Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Geezertronic
New Contributor

CLI, Sequence Grouping, and adding new policies

Hi.  Running a FortiGate 800D running v6.0.4 build 0231.

 

Please can someone advise how I can create Sequence Groups via CLI, then add a new IPv4 policy to be located under that sequence group again via CLI.

 

Thanks

9 REPLIES 9
hubertzw
Contributor III

What do you mean by 'Sequence Groups'?

 

This is how you can move policy under specific policy ID: 

config firewall policy  move policy_ID [before|after] policy_ID

ede_pfau

There is no sequence numbering or grouping in CLI. Policies are uniquely numbered with an policy-ID. Only in the GUI, policies are grouped by source & dest interface, and sequentially re-numbered.

That's why many users discard the "sequence ID" column and add "policyID", as then you can find it in the CLI.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Geezertronic

In the GUI, you can create Sequence Groups and have different policies under each sequence group - they offer no usage value other than to group policies together based on usage.  Can you not create these groups via the CLI and assign policies to be under them rather than do all of that via the GUI?

ede_pfau

Only now I understand - you're working in sequence view of the Policy table. AFAIK there is no CLI equivalent of sequence grouping. I've created one, and searched the complete config for it's name - nothing. Seems to be a GUI tool only.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Geezertronic

Thanks.  I searched the config as well and could not find it - very weird.

ede_pfau

Unfortunate for you, but not weird. The recommended organisation model for policies is the interface pair grouping in GUI. I would agree that (with a lot of policies, like 100s) one could think of different grouping schemes, but...it's not the way it is.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Geezertronic

So is best practice to specify source and destination interfaces for each policy?  

AlexS

To set:

config firewall policy edit <policy ID> set global-label "Sequence Group Name"

 

Any policies below will be in that same Group until you specify another global-label.

Geezertronic

Thanks, that is just what I am looking for

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors