Managing multiple firewalls individually across distributed remote locations quickly leads to configuration drift, human error, and compliance auditing headaches. Fortinet centralizes device administration through FortiManager, allowing security teams to control security policies, firmware upgrades, and device settings from a single management console. Knowing how to add FortiGate to FortiManager correctly ensures seamless onboarding without disrupting existing network connectivity or overwriting critical local settings.
In this technical tutorial, you will learn how to prepare a FortiGate firewall, establish a secure management tunnel to FortiManager, authorize the device, and import its running configuration and policy package into an Administrative Domain (ADOM).
Real-Life Scenario
A growing enterprise organization is deploying a new branch office firewall (named FGT-BRANCH-01). The local firewall has already been deployed with basic interface settings, WAN routing, and local security policies to provide immediate internet access to local users.
The network engineering team must now onboard FGT-BRANCH-01 into the primary central management appliance (FMG-HQ-01). The key requirements for this onboarding process are:
- Establish a secure, encrypted management channel between the branch firewall and FortiManager.
- Import the existing running firewall configuration and local policy rules without causing network downtime.
- Ensure future policy modifications and security profile updates are deployed centrally from FortiManager.
Lab Topology
The following diagram illustrates the management path between the HQ FortiManager and the Branch FortiGate across the network infrastructure.
+------------------------------------+ +------------------------------------+
| FMG-HQ-01 | | FGT-BRANCH-01 |
| (FortiManager Unit) | | (FortiGate Unit) |
| | | |
| Management IP: 192.0.2.100/24 | | WAN IP: 198.51.100.1/24 |
| ADOM: Branch-Firewalls (v7.2) | | FortiOS: 7.2.5 |
+-----------------+------------------+ +-----------------+------------------+
| |
| |
+------------------ [ IP Network ] ------------------+
Encrypted FGFM Tunnel
(TCP Port 541)
Example Addressing and Objects
The table below lists the lab environment attributes referenced throughout this guide. Replace these LAB values with your production environment parameters.
| Device Name | Role / Description | IP Address / Subnet | Interface | Management Access |
|---|---|---|---|---|
FMG-HQ-01 |
Central Management Appliance | 192.0.2.100/24 |
port1 |
HTTPS, SSH, FGFM |
FGT-BRANCH-01 |
Remote Branch Firewall | 198.51.100.1/24 |
port1 (WAN) |
HTTPS, SSH, Ping, FGFM |
FGT-BRANCH-01 |
Branch Local Gateway | 203.0.113.1/24 |
port2 (LAN) |
HTTPS, SSH, Ping |
Prerequisites
Before connecting your FortiGate to FortiManager, verify that the following prerequisites are met:
- Software Compatibility: The FortiManager firmware version must equal or exceed the highest FortiOS version among managed devices. Always consult the Fortinet Firmware Compatibility Matrix before onboarding.
- ADOM Configuration: Administrative Domains (ADOMs) must be enabled on FortiManager if you manage devices running different FortiOS major releases or maintain multi-tenant environments. Ensure an ADOM matching the FortiGate OS version exists.
- Network Reachability: Firewalls, routers, or access control lists (ACLs) between the devices must permit bidirectional communication on TCP port 541 (the FortiGate to FortiManager or FGFM protocol).
- Administrative Rights: You need an administrator account on FortiManager with read/write permissions to the target ADOM, and full administrative access on the target FortiGate.
Step-by-Step GUI Configuration
You can add a FortiGate to FortiManager using either a FortiManager-initiated discovery (push method) or a FortiGate-initiated registration (pull method). This section covers the recommended discovery workflow initiated from FortiManager.
Phase 1: Enable Management Access on FortiGate
FortiGate will reject management probes if the managing interface does not explicitly permit FortiGate-to-FortiManager (FGFM) protocol traffic.
- Log in to the FGT-BRANCH-01 web GUI.
- Navigate to Network > Interfaces.
- Select the incoming interface connected to the management network (e.g.,
port1) and click Edit. - Under Administrative Access, ensure the check box for FGFM is enabled.
