Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jrobetoy
New Contributor

FortiManager: Safe to enable the ADOM feature in production?

Good Morning,

 

I am learning and putting a plan together to create and apply global policies, and understand i will need to use ADOMs to do that, and they are disabled by default. Our FortiManager (7.4.1) is currently managing all of our production Fortigates. When i make the change, will the production Fortigates be affected at all?

 

Thanks,

Jesse

 

 

 

https://docs.fortinet.com/document/fortimanager/7.4.1/administration-guide/208717/enabling-and-disab...

 

By default, ADOMs are disabled. Enabling and configuring ADOMs can only be done by super user administrators.

When ADOMs are enabled, the Device Manager, Policy & Objects, AP Manager, and VPN Manager panes are displayed per ADOM. If FortiAnalyzer features are enabled, the FortiView, Log View, Incidents & Events, and Reports panes are also displayed per ADOM. You select the ADOM you need to work in when you log into the FortiManager unit. Switching between ADOMs.

To enable the ADOM feature:
Log in to the FortiManager as a super user administrator.
Go to Dashboard.
In the System Information widget, toggle the Administrative Domain switch to ON.
You will be automatically logged out of the FortiManager and returned to the log in screen.

 

 

 

 

3 REPLIES 3
AEK
SuperUser
SuperUser

Hello Jesse

As per my experience with FMG, it never changes anything on your FGT unless you push a configuration.

Enabling ADOMs will not push anything to your FGT.

 

Edit: take a backup before enabling ADOMs, just in case.

AEK
AEK
vraev
Staff
Staff

Hi @jrobetoy ,

 

After the ADOM is enabled the current users will be logged out and then they can login again.

So its good to make it before or after the working hours.

 

Note: Although this activity itself does not delete any logs from the device, we always recommend to keep a regular backup of the logs/reports/configuration before proceeding with any such activities.
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-Backup-and-restore-of-FortiAnalyzer-se...

V.R.
asrour
Staff
Staff

Hello @jrobetoy 

you can download a trial FMG vm and a FGT vm images from the support portal.

FMG will allow you to add 3 devices.

you can do your testing there before applying to prod FMG 

A Srour
Labels
Top Kudoed Authors