FortiManager Cloud – Static routes with address groups: how do you handle this?
Hi everyone,
I’m currently using FortiManager Cloud to manage my FortiGate devices.
When I was configuring static routes directly on the FortiGate, I used to rely on address objects and especially address groups as route destinations (Named Address with allow‑routing).
This approach was very convenient to group multiple networks behind a single static route and keep the routing configuration clean and readable.
With FortiManager (Static Route Templates), I understand that this option is not available:
- Destinations seem to be limited to Subnet / Internet Service / Internet Service Custom.
- There is no way to select an address object or an address group as a destination, unlike local FortiGate configuration.
I’ve seen that meta‑fields (variables) can be used to inject subnets into route templates, but:
- This does not really replace the concept of address groups.
- It doesn’t fully meet the use case I had before.
So I’m wondering how you deal with this in practice:
- How do you handle static routing in this scenario?
- Do you end up configuring one static route per network?
- Are you using CLI templates, scripts, or another workaround?
- Is anyone aware of a planned evolution in FortiManager to support address objects or groups in static routes?
I haven’t found any clear official statement on this limitation, and it does make the configuration a bit more complex compared to managing routes directly on the FortiGate.
I’d really appreciate feedback, best practices, or experience from others using FortiManager Cloud.
Thanks in advance!
Â
B-W