FortiLink device detection relies on FortiGate'sDevice IdentificationandIoT Detectioncapabilities to classify devices connected to FortiSwitch ports.
To enabledevice identificationandvulnerability detectionfor IoT/endpoint devices in LAN Edge deployments, FortiGate must subscribe to the correct FortiGuard services.
1. Required FortiGuard License for Device Identification (IoT Detection)
The FortiOS documentation clearly states:
“IoT detection service… requires anAttack Surface Security Rating service licenseto download the IoT signature package.”
Additionally:
“The following settings are required for IoT device detection:
A validAttack Surface Security Rating service licenseto download the IoT signature package.”
This service provides:
IoT signature package
IoT device classification
Device behavior profiling
This makesAttack Surface Securitymandatory for FortiLink device detection.
2. Required FortiGuard License for Device Vulnerability Detection
FortiOS further clarifies that IoT vulnerabilities require theIoT Detection license, which is included under the same Attack Surface service entitlement:
“To detect IoT vulnerabilities the FortiGate must have a validIoT Definitions license…”
The IoT Definitions license comeswith the Attack Surface Security Rating serviceand is used for:
Scanning connected devices
Identifying IoT/endpoint vulnerabilities
Reporting vulnerability severity
Enabling NAC-based remediation (VLAN steering, port isolation)
In LAN Edge Architect, this license combination is emphasized as a foundational requirement for:
FortiSwitch NAC
FortiLink device profiling
Automated quarantine actions
IoT device classification
Vulnerability-based segmentation
3. Why the Correct Answer Is Option D
OptionDlists:
✔FortiGuard Attack Surface Security
✔FortiGuard IoT Detection
These are exactly the services required per FortiOS 7.4.1:
Attack Surface Security Rating→ provides IoT signature package + vulnerability data
IoT Detection (Definitions)→ enables actual device-type and vulnerability identification
Together they powerFortiLink Device DetectionandIoT Vulnerability Detection, which are essential LAN Edge security functions.
4. Why Other Options Are Incorrect
A. Vulnerability Management + Endpoint Protection
Not used for FortiLink device detection; Endpoint detection relies on IoT service, not FortiClient.
B. Threat Intelligence + IoT Detection
Threat Intelligence (ThreatIntel DB) is used for FAZ IOC, not LAN Edge device detection.
C. Threat Intelligence + Endpoint Protection
Same issue—does not provide IoT device classification or vulnerability scanning.
LAN Edge 7.6 Architect Context Summary
In LAN Edge designs:
FortiGate acts as the controller for FortiSwitch via FortiLink.
Device detection is done at the FortiGate level using NAC/IoT signature capabilities.
Vulnerability detection enables dynamic segmentation decisions (e.g., move device to quarantine VLAN).
To support this, two licenses aremandatory:
Attack Surface Security(includes Security Rating + IoT Detection DB)
IoT Detection(part of the same entitlement, but explicitly required for vulnerability detection)
Thus the verified answer aligns perfectly with LAN Edge operational requirements and Fortinet documentation.