FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
Arif69
Staff
Staff
Article Id 420171
Description This article describes how to enable the 'antispam-force-off' and 'webfilter-force-off' FortiGuard settings from the FortiManager device database to FortiGate.
Scope FortiManager.
Solution

Currently, the settings for 'antispam-force-off' and 'webfilter-force-off' of FortiGuard settings in local FortiGate are disabled:

 

chrome_qEARg0qeiB.png

 

To enable the settings from FortiManager, navigate to Device Manager -> Device & Groups -> FortiGate -> CLI Configurations -> System -> FortiGuard. Enable the 'antispam-force-off' and 'webfilter-force-off'.

 

chrome_HX6amqz8HY.png

 chrome_DPZWDZoaJD.png

 

However, when trying to install the changes to the FortiGate, there are no changes to be pushed:

 

chrome_Dkd8MYtlOW.png

 

After the installation is finished, somehow the 'antispam-force-off' and 'webfilter-force-off' settings are automatically disabled:

 

chrome_Ufge6Ya2yY.png

 

chrome_SplvdVAGyA.png

 

After further investigation, it was found that the FortiGate is assigned a system template with the 'FortiGuard' setting enabled:

 

siLC7SZCGz.png

 

To solve this issue, there are two ways:

  1. Disable the 'FortiGuard' setting.
  2. Or unassign the template from the FortiGate.

 

Next, navigate to Device Manager -> Device & Groups -> FortiGate -> CLI Configurations -> System -> FortiGuard to enable the 'antispam-force-off' and 'webfilter-force-off' again.

 

After that, it can be seen that FortiManager is now able to push the 'antispam-force-off' and 'webfilter-force-off' settings:

 

chrome_NRMfR3oxrt.png