On this page
Fortinet
FortiGate (non-management device)
- Dashboard Widgets
-
General (General overview of the system)
-
Cleanup (Summary of the number of rules that are disabled or fully shadowed)
-
USP Compliance (The number of rules with violations, according to their severity level)
-
Audit (The number of rules with expired access or will have access expire within the next month)
-
Recent Changes (Rules and devices with changes in the past 30 days)
- Browsers
-
Rule Viewer (see Rule Viewer)
-
Object Lookup (See Object Lookup)
-
USP Viewer (see USP Viewer)
-
USP Alert Manager Viewer (see USP Alerts Manager)
-
USP Exceptions Viewer (see USP Exceptions)
-
Changes (see Change Browser)
-
Cleanup (see Cleanup Browser)
-
Device Viewer (see Device Viewer)
- Change Management
-
Rule and Object Usage Report (Displays statistics for most-used, least-used, and unused rules and objects)
-
Change Management (Policy and Side-by-Side policy change comparison in the Compare tab, Comparison report, and New Revision report)
-
Full Accountability (Details of the revision, including who made the revision and when)
-
Display IPv6 objects
-
Graphical Policy (Policies are displayed in SecureTrack as they are shown in the vendor's management software)
-
Real-time Monitoring (Regularly automatically fetches policy information from the device)
-
Create SecureChange ticket from Rule Viewer for:
-
Rule Decommission (Removes selected rules from supported devices)
-
-
Automatic Policy Generation (APG) (Analyzes firewall logs to determine actual business practices, and creates an optimized rulebase that limits traffic allowance to traffic actually used in the organization)
- Topology
-
Static Topology
-
Dynamic Topology
-
Calculate impact of VPN policies
- Offline Analysis
-
Not supported when device is configured for high availability
Notes for FortiGate (non-management device)
-
For FortiGate policies, only Profile-based NGFW (next-generation firewall) mode is supported.
FortiManager Advanced (managing FortiGate)
Advanced means device management mode in SecureTrack is Advanced management
- Dashboard Widgets
-
General (General overview of the system)
-
Cleanup (Summary of the number of rules that are disabled or fully shadowed)
-
USP Compliance (The number of rules with violations, according to their severity level)
-
Audit (The number of rules with expired access or will have access expire within the next month)
-
Recent Changes (Rules and devices with changes in the past 30 days)
- Browsers
-
Rule Viewer (see Rule Viewer)
-
Object Lookup (See Object Lookup)
-
USP Viewer (see USP Viewer)
-
USP Alert Manager Viewer (see USP Alerts Manager)
-
USP Exceptions Viewer (see USP Exceptions)
-
Changes (see Change Browser)
-
Cleanup (see Cleanup Browser)
-
Device Viewer (see Device Viewer)
- Change Management
-
Rule and Object Usage Report (Displays statistics for most-used, least-used, and unused rules and objects)
-
Change Management (Policy and Side-by-Side policy change comparison in the Compare tab, Comparison report, and New Revision report)
-
Full Accountability (Details of the revision, including who made the revision and when)
- Display IPv6 objects, routes, and interfaces
-
Graphical Policy (Policies are displayed in SecureTrack as they are shown in the vendor's management software)
-
Change Window (see View and Update a Change Window)
-
Real-time Monitoring (Regularly automatically fetches policy information from the device)
-
Create SecureChange ticket from Rule Viewer for:
-
Rule Decommission (Removes selected rules from supported devices)
-
Rule Modification (Receives rules from the Rule Viewer and lets you create a ticket in SecureChange for a handler to update firewall rules for supported devices)
-
Rule Recertification(Used to document and verify the need for a rule)
-
-
Automatic Policy Generation (APG) (Analyzes firewall logs to determine actual business practices, and creates an optimized rulebase that limits traffic allowance to traffic actually used in the organization)
- Topology
-
Static Topology
-
Dynamic Topology
-
Calculate impact of NAT rules
-
IPv6 routes
-
Path analysis with IPv6 addresses in source and destination
- SD-WAN: Supported for FortiManager 7.0 and later. The SD-WAN rules must be created using the SD-WAN templates and the ADOM version must be 7.0 or later.
-
Connectivity via VPN
-
User Identity (Supported for user groups but not FSSO groups)
Notes for FortiManager Advanced (6.4 or later)
FortiManager policy block
FortiManager 6.4 and later supports visibility and topology for Fortinet FortiManager Policy Block.
FortiManager web filters
Web Filters are supported.
(From TOS 5.4) Automating FortiGate/VDOM movement and name changes
(From TOS 5.4) When a FortiGate device or virtual domain (VDOM) is moved to a new administrative domain (ADOM) in FortiManager, TOS automatically detects the move and continues tracking the device, with full revision history preserved at the VDOM/firewall level. At the ADOM level, policy packages (Security Packages and Policy Blocks) are automatically assigned and aligned to match the new ADOM.
In addition, if a firewall name or VDOM name is changed, TOS automatically updates the name in the device tree.
(From TOS 5.4) Global objects
Supports provisioning global objects such as network objects, services, and object groups, in both IPv4 and IPv6 on Global ADOMs. Provisioning capabilities identical to ADOMs. See Configuring TOS for FortiManager Global Objects.
Topology
-
API for fetching dynamic topology is not supported for ADOM 5.2 and earlier.
-
Collect dynamic topology information is supported when dynamic addressing (DHCP) or routing protocols (OSPF and BGP) are in use.
-
Topology Map supports virtual routing and forwarding information which are part of the firewall revision.
IPv6 policies and upgrades
Upgrading to FortiManager 6.4 from an earlier version, deletes and recreates existing IPv6 policies.
In SecureTrack, these policies are displayed as a diff in the Change Report.
NAT
-
Destination NAT using Services as optional filters is not currently supported.
-
For FortiManager 6.4 and earlier, source NAT is not supported with Policy-based Policies when Central NAT is disabled.
-
FortiManager 6.0.5 and later supports calculating the impact of Central NAT rules.
Unsupported features
-
Global Rules
For Fortinet FortiManager Global Rules that are assigned to ADOM policies, the following features are not supported:
-
Automatic Policy Generator (APG)
-
Last hit for rules in Rule Viewer
-
Rule and object usage
-
-
General
These features are not supported:
-
Regulations report
-
Risks
-
Policy Analysis
-
Dynamic objects (treated as static object with the "default" as its value).
-
Policy support
-
Only Profile-based NGFW (next-generation firewall) mode is supported.
-
Fortinet security profile groups are supported.
Scripts
In Fortinet scripts, rule names must be within quotation marks. For example, "Escalation Rule".
Feature flags for device traffic management
You can use feature flags to manage FortiManager device traffic:
-
Ensure that FortiManager device provisioning changes from SecureChange will be pushed during the provisioning process.
-
Instruct a FortiManager device to log traffic immediately when a session begins rather than waiting for the session to close.
For more information, see Fortinet Feature Flags.
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague