Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mariano_lavia
New Contributor II

FortiManager is trying to unset all my global-label

After upgrading both FMG and FGT to version 7.6.4, every time I push the policy to the FGT, FMG is removing all my global-label, even if they are correctly set in the "CLI Configuration" window.

Bug or "feature"?Here I set global-labelHere I set global-label

image.png

6 REPLIES 6
asrour
Staff
Staff

what was the previous version of Fortigate before update?

A Srour
mariano_lavia

It was 7.6.3

rukalmu2
New Contributor

You cannot have objects with the same name in global as in adom. That's why we add a "g" before any object created in the global db. If you've promoted all of your objects to global with the same names, you're going to have a hard time getting this synced. I'd delete all global db objects and re-promote from adom to global and adding a "g" (no, don't use the ") even then it'll be quite challenging. If you know how to script it with postman it could move things forward faster

omegle xender
mariano_lavia

I didn't do any promotion, and I'm working with a single root adom (v7.6).

The "global-label" I'm referring to, is a property of the policy which allows to group and separate policies when you use the "Sequence Grouping View" option on FGT.

Every label is unique, there are no same name objects.

The same configuration was working good on v7.6.3 and the problem happened just after upgrading to v7.6.4, without any change.

asrour
Staff
Staff

hi @rukalmu2 

He means the global-label for the policy itself, after 7.4.x , the global label should be unique for the policy

A Srour
mariano_lavia
New Contributor II

After more testing, the issue is affecting only policies coming from policy blocks.

FMG does not allow to "Add Section" (i.e. global-labels) inside policy blocks, but this way, when you inspect policies on FGT using "Sequence Grouping View", all these policies will appear as "Uncategorized". To workaround this issue, we used "Edit in CLI" option to add a global-label where needed (trick learned in the past from the support).
After upgrading to 7.6.4, all these global-label are not pushed to the FGT, and the old one were removed. I can manually add a global-label from FGT interface, but FMG will remove it on next sync. This is very annoying, as the "Sequence Grouping View" will miss the groups and become useless.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors