Description |
This article describes how to register a FortiGate to a FortiManager from CLI. |
Scope | FortiGate, FortiManager. |
Solution |
Start by setting up configuration on the FortiGate with the following commands:
config system central-management
The FortiGate will then be visible in the FortiManager in the Root ADOM under the Unauthorized Devices:
It is now possible to authorize the unit on the FortiManager.
From version 6.0, by default, the FortiManager will use the default admin/<blank password> to contact the FortiGate. Therefore, if the FortiGate admin password is not blank, the FortiManager will be unable to authorize the device and authorization will fail.
These 2 possibilities to work around this issue:
execute batch start
config system central-management set serial-number "FMG_SN" end
Once one of the workarounds has been applied, it will be possible to authorize the FortiGate from the FortiManager GUI.
Alternatively, it is possible to configure the FortiManager to accept automatically registration requests from the FortiGate.
On the FortiManager:
config system admin setting end
On the FortiGate:
config system central-management
exe central-mgmt register-device <- FortiManager serial number, password on the FortiManager.
Note: If the FortiManager is connected to the FortiGate over the IPsec tunnel source IP address needs to configure under FortiGate central-management.
config system central-management
The FortiGate will then be automatically registered on the FortiManager. If ADOM is enabled, it will be added to the root ADOM.
4. Use this command to check the connection and registration status on the FortiGate:
diag fdsm central-mgmt status
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.