Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kinporsch
New Contributor

FortiAnalyzer ADOMs Question

Is it generally best practice to separate firewalls into ADOMs within FAZ?

I've been doing some research but have been getting mixed results. In FMG, it makes sense to separate firewalls by firmware version or by client; however, within FAZ, is there any downside of having a single ADOM for all firewalls? It would make global reporting possible (ie. quickly running a report to determine all firewall firmware versions). As far as I'm aware, reports could still be narrowed down to select firewalls.

I've also heard that licensing for FAZ may shift to include an ADOM-limit on top of the daily log rate. This has me a bit concerned because I have quite a few ADOMs per clients with only one or two firewalls each.

router login 192.168.l.l
3 REPLIES 3
AEK
Honored Contributor II

FAZ ADOMs are different from FMG ADOMs, for FAZ you can put all FGTs in a single ADOM, even if they have different versions, other ADOM must be created if you have other device types, e.g.: FML, FCT, ... etc

AEK
AEK
abelio
Valued Contributor

Useful only in a multi-tenant scenario IMHO.

When you need to isolate FAZ access to diferent customers, ADOMs helps you.

 

regards




/ Abel

regards / Abel
Debbie_FTNT
Staff
Staff

Hey kinporsch,

as AEK and abelio mentioned, FortiAnalyzer ADOMs are only really relevant for the following scenarios:

- different Fortinet products

-> you would have different ADOMs for FortiGate, FortiMail, FortiAuthenticator, etc

- multi-tenancy

-> if you offer a FortiAnalyzer to multiple of your own customers, you can use ADOMs to separate your customers from each other and ensure they only have access to their own ADOM and logs, and not to devices/logs/reports from other customers

 

In addition, if you have very large environments, ADOMs can help with organizining.

For example, if you have several thousand FortiGates scattered around the globe you might want to bundle them in ADOMs geographically to maintain some kind of organization; at some point reports spanning that many FortiGates would become very difficult to read.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Labels
Top Kudoed Authors