Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ZafirFX
New Contributor

FortiManager policy package

Dear users,

 

Just a question. Yesterday I have set up the Fortimanager and imported some Fortigates into it. 

All went well except the policy packages. All of them have status modified. 

 

I know I can push the policy back to the FortiGate to get it in sync but I'm afraid that it will broke something

Is there a quick way to fix that? How would you fix the modified packages to get them in sync

1 Solution
Debbie_FTNT
Staff
Staff

Hey ZafirFX,

the policy package is likely showing modified because you imported multiple FortiGates.

The logic is roughly as follows:
- import first FGT, create a slew of objects and a policy package

- import second FGT, including its objects

-> some of those objects already exist from import of the first FortiGate, and will be modified (changed to dynamic/have some definitions updated/etc)

-> if ANY of the modified objects is used in the first policy package, that package is displayed as modified

You can start the Installation Wizard, and then instead of installing, click on the Installation Preview (depending on firmware it's a table/log icon or an actual Preview button).

Check that for what changes FMG wants to push to the FortiGate(s).

-> if this is the first installation, a large number of objects will be deleted; this is expected as any unused objects will be removed, as Toshi mentioned before

-> pay attention to the interfaces, policies and routing, that they don't get touched

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++

View solution in original post

3 REPLIES 3
Toshi_Esumi
Esteemed Contributor III

I don't know how you created the policy packages for multiple FGTs. But at least you can see what would change, or not change, when you try re-installing the policy package by checking Instrall Preview. Then you can back off if anything might break and troubleshoot.
With my experience, sometimes it might try removing unused objects or something not at the time it synced up but later.

 

Toshi

Debbie_FTNT
Staff
Staff

Hey ZafirFX,

the policy package is likely showing modified because you imported multiple FortiGates.

The logic is roughly as follows:
- import first FGT, create a slew of objects and a policy package

- import second FGT, including its objects

-> some of those objects already exist from import of the first FortiGate, and will be modified (changed to dynamic/have some definitions updated/etc)

-> if ANY of the modified objects is used in the first policy package, that package is displayed as modified

You can start the Installation Wizard, and then instead of installing, click on the Installation Preview (depending on firmware it's a table/log icon or an actual Preview button).

Check that for what changes FMG wants to push to the FortiGate(s).

-> if this is the first installation, a large number of objects will be deleted; this is expected as any unused objects will be removed, as Toshi mentioned before

-> pay attention to the interfaces, policies and routing, that they don't get touched

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
ZafirFX

That was it. I'm using the same object name on all devices. On one of them had the binding to the different interface than on all other devices. When I imported the last one FGT the object get updated with the binding and all of the FGT's got Modified. Now it's solved

Labels
Top Kudoed Authors