Skip to main content
bigkeoni64
Explorer II
August 16, 2022
Solved

Fortimanager pushing to a FortiGate

  • August 16, 2022
  • 7 replies
  • 16348 views

Hello - I created a few address objects, then made a new Policy all in FMG. I have to push so I do :

 

Install wizard and go to the point of 'preview installation' The changes I did showed up as expected.

My next step is to actually push the changes.

 

My question is will anything else change? Do I need to do a backup before I push? Just curious if it will only change what is in the 'install preview'.

 

Just making sure I'm not taking down or changing anything else since this is my first go at it...

 

Mahalo

Best answer by Toshi_Esumi

I know only v6.4.x. Yours look like newer because the menu on the rev history is quite different from mine. But at least the config DB is in sync with the device. Only the policy package has a problem. Was it actually in sync before you made the changes? And how it's originally created? Imported from the config DB?

7 replies

Toshi_Esumi
SuperUser
SuperUser
August 16, 2022

If you can push the new config, the device is already on the FMG and have revisions of config backups. Go to the device's System:Dashboard and find Revision->Total Revisions. Then at the end of the line, there is an icon for Revision History menu. Click that to see all revision/backup history. When you highlight one of them, you can view the config and check "diff" from a previous version.

 

Yes, it would install exactly what's in preview.

If something went wrong after the installation, you can always "Revert" under "More" menu in the Revision History window.

 

Toshi

 

 

bigkeoni64
Explorer II
August 17, 2022

Well, unfortunately there were no revisions available, plus there are orange warning triangles on just about every individual rule.

 

I was to apprehensive to use the FMG to push the policy and objects, therefore I put it on the FortiGate directly.

 

Is there an auto-retrieve or can I force the FMG to pull the new FG policy?

It might be best I open a case to sort how to clean this up since we inherited things this way.

 

bigkeoni64_0-1660712125387.png

 

Toshi_Esumi
SuperUser
SuperUser
August 17, 2022

Are you sure it's on-line? What's in the device list status view under Device&Groups->Managed Devices? There should be Config Status column showing config DB sync status. If normal, there is a "green check mark" before the status.
Once it's registered to the FMG, there should be at least one revision auto-retrieved. If the Total Revisions is '0' while the system information like S/N, IP address, etc. is showing something must have gone wrong.
Manual retrieval is in the Revision History window's menu "Retrieve Config". But I guess it won't work or dimmed at the current state of the device on the FMG.

Share us the screen of the status list view and device dashboard. Or open a case at TAC to get it taken a look a.

 

Toshi

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.