Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kenny_loves_Nascar
New Contributor

FortiManager doesn't understand local-in policies on SD-WAN zone

Fortinet changed the way local-in-policies are created when an interface is part of an SD-WAN zone. From 7.4.6 and 7.6.1, the local-in policy is assigned to the SD-WAN zone instead of the interface as explained in the article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Local-in-Policy-is-Missing-after-upgrading...

 

This is great, however I'm dealing with issues now when I change these local-in-policies on the FortiManager. We run FortiManager 7.4.6. FortiManager 7.4.6 appears to not understand this new behaviour. I get a warning that I can't assign a local-in-policy to an SD-WAN zone when I create a local-in-policy in a policy package that's only assigned to firewalls that run FortiOS 7.4.6. That's quite annoying when you manage all your local-in-policies from the FortiManager. Is this intended behaviour in FortiOS 7.4.6 and if so, is there a fix on the way to bring this in line with FortiOS 7.4.6?

1 Solution
dingjerry_FTNT

Hi @Jeremy5385 ,

 

This is a bug. You may try with CLI template/Script as a workaround.

Regards,

Jerry

View solution in original post

13 REPLIES 13
Kenny_loves_Nascar

I've built a CLI template and assigned that to the FortiGate that runs 7.4.6. This works from FortiManager 7.4.6.

Jeremy5385

@dingjerry_FTNT  -  As reported by others with FMG 7.4, yes.  But this doesn't work with FMG 7.6.2 (#10230936 as tried). 

dingjerry_FTNT

Hi @Jeremy5385 ,

 

This bug is in FMG 7.4 and 7.6 trains.  The Fix Schedule is set to FMG 7.4.7 and 7.6.3.

Regards,

Jerry
HekateSwitch
New Contributor

To resolve the issue of FortiManager not recognizing local-in policies on SD-WAN zones, ensure correct SD-WAN zone configuration, properly apply local-in policies to the SD-WAN interface, and verify firmware compatibility. Also, check for any policy sync issues and review logs for error details.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors