Short answer
FortiManager becomes valuable once you run around five or more FortiGates, because managing each device by hand leads to configuration drift and inconsistent policy. It is also a fit when an auditor asks how firewall changes are approved, evidenced and rolled back, or when you need clean separation between business units or managed customers.
In detail
Common triggers:
- Rolling out a fifth or later FortiGate site
- Audit or regulatory questions about firewall change control
- Absorbing an acquired Fortinet estate into its own ADOM before harmonising
- Moving onto FirstNet Fortinet FWaaS or SD-WAN
- Outages caused by manual configuration drift
FirstNet runs FortiManager as a managed service, by default as a VM on FirstNet Private Cloud in South Africa. It designs the ADOM model before any device is enrolled, uses Zero-Touch Provisioning for new sites, runs a quarterly firmware programme and sends monthly reports on policy revisions, firmware drift and licence use.
FortiManager is a management platform only: it does not inspect traffic or block threats itself, which remains the job of your FortiGates.
Source: FirstNet Hosted Firewall & Network Security service page →
Didn’t answer your question?
