This article describes the case when the address group configured does not appear in the static route configuration; however, the address object is available.
6.0.x Onwards.
In certain cases address group configured does not appear in the static route configuration; however the address object is available.
Make sure all the address objects called in that address group must have 'set allow-routing enable' in the configuration. Also 'set allow-routing enable' should be enabled for the address group as well.
To check the configuration for the address object and address group, use the below CLI commands:
sh firewall address "address-object-name"
sh firewall addrgrp "address-group-name"
Through GUI it can be checked using the below:
'Policy & Objects -> Addresses': select the 'address object' which is part of 'address group' and in that 'Static route configuration' must be enabled.
Also, enable 'Static route configuration' for 'address group' as well, then only address-group-name will show in the Static Route list.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.