AdeGate

What can AdeGate do?

59 capabilities in eight groups. Pick one on the left; each explains what it does and what it gives you. See which plan includes which feature on the plan comparison page.

Access approval

RDP approval for Windows servers

When someone signs in to a Windows server over Remote Desktop, an approval request goes to their manager before the session opens. The user waits at the sign-in screen; once approved, the session opens on its own.

  • No RD Gateway, jump server or firewall rule required
  • Installed on the server with a single line copied from the panel
  • The server's NLA settings are never touched

SSH approval for Linux servers

The same approval flow applies to SSH logins on Linux servers. Without approval the session does not open; if rejected, the connection is closed.

  • Supports Ubuntu, Debian, RHEL, Rocky Linux and AlmaLinux
  • Installed with a single curl command copied from the panel

Approvers and approval duration

You decide who approves access to each server. Approval is given with one click from the link in the email; when the approval period ends, the next login needs approval again.

  • Approver list per server
  • Flexible approval durations
  • Every request, approval and rejection recorded with who made it and when

FortiGate VPN manager approval FortiGate

After a VPN user enters their password and two-factor code, their manager is asked for approval before the connection opens. Without approval, the connection is rejected.

  • A stolen password and code are not enough to get in
  • Approvals and rejections are recorded

FortiGate admin login approval FortiGate

Administrators signing in to the FortiGate admin panel or SSH pass a second person's approval after two-factor authentication. Who accessed the firewall configuration, when, and with whose permission is documented.

Nobody gets locked out

If you exceed your license's server limit, new servers switch to log-only mode instead of approval. No login is ever blocked; it is simply recorded.

Access reviews Pro and Enterprise

Reports active users, their last login and accounts unused for a long time, and records who signed off the review and when.

  • Produces evidence for ISO 27001 A.5.18 Access rights

Authentication

VPN two-factor authentication FortiGate

Adds two-factor authentication with Google or Microsoft Authenticator to FortiGate SSL VPN users. AdeGate connects to your FortiGate as a RADIUS server; no extra FortiToken licenses are needed.

  • Works with FortiClient
  • User groups and security policies stay unchanged

FortiGate admin two-factor authentication FortiGate

Separate two-factor authentication for FortiGate admin panel and SSH logins. Protects 1 admin account on Free, 3 on Pro and 5 on Enterprise.

VPN data transfer quota FortiGate

Set a daily data transfer quota per user, with per-user adjustments where needed. When the quota is exceeded, the user's new VPN connections are blocked, stopping possible malicious bulk data transfers.

  • Default quota with per-user exceptions
  • Quota usage visible in the panel and resettable when needed

VPN monitoring

VPN sessions and history FortiGate

Active SSL VPN sessions and full connection history: user, source IP, country, duration and data transferred.

IPsec tunnel tracking FortiGate

Status and traffic history of IPsec tunnels, with alerts when a tunnel goes down.

Impossible travel detection FortiGate

If the same user connects from two distant locations in less time than it would physically take to travel between them, an alert is raised. It is one of the clearest signs of stolen credentials.

After-hours VPN alert FortiGate

Alerts on VPN connections outside the working hours and weekends you define. Users who regularly work after hours can be added to an exception list.

New country detection FortiGate

Alerts when a VPN connection comes from a country not seen in the previous 30 days.

Learned data transfer alerts FortiGate

AdeGate records each user's past VPN activity and learns what is normal for them. When something unusual happens, such as a user transferring far more data than usual, it raises an alert.

VPN brute-force detection FortiGate

When many failed login attempts happen in a short time, an alert is raised together with the source IP.

Username scan detection FortiGate

Detects scanning attempts where different usernames are tried one after another to find valid accounts.

IPsec scan detection FortiGate

IKE negotiation and scan attempts from the internet are tracked separately from real user logins, with alerts on sudden spikes.

Per-user VPN report FortiGate

Each user's session count, total connection time and data downloaded and uploaded.

Security monitoring

IPS events and frequency anomalies FortiGate

FortiGate IPS events are recorded; an alert is raised when a signature appears more often than usual.

IP correlation FortiGate

If an IP address flagged by IPS also has an active session at the same time, an alert is raised. It is a sign the attacker may already be inside.

SYN flood detection FortiGate

Alerts on a possible half-open connection attack when the new session rate rises far above normal.

Banned IP tracking FortiGate

IP addresses banned by FortiGate and changes to that list are tracked.

IP reputation enrichment FortiGate

IP addresses in events are enriched with AbuseIPDB and VirusTotal data, so you can see at a glance whether an address is known to be malicious.

Security score FortiGate

Your FortiGate configuration is checked against best practices and scored; gaps are listed with recommendations.

