Cisco to Fortinet Overcomplication with objects and IPs
I am new to Fortinet / Fortigate and come from a Cisco background. I am considering swapping a Cisco firewall with a Fortigate firewall, however, there is 1 big roadblock stopping me from doing so.
The Cisco firewall in question has a relatively complex set of VPN tunnels that tunnel only to a list of specific IP addresses. This is essentially to allow a more secure configuration of only allowing a single IP to access certain services across a national footprint from several small offices that only have dynamic IP internet services. Rather than have X user per site all need to use a VPN client to individually to tunnel to the specific destinations, permanent tunnels are in place at each location that tunnels only traffic to the "protected" services for ease of access. Each office also has a slightly different list of IPs it can access.
On the cisco I basically have 4 different object-groups each with the correct list of IPs in them. Where Fortinet seemingly makes things overly complicated is that there does not appear to be a way to create a group of IPs where the IP addresses are merely specified. Fortigate seems to require that every IP used in a group FIRST have an INDIVIDUAL separate object created for it in order to place the IP address in a group.
I have a list of about 60 total IP addresses. It seems extremely clunky/disorganized to have to create 60 objects for IP addresses that will NEVER be referenced outside of the object group.
I am hoping that I am missing something and there is a more straightforward way that makes more sense to do this on the Fortigate.