A FortiGate estate rarely becomes difficult because of one firewall. It becomes difficult when a change needs to reach 20 branches, a compliance review needs proof of who approved a rule, or a rushed troubleshooting fix quietly creates policy drift between sites. That is the point at which IT leaders start asking: is FortiManager worth using?
For many Australian organisations running more than a small number of FortiGates, the answer is yes - provided it is deployed with a clear operating model. FortiManager centralises policy administration, device configuration and change control across Fortinet firewalls. Its value is not simply that it gives administrators one console. Its value is that it makes security management more repeatable, auditable and commercially manageable as the environment grows.
What FortiManager Actually Solves
FortiManager is Fortinet’s central management platform for FortiGate devices. Rather than having engineers sign in to each firewall separately, it provides a structured way to manage devices, common objects, policy packages, firmware planning and configuration changes from one place.
The practical benefit is consistency. A standard branch firewall policy can be designed once, then applied across comparable sites without rebuilding it device by device. Shared address objects, services and security profiles can be controlled centrally. When a new site opens, approved templates can shorten provisioning and reduce the likelihood that a key setting is missed during deployment.
That consistency matters for more than efficiency. Security incidents frequently expose basic operational gaps: an outdated policy at one branch, a temporary rule that was never removed, or a site that did not receive the same protective controls as the rest of the business. FortiManager helps teams identify and reduce that drift.
It also creates a more disciplined change process. Administrators can review policy changes before installation, retain revision history and work through controlled workflows rather than making untracked edits directly on live devices. For organisations subject to customer assurance requests, internal governance or regulatory obligations, that visibility is often as valuable as the time saved.
Is FortiManager Worth Using for Your Environment?
FortiManager is usually worth the investment when Fortinet management has become an operational task rather than an occasional administrative task. A business with one or two FortiGates and infrequent changes may gain limited value from introducing another platform. The direct management interface on each firewall can be perfectly suitable when the network is simple and the people managing it know the configuration well.
The calculation changes as soon as there are multiple sites, separate network zones, different business units or a need for standardised security controls. An organisation with ten locations does not necessarily have ten times the work. Without central management, however, it can have ten different versions of the same rule set, ten separate change records and ten opportunities for errors.
FortiManager is particularly well suited to organisations with:
- Multiple branches, warehouses, retail locations or distributed offices using FortiGate firewalls.
- A mixture of firewall models that still require consistent policies and security profiles.
- Internal or external audit requirements that demand clearer evidence of configuration control.
- Lean IT teams that need to apply approved changes quickly without sacrificing review processes.
- A managed service model where engineers administer separate customer or business environments securely.
The Features That Create Real Value
Policy packages and shared objects
Policy packages allow administrators to manage policies centrally for defined groups of FortiGates. A national business may use a common package for standard branches, another for head office and a separate package for higher-risk locations. This avoids forcing every firewall into an identical design while preserving common controls where they matter.
Shared objects are equally important. Address groups, service definitions, schedules and security profiles can be built once and reused. This improves naming consistency and reduces duplicate objects that make firewall rules harder to understand over time.
Administrative domains for separation
Administrative domains, commonly called ADOMs, allow environments to be separated within the platform. This is useful for enterprises with distinct divisions, organisations managing production and non-production environments, or service providers supporting multiple customers.
The separation is not merely cosmetic. It helps limit administrative scope, organise policy ownership and support a cleaner governance model. A network team should not need to sift through unrelated rules to make a controlled change in its own environment.
Revision history and controlled installation
A central platform is most valuable when it improves operational discipline. FortiManager records revisions and supports the review of pending changes before installation. If a policy deployment produces an unexpected outcome, administrators have a clearer path to understand what changed and when.
This is not a substitute for formal change management, testing or peer review. It does, however, give those processes a more reliable technical foundation. For organisations with limited security staff, that structure can materially reduce operational risk.
Standardised provisioning
New sites are where configuration shortcuts often appear. A project deadline approaches, equipment arrives, and an engineer builds what is needed to get connectivity working. Later, the team discovers the branch has a different logging setting, management access configuration or security profile from the approved standard.
FortiManager supports a more repeatable approach to provisioning. With well-designed templates and policy packages, IT teams can deploy new FortiGates according to an agreed baseline, then apply only the site-specific variations required for local connectivity.
Where FortiManager Can Be Overkill
FortiManager is not automatically the right answer for every Fortinet customer. It introduces a platform that must be designed, maintained and administered. Teams need to understand the relationship between device-level settings, centrally managed policy, local exceptions and installation workflows.
A small business with a single FortiGate, a straightforward internet connection and minimal policy changes may see more complexity than benefit. The cost of licensing or infrastructure, plus the time required to configure the management environment properly, may not be justified.
It can also disappoint teams that expect it to repair a poorly defined network design. Central management amplifies good standards, but it can distribute poor standards quickly as well. Before deploying it, organisations should rationalise firewall objects, document rule ownership and decide which policies should be global, regional or site-specific.
There is also a skills consideration. FortiManager is easier to operate when the team understands FortiGate policy behaviour and has a disciplined process for testing, approving and installing changes. A certified implementation partner can reduce the initial learning curve and prevent the platform becoming an underused dashboard.
FortiManager, FortiAnalyzer and Direct Management
FortiManager is sometimes confused with FortiAnalyzer because both support larger Fortinet environments. Their core purposes are different.
FortiManager focuses on configuration, policy lifecycle and central administration. FortiAnalyzer focuses on log collection, investigation, reporting and visibility. Most multi-site organisations benefit from both functions, but the business case should be assessed separately. Centralising firewall policy does not automatically provide the retention, reporting depth or incident investigation capability required from a logging platform.
Direct device management remains appropriate for small, stable environments. It is simple and has no central policy workflow to learn. The trade-off is that every change relies on people following the same process on every firewall, every time.
Cloud-based management may also suit organisations that want a lighter operational model. FortiManager becomes the stronger choice where policy scale, segmentation, governance and detailed administrative control are priorities.
How to Make the Investment Pay Off
The return on FortiManager depends heavily on implementation quality. Start by grouping devices according to genuine operational similarity, not just location. A small branch and a high-traffic distribution centre may both be remote sites, but they are unlikely to need the same policy package.
Establish naming standards before importing years of inconsistent objects. Define who owns policy approval, who can make emergency changes and how local exceptions are reviewed. Keep policy packages focused, and avoid creating so many variations that central management simply mirrors the disorder of direct administration.
It is also sensible to phase the rollout. Begin with a representative group of FortiGates, validate the templates and operational workflows, then expand in controlled stages. This approach protects business continuity and gives administrators time to become comfortable with the platform.
For organisations buying new FortiGate infrastructure or rationalising an existing estate, FortiSecure Store can help align the FortiManager design, licensing and implementation approach to the actual network rather than a generic bill of materials. That keeps the commercial investment connected to measurable operational outcomes.
The Practical Verdict
FortiManager earns its place when security policy needs to be consistent across more than a handful of FortiGates, when changes need accountability, or when a growing organisation cannot afford configuration drift. It is an operational control platform, not just a management console.
The best time to introduce it is before manual firewall administration becomes a source of risk, not after an audit, outage or security incident exposes the gaps. Build the standards first, deploy in stages and treat central management as part of your security operating model. That is how Fortinet security is done right, with cost and effort kept under control.

