Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Steven_Lengua
New Contributor

FortiManager or FortiAnalyzer

Would like to get one of these products. Not sure about the Manager since I really don' t care too much about centralized management. Anyone have any opinions one way of the other?

CAlengua

CAlengua
5 REPLIES 5
Dave_Hall
Honored Contributor

A local dealer could assist you in determining between the two, based on your company' s needs. For us, we have both devices -- We mainly use the FortiManager for backing up configs, tracking changes in configs, pushing down firmwares, " SSH' into devices that are behind double-NAT -- not so much " centralized management" (due to so many different client Fortigates using custom configs). Our company uses the FortiAnalyzer as a logging device. Depending on your company' s needs, this question may actually be moot -- on 5.0.x the FortiManager takes some of the features of a FortiAnalyzer, so you may just get by with using that instead of a full-blown FortiAnalyzer. -- which is why I suggest consulting with a local dealer on this.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Istvan_Takacs_FTNT

My 2c for the topic is that FM sometimes can be frustrating to use, especially if you got used to the FGT interface and you don' t have that many firewalls that would justify both the investment and the extra effort to learn it. If you are however managing a large FGT deployment than FM can be a Godsend that can make your life easier. You can use it to automate provisioning, reporting, patch management, centralized multitenant-control and many other tasks that would be a pain to implement in pure FGT environment. You can also live without FAZ if you have some 3rd party SIEM to receive logs and generate your custom reports. FAZ has its built-in, specialised reports though for FGT and using some features that even though could be extracted via a 3rd party tool, only with much more effort. So it' s all up not to your personal preference, but the size of the environment you have to manage, I guess.
Matthew_Mollenhauer
New Contributor III

We have a FAZ 2000B, FMG VM and IBM' s Qradar SIEM, but we are logging to the FMG. But between the FAZ & SIEM, the FAZ wins hands down from the point of view that it is updated on a regular basis to support the latest Fortinet logging formats, while we' ve had a problematic time getting IBM to update their DSM' s to support the Fortigates (the 5.2 upgrade killed most of our reporting). Having said that most 3rd party siem solutions generally support more types of devices and allow you to report on more events. My best advice, download the VM packages and use them for the trial period, they are limited in their licenses but you' ll get a better idea of what you' ll get. And as Dave said, a local dealer is also a good place to start. Regards, Matthew
Holy

Go for a VM Basic FortiManager with 10 Devices and Adoms (30 Days Free Test includive) it should give you enough time to deside whether or not use the FortiManager. and btw. the FortiAnalyzer is included you must just Enable it ont the FortiManager VM. @Matthew how long do you have Qradar as SIEM solution? are you happy with Qradar? what did u use before Qradar?

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Matthew_Mollenhauer
New Contributor III

how long do you have Qradar as SIEM solution? are you happy with Qradar? what did u use before Qradar?
We purchased the Qradar Appliances just before Q1 Labs was bought out by IBM, so 18-24 months. It is a good product and has a lot of log source DSM' s and many pre-canned Offense triggers. It' s correlation engine is good and custom offenses are somewhat easy to configure (Basically if you can describe the offense in a sentence or two you can write it) Overall we are happy with it, but it does require some tuning and unfortunately we don' t any dedicated security staff to " own" the system. So it' s not as good as it could be for us. But from a purely Fortigate log point of view the FAZ (or FMG) would win hands down, simply because it can correctly interpret the logs. Prior to getting Qradar we didn' t have a SIEM as such, we had syslog servers to receive, store and backup the logs but nothing that could do correlation. The closest we had was our 2000B FAZ. Regards, Matthew
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors