---
title: "Extend Fortinet FortiGate to Kubernetes with Calico Enterprise 2.7"
source: "https://www.tigera.io/blog/extend-fortinet-fortiguard-to-kubernetes-with-calico-enterprise-2-7/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Extend Fortinet FortiGate to Kubernetes with Calico Enterprise 2.7

By [John Armstrong](https://www.tigera.io/blog/author/john-armstrong/) on Mar 03, 2020 • 4 min read

We are excited to announce the general availability of Calico Enterprise 2.7. With this release, Fortinet’s 400,000 customers can use FortiGate to enforce network security policies into and out of the Kubernetes cluster as well as traffic between pods within the cluster.

- Kubernetes workloads populate the FortiGate GUI

- The network team can then create and enforce policies in FortiGate and have them enforced as Calico Policy

- Saves time and money and lets the network team retain the firewall responsibility (which also frees up time for ITOps)

![FortiGate GUI showing Kubernetes workloads (addresses/groups) managed by Tigera Calico Enterprise](/app/uploads/2020/03/fortigate-gui.png)

We have also added many new exciting capabilities that help platform engineers blow through barriers blocking their path to production, and advanced cybersecurity capabilities for those already running production workloads.

- Manage Network Security Across Multiple Kubernetes Clusters

- Enforce a Common Set of Security Controls Across Multiple Clusters

- Detect and Alert on Unauthorized Changes and Other Attack Vectors

- Self-Service Troubleshooting for End Users

- Detect and Prevent Malicious Data Exfiltration

## Manage Network Security Across Multiple Kubernetes Clusters

As the adoption of Kubernetes continues to accelerate, our customers are seeing the number of clusters in their environments rapidly multiplying. This has created a management challenge for IT Ops teams who are constantly pushed to find ways to do more with less. With Calico Enterprise 2.7, you can now manage security policies across multiple clusters from a single, centralized management console. This greatly simplifies cluster administration and opens the way for customers to more easily scale as new clusters are deployed within the organization.

## Enforce a Common Set of Security Controls Across Multiple Clusters

Another way that Calico Enterprise 2.7 supports scalability and simplifies cluster administration is through its ability to enforce a common set of security controls across multiple clusters. Corporate or regulatory security controls are implemented once and are then propagated across multiple clusters. Any subsequent change to security controls immediately rolls out to all clusters. All logging is captured in a central Elastic datastore and can be accessed for troubleshooting and proof of compliance with security requirements.

## Detect and Alert on Unauthorized Changes and Other Attack Vectors

![Screenshot of Calico's 'Create Alert' interface, showing options to define rules based on network flows and time, to detect](/app/uploads/2020/03/custom-alerts-gui.png)

As clusters migrate into production, data security and access controls become paramount concerns. Every organization has its own unique data protection requirements and processes. The Alert Builder in Calico Enterprise 2.7 enables security teams to define custom alerts that are consistent with the unique compliance requirements in their organization. Alert Builder can help security teams create a “tamper-proof” environment. For example, alerts can be created that detect and raise an alarm when an unauthorized change has been made in a cluster.

## Self-Service Troubleshooting for End Users

The last thing the platform team wants to be is a choke point in the system. But ITOps can occasionally be overwhelmed with a backlog of service requests, each one creating a source of frustration for the platform team and their internal customers. To ease the burden on ITOps, we have enabled Role-based Access Control (RBAC) for the Flow Visualizer in Calico Enterprise 2.7. With RBAC, granular privileges can be assigned to specific individuals (or teams) to access Flow Visualizer for the purpose of troubleshooting their own distributed applications, while restricting them from accessing other applications and sensitive data. Sharing the load helps speed problem resolution and frees the platform team to focus on more strategic activities.

## Detect and Prevent Malicious Data Exfiltration

Tor exit nodes are the gateways where encrypted Tor traffic hits the Internet and can be abused to monitor traffic. Consumer VPNs can sometimes be a cover for threat actors. Connections like these may indicate a compromise within a Kubernetes cluster and should be assumed to be suspicious until confirmed otherwise. New threat defense capabilities in Calico Enterprise 2.7 can detect the presence of Tor exit nodes and consumer VPNs, and alert the security team to take appropriate action.

————————————————-

[**Free Online Training**](https://www.tigera.io/events/)

Access Live and On-Demand Kubernetes Tutorials

[**Calico Enterprise – Free Trial**](https://www.calicocloud.io/home)

Solve Common Kubernetes Roadblocks and Advance Your Enterprise Adoption

[Partner/Integration](https://www.tigera.io/tags/partner-integration/)[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6162 metric#misses=17 metric#hit-ratio=99.7 metric#bytes=2234256 metric#prefetches=0 metric#store-reads=413 metric#store-writes=41 metric#store-hits=428 metric#store-misses=6 metric#sql-queries=43 metric#ms-total=1177.99 metric#ms-cache=56.72 metric#ms-cache-avg=0.1252 metric#ms-cache-ratio=4.8 sample#redis-hits=45244165 sample#redis-misses=7805999 sample#redis-hit-ratio=85.3 sample#redis-ops-per-sec=363 sample#redis-evicted-keys=0 sample#redis-used-memory=88036872 sample#redis-used-memory-rss=91267072 sample#redis-memory-fragmentation-ratio=1.0 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=21637 -->
