Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
johnlloyd_13
Contributor

FortiManager

hi,

we've got fortimanager in our production environment.

i'm trying to learn more about this product.

just a question, i can still configure settings on individual FG, i.e. L3 interface IP, L2 link aggregate, static routes, routing protocols, etc EXCEPT for FW policy and address object?

how about configuring IPSec VPN?

appreciate if someone can confirm my understanding is correct?

 

Thanks,
John
Thanks,John
3 REPLIES 3
Toshi_Esumi
Esteemed Contributor III

In an extreme example, if your want, you can register devices, FGTs, to FMG only to upgrade the firmware (requires a support on each FGT) from the FMG and backing up the config history while all configuration is done at the devices directly.

Then you can add "Policy & Object" management with policy packages, which are combination of one of policy sets and entire objects per ADOM. So that you can modify/add new policies at the policy set on FMG, then push the updates to all FGTs that use the same policy set.

You can add VPN Management (VPN Manager) for centralized management if you want to see/manage all VPNs on all managed FGT at one place. But I heard that would add some complication when you want to change something at one particular VPN, so I haven't used it yet. Someone else can chime in about VPN Manager.

But if you change your mind and want to regulate some common device config like DNS settings, interface allowaccesses, IP address/subnet, and so on, for multiple FGTs in one ADOM, I would recommend using "templates" to standardize those config items across the board, then you can see the config "sync" status. But of course optional.

Toshi

vraev
Staff
Staff

Hi @johnlloyd_13 ,

 

Regarding the VPN Manager it has its limitation.
The configuration is per ADOM, if you move a device in other ADOM you will need to recreate its configuration by the same way as it was manually. 
When you are using the VPN manager it is not a good practice to made changes directly on the FGT's.
The following articles will give you some examples:

https://community.fortinet.com/t5/FortiManager/Technical-Tip-Certificate-based-in-VPN-using-FortiMan...
https://docs.fortinet.com/document/fortimanager/7.4.2/administration-guide/49512/creating-external-g...
https://docs.fortinet.com/document/fortimanager/7.4.2/administration-guide/196461/creating-managed-g...
https://community.fortinet.com/t5/FortiManager/Technical-Note-How-to-create-a-Full-Mesh-IPsec-VPN-wi...
https://community.fortinet.com/t5/FortiManager/Technical-Note-How-to-configure-IPsec-VPN-in-FortiMan...
https://community.fortinet.com/t5/FortiManager/Technical-Note-Creating-new-Tunnel-Mode-IPsec-VPN-in/...


https://community.fortinet.com/t5/FortiManager/Technical-Tip-How-to-use-the-VPN-manager-default-zone...
https://docs.fortinet.com/document/fortimanager/7.2.2/administration-guide/762947/managing-vpn-gatew...

About the other questions:


https://docs.fortinet.com/document/fortimanager/7.2.2/administration-guide/962634/adoms
https://docs.fortinet.com/document/fortimanager/7.2.2/administration-guide/135259/adoms-and-devices
https://docs.fortinet.com/document/fortimanager/7.4.1/administration-guide/871900/viewing-configurat...
https://docs.fortinet.com/document/fortimanager/7.4.1/administration-guide/54616/adom-revisions

https://community.fortinet.com/t5/FortiManager/Technical-Tip-Configuration-import-from-the-device-to...

https://community.fortinet.com/t5/FortiManager/Troubleshooting-Tip-FortiGate-is-Out-of-sync-in-the-D...
https://community.fortinet.com/t5/FortiManager/Techincal-Tip-How-to-fix-synchronization-issue-in-For...
https://community.fortinet.com/t5/FortiManager/Technical-Tip-How-to-manually-upload-FortiGate-config...


Best,

V.R.
BradenSchoen

Thanks for those links, you made my day.

Labels
Top Kudoed Authors