Skip to main content
TomBruno
New Member
January 16, 2019
Question

Mass removal of custom devices

  • January 16, 2019
  • 5 replies
  • 9892 views

Hi All

For a customer I support we allow their users access to the network by collecting all their MAC addresses and adding them as Custom Devices to the FortiGate. Currently the firewall has nearly 6500 MAC address entries. We have been told we can delete any entry not seen for 3 months. and Friday is 3 months since the last reboot and there are nearly 3000 devices "last seen" on oct 18th that we can delete. 

 

Currently my method for deleting an entry is going to Device Inventory, going to edit it, removing all the custom groups, saving it and then deleting the entry. With the slow load times we see on this fortigate, this could mean hours of manually deleting entries. (I can highlight up to about 20/30 to delete manually, but have to go into each entry to remove the Custom Groups beforehand)

 

Would anyone have any advice to make these deletions a bit easier/speedier?

 

FortiGate Model: 1500D

Firmware: v5.4.8,build1183 (GA)

 

Thanks in advance

    5 replies

    Seppel
    New Member
    January 16, 2019

    Save config, edit the config file (remove the devices), and restore the config to the fortigate.

    but this works only with a reboot.

     

    regards

    emnoc
    New Member
    January 16, 2019

    I would explore a  expect script and seed file . Maybe add the device and time and then use some awk and grep and look for any  value older than  XYX and  script it out. Also maybe the  api reference guide might have some options.

    This is why doing these options are  task heavy and you need to  deploy some types of timer or expirations.

     

    Ken Felix

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!