What Myrmex Can Do
Read and diagnose
Inspect system status, interfaces, routing, sessions, policies, VPNs, and HA — read-only diagnostics.
Hardening audit
Run a Security Posture audit across roughly 130 FortiGate controls.
Policy hygiene
Find shadowed, unused, or zero-hit firewall policies and propose cleanups.
Configuration management
Back up, restore, and diff the device configuration; apply rule and VPN changes with approval.
Before You Start
- A Collector deployed on a network that can reach the FortiGate management IP over SSH. See Deploying the agent.
- SSH enabled on the FortiGate management interface.
- An administrator account Myrmex can use to log in (a read-only profile is enough for analysis; a read-write profile is required to apply changes).
Step 1 — Create the Access Account on the FortiGate
1
Enable SSH on the management interface
Under Network → Interfaces, edit the management interface and enable SSH under Administrative Access.
2
Create an admin profile (optional, recommended)
Under System → Admin Profiles, create a profile scoped to what Myrmex should do — read-only for analysis, or read-write to allow changes.
3
Create the administrator
Under System → Administrators, add an administrator with a strong password and assign the profile above. Note the username and password — you’ll enter them in Myrmex.
Step 2 — Add the Integration in Myrmex
In the Directory, choose Add Integration → FortiGate and fill in:Connect
Click Connect to validate the SSH connection and finish. The FortiGate then appears under Environment → Integrations, and you can start asking the AI about it in the Workspace.Configuration Backup and Change Tracking
Myrmex keeps a daily backup of the FortiGate configuration and can diff those backups over a period, so you can see exactly what changed on the device and when. Ask for it in the Workspace — for example, “show me what changed on this FortiGate in the last 7 days.”Myrmex does not store logs. It reads the device in real time and collects only
the data you ask for; the daily configuration backups are the exception that
makes point-in-time comparisons possible.