FortiManager - Assign FG to ADOM based on hostname
I've read a lot about the scripting/API functionality of the FMG, and am hoping someone has some ideas how to accomplish the following.
Our FMGs will be distributed globally in Azure DCs. Users will be assigned privileges to access specific FMGs and ADOMs based on their AD group membership. What I would like to be able to do, is sort/assign FG registrations based on the hostname of the FG itself.
What I would like to be able to do, is sort/assign FG registration based on the hostname of the FG itself. We have established a standard naming convention for our FGs in the field, with the 2 character ISO country code as the last characters in the FG's hostname. When an FG sends a registration request, I would like the request to automatically be placed in the proper ADOM (not the root ADOM) so that the admin for that country can then accept the registration and get the FG properly added to the regional FMG. We will potentially have 100+ registrations per month, and it does not make sense for our local team (basically me) to manually assign these FGs to the proper ADOM.
Pre-registration of the S/N would be a possibility, but this just adds more overhead to already overworked field service personnel. Using a pre-shared key based on the model can resolve some of the subsequent login/registration issues (field service does not know the admin pwd of the FG), but it still does not put the FG in the "right" ADOM.
Any ideas would be most welcome.
-JR
