Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kenny_loves_Nascar
New Contributor

FortiManager doesn't understand local-in policies on SD-WAN zone

Fortinet changed the way local-in-policies are created when an interface is part of an SD-WAN zone. From 7.4.6 and 7.6.1, the local-in policy is assigned to the SD-WAN zone instead of the interface as explained in the article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Local-in-Policy-is-Missing-after-upgrading...

 

This is great, however I'm dealing with issues now when I change these local-in-policies on the FortiManager. We run FortiManager 7.4.6. FortiManager 7.4.6 appears to not understand this new behaviour. I get a warning that I can't assign a local-in-policy to an SD-WAN zone when I create a local-in-policy in a policy package that's only assigned to firewalls that run FortiOS 7.4.6. That's quite annoying when you manage all your local-in-policies from the FortiManager. Is this intended behaviour in FortiOS 7.4.6 and if so, is there a fix on the way to bring this in line with FortiOS 7.4.6?

1 Solution
dingjerry_FTNT

Hi @Jeremy5385 ,

 

This is a bug. You may try with CLI template/Script as a workaround.

Regards,

Jerry

View solution in original post

13 REPLIES 13
PoEHub
New Contributor

It seems like you're encountering a compatibility issue between FortiManager 7.4.6 and FortiOS 7.4.6 regarding local-in policies on SD-WAN zones. This new method of assigning local-in-policies to SD-WAN zones is supported in FortiOS 7.4.6 and higher, but FortiManager 7.4.6 doesn't fully support this behavior yet. This could indeed be an unintended limitation in the current FortiManager version. I recommend reaching out to Fortinet support to confirm if a patch or update is on the way that will resolve this issue and bring FortiManager in line with the new FortiOS functionality.

dingjerry_FTNT

Hi @Kenny_loves_Nascar ,

 

This is a bug and we have an existing Mantis 1110780 for this bug.  The Fix schedule is set to FMG 7.4.7.

Regards,

Jerry
Jeremy5385
New Contributor II

I'm running into the same thing with upgrading a FGT to 7.4.6 and using FMG 7.6.2.  The FGT errors on receiving pushes with the individual ports (that are in SDWAN) to local-in polices, and FMG errors on pushing local-in policies that have SDWAN zones.  Frustrating.  I have opened a Support ticket for resolution and have not heard back yet.

dingjerry_FTNT

Hi @Jeremy5385 ,

 

This is a bug. You may try with CLI template/Script as a workaround.

Regards,

Jerry
Jeremy5385

Thanks!  I figured I was going to have to manually add my local-in polices using CLI (and the dependencies) for the time being.  With FMG pushing at a standstill, is there going to be a fast resolution as everything going forward is going to be having to be manually implemented as to not delete the manual config?  

dingjerry_FTNT

Unfortunately, I am afraid that there is no such a fast resolution.

Regards,

Jerry
Toshi_Esumi

I'm not sure with 7.4 FMG's behaviors. But if you remove the local-in-policy completely from a policy-package while the local-in-policy config is in device config DB, it wouldn't delete the existing local-in-policy from the DB or the device. It would change only UUID when you applied the modified policy package without local-in-policy.
You can always set up a CLI template/template group for the local-in-policy to make sure it's still "in sync". I just tested it with 7.2.8.

Toshi

Jeremy5385

With the FGT (7.4.6) having the local-in config (manually applied) and FMG not having this unit assigned to any local-in polices in Policies & Objects, they get removed on the next push, unless you're specifically referring to only pushing device config and not policy packages going forward.  In my circumstance with FMG 7.6.2, using the CLI Template does not work as the same checks are completed on the template, giving errors on pushing as tried with Support.

Toshi_Esumi

I pushed the modified policy package specifically. I guess that's the difference when we upgrade our FMG to 7.4.x, which I need to look into when we upgrade ours next year.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors