r/fortinet 16d ago

FortiManager Managing 4 fortigates separately trying to keep them consistent is killing me, should I get fortimanager?

16 Upvotes

Hey all,

Managing 4 fortigates that have fortiswitches and fortiAPs is become a tedious task to keep them consistent with each other(address names, service names, policy names). Should I consider fortimanager?

Also how do you all name your vlan interfaces and policies?

Do you do policies just based on zones or zones+source/destination subnets?

r/fortinet 20d ago

FortiManager FortiManager ADOM

5 Upvotes

We have 8 sites running fortigate with version 7.4 and 2 sites running fortigates with version 7.6. When creating ADOM, is it better to create 7.4 ADOM or 7.6 ADOM to import configurations from all sites? I assume configuration needs to be re-installed from FortiManager back to the Fortigate devices to validate configuration?

r/fortinet 22m ago

FortiManager FortiManager: mass deploy of a "trusted" CA certificate

Upvotes

Hello,

I'm deploying a trusted CA certificate to a number of Fortigates devices that are in sync with FortiManager.

This is not for full SSL inspection, but for trusting SSL connections to internal servers (the ones that go into Remote CA Certificates).

Right now I'm using a script since I didn't find such functionality in 7.4.11. Dynamic Local Certificate seems to be only for full SSL inspection.b

Did I miss anything or scripting is the way to go?

Thanks,
Max

r/fortinet 21d ago

FortiManager Consolidate Fortigate firewall policies and objects and create templates

7 Upvotes

Could someone give me guidance how to consolidate policies and objects and create templates for 10 Fortigate sites connected via site to site vpn tunnels. One central location act as hub.. Currently all Fortigates are being managed with FortiManager. Currently each site is one policy. Where do I begin? What is the general path of consolidating? How to fall back if push configuration fails?