Validating firewall address objects
Hello,
Just wondering if anyone has managed to export Fortigate address host objects and ip addresses to a text file or csv etc ?
What I am really trying to achieve is to identify any inconsistencies in the address objects where either the host no longer exists or where the ip has been reallocated to a different host. So the process would be to identify any address object with a 255.255.255.255 mask, do a DNS lookup, try to ping it etc and report on this.
If I could extract the address and ips then I could probably do the rest in a bash script or something, but I imagine someone has already done the initial extraction part ? I've found the perl script to extract the policies into a .csv, but I'm not a perl guy, so if someone has done this already, that would be very useful.
Thanks in advance,
Fortigate 310B
Fortimanager 400A
Fortianalyzer 200D