Running or managing a handful of firewalls is a walk on the cake as one can log into each one of these firewalls, make the necessary changes, and continue. But the scenario becomes disruptive when it is scaled to dozens, hundreds, or even thousands for FortiGate firewalls across multiple sites. This is when the crucial involvement of FortiManager does its job with maximum effectiveness. For larger device footprints, FortiManager is a tool that eliminates the hustle of logging into individual devices for new changes and configuring the drift between different sites.
FortiManager is Fortinet’s centralized management platform designed to manage, configure, and monitor FortiGate devices and the broader Fortinet Security Fabric at scale. In enterprise environments with hundreds or thousands of FortiGate appliances across multiple sites and clouds, FortiManager provides a single pane of glass for policy orchestration, firmware lifecycle management, and compliance enforcement.
Without centralized management, network security teams face configuration drift, inconsistent policies, slow change management, and audit failures. FortiManager addresses these challenges by providing template-based provisioning, revision control, workflow approval, and API-driven automation. This blog explores FortiManager’s architecture, deployment strategies, and operational best practices from a senior architect’s perspective.
Fortinet FortiManager
Known as the command center for all your firewall operations, FortiManager performs three main duties where the other tools compromise:
- Manages configurations across all your devices
- Automates policy deployment, eliminating manual configuration of each individual firewall
- Maintains consistency for all devices across your infrastructure
Network admins and security teams align to FortiManager to deal with multiple FortiGate firewall devices over a network. Meanwhile, single firewalls are easy to maintain and configure. When scaled, it’s a nightmare for manual management of these firewalls. Scale your network seamlessly with FortiManager where a single security policy can be pushed into all the devices, and firmware updates can also be done in a single push.
FortiManager either runs as a physical device, a virtual machine, or in the cloud, without breaking the sweat with setup in your environment for the devices you need to manage.
Key Features of FortiManager
Under the radar, FortiManager brings a pack of groundbreaking functionality into its interface, enabling the teams to remain hassle-free most of the time. It offers:
- Centralized policy management: Create security policies only one time and deploy them to multiple devices. A newly discovered threat can be mitigated across all devices with a single policy update, eliminating copy/paste options and vulnerable logins.
- Device configuration templates: Templates come with a standardized configuration to multiple FortiGate devices. Set up a baseline configuration and enable it across all locations in minutes. A simple template update would push it into everything.
- Automated firmware: Firmware updates in multiple applications are tricky puzzling efforts. However, FortiManager automates the entire process through scheduling updates, staging tests, or making them live over the entire network. It tracks and identifies devices that need updates and handles end-to-end deployments.
- Zero-touch provisioning & SD-WAN orchestration: Prebuilt templates enable faster deployment for new devices, reducing setup time for complex SD-WAN, SD-Branch and hybrid environments.
- Change management and approval of workflows: Every update that’s been pushed into the network needs validation or testing. Approval processes must be standardized for any rollouts, ensuring the business operations are smooth and safe. Logs are kept when changes have been approved and rolled out, with granularity to who made the changes and when.
- Multi-tenant support: FortiManager offers the flexibility to support different customers or divisions – multitenant support at scale. It is handled through Administrative Domains (ADOMs), which create isolated management spaces so that no risk of pushing a policy to the wrong network later sounds accidental.
- Script automation: Scripting transforms tedious tasks into direct operations. It’s a rapid way to automate configure changes, derive reports, or create custom workflows for the mundane work your team does.
- Backup and restore: Device configurations are backed up automatically. During the unexpected fails, you can quickly backup or restore the data, without manually recreating the rules for that particular site.
Architecture Deep Dive
Core Components
Administrative Domains (ADOMs)
ADOMs are the foundational multi-tenancy construct in FortiManager. Each ADOM provides a logically isolated management domain with its own device inventory, policy packages, objects, and administrator roles. This enables MSSPs to manage multiple customers on a single FortiManager instance, or enterprises to delegate management by business unit or geography.
ADOM Architecture
Policy and Object Management
FortiManager uses a policy package model where policies are defined centrally and installed to managed devices. Objects (addresses, services, schedules, VPN tunnels) are defined within an ADOM and referenced by policies. This allows a single address object change to propagate across all policies that reference it.
The installation process involves: (1) editing policies/objects in the ADOM database, (2) previewing changes via a diff against the device’s current configuration, (3) optional workflow approval, (4) installation to target devices, and (5) revision history tracking.