Brand protection Pro and Enterprise

Fake domains impersonating your company are regularly searched for in Certificate Transparency logs, so phishing sites can be spotted before they go live.

  • Your own domains are whitelisted and never trigger false alarms

External vulnerability scanning Enterprise

Your internet-facing web assets are scanned automatically every week with Nuclei, Nikto and testssl.sh; findings are tracked until they are closed.

SiberKapan threat feeds FortiGate

SiberKapan threat intelligence lists are added to FortiGate as external connectors, making it easy to block current malicious addresses.

External block list FortiGate

Add the IP addresses you choose to FortiGate's quarantine list from the AdeGate panel; traffic from those addresses is blocked by FortiGate.

Performance and infrastructure

Live dashboard FortiGate

CPU, memory and session count, interface traffic, top talkers and applications, a traffic map by country and the administrators currently signed in to FortiGate, all on one screen.

Learned performance anomalies FortiGate

AdeGate learns your device's normal CPU, memory and session levels for each hour of the day and alerts when they move clearly outside that range.

Thresholds FortiGate

Set your own warning and critical thresholds for CPU, memory, session count and failed login attempts; working hours and weekend alerts are configurable.

Interface alerts FortiGate

Alerts when interfaces go down or up, when error counters spike and when bandwidth thresholds you define are exceeded.

Crash snapshots FortiGate

At the moment of a performance anomaly, a snapshot of CPU cores, the busiest sessions and IPS events is saved, so you can find the root cause even after the problem has passed.

FortiGate HA monitoring FortiGate

The state of your FortiGate cluster and changes among its members are tracked.

DHCP pool usage FortiGate

DHCP pool usage per interface and active leases, with alerts at 85 percent and 95 percent.

License and firmware tracking FortiGate

FortiGate license expiry dates and the firmware version are tracked; known vulnerabilities affecting your version (NVD CVE records) are listed.

Changes and configuration

Real-time change detection FortiGate

Every FortiGate configuration change is recorded with who made it, whether from the GUI or CLI, and what changed. Changes to critical areas such as security policies, VPN, admin accounts, interfaces and routing trigger an immediate alert.

After-hours change alert FortiGate

Configuration changes made outside working hours trigger a separate alert.

Policy change history FortiGate

The history of each security policy's fields such as source, destination, service and action is kept, so you can see when and how a rule changed.

Policy analysis FortiGate

Lists rules that are never used, rules shadowed by another rule that never match, and the rules carrying the most traffic.

FortiGate configuration backup FortiGate

Your FortiGate configuration is backed up automatically every day and can be backed up manually at any time. Backups can be sent out by email or SFTP, differences between versions are shown in a readable way and every backup's integrity is verified.

Admin login records

Admin logins, logouts and failed attempts on FortiGate and logins to the AdeGate panel are recorded separately.

Compliance and audit

Log retention

Records are kept for 30, 180 or 365 days depending on your plan; expired records are cleaned up automatically.

Log archive and tamper-evident chain Pro and Enterprise

Records are archived and linked together with a cryptographic chain. Deleting or altering any past record is detected.

Audit record export Pro and Enterprise

Export change and access records as CSV to present to auditors.

ISO 27001 compliance report Pro and Enterprise

A summary of the technical evidence AdeGate provides for Annex A controls; viewable in the panel and downloadable as PDF.

Incident management

Turn alerts into incidents and track them: status (open, investigating, resolved, closed), root cause, corrective action, assignee and timeline.

Reports

Reports with an executive summary, VPN usage, alert breakdown and daily performance; viewable in the panel, downloadable as PDF and can be emailed weekly.

  • The change audit section of the report is included in Pro and Enterprise

Syslog forwarding Pro and Enterprise

AdeGate records are forwarded to your central log server or SIEM over syslog.

Platform

Runs on your own server

AdeGate installs on your own server running Ubuntu 24.04 with a single command; your logs and passwords never leave your company.

Notifications

Alerts are delivered in the panel and by email according to severity (info, warning, critical); you choose which levels send email. You are notified when a problem is resolved, too.

Panel security and users

Unlimited panel users; sign-in protected by CAPTCHA, a honeypot field and a temporary lockout after 5 failed attempts; mandatory password change for new users.

High availability (HA) Enterprise

A continuously synchronized hot standby runs on a second server. If the primary has a problem, the standby takes over with one click. The standby is installed with a single command from the Settings page.

Updates from the panel

New versions are installed from the panel with one click.

English and Turkish interface

Panel, emails and reports in English or Turkish; the time zone is configurable.

System health monitoring

AdeGate monitors its own health and alerts you when there is a problem and when it is resolved.