Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
To answer the first part of your question:
Assumptions for a best generic access policies design from forti manager please make sure the below are constant:
[ol]Note:
[ul]Created on 04-24-2021 07:05 PM
To answer the second part of your question
The conflict is shown on the Forti manager:
Please ensure all device & access policies deployment changes are performed from the
Forti manager only such that it could prevent to avoid conflicts.
Also please answer below :
Is this conflict error shown on the Device manager or on the access policy package on the fortimanager ?
I do here this way with 21 Sites:
All FGT are in FortiManager in an ADOM.
All FGt in adom use the same default policy package so there is no FGT specific policy packages.
If I need some policy to be deployed to only specific FGT I set those as installation target(s) for the policy.
Just Device config is FGT specific (execpt from the thingys that can be set in provisioning template in FGT).
Things I need in more than one adom (like Webfilter profiles) are in global adom in FMG.
FMG will not show live conflicts during configuration but it will prompt you upon deploying device config or policy package.
Once FGt are in FMG you should not change or create anything directly on them that is in policy package since FMG deployment will overwrite that.
If you change device config directly on a FGT that is in FMG make sure to perform a retrieve config in FMG before you deploy anything to that FGT from within FMG!
Works fine here so far...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.