Flow Diagrams
Device Registration and Provisioning
Zero-Touch Provisioning Flow
Policy Change Workflow
Change Management Workflow
FortiManager HA Architecture
Challenges and Possible Solutions
| Challenge | Without FortiManager | With FortiManager |
| Configuration Drift | Manual device-by-device management leads to inconsistencies | Centralized policy packages with automated compliance checks |
| Change Management | No audit trail, no approval workflow | Built-in workflow with review, approval, and revision history |
| Firmware Management | Manual firmware upgrades on each device | Scheduled firmware deployment with pre/post validation |
| Multi-Tenant Management | Separate management instances per customer | ADOM-based isolation on single platform |
| Compliance Auditing | Manual evidence collection for audits | Automated compliance reports and policy diff tracking |
| Disaster Recovery | No centralized backup of device configurations | Automatic config backup, revision history, and HA failover |
| Scale | CLI-based changes don’t scale beyond 10-20 devices | Manage 10,000+ devices from single console |
| API Automation | Device-by-device API calls | Single API endpoint for fleet-wide operations |
Security Features
- Role-Based Access Control (RBAC): Granular permissions by ADOM, device group, policy package, and object type
- Workflow Approval: Multi-stage change approval with configurable review chains
- Audit Logging: Complete record of all administrative actions with tamper-proof logging
- Encrypted Communications: TLS-encrypted management tunnel (FGFM) between FortiManager and managed devices
- Two-Factor Authentication: RADIUS, LDAP, TACACS+, and FortiToken integration for admin access
- Configuration Revision Control: Git-like versioning with diff, rollback, and branch capabilities
- Security Rating: Automated security posture assessment across all managed devices
- Trusted Host Restrictions: IP-based access control for FortiManager administrative interfaces
Â
Use Cases
| Use Case | Scale | Key Capabilities |
| Enterprise Multi-Site Management | 50-500 FortiGates | Centralized policy, firmware, VPN orchestration |
| MSSP Multi-Tenant | 1,000+ devices, 100+ customers | ADOM isolation, per-customer RBAC, white-label |
| SD-WAN Orchestration | Hub + 500 branches | Template-based SD-WAN provisioning, overlay management |
| Compliance & Audit | Regulated industry | Policy versioning, change tracking, automated reports |
| DevOps / IaC Integration | Cloud-native operations | JSON-RPC API, Terraform provider, Ansible modules |
| Zero-Touch Deployment | Rapid branch rollout | Auto-provisioning, model device, pre-staged configs |
Licensing Model
FortiManager is licensed based on the platform (hardware or VM) and the number of managed devices/ADOMs.
| Model | Managed Devices | ADOMs | Deployment |
| FMG-200G | Up to 30 | Up to 5 | Small enterprise |
| FMG-300G | Up to 100 | Up to 25 | Mid-enterprise |
| FMG-400G | Up to 1,000 | Up to 100 | Large enterprise |
| FMG-500G | Up to 10,000 | Up to 500 | MSSP / Service Provider |
| FortiManager-VM | Varies by license tier | Varies | Cloud / Virtual |
| FortiManager Cloud | SaaS model | Varies | Fully managed by Fortinet |
Â
Add-on licenses are available for additional device counts, ADOMs, and FortiAnalyzer integration. FortiManager Cloud (SaaS) is included in FortiGate 360 bundles.
Enterprise Readiness
- High Availability: Active-passive HA with database synchronization and automatic failover
- Scalability: Single instance manages up to 10,000 FortiGate devices across global deployments
- Multi-Tenancy: ADOM-based isolation with per-tenant administrators, policies, and objects
- API-First Design: JSON-RPC API enables Terraform, Ansible, and custom automation integration
- RBAC: Granular role-based access with custom profiles for operators, engineers, and auditors
- Backup & Recovery: Automated configuration backups with point-in-time recovery
- Integration: Native integration with FortiAnalyzer, FortiSOAR, and third-party SIEM/SOAR platforms
- Global Deployment: Multi-region management with hierarchical FortiManager clustering
Cloud and On-Premises Solutions
FortiManager is available as hardware appliances, virtual machines (VMware, Hyper-V, KVM, OpenStack), cloud marketplace images (AWS, Azure, GCP), and as a SaaS offering (FortiManager Cloud). The choice depends on organizational preferences for infrastructure management, data sovereignty requirements, and operational maturity.
| Deployment | Pros | Cons |
| Hardware Appliance | Dedicated resources, predictable performance | Capital expense, physical maintenance |
| Virtual Machine | Flexible resource allocation, easy DR | Shared infrastructure, licensing complexity |
| Cloud (IaaS) | Elastic scaling, global reach | Recurring cost, cloud dependency |
| FortiManager Cloud (SaaS) | Zero maintenance, auto-updates, included in 360 bundle | Data sovereignty concerns, limited customization |
Issues and Resolutions
| Issue | Root Cause | Resolution |
| Policy install fails with ‘object in use’ | Object referenced in multiple policy packages | Use ‘where used’ tool to find all references before modifying |
| ADOM database out of sync | Device config changed locally (not via FMG) | Run ‘Retrieve’ to sync device config back to FMG; enforce FMG as sole config source |
| Slow GUI performance | Large number of devices/objects in single ADOM | Split large ADOMs; increase VM resources; use API for bulk operations |
| HA failover not completing | Database sync lag between primary and secondary | Ensure dedicated high-bandwidth HA link; monitor sync status regularly |
| API calls returning timeout | Complex policy computations on large datasets | Use async API calls; paginate large queries; optimize ADOM structure |
| Firmware upgrade fails on device | Insufficient flash storage or incompatible upgrade path | Check upgrade path matrix; stage firmware to device before scheduling upgrade |
FortiManager is an essential component of any enterprise for Fortinet deployment. It transforms device-by-device management into scalable, auditable, and automated security operations. For organizations managing more than a handful of FortiGate devices, FortiManager’s centralized policy orchestration, workflow approvals, and API-driven automation are critical for maintaining security posture, operational efficiency, and regulatory compliance. The key to successful FortiManager deployment is investing in ADOM design, establishing change management workflows from day one, and leveraging the API for infrastructure-as-code integration.