Is it possible to use an object defined in the Global ADOM / Global Database within an ADOM without that object being referenced by a global policy?
We put all VIPs for a given customer into a VIP group with a predictable name. But there is no function in FMG to map a Global-level VIP group to multiple ADOMs - or some type of wild-card VIP group that automatically contains all VIPs. So I was hoping I could at least re-use the same address/service groups across all ADOMS.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Looks like there is a way, but doesn't actually work in 5.4.1 for me.
In FMG if you go to:
Global > Policy Packages > Assign Selected (in the menu bar)
It will pop up with a window and you have the option to "Assign ALL Objects".
However, it generates errors due to service categorization overlaps:
Device level already has object fw_srv_category:Network Services Device level already has object fw_srv_category:Web Access Device level already has object fw_srv_category:General Device level already has object fw_srv_category:Email
A work-around is to group all of your Global addresses into one master group, then do the same with services. Then create a Footer Policy referencing those two groups, and set the policy to deny traffic. That way you can push all Global objects you care about into whatever ADOMs you want to without affecting traffic.
pls check your FMG global database - object - services, and for mentioned group service, if their name has "g" in front?
Email Access -> gEmail Access
all global object name should have g in front to avoid conflict with local ADOM, except interface, which need to have same name interface at local ADOM
Thanks
Simon
Yep, all of the pre-defined services in Global have the 'g' in front except for "ALL". There is actually an "ALL" and an "gALL".
i see, error is for service category, pls check for global database - CLI only objects (you need to enable it in Tools - Display Options) and then check for firewall - service - category, not sure if object name is OK there?
Thanks
Simon
Yep that was it. I had used the fmpolicy command to clone a bunch of objects from an ADOM into Global, which included the built-in services and service categories. After checking the CLI-Only Objects under Global I was able to purge those categories and it worked.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.