Description | This article describes a number of methods that administrators can use to identify and remove duplicate and/or redundant Firewall objects on the FortiGate. This coincides with Fortinet Security Best Practice (FSBP) FSBP PO01.8, which recommends that admins 'check for similarly named objects with identical configurations' and subsequently remove the duplicates. |
Scope | FortiGate. |
Solution |
Generally speaking, it is the best practice to periodically reduce the number of redundant/duplicate objects present in the FortiGate configuration. This helps to reduce administrative 'clutter' and make it easier to identify what objects are actually in-use.
With that in mind, the following are some tips that admins can use to ease the process of removing redundant/duplicate Firewall objects. These tactics are listed in increasing order of effectiveness/risk (i.e. starting at individual object resolution and progressing to bulk deletions):
# <question mark character>
Related article: |