Technical Tip: FortiGate Security Fabric is unable to show Firewall Objects in conflict (Known Issue)
| Description | This article describes a known-issue with firewall object synchronization in the Fortinet Security Fabric. Admins may notice the following symptoms related to this issue:
|
| Scope | FortiGate, Security Fabric. |
| Solution | FortiGates within the Security Fabric can configure and synchronize firewall objects (such as address, service, and schedule objects) between one another. In the event of a conflict between members of the Fabric (such as a mismatch between object names), the FortiGate has a wizard that can be used to identify and resolve these conflicts. See the Additional Reading section below for more information regarding Security Fabric synchronization.
With that in mind, a known issue can occur when there is a significant number of object conflicts/differences (e.g. roughly 100 conflicts or more) between two FortiGates in the same Security Fabric. When this occurs, the symptoms mentioned above in the Description can occur where the FortiGate is unable to display the list of object conflicts and assist in the conflict resolution process. As a workaround, it is possible to manually compare the FortiGates various firewall object lists (under Policy & Objects) and manually resolve the differences.
With that being said, this issue has been identified by the Fortinet development team as Issue #863126, and it has since been resolved as of v7.0.13, v7.2.6, and v7.4.1. Admins are recommended to upgrade to the listed versions or later to resolve the issue, and it is not necessary to resolve the fabric object conflicts beforehand (the synchronisation wizard can assist with conflict resolution afterwards).
On v7.4.8, the same error, 'Firewall Objects conflict', is classified as a GUI issue and is resolved:
Related documents: |


