Skip to main content
TSC_JEFF
Visitor III
June 18, 2022
Solved

Managed Fortigate by Fortimanager not updating

  • June 18, 2022
  • 16 replies
  • 19833 views

Hi,

 

So I configured a managed Fortigate via Fortimanager, what I did was 

 

1. add an address object

2. added this address object to a dynamic group

 

For some reason it has been a day and I still don't see the new address object on the managed Fortigate. I do see under Configurations and Installations Config Status: Auto Update checked

 

Not sure how to troubleshoot this

 

Thanks in advance

Jeff

Best answer by Debbie_FTNT

I may be a bit late to the party, but it looks to be a bit as if you have the following:

- a static address (the address has no per-device-mapping), at least per the screenshot you shared

- a possibly dynamic group? I could not see a screenshot for the actual group, just the individual address

-> that means the group could have per-device-mapping (have different members for various FortiGates)

-> I would double-check the group itself and see if per-device-mapping is enabled, and if that is the case then check the group members that are configured for the specific FortiGate/Policy Package you're looking at

16 replies

Toshi_Esumi
SuperUser
SuperUser
June 18, 2022

"Auto-update" is for opposite direction from FGT config into Device config DB on FMG. You must be using a policy package and when you made the change of an object, the package sync status must have gone out of sync or modified. Until you push/install it, it's not going to be changed at the FGT.

You need to install the policy package.

 

Toshi

TSC_JEFF
TSC_JEFFAuthor
Visitor III
June 18, 2022

Thanks for the response, when you say install the policy package, not sure what that meant this is the first time I've dealt with FMG. Are you referring to the screen capture below

 

TSC_JEFF_0-1655512552362.png

 

Toshi_Esumi
SuperUser
SuperUser
June 18, 2022

Before blindly installing it, check the policy package status under Device Manager->Device&Groups like below. You might need to add "Policy Package Status" in "Column Settings. It should be out of sync.

 

Toshi_Esumi_0-1655512850997.png

 

TSC_JEFF
TSC_JEFFAuthor
Visitor III
June 18, 2022

Policy package shows a green check

TSC_JEFF_0-1655513119672.png

 

 

Toshi_Esumi
SuperUser
SuperUser
June 18, 2022

That means the address object you modified is NOT used in the policies in the package. In other words, if an object is not used, it would never be installed to the FGT.

markwarner
Staff
Staff
June 20, 2022

Hi Jeff,

It's important to understand how configuration on the device relates to configuration in the FortiManager.
You said you added an address object and put that in a group, but where was that configured?
If you make a configuration change on the FortiGate and auto-update is enabled in the FMG CLI (it is by default), the FGT will send its full configuration file to the FortiManager. This is known as a revision and you can check the revision history for a device in the Device Manager if you double click a device and check the Revision History button in the Configuration and Installation widget.


When this happens, the FortiManager Device Database is updated. The ADOM Database (Policy & Objects section of the GUI) is not updated. To update that you must either Import Policy or Install.
The ADOM database contains objects that can be shared with more than one device.
Import policy pulls the configuration from the Device Database and updates the ADOM Database. If you created the object on the device and are looking for it in Policy & Objects, this is the step that you are missing.


If you created the address and address group on the FortiManager then you only created it in the FortiManager's database. If you then install to the device and it's not pushing the address/group this is because it is not referenced in the Policy Package.
FMG is designed to keep unused objects in the FMG databases and should remove unused objects from the FGT CLI configuration to keep it clean.


If you created an object on the FMG under Policy & Objects, you must reference it in a Policy Package and then install to the device before you will see it show up on the FortiGate.


Always check the install preview before installing config to a FortiGate. It's your last chance to check that what you are about to install is what you actually want to install.


Mark.

sw2090
SuperUser
SuperUser
June 21, 2022

hm I ran into similar issues several times. I changed address objects (with or without per devicemapping) which ARE used in some policy in the policy package. I changed it in the FortiManager but when I wanted to roll the updated policy package out FMG stated there is nothing to deploy. It however did deploy the changes when I changed something else to make FMG deploy the packages. 

So looks to me that for some reason not every change seems to set the policy package out of sync...

Debbie_FTNT
Staff & Editor
Staff & Editor
June 21, 2022

I may be a bit late to the party, but it looks to be a bit as if you have the following:

- a static address (the address has no per-device-mapping), at least per the screenshot you shared

- a possibly dynamic group? I could not see a screenshot for the actual group, just the individual address

-> that means the group could have per-device-mapping (have different members for various FortiGates)

-> I would double-check the group itself and see if per-device-mapping is enabled, and if that is the case then check the group members that are configured for the specific FortiGate/Policy Package you're looking at

TSC_JEFF
TSC_JEFFAuthor
Visitor III
June 21, 2022

Thanks @Debbie_FTNT I just checked the group and indeed it uses Per Device mapping, I added the object there, pushed the policy and it reflected on the FGT,

 

Thanks guys for all the help. This is a good start for the week and I hope everyone is doing ok.

 

Jeff

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!