Skip to main content
LarW63
New Member
February 7, 2019
Question

ADOM package inspection mode is not consistent with its target VDOM inspection mode

  • February 7, 2019
  • 3 replies
  • 9711 views

Hi,

 

We're using FMG v5.6.7.  I was in the middle of updating some Objects in the Global ADOM and I Assigned All Objects to an ADOM called NS-Custom.  I then went to the NS-Custom ADOM to apply Policy updates to the Fortigates and every single one fails with "ADOM package inspection mode is not consistent with its target VDOM inspection mode".  At this point I'm stuck and cannot update any of the Fortigates under this ADOM.

 

Has anyone encountered this problem before and is there a fix?

 

Thank you,

LarW63

3 replies

brazz_FTNT
Staff
Staff
February 7, 2019

Hello, 

 

Thanks for sharing this case here. 

 

As you mentioned the package inspection mode is different.  

Go to CLI and run below command:

execute fmpolicy print-adom-package "Global"  <package name>  "policy package settings" +all

 

You may find the package name by typing the "?" like  execute fmpolicy print-adom-package "Global"  ?

 

 

Can you paste us the results here. 

*** I would like to see the current package inspection mode in your Global ADOM. *** Do you know how to check the  current package inspection mode in  ADOM NS-Custom?

go to Policy & Objects and right click on the policy package.

 

Also review this  https://forum.fortinet.com/tm.aspx?tree=true&m=158228&mpage=1

 

Let me know how it goes .

Thanks 

 

 

donatellamiller
New Member
February 8, 2019

If ADOMs are enabled, the Select an ADOM pane is displayed.Ensure that the installation targets for the policy package include the correct devices. or you may check Windows Resource Protection Could Not Perform The Requested Operation

Paul_Roberts
New Member
April 11, 2019

Hi   Had exactly the same problem going from 5.4 to 5.6.  Having upgraded the firewalls went into the ADOM and upgraded to 5.6.  Then had the error message when trying to push policy. Noticed if you right click on the policy name and click edit, it has the options for flow based or proxy based.  If 5.4 this isnt an option so in the upgrade it has automatically selected flow based, so once selected proxy based was able to push polices again.

 

Paul

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!