Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
elyamania
New Contributor

Change DNS configuration from Fortimanager

We have +700 Firewalls Fortigate managed with the Fortimanager and the FWs are configured with DNS and now we want to change the DNS IP adress in all the FWs Hwo to change the configuration of the DNS in devices (Firewalls) from the fortimanager?

2 Solutions
sw2090
Honored Contributor

The only way to do that - assuming you want the same DNS settngs on all FGT - would be to assign them to a provisioning template and enable the dns module in there and set it up there.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Yurisk

I'd suggest to look into scripting this on FMG side - this is exactly the use case for scripting. You can run the same CLI script on all Fortigates or run TCL script on device database then push to all the Fortigates.

Example to start reading: Administration Guide | FortiManager 6.2.0 | Fortinet Documentation Library

Also some experience sharing here Useful script example on Fortimanager | Fortinet Technical Discussion Forums

 

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.

View solution in original post

Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
4 REPLIES 4
sw2090
Honored Contributor

The only way to do that - assuming you want the same DNS settngs on all FGT - would be to assign them to a provisioning template and enable the dns module in there and set it up there.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Yurisk

I'd suggest to look into scripting this on FMG side - this is exactly the use case for scripting. You can run the same CLI script on all Fortigates or run TCL script on device database then push to all the Fortigates.

Example to start reading: Administration Guide | FortiManager 6.2.0 | Fortinet Documentation Library

Also some experience sharing here Useful script example on Fortimanager | Fortinet Technical Discussion Forums

 

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
sw2090
Honored Contributor

why should you script that if there is a more easier way? This can simply be done using provisioning template in FMG Device Manager. This is exactly one of the cases provisioning templates are there for.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Yurisk

I guess "more easier" is in the eye of the beholder :) - for me it is easier to run scripts than to mess and risk unpredictable consequences of templates, YMMV.

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Labels
Top Kudoed Authors