Fortinet white logo
Fortinet white logo

Management

Management

In Management, you can remotely manage FortiGate and FortiWiFi devices that are connected to the FortiGate Cloud service.

To access Management for a device, select the desired device in Assets, then go to Device View.

Note

When you run a function in FortiGate Cloud that applies to FortiGates, such as running a script, FortiGate Cloud does not pass the actual username of the user who performed the action to FortiOS:

For remotely accessing a FortiGate from FortiGate Cloud, FortiGate Cloud passes the username of the FortiGate Cloud user who performed the action as a randomized @fortigatecloud.com email address, such as 4aa567e55bc8@fortigatecloud.com, to FortiOS.

For other management features that a user can perform from FortiGate Cloud, such as running a script, FortiGate Cloud passes the username of the FortiGate Cloud user who performed the action as FortiGateCloud to FortiOS.

Therefore, when viewing logs on the affected FortiGate, you may see 4aa567e55bc8@fortigatecloud.com or FortiGateCloud as a username. For managed security service provider customers, this provides enhanced security by preventing subusers from seeing the primary account email address in the FortiGate logs.

Remote access

For the following FortiOS versions, remote access with full permission (read and write) requires a registered FortiGate Cloud Service subscription on the FortiGate:

  • 7.6.0 and later versions
  • 7.4.2 and later versions
  • 7.2.8 and later versions
  • 7.0.14 and later versions

You can use remote access in combination with configuration save mode for device configuration. See Using configuration save mode. This feature is available for FortiOS 7.0 and later versions.

To remotely access a device:

Remote access is only available for a device that has management enabled and the management tunnel is up.

  1. Go to Assets.
  2. Select the desired device, then click Remote Access.
  3. Click OK.
  4. A login page pops up for the user to enter the local username and password. A user with a prof_admin profile is allowed to remotely access a virtual domain (VDOM)-enabled device only if the user profile has access to the management VDOM.

You must first enable the management tunnel on your device before you can see any management functions. On the device, run the following CLI commands:

config system central-management

set mode backup

set type fortiguard

end

Management

Management

In Management, you can remotely manage FortiGate and FortiWiFi devices that are connected to the FortiGate Cloud service.

To access Management for a device, select the desired device in Assets, then go to Device View.

Note

When you run a function in FortiGate Cloud that applies to FortiGates, such as running a script, FortiGate Cloud does not pass the actual username of the user who performed the action to FortiOS:

For remotely accessing a FortiGate from FortiGate Cloud, FortiGate Cloud passes the username of the FortiGate Cloud user who performed the action as a randomized @fortigatecloud.com email address, such as 4aa567e55bc8@fortigatecloud.com, to FortiOS.

For other management features that a user can perform from FortiGate Cloud, such as running a script, FortiGate Cloud passes the username of the FortiGate Cloud user who performed the action as FortiGateCloud to FortiOS.

Therefore, when viewing logs on the affected FortiGate, you may see 4aa567e55bc8@fortigatecloud.com or FortiGateCloud as a username. For managed security service provider customers, this provides enhanced security by preventing subusers from seeing the primary account email address in the FortiGate logs.

Remote access

For the following FortiOS versions, remote access with full permission (read and write) requires a registered FortiGate Cloud Service subscription on the FortiGate:

  • 7.6.0 and later versions
  • 7.4.2 and later versions
  • 7.2.8 and later versions
  • 7.0.14 and later versions

You can use remote access in combination with configuration save mode for device configuration. See Using configuration save mode. This feature is available for FortiOS 7.0 and later versions.

To remotely access a device:

Remote access is only available for a device that has management enabled and the management tunnel is up.

  1. Go to Assets.
  2. Select the desired device, then click Remote Access.
  3. Click OK.
  4. A login page pops up for the user to enter the local username and password. A user with a prof_admin profile is allowed to remotely access a virtual domain (VDOM)-enabled device only if the user profile has access to the management VDOM.

You must first enable the management tunnel on your device before you can see any management functions. On the device, run the following CLI commands:

config system central-management

set mode backup

set type fortiguard

end