- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiManager Address Group Change
I have come across a strange issue. I have added a new member to an address group, so not changing a firewall rule directly. I can’t seem to find a way to push it to the Fortigate just as an address change?
If I add it directly on the Fortigate it complains it is out of sync, and doesn’t sync back. If I do a retrieve, it doesn’t pull it back in to the Fortimanager either.
Am I missing something obvious?
- Labels:
-
FortiManager
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As per my knowledge the address objector address group object will not be pushed the FGT unless it is used in a firewall rule.
If you can't push it then it is simply not used.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes the main group was already referenced in a Policy, all I have done is add an extra entry in the address group, it just wont see it and when I try to push it out it simply tries to set the group back to how it was previously before I added the group in Forti Manager,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @DT3 ,
It sounds like a bug.
What is the FMG version? If ADOM is enabled, what is the ADOM version? What is the FGT firmware version?
Is it possible that you can share the following for us to test?
1) FGT firewall policy using the address group
2) The address group in this issue
3) The new address object you wanted to add into the group
Jerry
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have found the reason why, when I add to the address group, further down there is an option for per-device mapping, which seems to differ from the main list. If i add it in per-device mapping it works as expected. Is there a way so it just applies from the main list?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
