FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
haziqsulaiman
Article Id 360422
Description This article describes how an address object can be created for FortiManager Cloud in FortiGate.
Scope

FortiGate, FortiManager Cloud.

Solution

Sometimes, it may be necessary to create an address object for FortiManager Cloud to be used in policies.

 

An address object for FortiManager Cloud can be created by going to the FortiGate -> Policy & Objects -> Addresses -> Create New -> Address and configuring the address as follows:
Address Type: FQDN.

FQDN: fortimanager.forticloud.com.

 

The following image shows an example of an address object for FortiManager Cloud in FortiGate that should be able to resolve to the correct IP.

 

addressobject.png

 

The Address object can then be referenced, to a firewall policy. For example, a firewall policy can be created in FortiGate by going to Policy & Objects -> Firewall Policy -> Create New, and the address object for FortiManager Cloud created previously can be referenced in the Source/Destination field as shown in the Firewall Policy configuration below.

 

policy.png

 

FortiGate can resolve this FQDN, as seen from the output of the command below:

 

iprope1.png

 

If FortiGate is unable to resolve the FQDN object, this is likely due to the DNS server being unable to resolve the FQDN. Make sure to use a DNS server that can resolve fortimanager.forticloud.com in FortiGate -> Network -> DNS.

 

Related article:

Technical Tip: Iprope policies group