Skip to main content
viks_a
New Member
April 25, 2017
Question

Fortimanager pushes unused objects to Fortigate

  • April 25, 2017
  • 9 replies
  • 15619 views

We have recently imported a policy package "X" from a fortigate into an ADOM , but there is a different policy package "Y" in the same ADOM which doesn't use any of the objects from policy package "X".

 

Now Policy package "Y" show the package as modified for all it's installation targets and when we go through the install wizard to look at the "download preview" it shows objects which were imported during "import policy package for X".

 

My question is does "Fortimanager" push unused objects even if they are not referenced in the Policy Package used by the installation targets ?  

9 replies

ergotherego
New Member
April 25, 2017

The only instance I know of where FMG pushes unreferenced objects is for security profiles. Everything else it pushes is referenced in the configuration somewhere.

 

Do Y and X make use of groups with the same name, but different members? Ie, the two groups with the same name got merged, and now have both members from both firewalls.

 

There is a bug in FMG 5.4 - 0401646 - that will cause other policy packages to show modified after importing a new PP or making changes. But it doesn't result in unreferenced changes being pushed down - in fact those are "blank pushes" where you have to go through the motions of installing just to clear that flag.

viks_a
viks_aAuthor
New Member
April 25, 2017

Y and X have nothing in common. Along with unused security profiles some common service objects are also pushed :(

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!