Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xkalib3r
New Contributor III

Fortimanager Policy and Device Settings Deployment Question

Hi All

 

We have just started using a Fortimanager (5.2.3) at a client with multiple branches. While I am very familiar with the Fortigates, the Fortimanager is still relatively new to me. That said, I have two main questions:

 

1. I have successfully deployed a policy package to multiple devices which is great - The problem I have is, what if I need to add a few device specific policies? For example, Fortigate A on subnet 192.168.1.0/24 has a device 192.168.1.10 which needs full outbound access. Fortigate B on subnet 192.168.2.0/24 has a device 192.168.2.10 which needs access to port 21 only. 

 

It would seem a bit silly to add both of the required policies to the general branches policy when they will only have an effect on the relevant Fortigate. So my question here is what is the best way to handle this type of situation?

 

2. There are several device settings that are also common to all branches. FSSO servers and groups for example. This question is two part:

 

2.1 Is there an easy way to clone settings from one device to another?

2.2 Besides using scripts, is there an easier way to deploy device settings?

 

Regards

 

 

FCNSA

FCNSP

FCWS

NSE5

NSE7

FCNSA FCNSP FCWS NSE5 NSE7
1 REPLY 1
scao_FTNT
Staff
Staff

for 1, in policy package, policy column settings, you can enable install on column, which can let you choose which device (from package installation target device list) only for which policy

 

 

for 2, depends on which device config, we have template support (in device manager) for some device config, like system template, wifi template etc

 

but for your mentioned FSSO server config (config user fsso) , it is in per device level and no shared db support, in 5.4, FMG may have design changed and move this config as shared db config (policy object config) similar as LDAP server

 

so for now in 5.2, you may need to use script, to copy this device db config to other devices, you can create a script and run for multiple devices at one time

 

Thanks

 

Simon

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors