Managing customer-owned FortiGate firewalls at scale is a complex yet rewarding responsibility for MSPs. While expanding service offerings, MSPs face challenges like diverse firmware versions, multi-client policy consistency, secure remote access, and patch management. Without a centralized strategy, configuration errors and downtime can impact SLA compliance and client trust.
This guide provides MSPs with practical strategies for managing FortiGate devices efficiently, ensuring security, operational efficiency, and customer satisfaction.
Table of Contents
- Part 1: MSP Use Cases: From Cisco Meraki and HPE Aruba to Fortinet FortiGate
- Part 2: FortiGate Management Options: FortiCloud, FortiManager, and Direct Access
- Part 3: Designing Multi-Tenant Structures: ADOMs and Role-Based Access
- Part 4: Managing Customer-Owned Devices: Security, MFA, and Remote Access
- Part 5: Operational Best Practices: Policy Packages, Script Reuse, Patch Management, and Change Control
- FAQ

Part 1: MSP Use Cases: From Cisco Meraki and HPE Aruba to Fortinet FortiGate
MSPs often manage heterogeneous networks that include Cisco Meraki, HPE Aruba, and FortiGate firewalls. FortiGate offers robust security, flexible deployment, and multi-tenant management capabilities, making it ideal for large-scale operations.
MSP scenarios for FortiGate include:
- Managing multi-client firewalls across various locations
- Centralizing policy enforcement for compliance and SLA adherence
- Integrating VPNs, SD-WAN, and Zero Trust frameworks
FortiGate allows MSPs to standardize security while accommodating client-specific requirements.
Part 2: FortiGate Management Options: FortiCloud, FortiManager, and Direct Access
MSPs must choose a management platform suited to their scale:
- FortiCloud: Cloud-based, ideal for small-to-medium MSPs, supports multi-client dashboards and basic automation.
- FortiManager: On-premises or virtual appliance, supports ADOMs, policy packages, script automation, and granular change control. Recommended for multi-tenant environments.
- Direct Device Access: Useful for troubleshooting or one-off changes but inefficient for large fleets.
Example CLI command to check connected devices on FortiManager:
get device status
For hardware procurement, FortiManager appliances, or FortiGate devices, Router-Switch provides rapid delivery, global shipping, and CCIE/CCNP-level support.
Part 3: Designing Multi-Tenant Structures: ADOMs and Role-Based Access
Key multi-tenant strategies:
- Assign each client to its own ADOM to isolate policies
- Apply Role-Based Access Control (RBAC) for admins, operators, or read-only users
- Use policy packages to enforce standard security rules while allowing client-specific configurations
This ensures operational efficiency and reduces cross-client conflicts.
Part 4: Managing Customer-Owned Devices: Security, MFA, and Remote Access
MSPs must address ownership and access challenges:
- Ownership & Agreements: Define responsibilities for remote management and configuration changes
- Secure Remote Access: Use VPNs, multi-factor authentication (MFA), or Azure SAML SSO for technicians
- Monitoring & Alerts: Configure FortiAnalyzer or FortiCloud to proactively detect issues
Proper planning prevents downtime and maintains SLA compliance.
Part 5: Operational Best Practices: Policy Packages, Script Reuse, Patch Management, and Change Control
- Policy Packages: Standardize rules across clients; deploy new branches quickly
- Script Reuse: Automate repetitive tasks like VPN setup, interface configuration, and logging
- Patch & Upgrade Management: Follow upgrade order: FortiAnalyzer → FortiManager → FortiGate, and ensure ADOM compatibility
- Change Control: Document changes, version policies, and approve workflows to minimize errors
These practices reduce human error, simplify management, and enhance client satisfaction.
FAQ
Q1.What is the difference between FortiCloud and FortiManager?
FortiCloud is cloud-based for small-to-medium MSP deployments with centralized dashboards. FortiManager is on-premises or virtual, supporting multi-tenant ADOMs, policy packages, scripting, and granular control.
Q2.How can MSPs securely manage customer-owned FortiGate devices?
Use formal agreements, secure VPN or SAML SSO, MFA, and monitoring tools like FortiAnalyzer or FortiCloud alerts for proactive management.
Q3.How to design ADOMs for multi-tenant management?
Assign each client its own ADOM, apply RBAC, and use policy packages for standardization with client-specific flexibility.

Expertise Builds Trust
20+ Years • 200+ Countries • 21500+ Customers/Projects
CCIE · JNCIE · NSE7 · ACDX · HPE Master ASE · Dell Server/AI Expert



































































































































