- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Bulk import policy address object into fortigate firewall from a text file
Hi
Is it possible to bulk import address objekt into fortigate fw from text file
need to set up a lot of address objects and map to to one address Group.
the text file look like this
config firewall address edit adr1 set subnet x.x.x.x 255.255.255.255 next edit adr2 set subnet y.y.y.y 255.255.255.255 next edit adr3 set subnet z.z.z.z 255.255.255.255 next repeat for each address end
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Edit
get it to work but only for 4976 objects.
is it a limit for max objects in fortigate 60D?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
edit
Find the limit for firewall objects is 5000 in fgt60D.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
read the max value matrix per fortios and model ( google ) . I'm sure you have pre-allocated address so the 5K number is not doable.
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rofo.xdf wrote:As others stated. 5000 is max, the remaining objects are probably default or preexisting ones.Edit
get it to work but only for 4976 objects.
is it a limit for max objects in fortigate 60D?
If you don't mind me asking: Why in the name of <insert deity> do you need more than 5000 address objects for? You can use IP Ranges or subnets.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hint: the TOR nodes list has currently ~ 6.969 entries ([link]https://www.dan.me.uk/tornodes/)[/link]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ede_pfau wrote:Which is a dynamic list by nature.hint: the TOR nodes list has currently ~ 6.969 entries (https://www.dan.me.uk/tornodes/)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure but sometimes you need to protect a network from some bad guy coming from the TOR realm.
The list from the website is refreshed every 30 minutes, and loading it takes only 1-2 minutes in all.
Of course it would be more convenient to have the same mechanism as for botnet C&C servers via the AV engine.
