Created on
‎02-27-2025
05:39 AM
Edited on
‎08-15-2025
05:58 AM
By
Stephen_G
Description |
This article describes a behavior where FSSO groups get deselected from firewall policies when users modify the Firewall policies through the GUI in v7.6. |
Scope | FortiGate in v7.6.1, v7.6.2, v7.6.3 is currently using FSSO Groups. |
Solution |
Users with FSSO integration can directly configure the FSSO groups in the Firewall policies without creating any local group in FortiGate: Directly use FSSO address group in firewall policies | FortiManager 6.2.
config firewall policy
In version 7.6.1, 7.6.2 or 7.6.3, when trying to open the Firewall policy through the GUI, the group restriction seems to be deselected.
If users modify, for example, a UTM profile through the GUI and save the configuration, the Firewall policy will be saved without the group's restriction.
Without the Group restriction, all users may have the possibility to match the Firewall policy.
Note: Using the CLI, group restrictions are not deselected.
Workaround:
FSSO_Group--> "CN=Administrator, CN=Users, DC=Fssotest,DC=com"
config firewall policy
With this configuration, when users modify the Firewall policy through the GUI, the FSSO group object will not be deselected.
This is a known issue in version 7.6.1, 7.6.2 and 7.6.3 and is fixed in v7.6.4.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.