Intro to Deploying FortiManager
Keith introduces this set of videos regarding the introduction and deployment of FortiManager from Fortinet.
FortiManager Overview
FortiManager is Fortinet’s centralized management platform that offers network administrators a single console to oversee multiple FortiGate firewalls and related devices. It simplifies operations by providing policy and device configuration management, centralized logging and reporting, firmware updates, and automation tools for large-scale deployments. This ensures consistent security policies, easier administration, and better visibility across multiple networks.
Knowledge Check
Match the FortiManager features with their descriptions.
This interactive assessment is available in the full learning experience.
Deploying FMG as a VM on-prem
The FortiManager can be deployed as a physical appliance or a VM on-premises. In this video, Keith demonstrates deploying the FMG as a VM in a VMware vSphere environment.
Knowledge Check
Which platform is used in the demonstration for deploying the FortiManager VM?
Initial Configuration of FortiManager
Keith shows the initial setup of FortiManager, including IP addresses, a default route, and DNS servers.
Knowledge Check
What is the correct IP address and network mask configuration for the FortiManager as per the game plan?
FortiManager GUI Overview
Keith presents a demonstration of the Graphical User Interface on the FortiManager.
Knowledge Check
What feature does FortiManager offer if you do not have a dedicated FortiAnalyzer appliance?
Validation Section
Keith presents a scenario to reinforce many of the concepts taught in this skill
Knowledge Check
What is a major benefit of using FortiManager for a company with multiple FortiGate firewalls?
View Transcript
Intro to Deploying FortiManager
0:00Hello and welcome. My name is Keith Barker and today one of two things is true
0:05and I'll let you decide number one I could be ready to go out on the street and
0:08direct traffic
0:09or secondly we can be here today this set of videos to take a look at why
0:14people are using
0:15for to manager how it works and also to deploy a for to manager inside of a
0:19network if you're thinking
0:21Keith I'll bet you this option too you'd be absolutely right so join me the
0:24next video and we'll start
0:25off by taking a big picture look at the wonderful world of for to manager I'll
0:30see you there in just a
0:31moment.
FortiManager Overview
0:00Let's begin in this overview by taking a look at some of the really tangible
0:04benefits that
0:05Fortamandr brings to the table. And a great way of doing that is to consider
0:09managing individual
0:10firewalls and their associated things like access points and switches, managing
0:15them all independently.
0:17So here I'm going to make a column called one by one, meaning managing each
0:20Fortigate individually,
0:22and then I'll put a dividing line right here, and then I'll put in this column
0:26here using Fortamandr.
0:27And I'm going to rewrite one by one a little bit there to make it really look
0:30like one by one,
0:31fantastic. And then over here on the left, let me go ahead and make a list of
0:34tasks.
0:35So one of the tasks we're going to want to do for our Fortigates is manage
0:39policy. You know,
0:40policy like what's allowed, what's not allowed, which security profiles we're
0:43going to use,
0:44how Nats can be implemented, and so forth. And if we have all these firewalls
0:47that we're doing
0:48independently, I'm going to put a frowny face right here one by one, and
0:51without a frowny face,
0:53for now, that's just recognizing that if we're doing it one by one, we're going
0:56to have to,
0:57you know, it's more tedious. You have to go to each device to make those
1:00changes.
1:00And secondly, there's a higher probability of inconsistency. So if we want some
1:05policy
1:06that's uniform across our entire enterprise, if we're doing it firewall by
1:10firewall by firewall,
1:11there's more of a possibility and chance we're going to miss the step or not
1:14have the exact same
1:15policy. We're on the Florida manager. The cool thing is we can create and edit
1:20at the
1:20Florida manager and push that configuration and that policy out to multiple
1:24devices in a consistent
1:26manner. So basically here for the one by one, I'm just going to put a frowny
1:30face pretty much
1:30all the way down the list. And then for the Florida manager, we're going to
1:34have it in a better
1:35situation for us all the way down the list as we identify various tasks where a
1:39Florida manager
1:40is going to be super helpful. Okay, another element besides managing policy is
1:44let's say we have
1:45some other configuration change we need to make. Again, making that
1:47configuration change,
1:48maybe it's something as simple as changing the DNS servers are going to use or
1:52the network
1:53time protocol settings or something else. If we're doing it one by one, it's a
1:56pain in the rear.
1:57If we're using for the manager, we can push up those changes from a single pain
2:01of less from a
2:01single console. Another common task that happens periodically is firmware
2:04updates. And so if we're
2:05updating firmware, once again, if we're doing it firewall by firewall by
2:08firewall, it's going to
2:09take a lot more time compared to doing it from a centralized management console
2:13of 40 manager.
2:14And even if we have like a brand new firewall that we're provisioning and
2:17setting up, instead of
2:18doing that from scratch, we can use features like zero touch provisioning,
2:21where you basically
2:22boot up the firewall, it calls home and auto configures, which is a feature we
2:27can implement
2:27through Florida manager. Another important aspect is monitoring to find out
2:31what's going on. So if
2:32we're doing it firewall by firewall firewall, firewall, that's a lot of
2:35security events and a lot of log
2:36files to go through. So solutions that include the 40 analyzer, which we could
2:41use for a centralized
2:42single console for managing and working with all of our logs and events. And we
2:47have some separate
2:47courses here at CBT, regarding 40 analyzer. However, if we want to use 40
2:51manager, we can use 40
2:53manager in conjunction with 40 analyzer, or if we don't have a 40 analyzer,
2:57there's also centralized
2:58logging support at the for the manager itself. So with or without a separate 40
3:03analyzer,
3:04it's another option for centralized managing and monitoring of our network. And
3:09that also ties
3:09into reporting, because if we're using the Florida manager, we can use
3:13centralized reporting regarding
3:14the state of our network. And that also can tie into the reporting features of
3:1840 analyzer,
3:19if we happen to have one of those as well. Now another recall that I learned
3:23about probably about
3:2430 plus years ago, was the concept of change control and change management.
