FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
Nur
Staff
Staff
Article Id 258252
Description

This article describes when FortiManager failed to push (from install preview or install report) the policy to FortiGate and the error mentioned below:

 

Starting log (Run on device)


Start installing
CQNORFW02 $ config firewall policy
CQNORFW02 (policy) $ edit 266
CQNORFW02 (266) $ set dstaddr  <object name>
entry not found in datasource

value parse error before <object name>
Command fail. Return code -3

Scope FortiManager,
Solution

This error related to the object could not be used from FortiGate in the destination address section.

Even FortiManager is able to assign the object, however, FortiGate will not accept the installation from FortiGate.

 

Example of MAC Address object:

Object : MAC-Address.

 

mac.JPG

 

The MAC address object is assigned to the Address Group:

 

mac.JPG

 

From FortiManager:

 

po.JPG

 

From FortiFate:

 

mac.JPG

 

From the FortiGate, there is no address group for testing2 where it is not possible to use as the destination address.

If an error such as 'entry not found in datasource' is visible from the installation preview or install report, do a check from FortiGate if the object is able to be assigned or not.

Contributors