How to manage VIP device groups in FortiOS 7.4.7 (FG-100F)
Hello Fortinet Community,
I’m working with a FortiGate 100F running FortiOS 7.4.7 (build 2731), and I need to apply specific firewall policies to a subset of internal devices—let’s say a group of VIPs or devices from a specific department like Marketing.
In previous FortiOS versions, we used the “Devices and Groups” feature to group hosts based on IP, MAC, or other identifiers, and then target those groups within policy rules.
I’ve now learned that this feature was removed as of FortiOS 7.0.1, as referenced in this article: :link: Technical Tip - Devices and Groups feature removed
Since that functionality is no longer available, my question is: What is the recommended approach now in FortiOS 7.4.x to dynamically group devices and apply policies?
I would prefer something that does not depend on user-based groups, as my use case is based on endpoint behavior or device identity, not user authentication (e.g., AD or RADIUS).
Any guidance or updated best practices would be really helpful.
Thanks in advance,
Aarón