- Click OK to save changes.
Phase 2: Discover and Register the FortiGate in FortiManager
Now, execute the discovery process from the FortiManager administrative console.
- Log in to the FMG-HQ-01 web GUI.
- Ensure you are in the correct Administrative Domain (e.g.,
Branch-Firewalls) using the top-left ADOM drop-down menu. - Navigate to Device Manager > Device & Groups.
- Click Add Device in the top toolbar.
- Select Discover Device.
- Enter the management IP address of the target FortiGate (e.g.,
198.51.100.1). - Enter the administrative credentials for the FortiGate unit (username:
admin) and click Next.
FortiManager connects to the FortiGate over TCP port 541, queries device details, and validates local serial numbers and firmware levels.
Phase 3: Complete Import Wizard and Create Policy Package
Once FortiManager discovers the FortiGate, complete the import wizard to pull the device settings and policy definitions into the FortiManager database.
- Verify the displayed device details (Model, Serial Number, Firmware Version) match your branch firewall.
- Assign a meaningful Device Name (e.g.,
FGT-BRANCH-01). - Click Next to proceed to the configuration import settings.
- Select Import Policy Configuration to ADOM. This action pulls local firewall policies, address objects, and security profiles into the central database.
- Specify a name for the new Policy Package (e.g.,
FGT-BRANCH-01-Policy). - Review the object conflict resolution screen if prompted. Select whether to keep FortiManager’s existing ADOM values or overwrite them with the local FortiGate values.
- Click Finish to complete the onboarding process.
CLI Configuration
For headless deployments, remote automation, or low-bandwidth environments, onboarding can be configured directly from the CLI. This section provides the precise commands needed on both devices.
1. Enable FGFM Access on FortiGate Interface
Configure the WAN/Management interface to allow incoming FGFM management connections:
config system interface
edit "port1"
set ip 198.51.100.1 255.255.255.0
set allowaccess ping https ssh fgfm
next
end
2. Point FortiGate to FortiManager
Configure the central management configuration block on the FortiGate to point to the FortiManager IP address:
config system central-management
set mode normal
set type fortimanager
set fmg "192.0.2.100"
end
By executing this command, the FortiGate proactively attempts an outbound FGFM session to FortiManager on TCP port 541. It will appear under Device Manager > Unauthorized Devices in FortiManager, where an administrator can authorize it with a single click.
How Traffic Flows: FGFM Protocol Mechanics
Understanding the underlying communication model between FortiGate and FortiManager simplifies operational tracking and troubleshooting.
[ FortiGate: fgfmd ] --- (Outbound TCP 541 / SSL) ---> [ FortiManager: fgfmd ]
| |
||
| |
| |
- Session Initiation: The FortiGate
fgfmddaemon initiates an outbound TCP handshake to the FortiManager IP address on port 541. - TLS/SSL Handshake: Both devices establish an encrypted TLS tunnel. Authentication relies on built-in Fortinet device certificates issued during manufacturing, or custom PKI certificates configured by the administrator.
- Tunnel Maintenance: Once authenticated, the FGFM tunnel stays active persistently. Heartbeat packets keep the tunnel alive across intermediate stateful firewalls or NAT gateways.
- Configuration Synchronization: When an administrator edits settings in Device Manager, FortiManager constructs a staging delta file. When installed, FortiManager transfers commands through the active FGFM tunnel, applies them locally on the FortiGate, and verifies the execution result.
Verification
Verify that the FortiGate is properly registered, connected, and in-sync with FortiManager using both CLI and GUI checks.
1. Verify Central Management Status on FortiGate
Run the following operational command on the FortiGate CLI:
get system central-management status
Output verification target:
Connection status: Connected
Registration status: Registered
Management server: 192.0.2.100
FGFM local address: 198.51.100.1
Ensure that the output explicitly reports Connection status: Connected and Registration status: Registered.
