Fortinet white logo
Fortinet white logo

Administration Guide

Enabling management of VM devices

Enabling management of VM devices

By default, VM serial numbers are not recognized when adding devices to FortiManager. This applies to:

  • FortiGate-VM

  • FortiCarrier-VM

  • FortiProxy-VM

  • FortiFirewall-VM

  • FortiAnalyzer-VM

This measure increases security of the FortiManager system by ensuring that VM devices can only be added to FortiManager when recognition of VM serial numbers has been enabled by an administrator.

If you attempt to add a VM device (for example, a model FortiGate-VM) to FortiManager while the fgfm-allow-vm command is disabled, a notice will appear informing you that adding VM devices is currently disabled and present you with an option to enable adding VM devices.

When upgrading from an earlier version of FortiManager that does not enforce this behavior, VM devices already managed by FortiManager will continue to be supported without interruption, but you must enable the fgfm-allow-vm command before you can add any additional VM devices.

To add a VM device to FortiManager in the CLI:
  1. In the FortiManager CLI, enable recognition of VM serial numbers:

    config sys global
        set fgfm-allow-vm enable
    end
  2. Proceed with adding the VM device through one of the supported methods. See Add devices.

Enabling management of VM devices

Enabling management of VM devices

By default, VM serial numbers are not recognized when adding devices to FortiManager. This applies to:

  • FortiGate-VM

  • FortiCarrier-VM

  • FortiProxy-VM

  • FortiFirewall-VM

  • FortiAnalyzer-VM

This measure increases security of the FortiManager system by ensuring that VM devices can only be added to FortiManager when recognition of VM serial numbers has been enabled by an administrator.

If you attempt to add a VM device (for example, a model FortiGate-VM) to FortiManager while the fgfm-allow-vm command is disabled, a notice will appear informing you that adding VM devices is currently disabled and present you with an option to enable adding VM devices.

When upgrading from an earlier version of FortiManager that does not enforce this behavior, VM devices already managed by FortiManager will continue to be supported without interruption, but you must enable the fgfm-allow-vm command before you can add any additional VM devices.

To add a VM device to FortiManager in the CLI:
  1. In the FortiManager CLI, enable recognition of VM serial numbers:

    config sys global
        set fgfm-allow-vm enable
    end
  2. Proceed with adding the VM device through one of the supported methods. See Add devices.