Policy Install Fails after Config Synchronized
Hi,
First, the platform is Fortimanager v5.4.5 with multiple Fortigate 200s running FortiOS v5.4.9. Initially, I was able to push policy from FMG without any problems.
I then needed to change some log settings on all of the FGs. So, in FMG I created and ran a Remote Fortigate Directly (CLI) script to change the settings, as follows.
config global config log fortianalyzer filter set local-traffic disable end config log syslogd filter set local-traffic disable end end
After running the Script, in Device Manager the FGs Config Status showed "Synchronized". I then tried to Install a Policy Package after having made an IPv4 policy change in FMG and received the following validation error.
Device:otk-fw-11 VDOM:root Copy device global objects
Post vdom failed: error :20 - interface binding contradiction
Copy objects for vdom root
Note that I only ever use 'Any' as the Interface when defining Objects.
After cross-checking objects, comparing before/after configs and trying several different things, I went into one of the FGs and deleted all of the existing Multicast Policies (there were only 7). After that I was then able to push the policy package, which recreated the 7 Multicast policies, without any issue.
Does anyone have any suggestions about what may be causing this weird behavior?
Thanks,
Larry
