Adding a FortiGate CNF instance to FortiManager
FortiManager can be used to install and monitor security features on FortiGate CNF instances.
|
|
FortiManager 7.2.2 or later is required. |
To add a FortiGate CNF instance to FortiManager:
-
In FortiGate CNF, in the Display Primary FortiGate Information field in the Edit CNF form, find the FortiGate connection details.
-
In FortiManager, go to Device & Groups > Add Device.
-
Click Discover Device.
-
Enter the IP Address of the FortiGate CNF instance.
-
Enable Use Legacy Device Login and enter the User Name and Password, then click Next.
-
Update or enter any required details and click Next.
-
Click Finish. The FortiGate CNF instance is added to FortiManager. There may be a short delay before the device is available.
-
Import the FG-traffic policy packagefrom the FortiGate CNF instance into FortiManager.
Use either Import each VDOM step by step or Automatically import one VDOM at a time to import FG-traffic. You do not need to import root.
Use this policy package in FortiManager to install policies to the FortiGate CNF instance.
|
|
FortiGate CNF clusters are treated differently than the normal FortiGate auto-scale cluster on AWS. Hover over the information icon next to the cluster name to see more information about the cluster.
|
Management restrictions
FortiGate CNF is a Fortinet-managed service and there are limited configurations that are permitted from FortiManager.
The following management operations are restricted:
-
VDOM creation not permitted and the option is greyed out.
-
Changes in CLI configuration are not permitted and if tried there is an error.
-
Changes to networking components of the FortiGate are restricted and if tried there is an error.
-
CLI access to the FortiGate CNF instance is not allowed from FortiManager.
-
FortiGate CNF only supports profile-based NGFW mode policy packages.
While FortiManager allows the selection of policy-based NGFW mode, this setting causes policy installation to fail.
|
|
In FortiManager, in Device Manager, the imported FortiGate CNF may display a message "Firmware Upgrade License Not Found". You may safely ignore this message. |
For more information about adding devices to FortiManager, see Adding online devices using Discover mode in the FortiManager Administration Guide.