3:29Because when there is a
3:29change made on a firewall or any component in our network as part of the
3:33infrastructure, it really
3:34needs to be approved by the change control board. We need to have backup plans
3:38in place. We need
3:39to set up change windows and make sure that we're not going to add risk or
3:43bring the system down
3:44based on some update or change we're making. So as part of for the manager, we
3:48can also set up
3:49workflows and revision comparison. So if we do have a firewall, for example, it
3:53's been locally
3:54configured or modified, we'll be able to see that drift that change that's been
3:59made here from 40
4:00manager. Another really cool feature is ADOMS, that's administrative domains.
4:04So an individual
4:0540 gate, there is no such thing as administrative domains. Now there are V DOMS
4:10virtual domains that
4:11we can set up on the 40 gates. But as far as like, for example, putting one
4:15admin in charge of these
4:16three firewalls and another admin in charge of this firewall, if we're doing it
4:20individually
4:21without a Ford manager, we can't really control that. However, with Ford
4:24manager, very similar to
4:2540 analyzer, we can set up administrative domains and then assign, for example,
4:29admin one responsible
4:30here, admin two responsible here. And that way they have the authority and the
4:34permissions to make
4:36those changes based on the administrative domain that they have the permissions
4:39in. Another thing
4:40about automation, although we do have some automation features in a security
4:44fabric with a 40 analyzer,
4:46we also with Ford manager, we can leverage scripts and automation on our 40
4:50gate devices from Ford
4:52manager. So I'm going to hear it here, put automation compared to managing the
4:56automation,
4:56which is the stitches, including the triggers and the actions on individual 40
5:00gates, we can do that
5:02essentially from Ford manager managing the automation. And one other big piece
5:06about Ford
5:06manager is scalability, because if we have like one or two 40 gates, we could
5:11probably pull that
5:12off with, you know, managing them independently. But once we start getting to
5:15the range of let's say
5:1610 to 15 or more 40 gates, it's not reasonable to do an effective job of
5:21managing and monitoring
5:23those 40 gates without some type of centralized management tool like 40 manager
5:27. So another
5:27we've taken a look at a lot of the benefits of 40 manager in the next video, I
5:31'd like to walk you
5:32through the process of a deployment of a for manager device in a network. So we
5:37'll do that in the next
5:38video and I'll see you there in just a moment.
Deploying FMG as a VM on-prem
0:00In this video, I'd like to walk into one of the options for deploying the FMG.
0:04That's an acronym for the Florida Manager.
0:06Now, we could use Florida Manager Services up in the cloud.
0:09We could have an appliances providing the Florida Manager functionality,
0:12or we could deploy Florida Manager as a VM.
0:15So in this demonstration, here is my current topology here in my lab
0:19environment.
0:20So I've got these three firewalls that are part of the same security fabric.
0:23I've got this firewall over here at the branch office, which is in an H.A. pair
0:27,
0:27using the IP addresses as shown.
0:30And they're also implemented in a zone-based firewall deployment as far as the
0:33firewall policies.
0:34Also, at the moment, I currently have a 40 analyzer that all these 40 gates are
0:38reporting into.
0:39However, I don't yet. Actually, the truth be told, I do have a Florida Manager
0:44that is in place ready to go. But because I want to walk you through the
0:48process of downloading
0:49and deploying a Florida Manager, we're going to just imagine for a moment that
0:52I don't yet
0:53have a Florida Manager VM deployed in my environment and that we're going to go
0:56ahead and get the
0:57image and deploy it. Now, as far as the deployment goes for a virtual machine,
1:02Fortinet has a VM image from Florida Manager for most virtualized platforms,
1:08including VSphere,
1:09which we'll be using as part of the demo, and Microsoft's Hyper-V and many
1:14others.
1:15Also, when we download the image for the Florida Manager, it's going to require
1:18an account, a user account up at Fortinet. And if we want to, we can also
1:23download the Florida Manager and then use a trial license. It's good for like a
1:28few devices that we
1:28can manage. And it also has a time limitation as well. So I'd like to walk you
1:32through the deployment
1:33of the Florida Manager VM. Now, a couple of things to be aware of in my
1:36technology here,
1:37my management network is the 192.168.1 network. And that's where my management
1:43PC is. And that's
1:44where my 40 analyzer is at .81. Firewall 1's management IP address on that sub
1:49net is 51. And
1:50that's a slash 24. And firewall 2 is at .52, firewall 3 is at 53. And the
1:55branch firewall
1:56is at .71. So without further ado, let's open up a browser. We'll head up to
2:01support. Fortinet.com.
2:03And let's get to work in getting that image. All right. So here we go. So I've
2:06logged in
2:07as my user account at Fortinet. And although they may change the interface from
2:11time to time,
2:12if we want to download an image currently, we'd go to support. And then over
2:15here under
2:16downloads, we have firmware download, VM images, service updates, etc. What we
2:20want to do is we
2:21want to download the VM image for the platform where we're going to deploy for
2:26to manager the VM.
2:28So we'll click here on VM images, and then we'll select the product. So from
2:31the drop down here,
2:32we want to download for to manager. And then for the platform, we'll go ahead
2:36and use the drop down
2:37here. And we want to download the image and in my environment, because I'm
2:41using vSphere and the
2:42ESXi host, I want to download the VM appropriate for that platform. So I'll
2:46click here for VM
2:47where ESXi because I'm running vSphere. And then we can choose our version. So
2:51here,
2:51763, you notice it's F as in feature. Now in a production environment, we don't
2:57want to run the
2:58feature version unless there's a really good and proven reason to because it's
3:02a feature version
3:04and there could be hiccups or problems along the way. So if we look at 747,
3:09here it is 747M,
3:11as in Mary, and that's the mature flavor. So for the demo, I am going to go
3:15with the feature version
3:16because it's a lab environment. And we'll go ahead and grab the correct image.
3:20Now,
3:20now there's two options to download. One says, do you want to download the
3:23image you need for
3:24an initial deployment of the VM, which we do, or do you want to upgrade from a
3:28previous version?
3:30So we'll go ahead and do the download here. It's only 410 megabytes as of right
3:34now.
