Skip to main content
pjang
Staff & Editor
Staff & Editor
October 4, 2024

Technical Tip: FortiGate Security Fabric is unable to show Firewall Objects in conflict (Known Issue)

  • October 4, 2024
  • 2 replies
  • 1422 views
Description

This article describes a known-issue with firewall object synchronization in the Fortinet Security Fabric. Admins may notice the following symptoms related to this issue:

  • FortiGates in the Security Fabric will display a warning indicating that there are firewall object conflicts between the Root and Downstream FortiGates.
  • An orange 'Fabric Conflicts' warning may appear in the top-right corner when visiting a sub-section of Policy & Objects in the web GUI (such as Addresses).
    • Hovering over this warning will display a message stating 'Objects in this table conflict with other FortiGates in the Fabric', as well as a button to 'Review firewall object conflicts'.
  • When viewing the Firewall Object Synchronization page on the FortiGate, no entries will be displayed (i.e. blank white page and/or 'No results' shown).
  • Additionally, an error message will appear in the bottom-right corner stating 'Error occurred while synchronizing tables'.
Scope FortiGate, Security Fabric.
Solution

FortiGates within the Security Fabric can configure and synchronize firewall objects (such as address, service, and schedule objects) between one another. In the event of a conflict between members of the Fabric (such as a mismatch between object names), the FortiGate has a wizard that can be used to identify and resolve these conflicts. See the Additional Reading section below for more information regarding Security Fabric synchronization.

 

With that in mind, a known issue can occur when there is a significant number of object conflicts/differences (e.g. roughly 100 conflicts or more) between two FortiGates in the same Security Fabric.

When this occurs, the symptoms mentioned above in the Description can occur where the FortiGate is unable to display the list of object conflicts and assist in the conflict resolution process. As a workaround, it is possible to manually compare the FortiGates various firewall object lists (under Policy & Objects) and manually resolve the differences.

 

Figure 1: Review firewall object conflictsFigure 1: Review firewall object conflicts

 

Figure 2: Firewall Object Synchronization page. Note the 'error occurred while synchronizing tables' message.Figure 2: Firewall Object Synchronization page. Note the 'error occurred while synchronizing tables' message.

 

With that being said, this issue has been identified by the Fortinet development team as Issue #863126, and it has since been resolved as of v7.0.13, v7.2.6, and v7.4.1.

Admins are recommended to upgrade to the listed versions or later to resolve the issue, and it is not necessary to resolve the fabric object conflicts beforehand (the synchronisation wizard can assist with conflict resolution afterwards).

 

On v7.4.8, the same error, 'Firewall Objects conflict', is classified as a GUI issue and is resolved:

  1. After restarting the downstream FortiGate and root FortiGate.
  2. Creating a new temporary address object with fabric-object enabled.

 

Related documents:

2 replies

communitas
New Member
June 22, 2026

i’m on 7.2.13 and the issue is back. So, not resolved.

communitas
New Member
June 22, 2026

no firewall objects in any fortigate I have are fabric global anyway, so how can there be any conflicts? 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!