Skip to main content
MBR
New Member
July 17, 2014
Question

Issue with address group nesting with FortiOS 5.2

  • July 17, 2014
  • 27 replies
  • 37740 views
Hi there, My firewall cluster throws me an error when i want to change members of an address group which is member of an other group (nested) When i try to change members is get the error " entry not found" Anyone else having this issue? or could anyone test this on an other 5.2 and 5.0.7 FG? You can test this is as follows: First create some test addresses: FW02A (address) # config firewall address FW02A (address) # edit zztest1 new entry ' zztest1' added FW02A (zztest1) # set subnet 10.0.0.1/32 FW02A (zztest1) # next FW02A (address) # edit zztest2 new entry ' zztest2' added FW02A (zztest2) # set subnet 10.0.0.2/32 FW02A (zztest2) # next FW02A (address) # edit zztest3 new entry ' zztest3' added FW02A (zztest3) # set subnet 10.0.0.3/32 FW02A (zztest3) # next FW02A (address) # end Then create two address groups where the first group is a member of the second FW02A # config firewall addrgrp FW02A (addrgrp) # edit zztestgrp1 new entry ' zztestgrp1' added FW02A (zztestgrp1) # set member zztest1 zztest2 FW02A (zztestgrp1) # next FW02A (addrgrp) # edit zztestgrp2 new entry ' zztestgrp2' added FW02A (zztestgrp2) # set member zztestgrp1 FW02A (zztestgrp2) # next And now try to change members of the first group: FW02A (addrgrp) # edit zztestgrp1 FW02A (zztestgrp1) # set member zztest1 zztest2 zztest3 entry not found in datasource value parse error before ' zztest1' Command fail. Return code -3 FW02A (zztestgrp1) # append member zztest3 entry not found in datasource value parse error before ' zztest3' Command fail. Return code -3 FW02A (zztestgrp1) # unselect zztest2 command parse error before ' zztest2' Command fail. Return code -61 When you remove the first group as a member of the second group all works properly. Hope some of you have time to test this on 5.0.7 and 5.2 setups. - MBR-

    27 replies

    emnoc
    New Member
    July 17, 2014
    Yes I ve seen that behavior also,not sure if 5.2 does the same but I will test and update you when I get chance todo so.I ' ve always hated nesting group due to stringing of dependencies it can create.
    MBR
    MBRAuthor
    New Member
    July 17, 2014
    I have performed some additional testing using a FG 5.0.7 and a FG 5.2 VM. When performing the steps described in my first post i can reproduce the error on the factory default FG 5.2 VM. The FG5.0.7 VM however is working properly. So this seems to be another BUG in the 5.2 GA release. I have asked Fortinet to confirm this. I' ll let you know. Think i' m going to downgrade to 5.0.7.. (upgraded to 5.2 to fix 2 other issues :( ) - MBR -
    Warren_Olson_FTNT
    Staff
    Staff
    July 17, 2014
    Confirmed the same issue MBR in VMs.
    MBR
    MBRAuthor
    New Member
    July 18, 2014
    Fortinet Support also acknowledged this issue. Hope they will come with a fix soon. - MBR -
    MBR
    MBRAuthor
    New Member
    July 18, 2014
    Downgraded to 5.0.7 today cause this issue is keeping me from doing daily maintenance on the firewall So we have to wait for some patches on 5.2 to make in usable.
    emnoc
    New Member
    July 18, 2014
    FWIW I tried to use the clear command under 5.2GA and found out there' s no way to modify a nested group; clear member The attribute can' t be empty! command_cli_unset:4774 clear MEMBER table oper error. ret=-56 Command fail. Return code -56
    MBR
    MBRAuthor
    New Member
    July 19, 2014
    Clear command indeed does not work. You can use " unselect member xxx" and " append member xxx" to change members. Documentation of Fortinet is incomplete. Does not even mention these commands.
    emnoc
    New Member
    July 19, 2014
    Cool, I was not aware of the unselect option and yes that fails also FWF60D (grp-all) # show config firewall addrgrp edit " grp-all" set uuid 3e14a0ec-0ecc-51e4-80b1-39b558bf83b2 set member " grp1" " grp2" next end FWF60D (grp-all) # unselect " grp2" command parse error before ' grp2' Command fail. Return code -61 Seems like 5.2GA needs some improvements
    MBR
    MBRAuthor
    New Member
    September 19, 2014
    Support told me this issue would be fixed in next release. 5.2.1 is released september 16th but i dont see this bug (#248808) fixed in the release notes however :( I asked support for clarification
    ede_pfau
    SuperUser
    SuperUser
    September 19, 2014
    I can confirm that modifying members in a nested address group is working in 5.2.1, via GUI and via CLI.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!