FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
awasfi_FTNT
Staff
Staff
Article Id 359743
Description

This article describes how to delete firewall objects which failed to delete due to a 'no write permission' error, as well as objects not used on any policy package.

Scope

FortiManager.

Solution

In some cases, a firewall object cannot be deleted from FortiManager while it is not used any where in policy package. The reason is that the object was used on a deleted policy within the policy package and still has a reference to this policy package.

 

When trying to delete the object, the following error appears:
Failed to delete object(s) due to the following reason: no write permission.

 

5.jpg

However, when checking where this object is being used, it shows No record found:

 

1.jpg

 

Proceed to Delete the object and the following confirmation message will appear:

 

2.jpg

 

Upon selecting OK, the following screen will show a message indicating that the object is used even though the object is not used on any policy.

 

3.jpg

 

Selecting 'Where used' again indicates that the object is not associated with any configuration.

 

4.jpg

 

Selecting Delete Anyway will result in the following error message as the object has references to deleted policies:

 

5.jpg

 

Use the following command to remove invalid policy references:

 

diagnose cdb upgrade force-retry del-invalid-node

 

6.jpg

 

Next, the object can be deleted from the GUI after the invalid reference has been removed.

 

This command exists starting from FortiManager versions 7.2.6, 7.4.4, 7.6.0 and above.