Skip to main content
DT3
New Member
January 17, 2025
Question

FortiManager Address Group Change

  • January 17, 2025
  • 8 replies
  • 3310 views

I have come across a strange issue. I have added a new member to an address group, so not changing a firewall rule directly. I can’t seem to find a way to push it to the Fortigate just as an address change?

 

If I add it directly on the Fortigate it complains it is out of sync, and doesn’t sync back. If I do a retrieve, it doesn’t pull it back in to the Fortimanager either.

 

Am I missing something obvious?

8 replies

AEK
SuperUser
SuperUser
January 17, 2025

As per my knowledge the address objector address group object will not be pushed the FGT unless it is used in a firewall rule.

If you can't push it then it is simply not used.

AEK
dingjerry_FTNT
Staff
Staff
January 17, 2025

Hi @DT3 ,

 

You did not say whether the address group is used or not.

 

As @AEK mentioned, you have to apply the address group in one firewall policy at least so FMG will push it to FGT.

 

 

DT3
DT3Author
New Member
January 17, 2025

Yes the main group was already referenced in a Policy, all I have done is add an extra entry in the address group, it just wont see it and when I try to push it out it simply tries to set the group back to how it was previously before I added the group in Forti Manager,

dingjerry_FTNT
Staff
Staff
January 17, 2025

Hi @DT3 ,

 

It sounds like a bug.

 

What is the FMG version?  If ADOM is enabled, what is the ADOM version?  What is the FGT firmware version?

 

Is it possible that you can share the following for us to test?

 

1) FGT firewall policy using the address group

2) The address group in this issue

3) The new address object you wanted to add into the group

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!