Hi. Running a FortiGate 800D running v6.0.4 build 0231.
Please can someone advise how I can create Sequence Groups via CLI, then add a new IPv4 policy to be located under that sequence group again via CLI.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
What do you mean by 'Sequence Groups'?
This is how you can move policy under specific policy ID:
config firewall policy move policy_ID [before|after] policy_ID
There is no sequence numbering or grouping in CLI. Policies are uniquely numbered with an policy-ID. Only in the GUI, policies are grouped by source & dest interface, and sequentially re-numbered.
That's why many users discard the "sequence ID" column and add "policyID", as then you can find it in the CLI.
In the GUI, you can create Sequence Groups and have different policies under each sequence group - they offer no usage value other than to group policies together based on usage. Can you not create these groups via the CLI and assign policies to be under them rather than do all of that via the GUI?
Only now I understand - you're working in sequence view of the Policy table. AFAIK there is no CLI equivalent of sequence grouping. I've created one, and searched the complete config for it's name - nothing. Seems to be a GUI tool only.
Thanks. I searched the config as well and could not find it - very weird.
Unfortunate for you, but not weird. The recommended organisation model for policies is the interface pair grouping in GUI. I would agree that (with a lot of policies, like 100s) one could think of different grouping schemes, but...it's not the way it is.
So is best practice to specify source and destination interfaces for each policy?
To set:
config firewall policy edit <policy ID> set global-label "Sequence Group Name"
Any policies below will be in that same Group until you specify another global-label.
Thanks, that is just what I am looking for
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.