Hello, everyone.
We've different sites with Fortigate 100F in HA. The different sites are connected via VPN, so they are visible to each other.
We're testing the evaluation version of Fortimanager to evaluate its functionalities.
Specifically, we would like to know if it is possible that, with a specific vDOM existing on both remote sites, Fortimanager is capable of replicating any new policy bidirectionally. In this way, the rules of that vDOM would be the same regardless of the site.
What we're looking for with this is that in the event of a catastrophe on one of the sites, it is easy to redirect traffic to the other site, with all the rules and policies that were needed on the downed site already existing.
We aren't clear if Fortimanager is capable of carrying out this requirement and if not, how could we carry it out? Through API?
Thanks in advance for the suggestions. All the best
Hello paulagonzalez,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello paulagonzalez,
We are still trying to get you an answer or help. We'll get back to you with someone who has an answer to your query.
Kind regards,
Hi,
From my experience, you can use FortiManager and create a single Policy Package that can be applied to both clusters in both sites under Installation Target ( preferably using a separate ADOM just for these devices/clusters ).
Using dynamic objects with Per device mapping and Normalized Interfaces, should accomplish this.
User | Count |
---|---|
1922 | |
1144 | |
769 | |
447 | |
277 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.