Short answer
In FirstNet's Fortinet service, FortiManager sets up your devices and FortiAnalyzer analyses what they see. With FirstNet running both, devices register once, logs flow automatically, and you can match FortiAnalyzer reports to FortiManager policy changes.
In detail
The two products are built as a pair. Here is how the three Fortinet layers fit:
- FortiGate and the wider fabric (FortiSwitch, FortiAP, FortiExtender, FortiSandbox): enforce policy and inspect traffic.
- FortiManager: plans and pushes changes, with install previews, revisions and one-click rollback.
- FortiAnalyzer, delivered as a service (FAZaaS): captures logs and evidence for analytics and compliance reports.
This closes the loop between planned changes and proof of what happened. That helps in audits: you can show when a policy changed and how traffic behaved after it.
Neither product replaces the other, and neither is a SIEM or a SOC. For 24/7 detection, FirstNet offers Sophos MDR with its Incident Response team.
By default, FirstNet runs both on its South African platform, under one managed-service contract.
Source: FirstNet Hosted Firewall & Network Security service page →
Didn’t answer your question?
