Skip to main content
kinporsch
New Member
May 21, 2022
Question

FortiAnalyzer ADOMs Question

  • May 21, 2022
  • 3 replies
  • 2246 views

Is it generally best practice to separate firewalls into ADOMs within FAZ?

I've been doing some research but have been getting mixed results. In FMG, it makes sense to separate firewalls by firmware version or by client; however, within FAZ, is there any downside of having a single ADOM for all firewalls? It would make global reporting possible (ie. quickly running a report to determine all firewall firmware versions). As far as I'm aware, reports could still be narrowed down to select firewalls.

I've also heard that licensing for FAZ may shift to include an ADOM-limit on top of the daily log rate. This has me a bit concerned because I have quite a few ADOMs per clients with only one or two firewalls each.

3 replies

AEK
SuperUser
SuperUser
May 21, 2022

FAZ ADOMs are different from FMG ADOMs, for FAZ you can put all FGTs in a single ADOM, even if they have different versions, other ADOM must be created if you have other device types, e.g.: FML, FCT, ... etc

AEK
abelio
SuperUser
SuperUser
May 21, 2022

Useful only in a multi-tenant scenario IMHO.

When you need to isolate FAZ access to diferent customers, ADOMs helps you.

 

Debbie_FTNT
Staff & Editor
Staff & Editor
May 23, 2022

Hey kinporsch,

as AEK and abelio mentioned, FortiAnalyzer ADOMs are only really relevant for the following scenarios:

- different Fortinet products

-> you would have different ADOMs for FortiGate, FortiMail, FortiAuthenticator, etc

- multi-tenancy

-> if you offer a FortiAnalyzer to multiple of your own customers, you can use ADOMs to separate your customers from each other and ensure they only have access to their own ADOM and logs, and not to devices/logs/reports from other customers

 

In addition, if you have very large environments, ADOMs can help with organizining.

For example, if you have several thousand FortiGates scattered around the globe you might want to bundle them in ADOMs geographically to maintain some kind of organization; at some point reports spanning that many FortiGates would become very difficult to read.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.