3:34Here's the hashes associated with it. We'll go ahead and click here, and that
3:38started the download.
3:39So that's downloading right now to my management computer. All right, so that
3:43is downloaded. Let
3:43me go ahead and grab it. So here is that file in my downloads folder. Also,
3:49before we use it,
3:50if you want to verify that you weren't downloading this from another site,
3:53which maybe you could
3:54inject malware or some other malicious code as part of the image, we could also
3:59do a validation
4:01using the checksum. So this is currently my downloads folder and I'm on a
4:05Windows 11 computer.
4:06So I'm going to go ahead and copy all the checksums right click, copy and I'll
4:09put that in a notepad
4:10document. So I'll right click paste. And there it is. So I have a regular is
4:14probably MD5 and
4:15the SHA 512 and looks like that wrapped. So let me go ahead and yeah, sure
4:19enough. So I've got a
4:20SHA 512 hash right here, and we can generate our own hash value on that same
4:25file. And it should
4:26match the same value that's provided from the website. So let's do that. Let me
4:30just bring up a
4:30command prompt. And here is a command prompt on my local computer. Let me just
4:34cd downloads.
4:35And then DIR and sure enough, there is our file. And let's do a get dash file
4:41hash. And because
4:42we're in that folder, he just copy and paste that name right there and paste
4:47and press enter.
4:47And there's a SHA 256 hash. So that gave us the SHA 256 hash, I need a SHA 512
4:53hash. So I need
4:54to tell it that I want the SHA 512 hash. So hit the up arrow key, and we use
4:59the dash algorithm
5:01space and then type in SHA 512, and press enter. And that should generate the
5:07SHA 512 hash. And that
5:09does not match up. So if we go back to the website, oh, unless I grabbed the
5:16wrong hash,
5:17I did I grabbed the hash for the upgrade, not for the actual new deployment.
5:21Let me grab that
5:22correct hash, right click copy my bad, go back to our notepad document. And let
5:26me get rid of all
5:27that and do a paste. And that is the SHA 512 hash for the zip for the new
5:33deployment. Let's bring
5:34back my command line. So now we compare the hash, DDC seven FF2, etc. That
5:40exactly matches right
5:42here, which implies that we have an untainted file directly from Fortnite and
5:46no one's tampered
5:47with it. Fantastic. So now that we have the file, I go ahead and close my not
5:52epad document.
5:53So now that we have the file, we can go ahead and extract it. So here my
5:57downloads folder,
5:58I'll right click and we'll go ahead and say extract all and pop up window, ask
6:02me where I want
6:02to extract it to. So I'll go ahead and click on extract. And there it goes,
6:06made a folder. And
6:07then it's putting those files in that folder. So the VMD case in this VMware
6:11environment,
6:12those are hard drives effectively. And then the OVFs are the instructions for
6:17the VM. So if you're
6:18deploying it in a current vSphere environment, we can use this one right here,
6:22VM 64, HW 14,
6:24that's hardware version 14, V opt out OVF. If you're deploying it on older
6:29flavor of vSphere,
6:30for example, six or seven, you might want to use one of the other options here.
6:35So to deploy the
6:35new VM based on these files, let me bring over my vSphere environment. So here
6:40's my vSphere
6:41environment. I've got a couple hosts that are up and running to ESXi host. And
6:44let's go ahead
6:45and deploy this on ESXi one as a demonstration. Now also, just so you know,
6:51behind the scenes,
6:52I've also got this VM right here called FMG 2025, which is already deployed.
6:58But I wanted to walk
6:58you through the process of deploying a new VM for Ford manager. So we're just
7:02gonna let that
7:03one sit for a while. We'll come back to it a little later. So to create a new
7:05VM, I'm going to go
7:06right here, my Fortinet folder, right click and say deploy OVF template, which
7:10is a fancy way of
7:11saying I wanted to play a new virtual machine from a template. And that's what
7:15we downloaded
7:16from Fortinet a few minutes ago. So we'll click here on deploy OVF template. In
7:20fact,
7:20let me make this font a little bit bigger so we can see a little bit better.
7:23Fantastic.
7:24So I'll right click here on this folder, deploy OVF template, and then I want
7:27to pull from a local
7:28file or files in this case. So I'll click here on upload files. And then here
7:33my downloads folder,
7:34I'll go to that folder for the extracted files and use my control key and grab
7:39FMG.vmdk. It's
7:40one hard drive data drive dot VMB case, the second hard drive. And then because
7:44I want a fairly
7:45current version of vSphere, I'm going to go ahead and use the hardware 14 VF
7:50dot OVF. And with
7:52those three selected, I'll click on open, then we'll go ahead and click on next
7:55. And then I'm
7:56going to call this FMG demo. And this FMG demo VM is going to be placed in the
8:02Fortinet folder,
8:02although we can move it if we want to either now or later, I'll leave it there
8:05for now. We can
8:06also say we want to customize the virtual machines hardware. So I'll go ahead
8:09and check that as well,
8:11and we'll click on next. And as far as which ESXi host we're going to run this
8:14on, I'm going to go
8:15ahead and put it on ESXi one and click on next. So ESXi one is one of the
8:20several rack servers I
8:22have behind me. And ESXi one has plenty of space and CPU and RAM to support the
8:27ford manager.
8:28All right, I'm reviewing details. It's going to go ahead and do thick provision
8:32ing, but I can
8:33change that as I go forward. Thick provisioning basically says, hey, I'm going
8:36to tie up 504 gigabytes
8:38right off the bat where thin provisioning would only use as much physical space
8:43as that VM needs
8:44to use. And it could grow dynamically up to the max. So I'll update that here
8:47as we continue. So
8:48I'll click on next, I'll agree by scrolling down and clicking on I accept all
8:52license agreements,
8:53click on next. And it's asking me effectively, where do you want to store this
8:57virtual machines
8:58files? So I've got a ice guzzi network attached storage. It's called ice guzzi
9:01three, grade five.
