FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
smkml
Staff
Staff
Article Id 416095
Description

 

This article describes why virtual wire pair configuration is being purged when performing an installation of FortiGate.

 

config being purge shows in install preview.png

Scope

 

FortiManager, FortiGate.

 

Solution

 

When the interface is configured from FortiGate or FortiManager Device Manager, but is not used at the policy level, this is expected.

 

This is because the virtual-wire-pair interface is a FortiManager policy package managed/controlled interface config, so it will install together with the Virtual Wire Pair policy and is considered as 'policy objects'.

 

The virtual-wire-pair interface needs to be used under Policy & Objects -> Policy Packages -> Firewall Virtual Wire Pair Policy (check under Tools -> Feature Visibility if this option is not visible).

 

Before that virtual-wire-pair needs to be referenced in the normalized Interface, and make sure the name is not the same as the existing Normalized Interface value under Policy & Objects -> Normalized Interface -> Virtual Wire Pair.

 

normalized interface for vwp.png

Once the normalized interface is configured, proceed to add it under policy.

 

use vwp in policy.png

 

If a normalized interface for a virtual wire pair is not created, it will not have an option to select in the policy.

 

Related article:

Troubleshooting Tip: Import policy package failed due to '(invalid in Virtual_wire_pair)) binding fa... 

Contributors