FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hpenmetsa
Staff
Staff
Article Id 327017
Description This article describes how to delete the configuration object on FortiGate, this example focuses on deleting an address group object.
Scope FortiOS.
Solution

In the following example, it is not possible to delete a configuration object (for example: address group) using the GUI, the 'Delete' option is grayed out. Attempting to delete the object via CLI also fails.

 

Step 1: First check the object references and dependencies, ensure it has no references

 

address-objects.PNG

 

To delete the address object from the GUI, it shows the Delete option greyed out.

 

delete.PNG

 

Attempting to delete the address group from CLI also fails.

 

addgrp.png

 

Try resetting the references for the address group object using the following command from the CLI.

 

diagnose sys cmdb refcnt reset <path.object.mkey>

 

For example:

 

reset-ref.PNG

 

 

Try deleting the address group object from the CLI again if it fails, as a last step:

 

  1. Download the FortiGate configuration file.
  2. Edit the configuration file and manually remove the Configured object.
  3. Upload the modified configuration file back to FortiGate.

 

By following these steps, it should be possible to load the configuration without objects into the FortiGate. It is also possible to use these steps to move the VLAN from one interface to another.