FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
heng
Staff
Staff
Article Id 268542
Description

This article describes the FortiManager closed network setup that supports the merging of entitlement file from multiple Account IDs.

It is supported in version 7.0.7 GA and later, 7.2.2 GA and later, 7.4.0 GA and later.

 

This feature is particularly useful for a FortiManager that is being set up as a closed network that used to manage different customer account IDs, namely a Managed Security Service Provider (MSSP) environment or a different IT/Network department within a same organization like ISP. 

Scope FortiManager version 7.0.7 GA and later, 7.2.2 GA and later, 7.4.0 GA and later.
Solution

Steps:

  1. Under the module of FortiGuard -> Settings, make sure that Enable Communication with FortiGuard Server is disabled.

 

image.png

 

     2. Under the FortiGuard -> Settings -> Service License -> Upload, it is possible to upload the latest entitlement file by getting it from Fortinet Customer Service or download it manually by enabling the entitlement file download feature in the support portal.

 

See related KB article to enable it:

Technical Tip: How to enable the Entitlement File Download feature in Support Portal

 

image.png

 

     3. Re-download the latest entitlement file every time and re-upload it if there is a new registered device under the same Account ID or a different Account ID to reflect the new device contract information.

 

     4. It is possible to upload the entitlement file from different Account IDs and the contract information will be merged and consolidated as one.

 

     5. For each time the entitlement file is re-uploaded, it is possible to run the CLI command diagnose fmupdate fds-dump subs in the FortiManager to verify the content of the contract information.  

Contributors