Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Gbarnes619
New Contributor

Fortigate 50B not accepting dstaddr for firewall policy

Hi all, I had to resort to reaching out here as I cannot seem to determine what the problem is. I have set up a firewall object-VIP and am attempting to set up the Firewall Policy but every time I make the entry it does not have my VIP in the dstaddr field of the policy. When I attempted to do it via CLI, it errored out with: commands.c:3952 cmf_query_table_delete() error Command fail. Return code -1 The command I attempted was: config firewall policy edit 11 set dstaddr XXXXX edit 11 set srcintf " wan1" set dstintf " internal" set srcaddr " any" set dstaddr " " set action accept set schedule " always" set service " SSH" set logtraffic enable set nat enable next Can someone explain what is happening and why I can' t set the dstaddr? Thanks in advance, -Greg
17 REPLIES 17
Gbarnes619
New Contributor

config firewall policy (policy) # edit 11 (11) # set dstaddr XXXXX commands.c:3952 cmf_query_table_delete() error Command fail. Return code -1 (11) #
rwpatterson
Valued Contributor III

What' s the firmware version?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Gbarnes619
New Contributor

v4.0,build0496,111108 (MR3 Patch 3)
rwpatterson
Valued Contributor III

Is the VIP name longer than about 16 characters? Does it have spaces embedded within?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Gbarnes619
New Contributor

8 Characters, No spaces.
rwpatterson
Valued Contributor III

The only thing I can think of is corrupt code. Have you tried upgrading to a later more stable version of code? Also, how long has that box been running? A reboot may enable you to make the change if the unit has been stressed for a long time.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Gbarnes619
New Contributor

Box uptime is 269 days. I haven' t upgraded recently no. I' ll try a reboot.
rwpatterson
Valued Contributor III

That would be the easiest thing to try.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors