Hi All,
We have a remote client VPN defined and have users authenticating against a local user group.
When adding local users to this user-group on the Fortimanager it shows that there is nothing to push down to the Fortigate.
As this user-group is just tied to the VPN it is not part of a policy. Is the only way around this by making a dummy policy with this user-group defined? as when its not part of a policy it doesn't push anything down, please can anyone confirm why this is the case?
Thanks,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
sounds very familiar, FortiManager after all these years doesn't always pick up on things which aren't tied to the more regular stuff like policies.
for sure also create a support ticket for this, it might be solved in newer versions and else at least a bug is created for it.
In this case I think the "problem" is that the VPN itself is device config while the usergroup is part of the policy package. The VPN is referencing the usergroup but FMG does not consider this in the policy package. So it sees the usergroup as unused in the policy package and does not deploy the changes.
The bug indeed is that FMG does not count crossreferences from device config to objects in policy package and mark the object in policy package as "in use".
As a workaround I created some dummy policy that don't harm anyone but use the usergroup so that is now in use ;)
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1670 | |
1082 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.