9:03Its capacity is 48 terabytes. And I have provisioned 18. So I have about 45 ter
9:08abytes of free space.
9:09That'll be great. Plenty. And then here I'm also going to specify that I want
9:13to do thin provisioning
9:14just to not tie up, for example, all the disk space that that VM needs, unless
9:19it really is
9:19using that disk space. So that's a way in a lab environment to not waste a
9:23bunch of space.
9:24And we'll click on next. Now it's asking me about the four network interface
9:27cards. So
9:28in the interface, whether it's the CLI or the GUI on the port of manager, this
9:31would show up as
9:32port one, port two, port three, port four. So I'm going to put port one, I'm
9:37going to browse and
9:38put it on my production 192 network with no tag. That means for me anyway, no
9:43802.1 queue tag.
9:44This is my basic management network, no tagging needed. So I'll select that
9:49with the radio button
9:50right there. And once it's selected, I'll click on OK. And then I'm not going
9:53to use the other three
9:54interfaces. So I can have them park wherever. And we'll click on next. Now it's
9:58asking us to
9:59customize some of these settings. I'm going to leave all the defaults and we'll
10:02customize that
10:02once we get the VM up and running, we'll click on next. And here it's showing
10:06us the details
10:08for the hardware, because I said I wanted to customize the hardware. So it's
10:10going to have four
10:11CPUs, 16 gigs of RAM. And these two are based on the new hard disk from the VMD
10:16K files. Now also
10:18here, if we scroll down, you know, it's just one network that we're here, which
10:22is going to be
10:23port one is too bad. It's not in the right order. However, anyway, that's going
10:26to be port one,
10:27based on what we said we wanted to have happen. And currently it's not showing
10:30us connected because
10:31the VM is not running. And there's a video card associated with it. So
10:35sometimes on the VM that
10:37you deploy, there's limits in place based on the license you're using regarding
10:41how much RAM and
10:42how much CPU it can support. So just be aware that initially, you may want to
10:47just deploy it without
10:48tweaking these values. And then based on your license, if you want to go back
10:51with the VM powered off,
10:52you can upgrade the number of CPUs, the amount of memory, if your license
10:55supports it. And so I'm
10:57going to go ahead and take all these settings that are currently in place and
11:00click on next.
11:01Here's a summary. The VM is going to be called fmg demo. It's coming from this
11:05template is going
11:06to be in this folder. There's the ESXi host providing the hypervisor services.
11:10It's going to do thin
11:12provisioning fantastic on that data store. And then the network one, which is
11:17port one, is coming map
11:18to that port group called prod 192 effectively placing it on my management
11:22network. And we'll
11:23go ahead and click on finish. All right, so if we go to recent tasks here, it
11:28is now importing
11:29and deploying that VM. I forget whether or not I said it should automatically
11:34power it up.
11:34But in any case, we'll see what happens and then we can power it up manually if
11:40we need to.
11:40So if we go down the folder here, once it's deployed, we see that VM here as
11:44well. And it's
11:45sort by name. And there it is right there. There's fmg demo. And it's currently
11:50not ready. It's
11:50still being deployed. So we'll give that a another minute or two to complete.
11:54Also, if you're interested
11:55in training while this is deploying, if you're interested in training on other
11:59for net products,
12:00for example, 40 analyzer or for to gate administration, we have separate
12:05courses on all those independently
12:06as well. So feel free to check out our entire library regarding for net
12:10products, if you have
12:11more specific training on any of those specific products. All right, so the
12:15import's done, the
12:16deployment's done. And if we click here, let me go ahead and close the recent
12:20tasks. There's our fmg
12:21demo. And here's summary. And currently it is powered off. So we could right
12:25click on this
12:26VM and go to power and then do power on here or with it selected, we could go
12:31ahead and simply
12:32click on this icon for the power on, which we're going to do right now. And
12:36that will power on that
12:37virtual machine. And then we'll go ahead and click on launch remote console.
12:41And that way we can have
12:42a little window, if you will, like sitting at the console of an appliance, we
12:47can logically sit at
12:48the console of this VM as it powers up. And this may take a few minutes. So we
12:52'll give it a minute
12:53or two to complete its power on. And then in the next video, I'd like to walk
12:57you through what the
12:58defaults are in place on this VM. And then I'd also like to walk you through
13:02changing those
13:03to meet your needs in your environment. So I'll see you in the next video as we
13:07continue the
13:07configuration of this newly deployed for the manager.
Initial Configuration of FortiManager
0:00In the previous video, we deployed the brand new 40-manager VM.
0:04However, we haven't configured any of the details on it yet for things like the
0:09IP address and
0:10mask it should use, the default gateway it's going to need so it can
0:13communicate with the outside world,
0:14and also making sure it has the ability to do name resolution. Now, the reason
0:18that's so important
0:19is because a 40-manager just being deployed without any licensing, including
0:24not even a trial license,
0:26it's not going to be too functional until it gets some licensing enabled on it.
0:30And to do that,
0:31it needs to talk out to the services at Fortinet, which is out on the internet.
0:35So regarding a
0:36game plan for configuration, here's like to do on this newly deployed 40-
0:40manager. We placed the
0:42Port 1 interface, we placed that on the management network. So it's logically
0:46in that same VLAN,
0:48that is Port 1. And currently by default, it's going to have an IP address of .
0:5399 at 192.168.1.99.
0:58And so that happens by default on many Fortinet products. However, and I get to
1:02take a look at
1:03what actually happened, if we have DHCP services in place, it's possible that
1:07that 40-manager is
1:08acting as a DHCP client. And if it is, that means it would have pulled an IP
1:13address if there was a
1:14DHCP server available on the network. We'll take a closer look in a moment just
1:18to confirm exactly
1:19what happened with its IP address. Now, secondly, we don't want to use either
1:23the default of .99 or
1:24a default DHCP assigned IP address. What we want to use is 192.168.1.82 based
1:32on our plan right there.
1:34And we want to use a 24-bit network mask. And that basically means this part of
1:38the IP address
1:39is the network. And this last octet, this last number here in the IPV4 address
1:43is the host portion.
