Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ccie_rothstein
New Contributor

FortiManager - Assign FG to ADOM based on hostname

I've read a lot about the scripting/API functionality of the FMG, and am hoping someone has some ideas how to accomplish the following.

 

Our FMGs will be distributed globally in Azure DCs. Users will be assigned privileges to access specific FMGs and ADOMs based on their AD group membership. What I would like to be able to do, is sort/assign FG registrations based on the hostname of the FG itself.

 

What I would like to be able to do, is sort/assign FG registration based on the hostname of the FG itself. We have established a standard naming convention for our FGs in the field, with the 2 character ISO country code as the last characters in the FG's hostname.  When an FG sends a registration request, I would like the request to automatically be placed in the proper ADOM (not the root ADOM) so that the admin for that country can then accept the registration and get the FG properly added to the regional FMG. We will potentially have 100+ registrations per month, and it does not make sense for our local team (basically me) to manually assign these FGs to the proper ADOM.

 

Pre-registration of the S/N would be a possibility, but this just adds more overhead to already overworked field service personnel. Using a pre-shared key based on the model can resolve some of the subsequent login/registration issues (field service does not know the admin pwd of the FG), but it still does not put the FG in the "right" ADOM.

 

Any ideas would be most welcome.

 

-JR

 

 

2 REPLIES 2
ccie_rothstein
New Contributor

I find it hard to believe that this is a such a unique issue that no one has yet to address it.

chall_FTNT

Sounds like an interesting idea.  This feature to auto-register new devices according to their hostname is not available.  Best to speak to your Fortinet sales team or Fortinet partner about the possibility of implementing this feature.

 

As for pre-registration of devices, it is possible to Export a current device list & then edit it for reimporting.  Unfortunately, the format is not very friendly for offline editing.  It is exported as a *.dat.  You can rename it to *.tgz & then unpack it to a *.json file.

 

I'm sure the JSON API could be used to pre-register devices if you wish to do this in a batch mode.  The exported device list should provide clues as to how to do this.

Chris Hall
Fortinet Technical Support
Labels
Top Kudoed Authors