Technical Tip: FortiManager CLI Configuration for ztna-tags-match-logic Not Pushing to FortiGate from CLI
| Description | The article describes that when modifying a ZTNA policy in FortiManager to change the ztna-tags-match-logic from OR to AND via CLI, the changes appear to be correctly applied but when the install wizard is used the setting reverts to default settings and do not get pushed on the FortiGate. |
| Scope | FortiGate, FortiManager. |
| Solution | The changes made in CLI through FortiManager appear correct initially but do not get saved after running the install wizard: LS-FGT80F-0001 (82) # show
Ensure that the changes are made correctly in FortiManager's ADOM database rather than directly on the FortiGate.
On the GUI the option can be found under Policy & Objects -> Firewall Policy, scroll down and expand Advanced Options look for ztna-tags-match-logic setting, and update it as needed.
After, the above setting push the install wizard and now it should save the config.
|