1:45Think of this like street 192.168.1 and house number 82. And this we want to
1:50have configured.
1:50For the gateway, we want to have .1 as the default gateway, because I have
1:54another
1:5540-gate firewall acting as default gateway at .1 on that management network
2:00that's doing address
2:01translation and other services to get that traffic out to the internet. And
2:05then for DNS,
2:06we could use the DNS servers that are built into Fortamanager, which very
2:10likely are going to include
2:11the Fortinet DNS servers, or we could use Google. So we could use 888 or Cloud
2:17Flare at 1.1.1.1 or
2:20another one at Google like 884.4, whatever we want to do. So for a game plan,
2:24let's go ahead and
2:25statically configure this information. And we'll do it from the command-lane
2:28interface at the
2:29Fortamanager. So with that in mind, it looks like our Fortamanager is currently
2:33running. Let's bring
2:35up the console and sure enough. And the first time we log in, the username is
2:39admin and there's no
2:41password. So that's a tough password to crack actually if you think there is a
2:44password, but it's
2:45just press enter. It's going to say, okay, great, you're forced to change the
2:48password. So I'll put
2:49in a new password instead of a blank password. I'll confirm that password and
2:53press enter. And if
2:55everything went well, we are now logged in as admin. Also from here, I'm going
2:59to do a show
3:00this to interface and press enter. And I can't even scroll. So let me do a show
3:05system interface
3:06port one. And sure enough, it is actually set for DHCP. So let's do a get
3:11system interface and a
3:12question mark. And you know, it does the information right there. So we've got
3:15an IP address of 1.8
3:16to 1 state 1.119, which is a DHCP assigned address. So we could, you know,
3:21remotely connect
3:22over there with a browser and start changing it. Or we could just do it right
3:26here from the command
3:26line, which is what I'd like to do. So I'm going to bring up a terminal
3:29emulator and just
3:30connect directly to 192.168.1.119 so that we have a bigger interface to play
3:35with. So this is the
3:36secure CRT terminal emulator. Let me just create a new session that goes to 119
3:39, even if it's
3:40temporarily. So click on the plus symbol there. SSH is great. Next, I'll call
3:45this demo fmg,
3:46port 22, username is going to be admin, click on next. And next, oh, you know
3:51what, I need to go
3:52back and put the IP address in right there. So for the host name, because I don
3:55't have DNS for
3:55that 192.168.1.119 fantastic. Next. And then the name can be demo fmg, click on
4:02finish. And then
4:03we'll go ahead and double click on that to connect. It wants to be know if I
4:06want to trust the host
4:07key, I do I'll accept and save that. And that wants the password, which I'll
4:11put in. This is my
4:12terminal emulator help me out here. I'll click on save password, even though we
4:15're going to change
4:15this IP address in a minute and click on OK. And then we are connected to this
4:1940 manager
4:20with a bigger font. So we can actually see better. All right, so I want to
4:22change three things. I
4:23don't want to be a DHCP assigned IP address. So we're going to do a config
4:27system interface.
4:28And let's go ahead and edit port one and press enter. And then we'll do a show
4:32to see the current
4:33settings. I'm going to do a set phone static as opposed to DHCP. And then we'll
4:37do a set IP. And
4:38we want to be 192.168.1. And let's take a look at our notes more more
4:43specifically, let's look at
4:44our topology. So we want it to be at dot 82. So I'll configure dot 82 for this
4:4940 manager VM. So
4:50I'll put 82. And this can be a slash 24 mask and press enter. We'll do a show.
4:55I also want to allow
4:56ping just so I can do a ping test if I need to. So I'm going to a set allowed
5:00access HTTPS, SSH,
5:03and also ping. If you also wanted to enable HTTP, it would automatically
5:08redirect over to HTTPS.
5:10So I'm going to leave HTTP off, I'll press enter, I'll type in next and
5:16because I configured a new IP address, I now have lost connectivity. So I need
5:20to go to dot 82.
5:22And I don't know if I have an entry for that. So I'm going to just update my
5:25terminal emulator
5:26here, right click, get a properties for the entry. And I'm going to call it FMG
5:31. And for the actual
5:32connection for SSH, it's now going to go to dot 82. So I'll add that and click
5:38on OK. And then
5:39we'll go ahead and double click to connect there. We'll accept and save. We'll
5:43go ahead and get
5:44rid of the demo FMG connection. And now we're at the Ford manager at its new IP
5:48address. So we did a
5:49show, just a interface, press enter. Now we can scroll up fantastic. There's
5:54port one with our
5:55settings fantastic. And next, let's go ahead and make sure we have routing set
5:59up because we're
6:00no longer a DHCP client. We want to make sure we have a default gateway set up.
6:04So we'll type in
6:04config system route, do a show. Currently, we have no routing configured. So we
6:08'll do an edit one,
6:10and it'll say set gateway. And we want 192 dot 168 dot 1 dot 1. We'll do a show
6:15just to confirm
6:15fantastic. We'll type in end. Oh, I didn't like that. Oh, I probably should
6:19have typed in next.
6:20Let's do that again. System route. Yep, didn't take it. So we'll edit one. So
6:25we'll edit one
6:26and set gateway. And a question mark. And the gateway is at 192 dot 168 dot 1
6:31dot 1. And let's
6:32type in next. And it does not like that. Why doesn't it like that? All right,
6:36what we'll do is
6:36we'll go to the GUI. And we can do it that way as well. We can also set the DNS
6:40at the GUI as well.
6:41So let's open up a browser and let's go to the GUI to this device. If we scroll
6:45up here,
6:46it should be available at 192.168.1.82. So as a precursor, let me go ahead and
6:51do a quick ping
6:53to 192 dot 168 dot 1 dot 82 to make sure we have reachability. Great, great,
6:57great. And we'll open
6:58for browser. And we'll go there through a browser. All right, so I've opened up
7:01a browser to HTTPS
7:03colon slash slash 192 dot 168 dot 1 to 82. My browser does not trust the issuer
7:08of the certificate,
7:09which is normal. So we'll click on advanced and click on proceed. Now at the
7:13moment, I'm a little
7:14bit in a bit of a pickle, because if we did try to specify, for example, our
7:20account and then log
7:21in with Forta Cloud, we can't get there because the default gateway isn't set.
