Haven't really looked at this for a solution, but I have a question, I want to create a Global Header Policy, and push to 10 FortiGates in an ADOM, seems straight forward, apart from I want to create my own normalised interface in the Global ADOM , called "WAN-GLOBAL" and select devices to map there repsective interfaces (some are wan,wan1, port1 etc) but you cant do this.
You can only map interfaces from devices in the ADOM, thats pointless, as I cant then use a normalised interface in the Global Header, as it cant map to anything? is it just a name in the GLOBAL HEADER? as long as its called the same there, and in the ADOM mapped interface?
Solved! Go to Solution.
Hello,
After adding a Normalized Interface to the local ADOM, it needs to be promoted to Global ADOM.
See this document about promoting to Global ADOM.
Once promoted to Global, it can be used in Header and Footer policies. Any mappings on local ADOM should be applied while installing the policies to FortiGate devices.
Thanks,
Just added mappings to the ADOM, but I cant select it in the Global Database for a Firewall Header Policy, that means its pointless mapping anything as it doesnt use the mappings? what am I missing here?
Hello,
After adding a Normalized Interface to the local ADOM, it needs to be promoted to Global ADOM.
See this document about promoting to Global ADOM.
Once promoted to Global, it can be used in Header and Footer policies. Any mappings on local ADOM should be applied while installing the policies to FortiGate devices.
Thanks,
I can see that now! thank you, what does this do though, will the local policy still work if I made changes?
Yes, local policies can use this normalized interface and will work normally. This just makes the interface available in Global DB for use in Global policies.
User | Count |
---|---|
2522 | |
1347 | |
794 | |
639 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.