Skip to content
Project 019-site hub-and-spoke FortiGate deployment

Nine FortiGate firewalls, each configured and maintained independently, brought under a single FortiManager control plane with a documented operating procedure behind it.

9Sites
01

Overview

Nine FortiGate firewalls, each configured and maintained independently, brought under a single FortiManager control plane with a documented operating procedure behind it.

02

Technical challenge

Nine sites meant nine separate policy sets, nine change windows and nine places for configuration to drift. Without a central management plane there was no consistent way to push policy, verify what was actually running on each device, or roll a change back cleanly.

03

Architecture

  • 01Hub-and-spoke topology with FortiManager as the central management plane and each site FortiGate as a managed spoke.
  • 02Administrative domains (ADOMs) used to separate management scope while keeping shared objects consistent.
  • 03Device authorization performed per site so each FortiGate was registered, verified and brought under management in a controlled order.
  • 04A defined sync workflow governing the direction of truth between FortiManager and each managed device.
04

Implementation

  • Authorised and onboarded nine FortiGate devices into FortiManager.
  • Structured ADOMs and shared policy objects for the estate.
  • Established the retrieve/install sync workflow and change sequence used for policy deployment.
  • Produced formal SOP documentation so the process is repeatable by the wider team.
05

Outcome

Nine sites operate under one management plane with authorised devices, structured ADOMs and a documented sync and change workflow.

06Related work