Is it generally best practice to separate firewalls into ADOMs within FAZ?
I've been doing some research but have been getting mixed results. In FMG, it makes sense to separate firewalls by firmware version or by client; however, within FAZ, is there any downside of having a single ADOM for all firewalls? It would make global reporting possible (ie. quickly running a report to determine all firewall firmware versions). As far as I'm aware, reports could still be narrowed down to select firewalls.
I've also heard that licensing for FAZ may shift to include an ADOM-limit on top of the daily log rate. This has me a bit concerned because I have quite a few ADOMs per clients with only one or two firewalls each.
FAZ ADOMs are different from FMG ADOMs, for FAZ you can put all FGTs in a single ADOM, even if they have different versions, other ADOM must be created if you have other device types, e.g.: FML, FCT, ... etc
Useful only in a multi-tenant scenario IMHO.
When you need to isolate FAZ access to diferent customers, ADOMs helps you.
regards
/ Abel
Hey kinporsch,
as AEK and abelio mentioned, FortiAnalyzer ADOMs are only really relevant for the following scenarios:
- different Fortinet products
-> you would have different ADOMs for FortiGate, FortiMail, FortiAuthenticator, etc
- multi-tenancy
-> if you offer a FortiAnalyzer to multiple of your own customers, you can use ADOMs to separate your customers from each other and ensure they only have access to their own ADOM and logs, and not to devices/logs/reports from other customers
In addition, if you have very large environments, ADOMs can help with organizining.
For example, if you have several thousand FortiGates scattered around the globe you might want to bundle them in ADOMs geographically to maintain some kind of organization; at some point reports spanning that many FortiGates would become very difficult to read.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.