Fortinet

FortiGate (standalone)

Access Requests
Manual target selection
Device object selection
Modify Group
Create/modify group
Add Access
Risk Analysis
Designer
Verifier
Authorization and documentation
Auto close
Remove Access
Verifier
Decommission Network Object
Impact Analysis
Verifier
Rule Recertification
Update metadata

Notes for FortiGate (standalone)

  • For FortiGate policies, only Profile-based NGFW (next-generation firewall) mode is supported.

FortiManager (managing FortiGate)

Access Requests
Manual target selection
Device object selection
User Identity (Supported for Source User Groups objects configured with type FSSO. Not supported for FSSO Groups object type)
Workflows for change automation are only relevant for ADOMs.
Modify Group
Designer
Syntax-based change
Provisioning + Committing
Provisioning + Committing in automatic step
Create/modify group, including Global Objects (from v5.4)
Add Access
Risk Analysis
Verifier
Designer
Provisioning + Committing
Provisioning + Committing in automatic step
Authorization and documentation
Auto close
Remove Access
Auto close
Verifier (topology mode only)
Designer
Provisioning
Provisioning in automatic step
Decommission Network Object
Impact Analysis
Designer
Provisioning + Committing
Verifier
Authorization and documentation
Clone Network Object Policy
Designer
Provisioning (or) Provisioning and Committing
Verifier
Rule Decommission
Designer
Provisioning + Committing
Provisioning + Committing in automatic step
Verifier
Authorization and documentation
Auto close
Rule Modification
Provisioning + Committing
Provisioning + Committing in automatic step
Rule Recertification
Update metadata

Notes for FortiManager Advanced (6.4 or later)

(From TOS 5.4) Global Objects

Supports provisioning global objects such as network objects, services, and object groups, in both IPv4 and IPv6 on Global ADOMs. Provisioning capabilities identical to ADOMs. See Configuring TOS for FortiManager Global Objects.

Policy Mode

For FortiManager policies, only Profile-based NGFW (next-generation firewall) mode is supported.

FQDN support
  • SecureChange: You can leverage automation tools, such as target selection, Verifier, and Designer, to automate access requests that contain FQDNs.

  • SecureTrack: Has visibility for FQDNs in security rules and change tracking, assessment, path analysis, and matching rules.

Access requests
  • Dynamic assignment and Skip this step if options do not list targets when topology is disabled.

    Workaround: Enter these targets manually, using free text.

  • Access requests support IPv6 objects, including Designer recommendations and Provisioning.

  • Designer gives priority to service objects that have a default timeout set in the firewall.
  • Security Profile Groups

    You can define the default for Security Profile Group (ContentID) in stconf. Once these profiles are set, Designer will create new rules accordingly for access requests. For details, see Configuring Log Forwarding and Security Profile Groups.

    Rule Modification Workflow
    • New objects in a Rule Modification workflow can only be created on the policy where the rule is located. It is not possible to create a global object in a hierarchical environment and add the object to a rule on a sibling policy.

    • In a Rule Modification workflow there is no zone validation for Fortinet FortiManager devices. While it is possible for a request to include adding objects from address books or adding zones to rules on other zones, validation will fail on provisioning.