7:26So what I'm going
7:27to do is I'm going to go ahead and say activate license. Oh, it's still asking
7:30me. Okay, let's go
7:31back to the CLI. And this will be the part of the troubleshooting portion of
7:36the skill is that
7:37it's getting this device online. We need to make sure it has correct routing
7:41and also correct DNS
7:43that it can use. So let's go back to the CLI. And let's do it from there. And
7:46let's go back and
7:47do that one more time. Big system route, do a show, yeah, didn't save any of
7:52that. And let's do edit
7:53one. And let's just take a look at what I forgot. I must have forgot to do
7:57something. So we'll do
7:58a question mark. Oh, I know. I need to set the destination. That's part of a
8:04default route is the
8:05destination is supposed to a set and a question mark and DST space question
8:10mark. And the destination
8:11is going to be the default routes syntax, which is 0.0 0 0 0, slash zero press
8:16center. Great. That's
8:17what I missed last time. And then we'll do a set gateway. And that's going to
8:21be 192.168.1.1
8:23press center. I just got a little ahead of myself. Then we'll type in and and I
8:27forgot one other
8:28thing I also need to tell it which interface, which is going to be port one. So
8:32what's really
8:32interesting is that, you know, once you do this a few times, it's easy to do it
8:36again. But if you
8:37haven't done it for a minute, sometimes you have errors that come up. And that
8:40's what we're doing
8:41right now is we're troubleshooting those. So let's go back in and we'll do a
8:44config system route.
8:45Then we'll do an edit one. And then we'll set the destination again for the
8:49default route.
8:49Then we'll set the actual next top address. And then we're also going to go
8:54ahead
8:55and specify the interface with a set space question mark. And I need to do
8:59device to
9:00specify the interface that default route should use. So do a set device space
9:05question mark.
9:06And we want port one press center. And then we'll type an end.
9:10Yeah, you know what? Fourth time's the charm. So if we go back now and take a
9:16look at the details
9:17of that, what I can config system route that can show. And there are the
9:22elements that we needed.
9:23So the parts that needed was the set device and Z gateway. And the destination
9:27is not required
9:29because it's not showing up here. It's a default. So if we did an execute ping,
9:32for example,
9:33to 8888, that could verify for us that the default gateway is perfectly fine on
9:40the system
9:40and functioning. And to verify DNS, we could go ahead and execute a ping to www
9:45.fordnet.com.
9:47And if that resolves, it also means that name resolution is working. And we
9:50want to configure
9:51the DNS we could prepare with a config system DNS press center with a show. And
9:55currently,
9:56these are the DNS servers it's using. So if we want to use other ones, we can
9:59with a set
10:00primary, and let's go ahead and use 8888. And let's set the secondary to 1111,
10:06little show,
10:08fantastic, well, they've been and now we're using those DNS servers. So once
10:11again,
10:11we can do a name resolution, a ping based on name, just a ping to www.fordnet.
10:15com. And that is still
10:17working fantastic. So back at the GUI of this newly deployed port manager, we
10:21could either
10:22activate a license, or we could ask for a free trial. At that point, we put in
10:27our username and
10:28password that we're going to be using up at Fortinet, and then click on login
10:32with Forta Cloud. Or if
10:33you're activating a license, and let's say a month ago or two months ago, your
10:37management IP address
10:38was one address, and now you want to use a different address, like you're rede
10:41ploying it in a different
10:42location. You'd also want to go up to support.fordnet.com and go to the details
10:47where your license is
10:48and specify what the management address is, give that a minute to settle, and
10:52then you could go
10:52ahead and use it here. So I'm just like free trial, putting my username and
10:55password and click on
10:56login with Forta Cloud. Well, I've got a free trial license agreement. I will
11:00accept that,
11:01scroll all the way to the end, click on accept, and now it's going out because
11:04it can. It can do
11:06name resolution. It can go out to the cloud services. So now it's going to
11:09restart to apply that trial
11:10license. And there's also limits on how many trial licenses you can have. So if
11:14you had a trial
11:15license, for example, five or six months ago, they may or may not let you have
11:19another trial
11:19license going forward. So we'll find out together in a minute or two what the
11:23status of a new trial
11:25license attempt is here, because I have had a trial license in the past. And as
11:29we go forward,
11:30for the actual Fortam manager we're going to be using, I've actually got a
11:33license that supports
11:34I think up to 13 devices. And so we'll be using a license copy going forward.
