Customer Service
Customer Service Information and Announcements
Vbharath_FTNT
Article Id 342534
Description This article describes how to add a FortiSASE instance to FortiManager for central management.
Scope FortiManager 7.4.4 or later & FortiSASE 24.3.42 or later.
Solution

FortiManager supports managing a FortiSASE instance from version 7.4.4 or later.

 

Before adding FortiSASE to FortiManager, the following prerequisites must be met.

 

  • The FortiManager and FortiSASE instances must be registered to the same FortiCare account.
  • Central Management must be enabled on FortiSASE.

 

The Central Management Feature on FortiSASE is not enabled by default. This feature is part of select availability features.

To enable Central Management on a FortiSASE instance, create a ticket with Fortinet Support.

 

Once the Central Management feature is enabled by Fortinet Support, it must be enabled manually in the FortiSASE GUI.
Log in to the FortiSASE GUI -> System -> Central Management -> Select 'Enable' and select Apply.

 sase-setting-centralmanagement.jpg

 

Note: Once Central Management is enabled and the FortiSASE instance is enabled, the administrator will receive a pop-up message in the GUI notifying that the configuration objects will be read-only and must be modified using FortiManager.

 

  • Central Management of FortiSASE supports only a one-way configuration sync from FortiManager to FortiSASE.
  • A maximum of 3000 objects can be synchronized at once from FortiManager.
 

sase-fmg-pop-up.jpg

 

Adding the FortiSASE instance on FortiManager.

 

Once Central Management is enabled on the FortiSASE instance, the Administrator will receive a notification in the FortiManager GUI.

 

sase-license-notification.png

 

Enable the FortiSASE connector under GUI -> Fabric View -> Fabric Connectors -> FortiSASE Connector.

 

Select the button 'Connector to FortiSASE' to enable the Connector.

 

sase-connector.png

 

Select an object to be installed to the FortiSASE instance and select the OK button. Select OK to save the configuration.

 

connector-config-2.png

 

The GUI will display the connection status. If there are no errors, the progress will take a few seconds to complete.

If the connection fails, verify the DNS settings on the FortiManager and also make sure the FortiManager has Internet access (HTTPS).

 

Once the configuration is complete, go back to the FortiSASE GUI to verify the instance is managed by FortiManager.

 

SASE_Central-management.png

 

From the FortiManager GUI, use the install wizard to install the device settings (only) to push object / configuration changes.

 

Useful links:

Central management - FortiSASE administration guide

Adding FortiSASE - administration guide