Scalable and Centralized Network Security Management: Fortinet FortiManager

Running or managing a handful of firewalls is a walk on the cake as one can log into each one of these firewalls, make the necessary changes, and continue. But the scenario becomes disruptive when it is scaled to dozens, hundreds, or even thousands for FortiGate firewalls across multiple sites. This is when the crucial involvement of FortiManager does its job with maximum effectiveness. For larger device footprints, FortiManager is a tool that eliminates the hustle of logging into individual devices for new changes and configuring the drift between different sites.

FortiManager is Fortinet’s centralized management platform designed to manage, configure, and monitor FortiGate devices and the broader Fortinet Security Fabric at scale. In enterprise environments with hundreds or thousands of FortiGate appliances across multiple sites and clouds, FortiManager provides a single pane of glass for policy orchestration, firmware lifecycle management, and compliance enforcement.

Without centralized management, network security teams face configuration drift, inconsistent policies, slow change management, and audit failures. FortiManager addresses these challenges by providing template-based provisioning, revision control, workflow approval, and API-driven automation. This blog explores FortiManager’s architecture, deployment strategies, and operational best practices from a senior architect’s perspective.

Fortinet FortiManager

Known as the command center for all your firewall operations, FortiManager performs three main duties where the other tools compromise:

  • Manages configurations across all your devices
  • Automates policy deployment, eliminating manual configuration of each individual firewall
  • Maintains consistency for all devices across your infrastructure

Network admins and security teams align to FortiManager to deal with multiple FortiGate firewall devices over a network. Meanwhile, single firewalls are easy to maintain and configure. When scaled, it’s a nightmare for manual management of these firewalls. Scale your network seamlessly with FortiManager where a single security policy can be pushed into all the devices, and firmware updates can also be done in a single push.

FortiManager either runs as a physical device, a virtual machine, or in the cloud, without breaking the sweat with setup in your environment for the devices you need to manage.

Key Features of FortiManager

Under the radar, FortiManager brings a pack of groundbreaking functionality into its interface, enabling the teams to remain hassle-free most of the time. It offers:

  • Centralized policy management: Create security policies only one time and deploy them to multiple devices. A newly discovered threat can be mitigated across all devices with a single policy update, eliminating copy/paste options and vulnerable logins.
  • Device configuration templates: Templates come with a standardized configuration to multiple FortiGate devices. Set up a baseline configuration and enable it across all locations in minutes. A simple template update would push it into everything.
  • Automated firmware: Firmware updates in multiple applications are tricky puzzling efforts. However, FortiManager automates the entire process through scheduling updates, staging tests, or making them live over the entire network. It tracks and identifies devices that need updates and handles end-to-end deployments.
  • Zero-touch provisioning & SD-WAN orchestration: Prebuilt templates enable faster deployment for new devices, reducing setup time for complex SD-WAN, SD-Branch and hybrid environments.
  • Change management and approval of workflows: Every update that’s been pushed into the network needs validation or testing. Approval processes must be standardized for any rollouts, ensuring the business operations are smooth and safe. Logs are kept when changes have been approved and rolled out, with granularity to who made the changes and when.
  • Multi-tenant support: FortiManager offers the flexibility to support different customers or divisions – multitenant support at scale. It is handled through Administrative Domains (ADOMs), which create isolated management spaces so that no risk of pushing a policy to the wrong network later sounds accidental.
  • Script automation: Scripting transforms tedious tasks into direct operations. It’s a rapid way to automate configure changes, derive reports, or create custom workflows for the mundane work your team does.
  • Backup and restore: Device configurations are backed up automatically. During the unexpected fails, you can quickly backup or restore the data, without manually recreating the rules for that particular site.

Architecture Deep Dive

Core Components

Administrative Domains (ADOMs)

ADOMs are the foundational multi-tenancy construct in FortiManager. Each ADOM provides a logically isolated management domain with its own device inventory, policy packages, objects, and administrator roles. This enables MSSPs to manage multiple customers on a single FortiManager instance, or enterprises to delegate management by business unit or geography.

ADOM Architecture

Policy and Object Management

FortiManager uses a policy package model where policies are defined centrally and installed to managed devices. Objects (addresses, services, schedules, VPN tunnels) are defined within an ADOM and referenced by policies. This allows a single address object change to propagate across all policies that reference it.

The installation process involves: (1) editing policies/objects in the ADOM database, (2) previewing changes via a diff against the device’s current configuration, (3) optional workflow approval, (4) installation to target devices, and (5) revision history tracking.