11:38But I did want to
11:39show you the process for deploying and getting a new Fortam manager up and
11:43running. So I still
11:44have the console open for this virtual machine. So it rebooted. And it actually
11:48applied this new
11:49serial number and it's doing an upgrade of sample reports and how it says it's
11:52ready to login. So
11:54for this page back here, I'm going to go ahead and hit F5 to refresh it, click
11:59on advanced and
12:00proceed and let's log in again. All right, so it's less than you to log in
12:03locally. Now this is the
12:05admin account and the password I set up at the CLI at the Fortam manager. So I
12:09'll log in as
12:10admin, I'll supply the password, and then we'll click on login. It says VM
12:13license is invalid,
12:14because system cannot find the matched management IP address. And that may be
12:18because I already
12:19had a previous license, they don't want to give you another eval license. In
12:22any case, at this
12:23point, I could just drag and drop my license file here, it would check that to
12:27make sure it's valid
12:28and then be up and running. So let me go ahead and I'm going to go ahead and
12:32log out. And let me
12:33show you here from the Fortam manager administrator guide for this version of
12:37Fortam manager. Let me
12:38show you what the wizard would look like in the event did continue. So if you
12:42did qualify for an
12:43eval license or you have a license file that you supplied, it would then walk
12:46you through this
12:47automated setup where make sure that you're registered with FortaCare, you
12:50specify the host
12:51name, you've changed your password, you've upgraded the firmware, and also it's
12:54going to encourage
12:55you to do a backup. And that's going to be presented after we do the initial
12:58login once it's called
12:59home, the Fortam manager is called home, and is validated the license that you
13:03have. So in our case,
13:04what I'm going to do is I'm going to take this Fortam manager demo, which we're
13:07no longer going
13:07to need. I'm going to right click and go to power, and I'm going to go ahead
13:11and I'm just going to
13:13power it off. Now that's not a graceful power off, that's just turning off the
13:16power like pulling
13:17the plug, but we're not going to be using it anymore. So it's going to turn off
13:20very quick,
13:21and I'll right click on that FMG demo, and then scroll down and just to delete
13:25from disk,
13:26and just remove it from my vSphere environment. Another is gone, we can go back
13:31up here,
13:31go to the FMG 2025, and it is in the state where I've just brought it up. I've
13:37configured the IP
13:38addresses, it's licensed, and it's ready to rock, but nothing else has been
13:42done on it. Let me go
13:43ahead and power this up. While it's powering up, let's launch a remote console,
13:46just take a look
13:47at its progress as it powers up. And then once it's up, I sort of log in and
13:51confirm we can log in
13:52via the GUI to this Fortam manager. And this is going to be the one we're going
13:57to be using going
13:58forward for the downloads and the integration with 40 analyzer and the onboard
14:02ing of 40 gates
14:03and the centralized management of those 40 gates. So we're just going to give
14:06it a minute until we
14:07have a prompt here indicating it's ready for us to log in. Also, even if the
14:11command line, like the
14:12console view says, you know, go ahead and log in, it may take a few extra
14:17seconds or two for all the
14:19back end stuff that supports the web interface to fully initialize. So if it
14:23does say log in here,
14:25you may want to give it a moment or two before logging into the GUI, just to
14:28make sure that it's
14:29ready. All right, says upgrading sample reports is done. And in a moment, we
14:33should have a prompt
14:34and once that shows up, we'll then try the GUI once again. All right, there's
14:39our FMG 2025 login,
14:41and let's go to another window and try logging in. All right, so I've connected
14:45to HTTPS colon
14:46slash one 92 dot 168 dot one dot 82. This is a good sign is asking me to log in
14:52a log down is the
14:53local admin account will supply the password and we'll click login. All right,
14:58fantastic. So it's
14:59registered. I've got a license that'll support up to 13 managed devices, which
15:04is also going to
15:05include V doms virtual domains if we have those set up, and it's been up for
15:09about three minutes
15:10and seven seconds, because we just powered it up and it's running version seven
15:13dot six three.
15:14So now that we have this 40 manager set up, and is currently connected to the
15:19internet,
15:20in the next video, I'd like to give you a high level tour of the graphical user
15:24interface here
15:25on 40 manager. So see you in the next video for exactly that.
FortiManager GUI Overview
0:00So in the previous video, we took our newly deployed Port-a-Manager,
0:03we then with some troubleshooting, set up and made sure it had a default
0:08gateway that was functioning,
0:09also the IP address that we wanted to use, and we also verified that we could
0:13log in to the GUI.
0:14So now that it is up and running and available, in this video, I'd like to give
0:18you a high-level
0:19tour of the graphical user interface here on the 40-Manager. So here in the 40-
0:24Manager, they have
0:25changed the interface a little bit over the years. So instead of having the
0:29tiles that they had
0:30previously, they simply have the options here on the left. So here's the
0:34dashboard. Much like other
0:35Fortnite products, you can toggle the widgets you want to see or not see based
0:39on what you want to
0:40have available here on the dashboard. So here's the system information, I'll
0:43make that bigger,
0:44it has the host name, serial number, the HA status, the firmware version,
0:49whether or not
0:49administrative domains are enabled or not, and also whether or not 40-analyzer
0:53features are
0:53enabled. So just as it heads up, 40-analyzer features allows some of those same
0:58functions,
0:59not quite the elaborateness of 40- Analyzer, but if you don't have a dedicated
1:0340- Analyzer
1:04appliance or device, you can tell the 40-Manager that you want some of those
1:08features here,
1:09and it'll give you like a subset of 40- Analyzer features built in as part of
1:1440-Manager.
1:15But because we already have a separate 40- Analyzer, we don't need to enable
1:18that. So
1:18go ahead and close that. And there's license information, system resource
1:22information,
1:23the ports involved under unit operation, also right here, we can click on
1:26restart or shut down
1:27if you want to restart or shut down the 40-Manager. And there's other widgets
1:31as well.
1:31As we go down, there's device manager, this is how you'd manage your devices.
1:35For example,
1:35like 40-gate firewalls, then we have policy and objects, including packages
1:38that we can use
1:39with those 40-gate firewalls. There's an SD-WAN manager, there's an AP manager,
1:44a Fortnite switch
1:45manager, an extended manager, a fabric view section, and one for 40-AI, which
1:50is a separate
1:50license product. So if you want to use 40-AI, you have to purchase that license
1:55as well,
1:55a section for Fortiguard, and then a final section for system settings. So
1:59under system settings,
2:00if you scroll down and we go to network, this is where we can see the network
2:04from the GUI.
2:05So here's port number one, there's the IP address 192.1.82 with a 24-bit mask.
2:11If we scroll down,
2:12here's the DNS that we configured for IPv4, and here's our default route with
2:17the default gateway
2:18being 192.168.1.1. And here, under settings, we can control the default HTTP
2:25port and HTTPS
2:26port. Should you need those changed? We're going to redirect from HTTP over to
2:30HTTPS.
2:31And if you want to change the look and feel here, we can. So currently, I have
2:3540-analyzer
2:36with a cat theme. So for Fortiguard, let's go ahead and how about a summer
2:42theme. And that way,
2:43when we see it, we'll know exactly where we're at. We'll click on apply, and
2:46that's going to refresh
2:47this page. And now that that's done, let's go back to the dashboard page, which
2:51is right here.
