Hi All
We have just started using a Fortimanager (5.2.3) at a client with multiple branches. While I am very familiar with the Fortigates, the Fortimanager is still relatively new to me. That said, I have two main questions:
1. I have successfully deployed a policy package to multiple devices which is great - The problem I have is, what if I need to add a few device specific policies? For example, Fortigate A on subnet 192.168.1.0/24 has a device 192.168.1.10 which needs full outbound access. Fortigate B on subnet 192.168.2.0/24 has a device 192.168.2.10 which needs access to port 21 only.
It would seem a bit silly to add both of the required policies to the general branches policy when they will only have an effect on the relevant Fortigate. So my question here is what is the best way to handle this type of situation?
2. There are several device settings that are also common to all branches. FSSO servers and groups for example. This question is two part:
2.1 Is there an easy way to clone settings from one device to another?
2.2 Besides using scripts, is there an easier way to deploy device settings?
Regards
FCNSA
FCNSP
FCWS
NSE5
NSE7
for 1, in policy package, policy column settings, you can enable install on column, which can let you choose which device (from package installation target device list) only for which policy
for 2, depends on which device config, we have template support (in device manager) for some device config, like system template, wifi template etc
but for your mentioned FSSO server config (config user fsso) , it is in per device level and no shared db support, in 5.4, FMG may have design changed and move this config as shared db config (policy object config) similar as LDAP server
so for now in 5.2, you may need to use script, to copy this device db config to other devices, you can create a script and run for multiple devices at one time
Thanks
Simon
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.