Failed to push LDAP configuration to fortigate due to lack of policy object
Hi,
We have several fortigate firewalls managed by a fortimanager machine.
We would like to add "local" active directory administrators to the fortigate machines , and for that , we configured the AD details + Users on the fortimanager.
The problem is that fortimanager will not push the AD & User configuration to the fortigate firewalls , if the users are not part of the policy.
Do we really need to create a bogus policy rule that will have the admin user AD group , only so the fortimanger will push the AD & user configuration to the firewalls ? What will happen if someone will remove the policy rule by mistake, we will loose the users configuration ?
I believe this is a bad design by fortigate that require policy statement to allow AD & User configuration to be pushed to the firewalls. Any way to work around this ?
Thanks,
Guy
