Hi all,
I'm currently updating my fortimanager configuration.
The problem I'm struggling with is about dynamic addresses used in interfaces with a captive portal. I have many fortigates with a specific interface that handles guests access (through the captive portal) and I need to tell Fortimanager to insert in the exempt list different addresses.
Using dynamic addresses mapped to single devices does not seem to work.
When I'll try to install policy packages fortimanager ignores the mapped dynamic address (for different fortigate).
Rizio
Solved! Go to Solution.
Created on 11-24-2025 12:24 AM Edited on 11-24-2025 12:27 AM
Hello Jean-Philippe,
I've found the solution; I've do a simple "retrive configuration" within the firewall configuration history of fortimanager.
This has solve the issue.
Rizio
P.S. How can I mark this post as RESOLVED?
Hello Rizio,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Created on 11-24-2025 12:24 AM Edited on 11-24-2025 12:27 AM
Hello Jean-Philippe,
I've found the solution; I've do a simple "retrive configuration" within the firewall configuration history of fortimanager.
This has solve the issue.
Rizio
P.S. How can I mark this post as RESOLVED?
Hello Rizios,
Thanks for the update and for sharing to everyone the solution :)
I will mark it as resolved, thanks again!
Thank you Jean-Philippe.
Rizio
FortiManager doesn’t fully support dynamic addresses in policy package installations for multiple FortiGates. When you map a dynamic address to a device interface, FortiManager can ignore it because it cannot resolve the IP until runtime.
A few approaches to work around this:
Use IP Pools or VIPs instead of dynamic addresses where possible—these are fully recognized during policy installation.
Create device-specific address objects on each FortiGate and reference them in FortiManager policies rather than relying on a single dynamic object.
If dynamic addresses must be used, consider installing policies directly from the FortiGate GUI or using scripts to update the exempt lists after policy installation.
Unfortunately, there’s no native way to make FortiManager dynamically resolve guest IPs across multiple devices in a single policy package. Device-specific objects or runtime updates are the most reliable solution.
| User | Count |
|---|---|
| 2806 | |
| 1425 | |
| 812 | |
| 757 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.