Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Pham_Phu_Cuong
New Contributor

Question about Administrative Domain (ADOM)

Hello everybody,

 

I'm working with FAZ VM64 ver 5.2.3. I have Fortigates with different versions connected to it (4.3, 5.0, 5.2). When creating ADOM, there is a selection for the version of the Fortigate (4.3/5.0/5.2). I'm wondering if there is any affect of that selection if I want to group different version of Fortigates into one ADOM.

 

To put it in another way, should you create separate ADOM for different versions of Fortigate. If not, what would be the consequences of putting different versions of FGT into one ADOM.

 

I tried digging around for the answer but cannot find anything.

 

Do you have any ideas or experiences on this?

 

Thanks,

Pham Phu Cuong

4 REPLIES 4
Pham_Phu_Cuong
New Contributor

Has anyone ever wondering about this?

 

In case you ask why I would think about this, here is the big picture.

I have several users (restricted_user admins) that I’d like to create 1 ADOM for each user (just to simplify the process), hence the need for grouping different versions of FGT into one ADOM.

I understand the right version for ADOM would be prefered. If I have only one FGT I wouldn’t think of choosing different version for the ADOM. What I was trying to figure out is what kind of issues would come up in order to convince other users to deal with multiple ADOMs.

 

Thanks,

Cuong

MikePruett

Pham,

 

I added another reply to your question on the comments but wanted to reply here as well. You can assign it however you want and it will work fine. 

 

You can organize these devices by:

• Firmware version: group all devices with the same firmware version into an ADOM.

• Geographic regions: group all devices for a specific geographic region into an ADOM, and devices for a different region into another ADOM.

• Administrative users: group devices into separate ADOMs based for specific administrators responsible for the group of devices.

• Customers: group all devices for one customer into an ADOM, and devices for another customer into another ADOM.

 

Hope this helps!

Mike Pruett Fortinet GURU | Fortinet Training Videos
Pham_Phu_Cuong

Hi Mike,

Thanks for the reply.

"Geographic regions" is what I'm trying to achieve here. In one particular region, they have multiple Fortigates with different firmware version.

MikePruett

Shouldn't be an issue. If you experience any though let us know and we will help as best we can!

Mike Pruett Fortinet GURU | Fortinet Training Videos
Labels
Top Kudoed Authors