I've read a lot about the scripting/API functionality of the FMG, and am hoping someone has some ideas how to accomplish the following.
Our FMGs will be distributed globally in Azure DCs. Users will be assigned privileges to access specific FMGs and ADOMs based on their AD group membership. What I would like to be able to do, is sort/assign FG registrations based on the hostname of the FG itself.
What I would like to be able to do, is sort/assign FG registration based on the hostname of the FG itself. We have established a standard naming convention for our FGs in the field, with the 2 character ISO country code as the last characters in the FG's hostname. When an FG sends a registration request, I would like the request to automatically be placed in the proper ADOM (not the root ADOM) so that the admin for that country can then accept the registration and get the FG properly added to the regional FMG. We will potentially have 100+ registrations per month, and it does not make sense for our local team (basically me) to manually assign these FGs to the proper ADOM.
Pre-registration of the S/N would be a possibility, but this just adds more overhead to already overworked field service personnel. Using a pre-shared key based on the model can resolve some of the subsequent login/registration issues (field service does not know the admin pwd of the FG), but it still does not put the FG in the "right" ADOM.
Any ideas would be most welcome.
-JR
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I find it hard to believe that this is a such a unique issue that no one has yet to address it.
Sounds like an interesting idea. This feature to auto-register new devices according to their hostname is not available. Best to speak to your Fortinet sales team or Fortinet partner about the possibility of implementing this feature.
As for pre-registration of devices, it is possible to Export a current device list & then edit it for reimporting. Unfortunately, the format is not very friendly for offline editing. It is exported as a *.dat. You can rename it to *.tgz & then unpack it to a *.json file.
I'm sure the JSON API could be used to pre-register devices if you wish to do this in a batch mode. The exported device list should provide clues as to how to do this.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.