fortinet firewalls. Discovery uses the pattern to run horizontal discovery.  
Note:  
Only the REST-based Fortinet firewall discovery method finds FortiGate VDOMs. The SNMP-based Fortinet firewall discovery method doesn't discover them. For information on REST-based Fortinet firewall and FortiGate Virtual Domains (VDOMs) discovery, see [Fortinet firewall and FortiGate VDOM REST-based discovery](https://servicenow-prod.fluidtopics.net/RkAGAqxHMZ5_XbFupjOXLw "The Discovery and Service Mapping Patterns application uses the Next Generation Fortinet Network Firewall - REST pattern to find Fortinet firewalls through REST API calls. Additionally, the pattern extension VDOM Discovery finds FortiGate Virtual Domains (VDOMs). Discovering some of these resources may require updating to the latest version of the Discovery and Service Mapping Patterns application from the ServiceNow Store.").

## Request apps on the Store {#fortinet-fw-discovery__section_lml_jd3_slb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#fortinet-fw-discovery__inline-send-to-store}
To learn about Fortinet firewalls and their versions that you can discover, refer to [Detailed information on products discovered by ITOM Visibility](https://servicenow-prod.fluidtopics.net/AB0jKyDtjf78iS3uAPUKpg "Discovery and Service Mapping can discover a wide range of operating systems and applications.").

## Fortinet Firewall data model {#fortinet-fw-discovery__section_data_model}

The Next Generation Fortinet Network Firewall pattern introduces the following CI classes that extend an existing CMDB class.  
{#fortinet-fw-discovery__table_extends_fortinet__entry__2}

| CI class | Extends from |
|-|-|
| Fortinet Firewall Cluster \[cmdb_ci_firewall_cluster_fortinet\] | Firewall Cluster \[cmdb_ci_firewall_cluster\] |
| Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] | Firewall Device \[cmdb_ci_firewall_device\] |
[Table 1. CI classes introduced by this pattern]

{#fortinet-fw-discovery__table_extends_fortinet}

## Prerequisites {#fortinet-fw-discovery__section_pgt_4xz_ykb}

Verify the applications are up to date
:
    * Discovery and Service Mapping Patterns
    * CMDB CI Class Models
    {#fortinet-fw-discovery__ul_k2z_q5n_tcc}

Ensure SNMP access
:   Ensure that your Fortinet firewall device has SNMP access.

Configure SNMP credentials
:   On the ServiceNow instance, configure SNMP credentials. For more information, see [SNMP credentials](https://www.servicenow.com/docs/access?context=c_SNMPCredentials&version=yokohama&pubname=yokohama-platform-security&ft:locale=en-US).

Add SNMP system OID record to ServiceNow instance
:   Add the SNMP system OID record for the Fortinet device to the ServiceNow instance. Update the following:

    * Classifier: Fortinet Firewall
    * Class: Fortinet Firewall Device
    {#fortinet-fw-discovery__ul_rxb_ysn_tcc}

Run a horizontal discovery
:   For more information, see [Running discoveries in your network](https://servicenow-prod.fluidtopics.net/z1YAnBcRkarsV70KmkIhPw "You can run discoveries from schedules or scripts to create configuration items, define subnets, or to find resources in AWS and Azure clouds.").

## Data collected by Discovery during horizontal discovery {#fortinet-fw-discovery__section_bpg_qxz_ykb}

Discovery populates the data in the CMDB when running the Next Generation Fortinet Network Firewall Pattern.  
{#fortinet-fw-discovery__table_r5g_4rw_rcc__entry__2}

| Field | Description |
|-|-|
| Name \[name\] | Hostname. |
| Fully qualified domain name \[fqdn\] | Fully qualified domain name. |
| IP address \[ip_address\] | IP address. |
| Manufacturer \[manufacturer\] | Device manufacturer. |
| Description \[short_description\] | Short description of the Fortinet firewall cluster. |
| Model Number \[model_number\] | Device model number. |
| Hardware Operating System \[hardware_os\] | OS running on the hardware. |
| Hardware OS Version \[hardware_os_version\] | OS version running on the hardware. |
[Table 2. Fortinet Firewall Cluster \[cmdb_ci_firewall_cluster_fortinet\]]