2:52Fantastic. And let's confirm what we've done. We deployed the Fortiguard as a
2:56VM on-prem. We
2:58also configured its IP address, the DNS information and the default gateway. So
3:02we could go ahead
3:03and reach out to Fortinet services on the cloud, which is critical if we want
3:07to have either the
3:08e-Vell license or our actual license we're using be applied to this Fortin
3:11Manager. Now, there are
3:14some of the corner cases where if we have a Fortin Manager that's air-gapped
3:16and you can't get to
3:17the internet, there's also options for applying a license there. However, for
3:21most companies,
3:22they're going to want Fortin Manager with access to the internet, not only for
3:25licensing, but also
3:26for updates and care and feeding from Fortiguard. And so now that this Fortin
3:30Manager is in place
3:32in our network, in subsequent sets of videos and subsequent skills, we can take
3:36a look at doing the
3:36next logical steps, which could include things such as setting up
3:40administrative domains,
3:42configuring additional administrators, and making sure that our Fortigate firew
3:46alls as well as our
3:48Forti Analyzer are tightly integrated and onboarded here at the Fortin Manager.
3:53So all that more
3:53will cover in subsequent sets of skills.
Validation Section
0:00To wrap up this set of videos regarding Ford manager and the deployment of the
0:04Ford manager,
0:04I'd like to propose a customer scenario. Let's say that you and I are
0:08consulting for a company
0:10and they're not sure whether or not a Ford manager is a justifiable expense
0:15that they should add to
0:16their network. So what are the things that we could say to them that would help
0:21identify whether
0:22or not it would be valuable and worth the expense? Because the licensing is not
0:26free, that's for sure.
0:27So how do we approach this? So what I'd like you to do is this, pause the video
0:31right now,
0:32take a moment, consider some of the factors that might be a good business case
0:37for using a Ford
0:38manager and then when you're done, click on resume and then we can collaborate
0:42in preparation for
0:43meaning with that customer. So I'll see you in a few moments after you have a
0:47chance to consider this.
0:48So I'm curious what are some of the items or ideas that we should bring up to
0:56the customer
0:57that you thought of? So I have a few of my own and let's just chat about that
1:00for a moment. Number one,
1:02if they have like one 40 gate firewall and maybe a switch and an access point,
1:08they probably don't
1:09need for the manager. However, if they've got five or more 40 gate firewalls,
1:15the centralized
1:17management that Ford manager brings to the table is going to save them a lot of
1:20configuration
1:21mistakes. And it's also going to make sure they have more consistency in their
1:25deployment and
1:26have a better view of what's happening on the network, whether they use the
1:30internal logging here
1:31at the Ford manager or if they're integrating a 40 analyzer. So I'm going to
1:35say the first major
1:36benefit is centralized management. The second big thing is going to be saving
1:40time. So if they do
1:41have multiple firewalls and they want to push out or update configs or the
1:46policies, the actual time
1:47to do that is going to be a lot less time if they're using templates and
1:52pushing out those policies
1:53to all the 40 gate firewalls or two groups of firewalls based on what
1:57configurations need to go
1:58where. So as far as time savings, they're going to save time with
2:01configurations of any type on
2:03the 40 gates and also going to save time with updates. So if they're updating
2:06firmware, those
2:07firmware updates after they get through change control and testing, those are
2:10going to take a
2:10lot less time as opposed to doing it firewall by firewall by firewall, we have
2:15all that pushed out
2:16via Ford manager. Also, because we're doing centralized management, we're also
2:19going to have
2:20centralized reporting and monitoring. And that's also important to have
2:23centralized because if there's
2:24like a virus that's out breaking on the network or a worm or something else
2:27that's happening or
2:28malware and it's going from machine to machine to machine across different
2:32parts of our network,
2:33it'd be good to have a bird's eye view of exactly what's happening. So 40 analy
2:38zer can certainly help
2:39with that. And the 40 manager in conjunction with 40 analyzer can help with
2:43that as well. Because
2:44instead of just wondering if the firewalls are all in sync as far as their
2:47policies and configurations,
2:48or if we're wondering, I wonder if somebody logged in locally made a change
2:52here,
2:52Ford manager can track all of that and give us reports and identify exactly
2:57what change,
2:58for example, when it shouldn't, sometimes this referred to as configuration
3:01drift,
3:01where, you know, configuration change over time, but they're not authorized. So
3:05the 40 manager can
3:06help us be aware of that and also help lock that down. And if this customer
3:09wants to set up
3:10separate management domains, for example, maybe having one group of admins in
3:16charge of this,
3:16set a firewall, and another admin over here responsible for this one, or maybe
3:20they have
3:20some customers were using virtual domains inside of the firewalls, and we're
3:24splitting up the firewalls,
3:26and we want to give individual customers access into certain portions of those
3:29firewalls. Another
3:31really good benefit of Ford manager is that we can literally set up those
3:34separate administrative
3:35domains that can contain individual firewalls or individual V-dombs from
3:39specific firewalls,
3:41and that way they can give management access and visibility to the right admins
3:45, whether those
3:46admins are all in-house or whether those admins are individual customers
3:51leveraging some of the
3:52services provided by the service provider, and a really quick way of
3:55identifying whether or not
3:56Ford manager would be valuable for a company is if they have multiple firewalls
4:01. So if they've got,
4:02like, five or six 40 gates, plus they have four to switch behind that and 40 AP
4:07s and so forth,
4:08it's very likely they're going to benefit with all these options by using Ford
4:12manager. For a
4:13company that has a single 40 gate, no, because if they have a single 40 gate,
4:17it's a one-stop shop
4:19regarding all the stuff that's going on, and they really don't need to have a
4:22centralized ability to
4:23manage all their 40 gate firewalls if they just have one. So thanks for joining
4:27me. In this set of
4:28videos regarding getting a Ford manager deployed on a network, and we're going
4:31to use this infrastructure
4:32as we go forward in our subsequent set of skills regarding Ford manager. So I
4:36look forward to seeing
4:37you, my friend, in those sets of videos in the very near future. Until then, I
4:42hope this has been
4:42informative, and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year