Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TheOnlyJames
New Contributor III

Fortimanager Normalised Interface

Haven't really looked at this for a solution, but I have a question, I want to create a Global Header Policy, and push to 10 FortiGates in an ADOM,  seems straight forward, apart from I want to create my own normalised interface in the Global ADOM , called "WAN-GLOBAL"  and select devices to map there repsective interfaces (some are wan,wan1, port1 etc)  but you cant do this. 

 

You can only map interfaces from devices in the ADOM, thats pointless, as I cant then use a normalised interface in the Global Header, as it cant map to anything?  is it just a name in the GLOBAL HEADER? as long as its called the same there, and in the ADOM mapped interface?

1 Solution
singhl
Staff
Staff

Hello,

After adding a Normalized Interface to the local ADOM, it needs to be promoted to Global ADOM.
See this document about promoting to Global ADOM.
Once promoted to Global, it can be used in Header and Footer policies. Any mappings on local ADOM should be applied while installing the policies to FortiGate devices.

 

Thanks,

Lovepreet Singh

View solution in original post

4 REPLIES 4
TheOnlyJames
New Contributor III

Just added mappings to the ADOM, but I cant select it in the Global Database for a Firewall Header Policy, that means its pointless mapping anything as it doesnt use the mappings? what am I missing here?

 

singhl
Staff
Staff

Hello,

After adding a Normalized Interface to the local ADOM, it needs to be promoted to Global ADOM.
See this document about promoting to Global ADOM.
Once promoted to Global, it can be used in Header and Footer policies. Any mappings on local ADOM should be applied while installing the policies to FortiGate devices.

 

Thanks,

Lovepreet Singh
TheOnlyJames
New Contributor III

I can see that now! thank you, what does this do though, will the local policy still work if I made changes?

singhl
Staff
Staff

Yes, local policies can use this normalized interface and will work normally. This just makes the interface available in Global DB for use in Global policies.

Lovepreet Singh
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors