Skip to main content
prashanth_rnm
New Member
September 26, 2020
Question

Fortimanager Policy Package Diff

  • September 26, 2020
  • 1 reply
  • 2682 views

Hi There,

  I'm pretty new to the Fortimanager and I came across an issue while I push a policy to the firewall.

Generally I will check the Policy Package Difference before pushing the rule.

While I was checking I come across some changes apart from what I have created/modified.

Generally I'm noticing this on the Policy Object. Some examples as below

 

Example 1:

Changed

Name: <blank>

Category: 316

Detail: "serial-number"

 

The above is showing me that the serial number is changed but when I looked at the values I saw the previous and current values are the same only on the updated values serial number is showed between ""

 

Example 2:

Changed

Name: <Local Firewall Admin Username>

Category:5

Detail: <blank>

 

What is the reason I'm seeing these difference as those were not the changes done by me?

Is there any documents available that describe more details on the Category Code?

 

Thanks in Advance

Prashanth

 

 

    1 reply

    Fullmoon
    New Member
    September 28, 2020

    it seems this is common if you managed multiple FGs devices with same objects (name and address) for example default values for ssl vpn. I often encountered this when adding and deleting lists of FGs under my FMG device manager. To fixed from my end, I need to do a dynamic mapping object. Please see link https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1200_Policy%20and%20Objects/1200_Managing%20objects/0400_Map%20a%20dynamic%20object.htm

     

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.