Skip to main content
aagrafi
New Member
January 18, 2018
Solved

Setting CNAT in the Global ADOM

  • January 18, 2018
  • 7 replies
  • 11442 views

Hello,

I tried to set a new Global policy package (or even edit the default one) and I noticed that FMG did not give me any option to set the CNAT policy (the Admin Guide says that it should). Then I created a policy package inside a certain ADOM, but when I changed that CNAT settings, I got the error "Global adom package CNAT is not consistent with local adom package CNAT"

 

I got a similar error when tried to change the inspection mode from flow to proxy.

 

Do you know how can I set the NAT or the inspection mode, so that there is no conflict between the Global ADOM and a certain ADOM? Furthermore, when I have multiple ADOMs, others with CNAT, others without CNAT, others in proxy mode, others in flow mode, how can I coordinate each ADOM settings with the Global ADOM settings?

 

Finally, it seems that in FMG 5.6 the Global ADOM refers to 5.6 also. Can we have multiple Global ADOMs, each one for every f/w version? Does this functionality make any sense at all?

 

Thanks

Andreas

    Best answer by brazz_FTNT

    Hey Team,

    I would like to bring this point to your attention:

    In FMG, using execute fmpolicy print-adom-package Global <package ID> 1103

    Will show us ,for example,something like below:

    +++++++++++++++++++++++++++++++++++++++++++++++++++++ config policy package settings set fwpolicy-implicit-log disable set fwpolicy6-implicit-log disable set checksum "1519420176-1929618009" set central-nat disable

    set inspection-mode flow<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

    set ngfw-mode profile-based set ssl-ssh-profile ""

    end

    +++++++++++++++++++++++++++++++++++++++++++++++++++++

    In this example, I just created global policy rule and then I assigned it to the target ADOM .

    It is complaining "Assigning global policy package default to adom TEST failed"

    In order to modify the mode of global PP, I just created below scripts and ran it against the Global PP. Global ADOM--->Object Configuration--->Tools---> Display Options--->Advanced--->Scripts ((need to be selected))--->Create--->run(right Click)

    ++++++++++++++++++++++++++++++++++++++++++++++++ config policy package settings set inspection-mode proxy end ++++++++++++++++++++++++++++++++++++++++++++++++

    Please see the results after running the scrips:

    FMG-VM64 # execute fmpolicy print-adom-package Global 1166 1103 Dump all objects for category [policy package settings] in adom [Global] package [1166]: --------------- config policy package settings set fwpolicy-implicit-log disable set fwpolicy6-implicit-log disable set checksum "1519423955-254522136" set central-nat disable set inspection-mode proxy<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< set ngfw-mode profile-based set ssl-ssh-profile ""

    end

    ++++++++++++++++++++++++++++++++++++++++++++++++++++++

    Let me know if you found this one useful.

    Cheers

     

     

     

     

    7 replies

    chall_FTNT
    Staff
    Staff
    January 18, 2018

    > I got the error "Global adom package CNAT is not consistent with local adom package CNAT"

     

    Currently, central NAT cannot be used with global policy packages (at the global level) as you discovered.  Consequently, central NAT should not be enabled in any ADOMs to which global policy packages will be assigned.

     

    > Finally, it seems that in FMG 5.6 the Global ADOM refers to 5.6 also. Can we have multiple Global ADOMs, each one for every f/w version? Does this functionality make any sense at all?

    In FMG 5.6.1, global version 5.4 can support ADOMs with versions 5.4 & 5.6.  There is only ever 1 global "ADOM".  Global version 5.6 will ONLY support ADOMs with version 5.6

    chall_FTNT
    Staff
    Staff
    January 18, 2018

    > I noticed that FMG did not give me any option to set the CNAT policy (the Admin Guide says that it should).

     

    Thanks for alerting us to this documentation error.  We will correct it since global policy packages do not have this option.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!