2. Verify Connectivity Status in FortiManager GUI
In the FortiManager GUI, navigate to Device Manager > Device & Groups. Examine the target device table entries:
- Connection Status: Must display a green icon indicating
Up. - Config Status: Should display
Synchronized. If it displaysModified, changes were made locally on the FortiGate that have not been retrieved into FortiManager. - Policy Status: Should display
SynchronizedorImported.
Troubleshooting
If the connection fails or FortiManager shows the device as offline, follow this structured troubleshooting workflow.
Step 1: Verify Layer 3 Reachability and Routing
Test network layer communication from the FortiGate CLI to FortiManager:
execute ping 192.0.2.100
If pings fail, check intermediate routing, default gateways, and upstream physical link states.
Step 2: Check Active Management Sessions
Verify whether the FortiGate is actively trying to open a session on TCP port 541 using the session table filter:
diagnose sys session filter dport 541
diagnose sys session list
If session output shows proto_state=01 or traffic staying in a single direction, an intermediate firewall or ISP access list is dropping TCP port 541.
Step 3: Run FGFM Debug Commands
To inspect real-time connection negotiation and certificate validation errors, enable daemon debugging for fgfmd on the FortiGate.
Execute the following commands on the FortiGate CLI:
diagnose debug reset
diagnose debug application fgfmd -1
diagnose debug enable
Observe the log output. Look for key operational markers:
fgfm_connect_mgmt_idx: Attempting outbound TCP session to management server.SSL_connect error: Certificate verification failed or SSL cipher suite mismatch.FGFM challenge authorization failed: Serial number mismatch or rejected registration request on FortiManager.
Stop the active debug process after capturing the output:
diagnose debug disable
diagnose debug reset
Common Mistakes
Avoid these frequent engineering pitfalls when adding FortiGates to FortiManager:
- Incompatible OS Version Mismatch: Attempting to add a FortiGate running FortiOS 7.2 to an ADOM configured for FortiOS 7.0. The ADOM major version must match the FortiOS release.
- Missing
fgfmAccess Parameter: Forgetting to check theFGFMadministrative access box on the listening interface. The FortiGate silently drops management packets on port 541 if this option is disabled. - Unsynchronized System Time (NTP): Certificate validation within the TLS handshake fails if the system clocks on the FortiGate and FortiManager drift apart by more than a few minutes. Ensure both devices sync to a reliable NTP server.
- Duplicate Serial Numbers: Cloned FortiGate virtual machines (VMs) deployed from a single template often share identical default serial numbers. FortiManager rejects duplicate serial entries.
- Overwriting Dynamic Interfaces Unintentionally: Failing to set up interface mappings during policy package imports. Always create dynamic interface mappings in FortiManager so policies translate cleanly across different hardware models.
Production Considerations
Keep these architectural best practices in mind when operating managed FortiGate firewalls in production environments:
- Policy Install Reversion Safety: FortiManager includes an automated rollback mechanism. If an installed policy package disrupts the FGFM management tunnel, FortiGate automatically rolls back to its previous working configuration state after a brief timeout (15 minutes by default).
- Use Install Previews (Diff Check): Before pushing policy updates from FortiManager to a live production firewall, always run the Install Preview tool. Review the raw CLI command diff to ensure no unexpected policy deletions or network changes occur.
- Lock Out Local Edits: Once managed by FortiManager, disable local configuration edits on the FortiGate to prevent configuration drift. This enforcement ensures FortiManager remains the single source of truth for security policy.
- Backup Configurations Centrally: Configure FortiManager to trigger an automated revision history backup every time an administrator logs out or commits changes.
Related FortiGate Guides
- FortiGate HA and failover
- FortiGate SD-WAN configuration
- FortiGate LDAP with Active Directory
- FortiGate session troubleshooting
Summary
Connecting your firewalls to a central control plane simplifies operations and strengthens security policy governance. When you add FortiGate to FortiManager, you establish a secure, encrypted FGFM tunnel over TCP port 541, import running configurations safely into structured ADOMs, and eliminate manual local device adjustments across your enterprise fleet.