Created on
01-19-2026
02:23 AM
Edited on
01-19-2026
02:24 AM
By
Jean-Philippe_P
| Description |
This article describes what Policy Blocks are and how to use them within the global policy packages. |
| Scope |
FortiManager. |
| Solution |
A Policy Block is essentially a set of policies, particularly useful when there are multiple Policy Packages that may have different Firewall Policies but share a common set of them. Any changes made to a Policy Block are inherited by every Policy Package to which the Policy Block is appended.
Policy Blocks is a hidden feature and must be activated on feature visibility:
Once done, the Policy Blocks menu shows up in the Global Database ADOM.
How to use Policy Blocks: Policy Blocks consists of two different sets of firewall policies: Firewall Header Policies and Firewall Footer Policies.
These two sets are independent and can be assigned separately to a Global Policy Package. For example, it is possible to apply only the Firewall Header Policy set of a Policy Block to a Global Policy Package.
The next step is to assign the Global Policy Package a Local ADOM.
Important note: the Global Database ADOM and local ADOMs:
Step 1: Select the Global Policy Package Assignment section, then select Add ADOM.
It is possible to assign the Global Policy Package:
This assignment procedure must be done whenever a Policy Block is appended or removed from a Global Policy Package. The Global Policy Package must be reassigned to synchronize the status.
Step 2: To synchronize the new changes, click on action and follow the instructions to assign the Global Policy Package to the needed Policy Packages (in the example, SPOKES Policy Package in SD-WAN ADOM).
Once done, the status changes to 'Up to date', and the new Firewall Policies show up on the Policy Package in local ADOM.
Install the policies on the firewall: To push the Firewall Policies on FortiGates, use the Install wizard tool with the option Install Policy Package.
Known Issues: In a scenario where a Policy Block is appended to two or more Global Policy Packages, both assigned to two or more Local Policy Packages of the same Local ADOM, the Header or Footer Firewall Policies of the Policy Block will not be added to the Local Policy Package associated with the Global Policy Package. With the Assignment done for the second step (Step 2).
A symptom of the problem is that in the Second Global Policy Package Assignment Page, the Status of the Assignment remains 'Up to Date' after a Policy Block is appended or removed.
The problem is tracked with the bug id 1244194 and is solved starting from the firmware release v7.4.9, v7.6.6, and v8.0.1.
Related documents:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.