Skip to main content
Rainer
New Member
October 9, 2018
Question

Export / import objects from one ADOM to another?

  • October 9, 2018
  • 8 replies
  • 12390 views

Hello,

 

I am looking for a solution how to use firewall objects from one ADOM in another one.

Is there a possibility to share objects?

Or is it possible to export the objects database and import it in the other ADOM?

 

regards

Rainer

8 replies

wolfschen
New Member
October 9, 2018

Hello Rainer,

 

you can try this one:

On FortiManager ssh session you can use:

'exec fmpolicy clone-adom-object ' command.

It is a little bit difficult, because each parameter you must enter from list which is showing you when type you a '?' on console.

I have just one ADOM for one Firmware version and I can just only clone object inside ADOM. It looks for me as follow:

exec fmpolicy clone-adom-object 3 140 "Objectname which I want copy" 3 "new name of copied object",

where:

exec fmpolicy clone-adom-object - base command

with parameters:

3 - source ADOM - id of my ADOM (obtained with '?')

140 - it is category ID (I don't know if it is a standard ID schema, but for me it's a "firewall addresses" (obtained with '?')

"Objectname which I want copy" - named object in ADOM

3 - destination ADOM - id of my ADOM (obtained with '?')

"new name of copied object" - new object name

 

Kinkasi
New Member
February 27, 2026

Hello Wolf,

 

Im doing this right now and having issues in Webfilter, AV, IPS, SSL/SSH for all these things, I'm getting the -1002 error. 

 

Output:- AZ-FM-INTL # execute fmpolicy clone-adom-object 222 1111 OBJ-NAME 3333
Command fail. Return code -1002. 

and i have been searching for KB's all day long no hint why this is happening 

But with the same command i have moved the APP CNTRL and DNS FILTER.

 

Thanks,

Kasi

brazz_FTNT
Staff
Staff
October 9, 2018

Hello Rainer, 

 

I am looking for a solution how to use firewall objects from one ADOM in another one.

Is there a possibility to share objects?

Or is it possible to export the objects database and import it in the other ADOM?

 

execute fmpolicy clone-adom-object ?  ---->Clone ADOM object to another ADOM.

 

 

This commands is only useful when you are looking for duplicate  couple of objects because you need to copy each objects individually. (Also the Source and Destination ADOM have to be on the same version)

 

I would suggest connect another FGT to the Old ADOM , push the PP to it then move the FGT to the new ADOM. Retrieve the config and then import the PP to the New ADOM.  (Of course we need to pay special attention to FGT,FMG ,and ADOMs Versions )

 

 

Let me know if  you find this solution useful. 

 

 

CHeers 

 

Rainer
RainerAuthor
New Member
October 10, 2018

Hello,

thanks for the answers so far.

So, as I understand it by now, there is no tool that could directly help in this situation.

I was already thinking about importing Objects and Policies from Fortigates of the other ADOM.

We have many objects defined in FMG and not all of them are on all Fortigates, so the best would be to have a copy of all Objects in the new ADOM.

Maybe we have to import the objects from all the Fortigates one Fortigate by the other until the object Database ion the new ADOM is complete.

regards

Rainer

brazz_FTNT
Staff
Staff
October 10, 2018

Hello Rainer, 

 

 

Yes currently there is not any feature like that. As I know Fortinet  is always welcoming new Ideas. You may consider talking to your Fortinet Sales Engineer and submitting a new feature request. 

 

How about creating a dummy policy/policies and assign those objects to them . Then install  it to one of your  FGTs. Once it is complete just transfer the FGT to the new ADOM  then import the PP to the NewADOM. In this case, all of the objects would be importing to the New ADOM.

 

Cheers

sw2090
SuperUser
SuperUser
February 27, 2026

if you need it in more than one adom in FMG you could also promote these to the global adom so you can assign them to any adom you have enabled for that in  the gobal one.

Just keep in mind to assign ALL objects because otherwise objects that have no reference in the selected adom will not be assigned.

 

We once did that with all our UTM Filter profiles and Security Profile Groups and also web rating overrides.

sw2090
SuperUser
SuperUser
February 27, 2026

You also could download one revision of a fgt in the adom that has the objects from FMG device manager. This contains devic config + policy package so has all you objects. Then find the objects in there and copy them and the corresponding headers (e.g. "config firewall address" for adress objects) to a text file and then use that to create a script in fmg device manager in the adom you need the obects and run that script against the adom db to add the objects.

Kinkasi
New Member
February 27, 2026

Thanks sir sw2090,

 

Can you please share any kb on it and as well regarding the datfile fmg backup which i had taken i wasnt able to open it tried many tools and methods the kb on how to open faz backup is also not working for this 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.