Created on 
    
	
		
		
		‎02-27-2025
	
		
		05:39 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
  Edited on 
    
	
		
		
		‎08-15-2025
	
		
		05:58 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 By  
				
		 Stephen_G
		
			Stephen_G
		
		
		
		
		
		
		
		
	
			 
		
| Description | This article describes a behavior where FSSO groups get deselected from firewall policies when users modify the Firewall policies through the GUI in v7.6. | 
| Scope | FortiGate in v7.6.1, v7.6.2, v7.6.3 is currently using FSSO Groups. | 
| Solution | Users with FSSO integration can directly configure the FSSO groups in the Firewall policies without creating any local group in FortiGate: Directly use FSSO address group in firewall policies | FortiManager 6.2. 
 config firewall policy 
 In version 7.6.1, 7.6.2 or 7.6.3, when trying to open the Firewall policy through the GUI, the group restriction seems to be deselected. 
 
 If users modify, for example, a UTM profile through the GUI and save the configuration, the Firewall policy will be saved without the group's restriction. 
 Without the Group restriction, all users may have the possibility to match the Firewall policy. 
 Note: Using the CLI, group restrictions are not deselected. 
 Workaround: 
 
 
 FSSO_Group--> "CN=Administrator, CN=Users, DC=Fssotest,DC=com" 
 
 config firewall policy 
 With this configuration, when users modify the Firewall policy through the GUI, the FSSO group object will not be deselected. 
 This is a known issue in version 7.6.1, 7.6.2 and 7.6.3 and is fixed in v7.6.4. 
 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.