Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
OddCypher
New Contributor

FortiManager: Find and Replace Address Objects with automated

Hello,

 

due to a domain change/migration I have to "clone" over 600 firewall adress objects (Type FQDN), keeping them in their policies and also their firewall address groups, as well as also the original object, so that we have them both active until the migration period is over and then we can delete the old ones.

 

(e.g. srv-01.prod.domain.net -> srv-01.test.domain.net)

 

In the past, when we had about up to 30 objects or so, we solved this by the "find and replace" function on the FortiManager GUI, as it automatically also considers the objects membership in groups and policies and you were able to replace the object with itself and the new, modified one.

 


I am looking for ideas how to automate this process, so I don't have to click and replace hundrets of objects manually. Are there any suggestions how to do this? 

 

Thanks a lot in advance.

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
ede_pfau
SuperUser
SuperUser

jinja2 is the way to go. Maybe you could post an example and I'll try to give you a hint.

 

One obstacle is that you cannot directly script on the global or ADOM database. I've worked around that by scripting addresses on a Fortigate, and re-import it's config into the db.

 

 

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors