Description | This article describes how to add the existing address objects on the address group when manually created or created by IPsec VPN Wizard. |
Scope | FortiGate. |
Solution |
When trying to add address object to the address group the address object is not visible under members section or when creating an IPSEC VPN using a VPN Wizard, the address object is not visible in the address group.
GUI:
When trying to add an existing address object, some will not be shown in the select entries of the address groups. This is due to the option of 'Static route configuration' on the address objects.
When this option is selected or enabled in the address group, only address objects that have Static route configuration enabled can be seen. It is the same when Static route configuration is disabled; only address objects with Static route configuration can be seen, and the same with the IPSEC VPN Wizard, the address groups in the IPSEC Wizard are created with a 'Static route configuration' enable option by default.
GUI:
To add the address objects to the address groups, the 'Static route configuration' option should be the same on both address objects and address groups. If address objects have different settings than address groups, then those address objects will not appear to be selected in the address groups.
GUI:
In the above screenshot, the localSubnet_2 address object did not appear previously on screenshot 2 due to the 'Static route configuration' being disabled. After enabling that setting, the localSubnet_2 address object appeared in the select entries of the address group.
Note: From v7.6, the option 'Static route configuration' is changed to 'Routing configuration'.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.