On this page
Fortinet
FortiGate (standalone)
- Access Requests
- Manual target selection
- Device object selection
- Modify Group
- Create/modify group
- Add Access
- Risk Analysis
- Designer
- Verifier
- Authorization and documentation
- Auto close
- Remove Access
- Verifier
- Decommission Network Object
- Impact Analysis
- Verifier
- Rule Recertification
- Update metadata
Notes for FortiGate (standalone)
-
For FortiGate policies, only Profile-based NGFW (next-generation firewall) mode is supported.
FortiManager (managing FortiGate)
- Access Requests
- Manual target selection
- Device object selection
- User Identity (Supported for Source User Groups objects configured with type FSSO. Not supported for FSSO Groups object type)
- Workflows for change automation are only relevant for ADOMs.
- Modify Group
- Designer
- Syntax-based change
- Provisioning + Committing
- Provisioning + Committing in automatic step
- Create/modify group, including Global Objects (from v5.4)
- Add Access
- Risk Analysis
- Verifier
- Designer
- Provisioning + Committing
- Provisioning + Committing in automatic step
- Authorization and documentation
- Auto close
- Remove Access
- Auto close
- Verifier (topology mode only)
- Designer
- Provisioning
- Provisioning in automatic step
- Decommission Network Object
- Impact Analysis
- Designer
- Provisioning + Committing
- Verifier
- Authorization and documentation
- Clone Network Object Policy
- Designer
- Provisioning (or) Provisioning and Committing
- Verifier
- Rule Decommission
- Designer
- Provisioning + Committing
- Provisioning + Committing in automatic step
- Verifier
- Authorization and documentation
- Auto close
- Rule Modification
- Provisioning + Committing
- Provisioning + Committing in automatic step
- Rule Recertification
- Update metadata
Notes for FortiManager Advanced (6.4 or later)
(From TOS 5.4) Global Objects
Supports provisioning global objects such as network objects, services, and object groups, in both IPv4 and IPv6 on Global ADOMs. Provisioning capabilities identical to ADOMs. See Configuring TOS for FortiManager Global Objects.
Policy Mode
For FortiManager policies, only Profile-based NGFW (next-generation firewall) mode is supported.
FQDN support
-
SecureChange: You can leverage automation tools, such as target selection, Verifier, and Designer, to automate access requests that contain FQDNs.
-
SecureTrack: Has visibility for FQDNs in security rules and change tracking, assessment, path analysis, and matching rules.
Access requests
-
Dynamic assignment and Skip this step if options do not list targets when topology is disabled.
Workaround: Enter these targets manually, using free text.
-
Access requests support IPv6 objects, including Designer recommendations and Provisioning.
Security Profile Groups
You can define the default for Security Profile Group (ContentID) in stconf. Once these profiles are set, Designer will create new rules accordingly for access requests. For details, see Configuring Log Forwarding and Security Profile Groups.
Rule Modification Workflow
-
New objects in a Rule Modification workflow can only be created on the policy where the rule is located. It is not possible to create a global object in a hierarchical environment and add the object to a rule on a sibling policy.
-
In a Rule Modification workflow there is no zone validation for Fortinet FortiManager devices. While it is possible for a request to include adding objects from address books or adding zones to rules on other zones, validation will fail on provisioning.
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague