Overview
Nine FortiGate firewalls, each configured and maintained independently, brought under a single FortiManager control plane with a documented operating procedure behind it.
Technical challenge
Nine sites meant nine separate policy sets, nine change windows and nine places for configuration to drift. Without a central management plane there was no consistent way to push policy, verify what was actually running on each device, or roll a change back cleanly.
Architecture
- 01Hub-and-spoke topology with FortiManager as the central management plane and each site FortiGate as a managed spoke.
- 02Administrative domains (ADOMs) used to separate management scope while keeping shared objects consistent.
- 03Device authorization performed per site so each FortiGate was registered, verified and brought under management in a controlled order.
- 04A defined sync workflow governing the direction of truth between FortiManager and each managed device.
Implementation
- Authorised and onboarded nine FortiGate devices into FortiManager.
- Structured ADOMs and shared policy objects for the estate.
- Established the retrieve/install sync workflow and change sequence used for policy deployment.
- Produced formal SOP documentation so the process is repeatable by the wider team.
Outcome
Nine sites operate under one management plane with authorised devices, structured ADOMs and a documented sync and change workflow.