Hello,
Fortimanager version : 7.4.7
Fortigate version : 7.4.8
Adom : 7.4
Our fortimanager try to push object who aren't use in Policy package or SDWAN rules
For example :
config vdom
edit SDWAN
config firewall address
edit "ACE-1"
12fc575c-6239-51f0-6d5e-bf3aff5d5940
set subnet 10.10.10.10 255.255.255.255
next
I checked the CLI configurations on FortiManager, and this object does not exist in the database of Fortigate.
Other problem, when i modify a groupe like GRP-FORTIGATE, the adress object is not add in the group when i push. But in GUI of fortimanager, group and entry are good
Best regards,
Killian
Hi @kleberre ,
Kindly check if you have any assigned template to the device which related to the configuration, or else you may tried to perform Retrieve, and check it it still try to install unwanted changes.
The second issue, you may check on the group GRP-FORTIGATE under per-device mapping, you may need to add in the specific FGT that you need to install.
Created on 07-17-2025 12:41 AM Edited on 07-17-2025 12:41 AM
Hello,
I use SD-WAN templates, but I’m not using any of the objects pushed by FortiManager. I have already try to retrieve but no change. Still facing the issue.
I have already checked, and there is no per-device mapping configured.
User | Count |
---|---|
2642 | |
1405 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.