Knowledge Hub · Security

How does FortiManager reduce the risk of firewall changes in FirstNet's managed service?

Hosted Firewall & Network Security · Answered by FirstNet Technology Services

Short answer

FortiManager lets changes be validated before they reach your firewalls. FirstNet uses install previews, policy package validation, ADOM and device revisions, and one-click rollback to a known-good configuration, and its change process requires an install preview, peer review and a documented rollback step for every policy install.

In detail

The controls in practice:

  • Policy packages: firewall, NAT and security policies built once, validated, then installed to one or many devices
  • Shared object database: change an address or service once, rather than editing each firewall by hand
  • Workspace mode and approval workflows: changes are isolated and approved before installation, which suits regulated estates
  • Staged, scheduled rollouts across sites
  • Firmware drift reports, with a quarterly firmware programme to keep the estate aligned

Each customer or business unit has its own ADOM, so a change in one estate cannot spill into another.

When FortiAnalyzer as a Service is also in place, reports can be cross-referenced against policy revisions, giving auditors evidence of what changed and what happened afterwards.

Source: FirstNet Hosted Firewall & Network Security service page →

Didn’t answer your question?

Call