Fortinet black logo

Administration Guide

Adding a FortiGate CNF instance to FortiManager

Adding a FortiGate CNF instance to FortiManager

FortiManager can be used to install and monitor security features on FortiGate CNF instances.

Caution

FortiManager 7.2.2 or later is required.

To add a FortiGate CNF instance to FortiManager:
  1. In FortiGate CNF, in the Display Primary FortiGate Information field in the Edit CNF form, find the FortiGate connection details.

  2. In FortiManager, go to Device & Groups > Add Device.

  3. Click Discover Device.

  4. Enter the IP Address of the FortiGate CNF instance.

  5. Enable Use Legacy Device Login and enter the User Name and Password, then click Next.

  6. Update or enter any required details and click Next.

  7. Click Finish. The FortiGate CNF instance is added to FortiManager. There may be a short delay before the device is available.

  8. Import the FG-traffic policy packagefrom the FortiGate CNF instance into FortiManager.

    Tooltip

    Use either Import each VDOM step by step or Automatically import one VDOM at a time to import FG-traffic. You do not need to import root.

    Use this policy package in FortiManager to install policies to the FortiGate CNF instance.

Note

FortiGate CNF clusters are treated differently than the normal FortiGate auto-scale cluster on AWS. Hover over the information icon next to the cluster name to see more information about the cluster.

Management restrictions

FortiGate CNF is a Fortinet-managed service and there are limited configurations that are permitted from FortiManager.

The following management operations are restricted:

  • VDOM creation not permitted and the option is greyed out.

  • Changes in CLI configuration are not permitted and if tried there is an error.

  • Changes to networking components of the FortiGate are restricted and if tried there is an error.

  • CLI access to the FortiGate CNF instance is not allowed from FortiManager.

  • FortiGate CNF only supports profile-based NGFW mode policy packages.

    While FortiManager allows the selection of policy-based NGFW mode, this setting causes policy installation to fail.

Note

In FortiManager, in Device Manager, the imported FortiGate CNF may display a message "Firmware Upgrade License Not Found". You may safely ignore this message.

For more information about adding devices to FortiManager, see Adding online devices using Discover mode in the FortiManager Administration Guide.

Adding a FortiGate CNF instance to FortiManager

FortiManager can be used to install and monitor security features on FortiGate CNF instances.

Caution

FortiManager 7.2.2 or later is required.

To add a FortiGate CNF instance to FortiManager:
  1. In FortiGate CNF, in the Display Primary FortiGate Information field in the Edit CNF form, find the FortiGate connection details.

  2. In FortiManager, go to Device & Groups > Add Device.

  3. Click Discover Device.

  4. Enter the IP Address of the FortiGate CNF instance.

  5. Enable Use Legacy Device Login and enter the User Name and Password, then click Next.

  6. Update or enter any required details and click Next.

  7. Click Finish. The FortiGate CNF instance is added to FortiManager. There may be a short delay before the device is available.

  8. Import the FG-traffic policy packagefrom the FortiGate CNF instance into FortiManager.

    Tooltip

    Use either Import each VDOM step by step or Automatically import one VDOM at a time to import FG-traffic. You do not need to import root.

    Use this policy package in FortiManager to install policies to the FortiGate CNF instance.

Note

FortiGate CNF clusters are treated differently than the normal FortiGate auto-scale cluster on AWS. Hover over the information icon next to the cluster name to see more information about the cluster.

Management restrictions

FortiGate CNF is a Fortinet-managed service and there are limited configurations that are permitted from FortiManager.

The following management operations are restricted:

  • VDOM creation not permitted and the option is greyed out.

  • Changes in CLI configuration are not permitted and if tried there is an error.

  • Changes to networking components of the FortiGate are restricted and if tried there is an error.

  • CLI access to the FortiGate CNF instance is not allowed from FortiManager.

  • FortiGate CNF only supports profile-based NGFW mode policy packages.

    While FortiManager allows the selection of policy-based NGFW mode, this setting causes policy installation to fail.

Note

In FortiManager, in Device Manager, the imported FortiGate CNF may display a message "Firmware Upgrade License Not Found". You may safely ignore this message.

For more information about adding devices to FortiManager, see Adding online devices using Discover mode in the FortiManager Administration Guide.