Skip to main content
aagrafi
New Member
January 17, 2018
Solved

Maintaining a common policy package

  • January 17, 2018
  • 6 replies
  • 7517 views

Hello,

Can we combine two (or more) policy packages in the same FG or group of FGs with FMG? My ultimate goal is to have the following functionality in the FMG, regarding the security policy management:

a. Have a common policy package for a group of FGs on my network and

b. Selectively add firewall policy lines to some FGs in the group.

 

I remember in FMG 5.2 that we could do that by using different device-targets per firewall policy line, but I don't see this in 5.6.

 

I hope I was clear in explaining my requirement. I consider this requirement very important for FMG, because otherwise we are forced to use different policy package per FG device.

 

Thanks

Andreas

 

    Best answer by neonbit

    You can still select which policies get installed no which Fortigates using 5.6. By default the column is not shown, to show it select Column Settings > Install On.

     

    Once done you can see another column added where the default value is 'Installation Targets'.

     

    You can now select which policies get installed on which FGTs. I'd recommend creating sections in your policies for easier management if possible. A section like 'Policies for all firewalls', 'FGT1 policies' 'FGT2 policies' etc.

     

    6 replies

    jsanders
    New Member
    January 17, 2018

    We use ADOM's and Header Policies for this. However, we've been discouraged more than once from using Global Objects and header/footer policies as FTNT doesn't prefer us use those. Rumor has it b/c Global elements add so much complexity during upgrades and migrations. Could be total hearsay.

     

    Would be very nice if there was a "device-targets" column or something like that.

    chall_FTNT
    Staff
    Staff
    January 17, 2018

    jsanders wrote:

    we've been discouraged more than once from using Global Objects and header/footer policies as FTNT doesn't prefer us use those. Rumor has it b/c Global elements add so much complexity during upgrades and migrations.

    Jsanders, I am sorry you have that you received that impression from Fortinet.  On behalf of the TAC, I can say that we have no hesitation in use of global policy packages. 

     

    Special Case Scenario:

    Complications with global policy package assign/unassign can arise if global objects are subsequently used in ADOM-level policies but we are investigating the possibility of giving the global level full visibility into global object use across all ADOMs.   But if you do not use global objects when building policies at the ADOM level, you won't run into that complication.

     

    Andreas,

    We don't have any automated way of combining policy packages.  But you can copy & paste policies from 1 policy package to another in order to manually build a merged policy package.

    neonbit
    neonbitAnswer
    New Member
    January 17, 2018

    You can still select which policies get installed no which Fortigates using 5.6. By default the column is not shown, to show it select Column Settings > Install On.

     

    Once done you can see another column added where the default value is 'Installation Targets'.

     

    You can now select which policies get installed on which FGTs. I'd recommend creating sections in your policies for easier management if possible. A section like 'Policies for all firewalls', 'FGT1 policies' 'FGT2 policies' etc.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.