{#fortinet-fw-discovery__table_r5g_4rw_rcc}  
{#fortinet-fw-discovery__table_o52_prw_rcc__entry__2}

| Field | Description |
|-|-|
| Name \[name\] | Hostname. |
| Serial Number \[serial_number\] | Serial number of the device. |
| Fully qualified domain name \[fqdn\] | Fully qualified domain name. |
| Operational Status \[operational_status\] | Indicates if the device is in active state. |
| IP address \[ip_address\] | IP address. |
| Manufacturer \[manufacturer\] | Device manufacturer. |
| Description \[short_description\] | Short description of the device. |
| Model Number \[model_number\] | Device model number. |
| Firmware \[firmware_version\] | Firmware version. |
| Hardware Operating System \[hardware_os\] | OS running on the hardware. |
| Hardware OS Version \[hardware_os_version\] | OS version running on the hardware. |
[Table 3. Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\]]

{#fortinet-fw-discovery__table_o52_prw_rcc}  
{#fortinet-fw-discovery__table_w2b_drw_rcc__entry__2}

| Field | Description |
|-|-|
| IP Address \[ip_address\] | IP address of the Fortinet firewall. |
| Netmask \[netmask\] | Netmask of the Fortinet firewall. |
| Nic \[nic\] | References the Network Adapter \[cmdb_ci_network_adapter\] table. |
[Table 4. IP Address \[cmdb_ci_ip_address\]]

{#fortinet-fw-discovery__table_w2b_drw_rcc}  
{#fortinet-fw-discovery__table_ybv_drw_rcc__entry__2}

| Field | Description |
|-|-|
| IP Address \[ip_address\] | IP address of the network adapter. |
| Netmask \[netmask\] | Netmask of the network adapter. |
| Alias \[alias\] | User-assigned name for the network adapter. |
| MAC Address \[mac_address\] | MAC address of the network adapter. |
| Name \[name\] | Name of the network adapter. |
| Configuration Item \[cmdb_ci\] | References the Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] table. |
[Table 5. Network Adapter \[cmdb_ci_network_adapter\]]

{#fortinet-fw-discovery__table_ybv_drw_rcc}  
{#fortinet-fw-discovery__table_z5x_drw_rcc__entry__2}

| Field | Description |
|-|-|
| Name \[name\] | Name of the Domain Name System (DNS). |
| IP Address \[ip_address\] | IP address of the DNS. |
[Table 6. DNS Name \[cmdb_ci_dns_name\]]

{#fortinet-fw-discovery__table_z5x_drw_rcc}  
This Dependency Views map on the Fortinet Firewall Device CI shows the Fortinet Firewall Cluster to which it belongs.  

## CI relationships {#fortinet-fw-discovery__section_x5q_xxz_ykb}

The Next Generation Fortinet Network Firewall pattern creates the following relationships and references to support Fortinet firewall discovery. References link to records in other tables and don't appear in the CI Relationship \[cmdb_rel_ci\] table.  
{#fortinet-fw-discovery__table_agp_zxz_ykb__entry__3}

| CI | Relationship | CI |
|-|-|-|
| Fortinet Firewall Cluster \[cmdb_ci_firewall_cluster_fortinet\] | Hosted on::Hosts | Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] |
| Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] | Owns::Owned by | IP Address \[cmdb_ci_ip_address\] |
| Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] | Owns::Owned by | Network Adapter \[cmdb_ci_network_adapter\] |
| Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] | Uses::Used by | Router Interface \[dscy_router_interface\] |
| Network Adapter \[cmdb_ci_network_adapter\] | Owns::Owned by | IP Address \[cmdb_ci_ip_address\] |
[Table 7. CI relationships]

{#fortinet-fw-discovery__table_agp_zxz_ykb}  
{#fortinet-fw-discovery__table_ci_references_fortinet__entry__3}

| CI | Field | Referenced CI |
|-|-|-|
| Serial Number \[cmdb_serial_number\] | Configuration item \[configuration_item\] | Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] |
| Network Adapter \[cmdb_ci_network_adapter\] | Configuration Item \[cmdb_ci\] | Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] |
| Router Interface \[dscy_router_interface\] | Configuration Item \[cmdb_ci\] | Fortinet Firewall Device \[cmdb_ci_firewall_device_fortinet\] |
| IP Address \[cmdb_ci_ip_address\] | Nic \[nic\] | Network Adapter \[cmdb_ci_network_adapter\] |
[Table 8. CI references]

{#fortinet-fw-discovery__table_ci_references_fortinet}