Flow Diagrams

Device Registration and Provisioning

Zero-Touch Provisioning Flow

Policy Change Workflow

Change Management Workflow

FortiManager HA Architecture

Challenges and Possible Solutions

Challenge Without FortiManager With FortiManager
Configuration Drift Manual device-by-device management leads to inconsistencies Centralized policy packages with automated compliance checks
Change Management No audit trail, no approval workflow Built-in workflow with review, approval, and revision history
Firmware Management Manual firmware upgrades on each device Scheduled firmware deployment with pre/post validation
Multi-Tenant Management Separate management instances per customer ADOM-based isolation on single platform
Compliance Auditing Manual evidence collection for audits Automated compliance reports and policy diff tracking
Disaster Recovery No centralized backup of device configurations Automatic config backup, revision history, and HA failover
Scale CLI-based changes don’t scale beyond 10-20 devices Manage 10,000+ devices from single console
API Automation Device-by-device API calls Single API endpoint for fleet-wide operations

Security Features

  • Role-Based Access Control (RBAC): Granular permissions by ADOM, device group, policy package, and object type
  • Workflow Approval: Multi-stage change approval with configurable review chains
  • Audit Logging: Complete record of all administrative actions with tamper-proof logging
  • Encrypted Communications: TLS-encrypted management tunnel (FGFM) between FortiManager and managed devices
  • Two-Factor Authentication: RADIUS, LDAP, TACACS+, and FortiToken integration for admin access
  • Configuration Revision Control: Git-like versioning with diff, rollback, and branch capabilities
  • Security Rating: Automated security posture assessment across all managed devices
  • Trusted Host Restrictions: IP-based access control for FortiManager administrative interfaces

 

Use Cases

Use Case Scale Key Capabilities
Enterprise Multi-Site Management 50-500 FortiGates Centralized policy, firmware, VPN orchestration
MSSP Multi-Tenant 1,000+ devices, 100+ customers ADOM isolation, per-customer RBAC, white-label
SD-WAN Orchestration Hub + 500 branches Template-based SD-WAN provisioning, overlay management
Compliance & Audit Regulated industry Policy versioning, change tracking, automated reports
DevOps / IaC Integration Cloud-native operations JSON-RPC API, Terraform provider, Ansible modules
Zero-Touch Deployment Rapid branch rollout Auto-provisioning, model device, pre-staged configs

Licensing Model

FortiManager is licensed based on the platform (hardware or VM) and the number of managed devices/ADOMs.

ModelManaged DevicesADOMsDeployment
FMG-200GUp to 30Up to 5Small enterprise
FMG-300GUp to 100Up to 25Mid-enterprise
FMG-400GUp to 1,000Up to 100Large enterprise
FMG-500GUp to 10,000Up to 500MSSP / Service Provider
FortiManager-VMVaries by license tierVariesCloud / Virtual
FortiManager CloudSaaS modelVariesFully managed by Fortinet

 

Add-on licenses are available for additional device counts, ADOMs, and FortiAnalyzer integration. FortiManager Cloud (SaaS) is included in FortiGate 360 bundles.

Enterprise Readiness

  • High Availability: Active-passive HA with database synchronization and automatic failover
  • Scalability: Single instance manages up to 10,000 FortiGate devices across global deployments
  • Multi-Tenancy: ADOM-based isolation with per-tenant administrators, policies, and objects
  • API-First Design: JSON-RPC API enables Terraform, Ansible, and custom automation integration
  • RBAC: Granular role-based access with custom profiles for operators, engineers, and auditors
  • Backup & Recovery: Automated configuration backups with point-in-time recovery
  • Integration: Native integration with FortiAnalyzer, FortiSOAR, and third-party SIEM/SOAR platforms
  • Global Deployment: Multi-region management with hierarchical FortiManager clustering

Cloud and On-Premises Solutions

FortiManager is available as hardware appliances, virtual machines (VMware, Hyper-V, KVM, OpenStack), cloud marketplace images (AWS, Azure, GCP), and as a SaaS offering (FortiManager Cloud). The choice depends on organizational preferences for infrastructure management, data sovereignty requirements, and operational maturity.

DeploymentProsCons
Hardware ApplianceDedicated resources, predictable performanceCapital expense, physical maintenance
Virtual MachineFlexible resource allocation, easy DRShared infrastructure, licensing complexity
Cloud (IaaS)Elastic scaling, global reachRecurring cost, cloud dependency
FortiManager Cloud (SaaS)Zero maintenance, auto-updates, included in 360 bundleData sovereignty concerns, limited customization

Issues and Resolutions

IssueRoot CauseResolution
Policy install fails with ‘object in use’Object referenced in multiple policy packagesUse ‘where used’ tool to find all references before modifying
ADOM database out of syncDevice config changed locally (not via FMG)Run ‘Retrieve’ to sync device config back to FMG; enforce FMG as sole config source
Slow GUI performanceLarge number of devices/objects in single ADOMSplit large ADOMs; increase VM resources; use API for bulk operations
HA failover not completingDatabase sync lag between primary and secondaryEnsure dedicated high-bandwidth HA link; monitor sync status regularly
API calls returning timeoutComplex policy computations on large datasetsUse async API calls; paginate large queries; optimize ADOM structure
Firmware upgrade fails on deviceInsufficient flash storage or incompatible upgrade pathCheck upgrade path matrix; stage firmware to device before scheduling upgrade


FortiManager is an essential component of any enterprise for Fortinet deployment. It transforms device-by-device management into scalable, auditable, and automated security operations. For organizations managing more than a handful of FortiGate devices, FortiManager’s centralized policy orchestration, workflow approvals, and API-driven automation are critical for maintaining security posture, operational efficiency, and regulatory compliance. The key to successful FortiManager deployment is investing in ADOM design, establishing change management workflows from day one, and leveraging the API for infrastructure-as-code integration.

Share:

Recent Posts

Categories: