Adding multiple FortiGates to FortiManager with identical objects but different subnets
Hi,
We have a number of FortiGate firewalls which range from SMB 60C (being migrated to 51E) to large 1000D. We have purchased FortiManager and installed version 5.4.3 as it covers most of our firewalls firmware.
I have recently learnt FortiManager can not manages all firewalls which are on different majour and minor release versions and this can only be managed under a single ADOM - is this correct, as I would under the impression FortiManager would provide a single manage plane for all the firewalls?
Around 30% of the configuration on the FortiGates are similar i.e. VPN tunnel to a main FortiGate firewalls. However, the naming convention used to reference these objects is different and in some cases the subnets could be different using identical object naming standards.
My understanding, is if I import the first FortiGate into the FortiManager under the same ADOM it will import the policies and objects within the ADOM database. If I then import the second firewall under the same ADOM, and the objects are named identical but configured with different IP or subnet it will become an issue. This is because FortiManager will replace the object it has within its database from the first firewall import and replace the subnet with the second firewall import. If later down the line, we update the first imported firewall it will change the subnet address on the firewall causing the incorrect subnet to be replace under the object - is this correct? What would be the recommended method on importing these firewalls into FortiManager?
My plan before learning the above was to import the firewalls into FortiManager and then work with making the objects and policies consistent, however, this is going to be impossible unless I check each firewalls for its objects?
Would appreciate any thoughts and advice.
Thanks,
Sam.